Journal of Computer Applications ›› 2024, Vol. 44 ›› Issue (6): 1663-1672.DOI: 10.11772/j.issn.1001-9081.2023060832

Special Issue: 综述 CCF第38届中国计算机应用大会 (CCF NCCA 2023)

• The 38th CCF National Conference of Computer Applications (CCF NCCA 2023) • Previous Articles     Next Articles

Review on security threats and defense measures in federated learning

Xuebin CHEN1,2,3, Zhiqiang REN1,2,3(), Hongyang ZHANG1,2,3   

  1. 1.College of Sciences,North China University of Science and Technology,Tangshan Hebei 063210,China
    2.Hebei Provincial Key Laboratory of Data Science and Application (North China University of Science and Technology),Tangshan Hebei 063210,China
    3.Tangshan Data Science Key Laboratory (North China University of Science and Technology),Tangshan Hebei 063210,China
  • Received:2023-07-04 Revised:2023-07-15 Accepted:2023-07-25 Online:2023-08-03 Published:2024-06-10
  • Contact: Zhiqiang REN
  • About author:CHEN Xuebin, born in 1970, Ph. D., professor. His research interests include big data security, IoT security, network security.
    ZHANG Hongyang, born in 1999, M. S. candidate. His research interests include data security, privacy protection.
  • Supported by:
    National Natural Science Foundation of China(U20A20179)


Federated learning is a distributed learning approach for solving the data sharing problem and privacy protection problem in machine learning, in which multiple parties jointly train a machine learning model and protect the privacy of data. However, there are security threats inherent in federated learning, which makes federated learning face great challenges in practical applications. Therefore, analyzing the attacks faced by federation learning and the corresponding defensive measures are crucial for the development and application of federation learning. First, the definition, process and classification of federated learning were introduced, and the attacker model in federated learning was introduced. Then, the possible attacks in terms of both robustness and privacy of federated learning systems were introduced, and the corresponding defense measures were introduced as well. Furthermore, the shortcomings of the defense schemes were also pointed out. Finally, a secure federated learning system was envisioned.

Key words: federated learning, privacy protection, attack and defense, machine learning, robustness and privacy



