상세 보기
Norm-Based Outlier Filtering and Consensus Aggregation for Robust Federated Learning
- Yeo, Hasung;
- Lee, Joon-Woo
WEB OF SCIENCE
0SCOPUS
0초록
Federated Learning (FL) enables collaborative training of machine learning models across distributed clients without sharing private data, making it ideal for privacy-sensitive applications. However, FL is highly vulnerable to backdoor attacks, especially those designed to persist undetected over time. One of the most advanced of these is the Irreversible Backdoor Attack (IBA), which remains effective even after malicious clients are removed by aligning its updates with benign ones. In this paper, we propose a novel defense framework called Norm-Based Outlier Filtering and Consensus-Aware Aggregation (NOFCA) to effectively defend against such attacks. NOFCA combines norm-based outlier removal of client updates with a consensus-direction-based perturbation mechanism that disrupts the insertion of aligned adversarial updates. Unlike conventional aggregation rules or heuristic-based filtering, our method actively removes anomalous updates and performs adjusted aggregation based on the consensus direction of benign clients, thereby effectively obstructing backdoor attacks. Experimental results on MNIST and CIFAR-10 datasets demonstrate that NOFCA consistently achieves the lowest backdoor accuracy across all evaluated attack scenarios while maintaining competitive main accuracy. Furthermore, under fixed-frequency attack settings, where the attacker participates in every communication round, NOFCA shows robust and stable performance, maintaining strong defense even in highly persistent threat conditions. These findings confirm the effectiveness of NOFCA as a practical and resilient defense strategy for real-world FL systems.
키워드
- 제목
- Norm-Based Outlier Filtering and Consensus Aggregation for Robust Federated Learning
- 저자
- Yeo, Hasung; Lee, Joon-Woo
- 발행일
- 2025
- 유형
- Article
- 저널명
- IEEE Access
- 권
- 13
- 페이지
- 104926 ~ 104936