FLDetector: Defending Federated Learning Against Model Poisoning Attacks via Detecting Malicious Clients
Zaixi Zhang, Xiaoyu Cao, Jinyuan Jia, Neil Zhenqiang Gong
Abstract
Federated learning (FL) is vulnerable to model poisoning attacks, in which malicious clients corrupt the global model via sending manipulated model updates to the server. Existing defenses mainly rely on Byzantine-robust or provably robust FL methods, which aim to learn an accurate global model even if some clients are malicious. However, they can only resist a small number of malicious clients. It is still an open challenge how to defend against model poisoning attacks with a large number of malicious clients. Our FLDetector addresses this challenge via detecting malicious clients. FLDetector aims to detect and remove majority of the malicious clients such that a Byzantine-robust or provably robust FL method can learn an accurate global model using the remaining clients. Our key observation is that, in model poisoning attacks, the model updates from a client in multiple iterations are inconsistent. Therefore, FLDetector detects malicious clients via checking their model-updates consistency. Roughly speaking, the server predicts a client's model update in each iteration based on historical model updates, and flags a client as malicious if the received model update from the client and the predicted model update are inconsistent in multiple iterations. Our extensive experiments on three benchmark datasets show that FLDetector can accurately detect malicious clients in multiple state-of-the-art model poisoning attacks and adaptive attacks tailored to FLDetector. After removing the detected malicious clients, existing Byzantine-robust FL methods can learn accurate global models. CCS CONCEPTS • Security and privacy → Intrusion/anomaly detection and malware mitigation; • Computing methodologies → Distributed artificial intelligence.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c5c7cd05-14ff-41d4-afdb-95f04030b9e3Cited by top-tier papers35
- Eliminating Domain Bias for Federated Learning in Representation SpaceJianqing Zhang, Yang Hua, Jian Cao, Hao Wang et al.NeurIPS 2023 · 105 citations
- Untargeted Attack against Federated Recommendation Systems via Poisonous Item Embeddings and the DefenseYang Yu, Qi Liu, Likang Wu, Runlong Yu et al.AAAI 2023 · 73 citations
- Backdoor Federated Learning by Poisoning Backdoor-Critical LayersHaomin Zhuang, Mingxian Yu, Hao Wang, Yang Hua et al.ICLR 2024 · 40 citations
- Byzantine-Robust Decentralized Federated LearningMinghong Fang, Zifan Zhang, Hairi, Prashant Khanduri et al.CCS 2024 · 38 citations
- DeFL: Defending against Model Poisoning Attacks in Federated Learning via Critical Learning Periods AwarenessGang Yan, Hao Wang, Xu Yuan, Jian LiAAAI 2023 · 38 citations
Builds on5
- DBA: Distributed Backdoor Attacks against Federated LearningChulin Xie, Keli Huang, Pin-Yu Chen, Bo LiICLR 2020 · 901 citations
- Provably Secure Federated Learning against Malicious ClientsXiaoyu Cao, Jinyuan Jia, Neil Zhenqiang GongAAAI 2021 · 161 citations
- FLTrust: Byzantine-robust Federated Learning via Trust BootstrappingXiaoyu Cao, Minghong Fang, Jia Liu, Neil Zhenqiang GongNDSS 2021
- Manipulating the Byzantine: Optimizing Model Poisoning Attacks and Defenses for Federated LearningVirat Shejwalkar, Amir HoumansadrNDSS 2021
- Local Model Poisoning Attacks to Byzantine-Robust Federated LearningMinghong Fang, Xiaoyu Cao, Jinyuan Jia, Neil Zhenqiang GongUSENIX Security 2020
Related papers
- FedREDefense: Defending against Model Poisoning Attacks for Federated Learning using Model Update Reconstruction ErrorYueqi Xie, Minghong Fang, Neil Zhenqiang GongICML 2024 · 32 citations
- Model Poisoning Attacks to Federated Learning via Multi-Round ConsistencyYueqi Xie, Minghong Fang, Neil Zhenqiang GongCVPR 2025
- FedInv: Byzantine-Robust Federated Learning by Inversing Local Model UpdatesBo Zhao, Peng Sun, Tao Wang, Keyu JiangAAAI 2022 · 82 citations
- A Four-Pronged Defense Against Byzantine Attacks in Federated LearningWei Wan, Shengshan Hu, Minghui Li, Jianrong Lu et al.ACM MM 2023 · 26 citations
- FedRecover: Recovering from Poisoning Attacks in Federated Learning using Historical InformationXiaoyu Cao, Jinyuan Jia, Zaixi Zhang, Neil Zhenqiang GongS&P 2023
