Cybersecurity in Decentralized Machine Learning for Battery Management Systems: Threats, Detection, and Defense
Hämtar...
Ladda ner
Publicerad
Författare
Typ
Examensarbete för masterexamen
Master's Thesis
Master's Thesis
Modellbyggare
Tidskriftstitel
ISSN
Volymtitel
Utgivare
Sammanfattning
Federated Learning (FL) enables distributed devices to collaboratively train machine learning models without sharing raw data, making it suitable for Battery
Management Systems (BMSs) that estimate battery State of Health (SOH). However, FL remains vulnerable to attacks such as poisoning attacks in which malicious
participants manipulate local training or model updates to influence the learned
model.
This thesis investigates the security of decentralized battery health prediction systems implemented using the FEDn framework and an Adaptive Iterative Clustered
Federated Learning (AICFL) architecture. A controlled experimental environment
was developed to evaluate the impact of poisoning attacks on both traditional FL
and clustered FL. Three attack categories were implemented and analyzed: model
poisoning, stealth-oriented poisoning, and targeted backdoor attacks.
To support attack analysis, a server-side suspicious-client risk scoring mechanism
was developed to identify anomalous client behavior based on model update characteristics collected during training. Experimental results compare the effectiveness
of attacks in FL and AICFL environments and examine how clustering influences
attack propagation and model robustness.
Experimental results show that poisoning attacks can significantly affect model behavior in both FL and AICFL environments. The impact varies across attack types,
while the clustered architecture influences how malicious updates propagate through
the federation. The proposed risk-scoring mechanism was able to identify clients exhibiting suspicious update patterns during training.
The findings provide insights into the security challenges of clustered federated learning systems for battery management applications and contribute practical methods
for analyzing malicious behavior in decentralized AI systems.
Beskrivning
Ämne/nyckelord
Federated Learning, scaleout-Cognivity, Cybersecurity, BMS, Machine learning, Decentralized
