Algoritmo para Detecção e Mitigação de Ataques de Inversão de Rótulos no Aprendizado Federado
Resumo
O Aprendizado Federado (FL) permite treinar modelos de aprendizado de máquina de forma distribuída, preservando a privacidade dos dados. No entanto, ataques como o label-flipping podem comprometer o desempenho do modelo global. Este artigo tem como objetivo principal avaliar os impactos desse ataque em cenários com privacidade diferencial (DP) e compactação de modelos baseada em FedSketch, além de desenvolver e avaliar um método de detecção de clientes mal-intencionados para aumentar a robustez do treinamento.Referências
Dwork, C. (2006). Differential privacy. In Bugliesi, M., Preneel, B., Sassone, V., and Wegener, I., editors, Automata, Languages and Programming, pages 1–12, Berlin, Heidelberg. Springer Berlin Heidelberg.
Elmahfoud, E., Hajla, S. E., Maleh, Y., Mounir, S., and Ouazzane, K. (2025). Label flipping attacks in hierarchical federated learning for intrusion detection in iot. Information Security Journal: A Global Perspective, 34(4):310–326.
Geiping, J., Bauermeister, H., Dröge, H., and Moeller, M. (2020). Inverting gradients - how easy is it to break privacy in federated learning? In Proceedings of the 34th International Conference on Neural Information Processing Systems, NIPS ’20, Red Hook, NY, USA. Curran Associates Inc.
Jebreel, N. M., Domingo-Ferrer, J., Sánchez, D., and Blanco-Justicia, A. (2024). Lfighter: Defending against the label-flipping attack in federated learning. Neural Netw., 170(C):111–126.
Korkmaz, A., Alhonainy, A., and Rao, P. (2022). An Evaluation of Federated Learning Techniques for Secure and Privacy-Preserving Machine Learning on Medical Datasets . In 2022 IEEE Applied Imagery Pattern Recognition Workshop (AIPR), pages 1–7, Los Alamitos, CA, USA. IEEE Computer Society.
Mammen, P. M. (2021). Federated learning: Opportunities and challenges.
McMahan, B., Moore, E., Ramage, D., Hampson, S., and Arcas, B. A. y. (2017). Communication-Efficient Learning of Deep Networks from Decentralized Data. In Singh, A. and Zhu, J., editors, Proceedings of the 20th International Conference on Artificial Intelligence and Statistics, volume 54 of Proceedings of Machine Learning Research, pages 1273–1282. PMLR.
Sarmento, E., Mota, V., and Villaça, R. (2024). Privacidade e comunicação eficiente em aprendizado federado: Uma abordagem utilizando estruturas de dados probabilísticas e seleção de clientes. In Anais do XLII Simpósio Brasileiro de Redes de Computadores e Sistemas Distribuídos, pages 85–98, Porto Alegre, RS, Brasil. SBC.
Shen, X., Liu, Y., Li, F., and Li, C. (2024). Privacy-preserving federated learning against label-flipping attacks on non-iid data. IEEE Internet of Things Journal, 11(1):1241–1255.
Shokri, R., Stronati, M., Song, C., and Shmatikov, V. (2017). Membership Inference Attacks Against Machine Learning Models . In 2017 IEEE Symposium on Security and Privacy (SP), pages 3–18, Los Alamitos, CA, USA. IEEE Computer Society.
Souza, A., Bittencourt, L., Cerqueira, E., Loureiro, A., and Villas, L. (2023). Dispositivos, eu escolho vocês: Seleção de clientes adaptativa para comunicação eficiente em aprendizado federado. In Anais do XLI Simpósio Brasileiro de Redes de Computadores e Sistemas Distribuídos, pages 1–14, Porto Alegre, RS, Brasil. SBC.
Wang, T., Zheng, Z., and Lin, F. (2025). Federated learning framework based on trimmed mean aggregation rules. Expert Systems with Applications, 270:126354.
Zhao, B., Mopuri, K. R., and Bilen, H. (2020). idlg: Improved deep leakage from gradients.
Elmahfoud, E., Hajla, S. E., Maleh, Y., Mounir, S., and Ouazzane, K. (2025). Label flipping attacks in hierarchical federated learning for intrusion detection in iot. Information Security Journal: A Global Perspective, 34(4):310–326.
Geiping, J., Bauermeister, H., Dröge, H., and Moeller, M. (2020). Inverting gradients - how easy is it to break privacy in federated learning? In Proceedings of the 34th International Conference on Neural Information Processing Systems, NIPS ’20, Red Hook, NY, USA. Curran Associates Inc.
Jebreel, N. M., Domingo-Ferrer, J., Sánchez, D., and Blanco-Justicia, A. (2024). Lfighter: Defending against the label-flipping attack in federated learning. Neural Netw., 170(C):111–126.
Korkmaz, A., Alhonainy, A., and Rao, P. (2022). An Evaluation of Federated Learning Techniques for Secure and Privacy-Preserving Machine Learning on Medical Datasets . In 2022 IEEE Applied Imagery Pattern Recognition Workshop (AIPR), pages 1–7, Los Alamitos, CA, USA. IEEE Computer Society.
Mammen, P. M. (2021). Federated learning: Opportunities and challenges.
McMahan, B., Moore, E., Ramage, D., Hampson, S., and Arcas, B. A. y. (2017). Communication-Efficient Learning of Deep Networks from Decentralized Data. In Singh, A. and Zhu, J., editors, Proceedings of the 20th International Conference on Artificial Intelligence and Statistics, volume 54 of Proceedings of Machine Learning Research, pages 1273–1282. PMLR.
Sarmento, E., Mota, V., and Villaça, R. (2024). Privacidade e comunicação eficiente em aprendizado federado: Uma abordagem utilizando estruturas de dados probabilísticas e seleção de clientes. In Anais do XLII Simpósio Brasileiro de Redes de Computadores e Sistemas Distribuídos, pages 85–98, Porto Alegre, RS, Brasil. SBC.
Shen, X., Liu, Y., Li, F., and Li, C. (2024). Privacy-preserving federated learning against label-flipping attacks on non-iid data. IEEE Internet of Things Journal, 11(1):1241–1255.
Shokri, R., Stronati, M., Song, C., and Shmatikov, V. (2017). Membership Inference Attacks Against Machine Learning Models . In 2017 IEEE Symposium on Security and Privacy (SP), pages 3–18, Los Alamitos, CA, USA. IEEE Computer Society.
Souza, A., Bittencourt, L., Cerqueira, E., Loureiro, A., and Villas, L. (2023). Dispositivos, eu escolho vocês: Seleção de clientes adaptativa para comunicação eficiente em aprendizado federado. In Anais do XLI Simpósio Brasileiro de Redes de Computadores e Sistemas Distribuídos, pages 1–14, Porto Alegre, RS, Brasil. SBC.
Wang, T., Zheng, Z., and Lin, F. (2025). Federated learning framework based on trimmed mean aggregation rules. Expert Systems with Applications, 270:126354.
Zhao, B., Mopuri, K. R., and Bilen, H. (2020). idlg: Improved deep leakage from gradients.
Publicado
01/09/2026
Como Citar
BATISTA, João Pedro Camargo; VILLAÇA, Rodolfo S..
Algoritmo para Detecção e Mitigação de Ataques de Inversão de Rótulos no Aprendizado Federado. In: WORKSHOP DE TRABALHOS DE INICIAÇÃO CIENTÍFICA E DE GRADUAÇÃO - SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ.
Anais [...].
Porto Alegre: Sociedade Brasileira de Computação,
2026
.
p. 346-357.
DOI: https://doi.org/10.5753/sbseg_estendido.2026.29860.
