IP Library Granted Patent US 12,353,604
Granted Patent B2
US 12,353,604 · App. 17/937,842 · Granted Jul 8, 2025

Detecting client isolation attacks in federated learning through overfitting monitoring

Inventors: Maira Beatriz Hernandez Moran (Rio de Janeiro, BR); Paulo Abelha Ferreira (Rio de Janeiro, BR); Pablo Nascimento da Silva (Niterói, BR)
Assignee: Dell Products L.P.
G06F21/64G06N20/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,353,604
App. No.
17/937,842
Granted
Jul 8, 2025
Kind
B2
Abstract

One example method includes receiving at a client node of a federation a global machine-learning model that is to be trained by the client node using a training dataset that is local to the client node. In response to receiving the global machine-learning model, determining at the client node if the global machine-learning model is trending toward an overfitted state using a validation dataset. The overfitted state indicates that the global machine-learning model has not been received from a server that is part of the federation because of a client isolation attack. In response to determining that the global machine-learning model is trending towards the overfitting state, causing the client node to leave the federation. In response to determining that the global machine-learning model is not trending towards the overfitted state, training the global machine-learning model using the training dataset to thereby update the global machine-learning model.

Claims (38)

1. A method, comprising:

receiving at a client node of a federation a global machine-learning model that is to be trained by the client node using a training dataset that is local to the client node;

in response to receiving the global machine-learning model, determining at the client node if the global machine-learning model is trending toward an overfitted state using a validation dataset, the validation dataset being a subset of data local to the client node that is not included in the training dataset, the overfitted state being indicative that the global machine-learning model has not been received from a server that is part of the federation because of a client isolation attack on the client node, wherein determining if the global machine-learning model is trending toward an overfitted state using the validation dataset comprises:

determining a training error when the global machine-learning model is trained using the training dataset;

determining a validation error when the global machine-learning model is trained using the validation dataset;

comparing the training error to a training error threshold; and

comparing the validation error to a validation error threshold, and it is indicative that the global machine-learning model is in the overfitted state when the training error is above the training error threshold and the validation error is below the validation error threshold;

in response to determining that the global machine-learning model is trending towards the overfitting state, causing the client node to leave the federation; and

in response to determining that the global machine-learning model is not trending towards the overfitted state, training the global machine-learning model using the training dataset to thereby update the global machine-learning model.

2. The method of claim 1 , further comprising:

sending the updated global machine-learning model to the server.

3. The method of claim 1 , wherein the global machine-learning model is received from a malicious party who has intercepted a process flow between the client node and the server during the client isolation attack.

4. The method of claim 3 , wherein leaving the federation comprises causing the client node to interrupt communication with the server and/or the malicious party.

5. The method of claim 1 , further comprising:

generating the training dataset and the validation dataset prior to training the global machine-learning model.

6. The method of claim 5 , wherein generating the training dataset and the validation dataset comprises splitting an overall dataset that is local to the client node into at least the training dataset and the validation dataset.

7. The method of claim 1 , wherein it is indicative that the global machine-learning model is received from the server when the training error is below the training error threshold and the validation error is below the validation error threshold.

8. The method of claim 1 , wherein determining if the global machine-learning model is trending toward an overfitted state using the validation dataset comprises:

using the validation dataset as an input into a validation process that is configured to output a result indicating the overfitted state.

9. A non-transitory storage medium having stored therein instructions that are executable by one or more hardware processors to perform operations comprising:

receiving at a client node of a federation a global machine-learning model that is to be trained by the client node using a training dataset that is local to the client node;

in response to receiving the global machine-learning model, determining at the client node if the global machine-learning model is trending toward an overfitted state using a validation dataset, the validation dataset being a subset of data local to the client node that is not included in the training dataset, the overfitted state being indicative that the global machine-learning model has not been received from a server that is part of the federation because of a client isolation attack on the client node, wherein determining if the global machine-learning model is trending toward an overfitted state using the validation dataset comprises:

determining a training error when the global machine-learning model is trained using the training dataset;

determining a validation error when the global machine-learning model is trained using the validation dataset;

comparing the training error to a training error threshold; and

comparing the validation error to a validation error threshold, and it is indicative that the global machine-learning model is in the overfitted state when the training error is above the training error threshold and the validation error is below the validation error threshold;

in response to determining that the global machine-learning model is trending towards the overfitting state, causing the client node to leave the federation; and

in response to determining that the global machine-learning model is not trending towards the overfitted state, training the global machine-learning model using the training dataset to thereby update the global machine-learning model.

10. The non-transitory storage medium of claim 9 , further comprising the following operation:

sending the updated global machine-learning model to the server.

11. The non-transitory storage medium of claim 9 , wherein the global machine-learning model is received from a malicious party who has intercepted a process flow between the client node and the server during the client isolation attack.

12. The non-transitory storage medium of claim 11 , wherein leaving the federation comprises causing the client node to interrupt communication with the server and/or the malicious party.

