FedRACE: A Hierarchical and Statistical Framework for Robust Federated Learning
Gang Yan, Sikai Yang, Wan Du
Abstract
Integrating large pre-trained models into federated learning (FL) can significantly improve generalization and convergence efficiency. A widely adopted strategy freezes the pre-trained backbone and fine-tunes a lightweight task head, thereby reducing computational and communication costs. However, this partial fine-tuning paradigm introduces new security risks, making the system vulnerable to poisoned updates and backdoor attacks. To address these challenges, we propose FEDRACE, a unified framework for robust FL with partially frozen models. FEDRACE comprises two core components: HStat-Net, a hierarchical network that refines frozen features into compact, linearly separable representations; and DevGuard, a serverside mechanism that detects malicious clients by evaluating statistical deviance in class-level predictions modeling generalized linear models (GLMs). DevGuard further incorporates adaptive thresholding based on theoretical misclassification bounds and employs randomized majority voting to enhance detection reliability. We implement FEDRACE on the FedScale platform and evaluate it on CIFAR-100, Food-101, and Tiny ImageNet under diverse attack scenarios. FEDRACE achieves a true positive rate of up to 99.3% with a false positive rate below 1.2%, while preserving model accuracy and improving generalization.
Existing defenses such as Trimmed-Mean [19], Multi-Krum [20], and reputation-based methods like FLShield [21] and FLAIR [22] often rely on gradient statistics or fixed heuristics. While these methods are effective in some settings, they struggle to detect subtle semantic manipulations, especially when only the head is trainable [23,24]. These limitations raise a key research question: How can we integrate large pre-trained models into FL while enabling reliable and adaptive detection of malicious clients?
To answer this question, we propose FEDRACE, a unified framework for Federated Representationbased Adaptive Client Evaluation. FEDRACE combines hierarchical representation learning with statistical client evaluation to improve FL robustness. It consists of two main components: (1) HStat-Net, a Hierarchical Statistical Network that transforms fixed features into compact and linearly separable representations using a triplet loss, and (2) DevGuard, a server-side evaluation mechanism that uses a generalized linear model (GLM) to identify clients with abnormal semantic behavior through deviance analysis.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on22
- Learning Transferable Visual Models From Natural Language SupervisionAlec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh et al.ICML 2021 · 47,906 citations
- An Image is Worth 16x16 Words: Transformers for Image Recognition at ScaleAlexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn et al.ICLR 2021 · 21,477 citations
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Manipulating Machine Learning: Poisoning Attacks and Countermeasures for Regression LearningMatthew Jagielski, Alina Oprea, Battista Biggio, Chang Liu et al.S&P 2018 · 867 citations
- Attack of the Tails: Yes, You Really Can Backdoor Federated LearningHongyi Wang, Kartik Sreenivasan, Shashank Rajput, Harit Vishwakarma et al.NeurIPS 2020 · 862 citations
Related papers
- Every Vote Counts: Ranking-Based Training of Federated Learning to Resist Poisoning AttacksHamid Mozaffari, Virat Shejwalkar, Amir HoumansadrUSENIX Security 2023
- RobFL: Robust Federated Learning via Feature Center Separation and Malicious Center DetectionTing Zhou, Ning Liu, Bo Song, Hongtao Lv et al.ICDE 2024 · 3 citations
- MESAS: Poisoning Defense for Federated Learning Resilient against Adaptive AttackersTorsten Krauß, Alexandra DmitrienkoCCS 2023 · 20 citations
- 3DFed: Adaptive and Extensible Framework for Covert Backdoor Attack in Federated LearningHaoyang Li, Qingqing Ye, Haibo Hu, Jin Li et al.S&P 2023
- FedRoLA: Robust Federated Learning Against Model Poisoning via Layer-based AggregationGang Yan, Hao Wang, Xu Yuan, Jian LiKDD 2024 · 6 citations
