Repository logo

Cluster-based scoring for malicious model detection in federated learning

dc.contributorGraduate program in Computer Engineering.
dc.contributor.advisorYurdakul, Arda.
dc.contributor.authorÇağlayan, Cem.
dc.date.accessioned2025-04-14T12:09:54Z
dc.date.available2025-04-14T12:09:54Z
dc.date.issued2023
dc.description.abstractFederated learning is a distributed machine learning technique aggregating every client model on a server to obtain a global model. However, some clients may harm the system by poisoning their model or data to make the global model irrelevant to its objective. This thesis introduces an approach for the server to detect adversarial models by coordinate-based statistical comparison and eliminate them from the system prior to aggregation. A new attack type, layer poisoning, where the malicious nodes prefer poisoning selected small size layers of the model to deceive the detection system, is also introduced. Adaptive thresholding is adopted for preserving the robustness of the detection mechanism for various network against different attack types. A simulation framework is developed to benchmark and realize tests as a distributed system. Experiments that use random sampling of independent and identically distributed (iid) datasets with different batch sizes have been carried out to show that the proposed method can identify the malicious nodes successfully even if some of the clients learn slower than others or send quantized model weights due to energy limitations. The proposed approach is extensively tested with malicious-benign client ratios, model types, and datasets to present its versatility. The results show that the proposed system successfully eliminates the malicious models when their generating clients constitute at most 45% of the network. Comparison with the approaches from the literature shows that the proposed method performs the same as or better than the state of art solutions.
dc.format.pagesxiii, 54 leaves
dc.identifier.otherGraduate program in Computer Engineering. TKL 2023 U68 PhD (Thes SOC 2023 S37
dc.identifier.urihttps://hdl.handle.net/20.500.14908/21514
dc.publisherThesis (M.S.) - Bogazici University. Institute for Graduate Studies in Science and Engineering, 2023.
dc.subject.lcshComputer communication systems.
dc.subject.lcshSoftware engineering.
dc.subject.lcshMachine learning.
dc.titleCluster-based scoring for malicious model detection in federated learning

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
b2795930.038505.001.PDF
Size:
7 MB
Format:
Adobe Portable Document Format

Collections