IEEE Access (Jan 2023)

Poisoning Attacks in Federated Learning: A Survey

  • Geming Xia,
  • Jian Chen,
  • Chaodong Yu,
  • Jun Ma

DOI
https://doi.org/10.1109/ACCESS.2023.3238823
Journal volume & issue
Vol. 11
pp. 10708 – 10722

Abstract

Read online

Federated learning faces many security and privacy issues. Among them, poisoning attacks can significantly impact global models, and malicious attackers can prevent global models from converging or even manipulating the prediction results of global models. Defending against poisoning attacks is a very urgent and challenging task. However, the systematic reviews of poisoning attacks and their corresponding defense strategies from a privacy-preserving perspective still need more effort. This survey provides an in-depth and up-to-date overview of poisoning attacks and corresponding defense strategies in federated learning. We first classify the poisoning attacks according to their methods and targets. Next, we analyze the differences and connections between the various categories of poisoning attacks. In addition, we classify the defense strategies against poisoning attacks in federated learning into three categories and analyze their advantages and disadvantages. Finally, we discuss the privacy protection problem in poisoning attacks and their countermeasure and propose potential research directions from the perspective of attack and defense, respectively.

Keywords