跳到主要导航 跳到搜索 跳到主要内容

FLock: Robust and Privacy-Preserving Federated Learning based on Practical Blockchain State Channels

  • Ruonan Chen
  • , Ye Dong
  • , Yizhong Liu*
  • , Tingyu Fan
  • , Dawei Li*
  • , Zhenyu Guan
  • , Jianwei Liu*
  • , Jianying Zhou
  • *此作品的通讯作者
  • Beihang University
  • Singapore University of Technology and Design
  • CAS - Institute of Information Engineering

科研成果: 书/报告/会议事项章节会议稿件同行评审

摘要

Federated Learning (FL) is a distributed machine learning paradigm that allows multiple clients to train models collaboratively without sharing local data. Numerous works have explored security and privacy protection in FL, as well as its integration with blockchain technology. However, existing FL works still face critical issues. i) It is difficult to achieving poisoning robustness and data privacy while ensuring high model accuracy. Malicious clients can launch poisoning attacks that degrade the global model. Besides, aggregators can infer private data from the gradients, causing privacy leakages. Existing privacy-preserving poisoning defense FL solutions suffer from decreased model accuracy and high computational overhead. ii) Blockchain-assisted FL records iterative gradient updates on-chain to prevent model tampering, yet existing schemes are not compatible with practical blockchains and incur high costs for maintaining the gradients on-chain. Besides, incentives are overlooked, where unfair reward distribution hinders the sustainable development of the FL community. In this work, we propose FLock, a robust and privacy-preserving FL scheme based on practical blockchain state channels. First, we propose a lightweight secure Multi-party Computation (MPC)-friendly robust aggregation method through quantization, median, and Hamming distance, which could resist poisoning attacks against up to < 50% malicious clients. Besides, we propose communication-efficient Shamir’s secret sharing-based MPC protocols to protect data privacy with high model accuracy. Second, we utilize blockchain off-chain state channels to achieve immutable model records and incentive distribution. FLock achieves cost-effective compatibility with practical cryptocurrency platforms, e.g. Ethereum, along with fair incentives, by merging the secure aggregation into a multi-party state channel. In addition, a pipelined Byzantine Fault-Tolerant (BFT) consensus is integrated where each aggregator can reconstruct the final aggregated results. Lastly, we implement FLock and the evaluation results demonstrate that FLock enhances robustness and privacy, while maintaining efficiency and high model accuracy. Even with 25 aggregators and 100 clients, FLock can complete one secure aggregation for ResNet in 2 minutes over a WAN. FLock successfully implements secure aggregation with such a large number of aggregators, thereby enhancing the fault tolerance of the aggregation.

源语言英语
主期刊名WWW 2025 - Proceedings of the ACM Web Conference
出版商Association for Computing Machinery, Inc
884-895
页数12
ISBN(电子版)9798400712746
DOI
出版状态已出版 - 28 4月 2025
活动34th ACM Web Conference, WWW 2025 - Sydney, 澳大利亚
期限: 28 4月 20252 5月 2025

出版系列

姓名WWW 2025 - Proceedings of the ACM Web Conference

会议

会议34th ACM Web Conference, WWW 2025
国家/地区澳大利亚
Sydney
时期28/04/252/05/25

学术指纹

探究 'FLock: Robust and Privacy-Preserving Federated Learning based on Practical Blockchain State Channels' 的科研主题。它们共同构成独一无二的学术指纹。

引用此