Skip to main navigation Skip to search Skip to main content

Effective Dual-Layer Poison Attacks Detection in Privacy-preserving Federated Learning

  • Xiao Zhang
  • , Haotian Chi
  • , Yonggang Li
  • , Shunrong Jiang
  • , Xiaojiang Du
  • , Danny Hughes
  • China University of Mining and Technology
  • Shanxi University
  • KU Leuven

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Although federated learning offers a certain degree of privacy by aggregating user gradients instead of raw data, it remains vulnerable to various attacks, such as model poisoning. Existing defense mechanisms often address poisoning threats at the cost of exposing gradient information, which can lead to privacy risks such as member inference attacks. While techniques like cryptography or differential privacy can be employed to mitigate these risks, they often come with significant efficiency trade-offs. At the same time, a non-IID heterogeneous environment is also a big challenge. To address these challenges holistically, this paper proposes a dual-layer detection scheme (EDDFL). It combines norm-based filtering and isolation forest detection to effectively filter out malicious gradients, thereby preserving model accuracy even in adversarial environments. Furthermore, we incorporate a gradient quantization method that not only protects gradient privacy but also improves communication efficiency. Compared with existing approaches, the proposed method effectively addresses the challenges of model poisoning, gradient leakage, and data heterogeneity under non-IID settings. Experimental results demonstrate that our scheme significantly reduces both computational and communication overhead while maintaining privacy guarantees.

Original languageEnglish
Title of host publicationGLOBECOM 2025 - 2025 IEEE Global Communications Conference
Pages2300-2305
Number of pages6
ISBN (Electronic)9798331577810
DOIs
StatePublished - 2025
Event2025 IEEE Global Communications Conference, GLOBECOM 2025 - Taipei, Taiwan, Province of China
Duration: 8 Dec 202512 Dec 2025

Publication series

NameProceedings - IEEE Global Communications Conference, GLOBECOM
ISSN (Print)2334-0983
ISSN (Electronic)2576-6813

Conference

Conference2025 IEEE Global Communications Conference, GLOBECOM 2025
Country/TerritoryTaiwan, Province of China
CityTaipei
Period8/12/2512/12/25

Keywords

  • Poison attacks
  • federated learning
  • gradient quantization
  • privacy-preserving

Fingerprint

Dive into the research topics of 'Effective Dual-Layer Poison Attacks Detection in Privacy-preserving Federated Learning'. Together they form a unique fingerprint.

Cite this