Norm-Based Outlier Filtering and Consensus Aggregation for Robust Federated Learning

Citations

WEB OF SCIENCE

0
Citations

SCOPUS

0

초록

Federated Learning (FL) enables collaborative training of machine learning models across distributed clients without sharing private data, making it ideal for privacy-sensitive applications. However, FL is highly vulnerable to backdoor attacks, especially those designed to persist undetected over time. One of the most advanced of these is the Irreversible Backdoor Attack (IBA), which remains effective even after malicious clients are removed by aligning its updates with benign ones. In this paper, we propose a novel defense framework called Norm-Based Outlier Filtering and Consensus-Aware Aggregation (NOFCA) to effectively defend against such attacks. NOFCA combines norm-based outlier removal of client updates with a consensus-direction-based perturbation mechanism that disrupts the insertion of aligned adversarial updates. Unlike conventional aggregation rules or heuristic-based filtering, our method actively removes anomalous updates and performs adjusted aggregation based on the consensus direction of benign clients, thereby effectively obstructing backdoor attacks. Experimental results on MNIST and CIFAR-10 datasets demonstrate that NOFCA consistently achieves the lowest backdoor accuracy across all evaluated attack scenarios while maintaining competitive main accuracy. Furthermore, under fixed-frequency attack settings, where the attacker participates in every communication round, NOFCA shows robust and stable performance, maintaining strong defense even in highly persistent threat conditions. These findings confirm the effectiveness of NOFCA as a practical and resilient defense strategy for real-world FL systems.

키워드

Federated learningData modelsRobustnessFilteringComputational modelingCryptographyTrainingAdaptation modelsScalabilityPrivacymachine learningcollaborative AIprivacysecurity
제목
Norm-Based Outlier Filtering and Consensus Aggregation for Robust Federated Learning
저자
Yeo, HasungLee, Joon-Woo
DOI
10.1109/ACCESS.2025.3580198
발행일
2025
유형
Article
저널명
IEEE Access
13
페이지
104926 ~ 104936

파일 다운로드