13. The non-transitory storage medium of claim 9 , further comprising the following operation:

generating the training dataset and the validation dataset prior to training the global machine-learning model.

14. The non-transitory storage medium of claim 13 , wherein generating the training dataset and the validation dataset comprises splitting an overall dataset that is local to the client node into at least the training dataset and the validation dataset.

15. The non-transitory storage medium of claim 9 , wherein it is indicative that the global machine-learning model is received from the server when the training error is below the training error threshold and the validation error is below the validation error threshold.

16. The non-transitory storage medium of claim 9 , wherein determining if the global machine-learning model is trending toward an overfitted state using the validation dataset comprises:

using the validation dataset as an input into a validation process that is configured to output a result indicating the overfitted state.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 4, 2022
From: MORAN, MAIRA BEATRIZ HERNANDEZ; FERREIRA, PAULO ABELHA; NASCIMENTO DA SILVA, PABLO
To: DELL PRODUCTS L.P.
Reel/Frame 061303/0328 →
Continuity (1)
Related Publication 20240111903A1 · Apr 4, 2024
References Cited (43)
US 10719301B1 · Dasgupta · 2020 [cited by examiner]
US 11556746B1 · Dasgupta · 2023 [cited by examiner]
US 11848828B1 · Talasila · 2023 [cited by examiner]
US 11948297B1 · Cogan · 2024 [cited by examiner]
US 12086053B1 · Cela Diaz · 2024 [cited by examiner]
US 20150193697A1 · Vasseur · 2015 [cited by examiner]
US 20200005133A1 · Zhang · 2020 [cited by examiner]
US 20200349047A1 · Faibish · 2020 [cited by examiner]
US 20200364620A1 · Jordan · 2020 [cited by examiner]
US 20210034947A1 · Wang · 2021 [cited by examiner]
US 20210064760A1 · Sharma · 2021 [cited by examiner]
US 20210248420A1 · Zhong · 2021 [cited by examiner]
US 20210303695A1 · Grosse · 2021 [cited by examiner]
US 20210357508A1 · Elovici · 2021 [cited by examiner]
US 20210398017A1 · Garg · 2021 [cited by examiner]
US 20220075605A1 · Iyer · 2022 [cited by examiner]
US 20220292387A1 · Zhou · 2022 [cited by examiner]
US 20220343219A1 · Takasaki · 2022 [cited by examiner]
US 20230087863A1 · Gong · 2023 [cited by examiner]
US 20230106985A1 · Hu · 2023 [cited by examiner]
US 20230153633A1 · Mohalik · 2023 [cited by examiner]
US 20230177378A1 · Hassan · 2023 [cited by examiner]
US 20230237311A1 · Taghia · 2023 [cited by examiner]
US 20230274004A1 · Kanani · 2023 [cited by examiner]
US 20230334319A1 · Ferreira · 2023 [cited by examiner]
US 20230351049A1 · Annau · 2023 [cited by examiner]
US 20230419172A1 · Ickin · 2023 [cited by examiner]
US 20240006080A1 · Molero Leon · 2024 [cited by examiner]
US 20240012942A1 · Zhou · 2024 [cited by examiner]
US 20240037234A1 · Fraboni · 2024 [cited by examiner]
US 20240054391A1 · Guha Thakurta · 2024 [cited by examiner]
US 20240086700A1 · Kim · 2024 [cited by examiner]
US 20240104438A1 · Sesha · 2024 [cited by examiner]
US 20240119340A1 · Ferreira · 2024 [cited by examiner]
US 20240127114A1 · Reyes · 2024 [cited by examiner]
US 20240256973A1 · Vandikas · 2024 [cited by examiner]
US 20240362501A1 · Nascimento da Silva · 2024 [cited by examiner]
US 20240382288A1 · Jaisson · 2024 [cited by examiner]
Velicheti, Raj Kiriti, Derek Xia, and Oluwasanmi Koyejo. “Secure Byzantine-Robust Distributed Learning via Clustering,” arXiv preprint arXiv:2110.02940 (2021). [cited by applicant]
Blanco-Justicia, Alberto, Domingo-Ferrer, Joseph, Martínez, Sergio, Sánchez, David, Flanagan, Adrian, and Tan, Kuan Eeik. “Achieving Security and Privacy in Federated Learning Systems: Survey, Research Challenges and Fu… [cited by applicant]
Rodríguez-Barroso, Nuria, et al. “Survey on Federated Learning Threats: concepts, taxonomy on attacks and defences, experimental study and challenges,” arXiv preprint arXiv:2201.08135 (2022). [cited by applicant]
Yeom, Samuel, et al. “Privacy Risk in Machine Learning: Analyzing the Connection to Overfitting,” 2018 IEEE 31st Computer Security Foundations Symposium (CSF). IEEE, 2018. [cited by applicant]
McMahan, H. B., et al. “Federated Learning of Deep Networks using Model Averaging,” CoRR abs/1602.05629, arXiv preprint arXiv:1602.05629 (2016). [cited by applicant]
Cited By (1)
US 12,505,382