FedInv: Byzantine-Robust Federated Learning by Inversing Local Model Updates
Bo Zhao, Peng Sun, Tao Wang, Keyu Jiang
Abstract
Federated learning (FL) is a privacy-preserving distributed machine learning paradigm that enables multiple clients to collaboratively train statistical models without disclosing raw training data. However, the inaccessible local training data and uninspectable local training process make FL susceptible to various Byzantine attacks (e.g., data poisoning and model poisoning attacks), aiming to manipulate the FL model training process and degrade the model performance. Most of the existing Byzantine-robust FL schemes cannot effectively defend against stealthy poisoning attacks that craft poisoned models statistically similar to benign models. Things worsen when many clients are compromised or data among clients are highly non-independent and identically distributed (non-IID). In this work, to address these issues, we propose FedInv, a novel Byzantine-robust FL framework by inversing local model updates. Specifically, in each round of local model aggregation in FedInv, the parameter server first inverses the local model updates submitted by each client to generate a corresponding dummy dataset. Then, the server identifies those dummy datasets with exceptional Wasserstein distances from others and excludes the related local model updates from model aggregation. We conduct an exhaustive experimental evaluation of FedInv. The results demonstrate that FedInv significantly outperforms the existing robust FL schemes in defending against stealthy poisoning attacks under highly non-IID data partitions.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers5
- A Four-Pronged Defense Against Byzantine Attacks in Federated LearningWei Wan, Shengshan Hu, Minghui Li, Jianrong Lu et al.ACM MM 2023 · 26 citations
- Byzantine-robust Decentralized Federated Learning via Dual-domain Clustering and Trust BootstrappingPeng Sun, Xinyang Liu, Zhibo Wang, Bo LiuCVPR 2024 · 21 citations
- FedAA: A Reinforcement Learning Perspective on Adaptive Aggregation for Fair and Robust Federated LearningJialuo He, Wei Chen, Xiaojin ZhangAAAI 2025 · 12 citations
- Breaking Secure Aggregation: Label Leakage from Aggregated Gradients in Federated LearningZhibo Wang, Zhiwei Chang, Jiahui Hu, Xiaoyi Pang et al.INFOCOM 2024 · 10 citations
- HydraProofs: Optimally Computing All Proofs in a Vector Commitment (With Applications to Efficient zkSNARKs Over Data from Multiple Users)Christodoulos Pappas, Dimitrios Papadopoulos, Charalampos PapamanthouS&P 2025
Builds on5
- Manipulating Machine Learning: Poisoning Attacks and Countermeasures for Regression LearningMatthew Jagielski, Alina Oprea, Battista Biggio, Chang Liu et al.S&P 2018 · 867 citations
- Zeno++: Robust Fully Asynchronous SGDCong Xie, Sanmi Koyejo, Indranil GuptaICML 2020 · 137 citations
- FLTrust: Byzantine-robust Federated Learning via Trust BootstrappingXiaoyu Cao, Minghong Fang, Jia Liu, Neil Zhenqiang GongNDSS 2021
- Manipulating the Byzantine: Optimizing Model Poisoning Attacks and Defenses for Federated LearningVirat Shejwalkar, Amir HoumansadrNDSS 2021
- Local Model Poisoning Attacks to Byzantine-Robust Federated LearningMinghong Fang, Xiaoyu Cao, Jinyuan Jia, Neil Zhenqiang GongUSENIX Security 2020
Related papers
- Do We Really Need to Design New Byzantine-robust Aggregation Rules?Minghong Fang, Seyedsina Nabavirazavi, Zhuqing Liu, Wei Sun et al.NDSS 2025
- Byzantine-Robust Decentralized Federated LearningMinghong Fang, Zifan Zhang, Hairi, Prashant Khanduri et al.CCS 2024 · 38 citations
- Enhancing Privacy Preservation in Federated Learning via Learning Rate PerturbationGuangnian Wan, Haitao Du, Xuejing Yuan, Jun Yang et al.ICCV 2023 · 2 citations
- FreqFed: A Frequency Analysis-Based Approach for Mitigating Poisoning Attacks in Federated LearningHossein Fereidooni, Alessandro Pegoraro, Phillip Rieger, Alexandra Dmitrienko et al.NDSS 2024
- On the Byzantine-Resilience of Distillation-Based Federated LearningChristophe Roux, Max Zimmer, Sebastian PokuttaICLR 2025
