On Defending against Label Flipping Poisoning Attack for Personalized Federated Learning
Journal
2025 International Wireless Communications and Mobile Computing (IWCMC)
Start Page
1041-1046
Date Issued
2025-05-12
Author(s)
Abstract
Personalized Federated Learning (PFL) enhances traditional Federated Learning (FL) by addressing the challenges associated with non-independent and identically distributed (non-IID) data and retains FL��s privacy-preserving feature. However, this decentralized architecture still presents security challenges. This study focuses on data poisoning attacks, particularly label flipping attacks in PFL, where some malicious clients upload poisoned model parameters to the server, which could then compromise the personalized models of honest clients during the server��s aggregation process. Moreover, we discovered that even with a small number of attackers, targeted data poisoning attacks are feasible and can significantly affect the model��s performance on specific labels. Finally, we propose four defensive strategies that have proven effective in identifying malicious clients. Additionally, we provide a framework that assists users in selecting the most suitable defense strategy based on their specific circumstances, thereby enhancing the robustness of the PFL architecture.
Publisher
IEEE
Type
conference paper
