FedRecover: Recovering from Poisoning Attacks in Federated Learning using Historical Information
Xiaoyu Cao, Jinyuan Jia, Zaixi Zhang, Neil Zhenqiang Gong
Abstract
Federated learning is vulnerable to poisoning attacks in which malicious clients poison the global model via sending malicious model updates to the server. Existing defenses focus on preventing a small number of malicious clients from poisoning the global model via robust federated learning methods and detecting malicious clients when there are a large number of them. However, it is still an open challenge how to recover the global model from poisoning attacks after the malicious clients are detected. A naive solution is to remove the detected malicious clients and train a new global model from scratch using the remaining clients. However, such train-from-scratch recovery method incurs a large computation and communication cost, which may be intolerable for resource-constrained clients such as smartphones and IoT devices.In this work, we propose FedRecover, a method that can recover an accurate global model from poisoning attacks with a small computation and communication cost for the clients. Our key idea is that the server estimates the clients’ model updates instead of asking the clients to compute and communicate them during the recovery process. In particular, the server stores the historical information, including the global models and clients’ model updates in each round, when training the poisoned global model before the malicious clients are detected. During the recovery process, the server estimates a client’s model update in each round using its stored historical information. Moreover, we further optimize FedRecover to recover a more accurate global model using warm-up, periodic correction, abnormality fixing, and final tuning strategies, in which the server asks the clients to compute and communicate their exact model updates. Theoretically, we show that the global model recovered by FedRecover is close to or the same as that recovered by train-from-scratch under some assumptions. Empirically, our evaluation on four datasets, three federated learning methods, as well as untargeted and targeted poisoning attacks (e.g., backdoor attacks) shows that FedRecover is both accurate and efficient.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers16
- Byzantine-Robust Decentralized Federated LearningMinghong Fang, Zifan Zhang, Hairi, Prashant Khanduri et al.CCS 2024 · 38 citations
- SAFE: Machine Unlearning With Shard GraphsYonatan Dukler, Benjamin Bowman, Alessandro Achille, Aditya Golatkar et al.ICCV 2023 · 32 citations
- Poisoning Federated Recommender Systems with Fake UsersMing Yin, Yichang Xu, Minghong Fang, Neil Zhenqiang GongWWW 2024 · 32 citations
- FedGame: A Game-Theoretic Defense against Backdoor Attacks in Federated LearningJinyuan Jia, Zhuowen Yuan, Dinuka Sahabandu, Luyao Niu et al.NeurIPS 2023 · 32 citations
- Ferrari: Federated Feature Unlearning via Optimizing Feature SensitivityHanlin Gu, WinKent Ong, Chee Seng Chan, Lixin FanNeurIPS 2024 · 29 citations
Builds on11
- Neural Cleanse: Identifying and Mitigating Backdoor Attacks in Neural NetworksBolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li et al.S&P 2019 · 1,801 citations
- Machine UnlearningLucas Bourtoule, Varun Chandrasekaran, Christopher A. Choquette-Choo, Hengrui Jia et al.S&P 2021 · 1,381 citations
- FLDetector: Defending Federated Learning Against Model Poisoning Attacks via Detecting Malicious ClientsZaixi Zhang, Xiaoyu Cao, Jinyuan Jia, Neil Zhenqiang GongKDD 2022 · 293 citations
- DeltaGrad: Rapid retraining of machine learning modelsYinjun Wu, Edgar Dobriban, Susan B. DavidsonICML 2020 · 262 citations
- Provably Secure Federated Learning against Malicious ClientsXiaoyu Cao, Jinyuan Jia, Neil Zhenqiang GongAAAI 2021 · 161 citations
Related papers
- Tracing Back the Malicious Clients in Poisoning Attacks to Federated LearningYuqi Jia, Minghong Fang, Hongbin Liu, Jinghuai Zhang et al.NeurIPS 2025 · 8 citations
- FL-WBC: Enhancing Robustness against Model Poisoning Attacks in Federated Learning from a Client PerspectiveJingwei Sun, Ang Li, Louis DiValentin, Amin Hassanzadeh et al.NeurIPS 2021 · 131 citations
- FedREDefense: Defending against Model Poisoning Attacks for Federated Learning using Model Update Reconstruction ErrorYueqi Xie, Minghong Fang, Neil Zhenqiang GongICML 2024 · 32 citations
- DeFL: Defending against Model Poisoning Attacks in Federated Learning via Critical Learning Periods AwarenessGang Yan, Hao Wang, Xu Yuan, Jian LiAAAI 2023 · 38 citations
- FreqFed: A Frequency Analysis-Based Approach for Mitigating Poisoning Attacks in Federated LearningHossein Fereidooni, Alessandro Pegoraro, Phillip Rieger, Alexandra Dmitrienko et al.NDSS 2024
