TY - GEN
T1 - Effective Dual-Layer Poison Attacks Detection in Privacy-preserving Federated Learning
AU - Zhang, Xiao
AU - Chi, Haotian
AU - Li, Yonggang
AU - Jiang, Shunrong
AU - Du, Xiaojiang
AU - Hughes, Danny
N1 - Publisher Copyright:
© 2025 IEEE.
PY - 2025
Y1 - 2025
N2 - Although federated learning offers a certain degree of privacy by aggregating user gradients instead of raw data, it remains vulnerable to various attacks, such as model poisoning. Existing defense mechanisms often address poisoning threats at the cost of exposing gradient information, which can lead to privacy risks such as member inference attacks. While techniques like cryptography or differential privacy can be employed to mitigate these risks, they often come with significant efficiency trade-offs. At the same time, a non-IID heterogeneous environment is also a big challenge. To address these challenges holistically, this paper proposes a dual-layer detection scheme (EDDFL). It combines norm-based filtering and isolation forest detection to effectively filter out malicious gradients, thereby preserving model accuracy even in adversarial environments. Furthermore, we incorporate a gradient quantization method that not only protects gradient privacy but also improves communication efficiency. Compared with existing approaches, the proposed method effectively addresses the challenges of model poisoning, gradient leakage, and data heterogeneity under non-IID settings. Experimental results demonstrate that our scheme significantly reduces both computational and communication overhead while maintaining privacy guarantees.
AB - Although federated learning offers a certain degree of privacy by aggregating user gradients instead of raw data, it remains vulnerable to various attacks, such as model poisoning. Existing defense mechanisms often address poisoning threats at the cost of exposing gradient information, which can lead to privacy risks such as member inference attacks. While techniques like cryptography or differential privacy can be employed to mitigate these risks, they often come with significant efficiency trade-offs. At the same time, a non-IID heterogeneous environment is also a big challenge. To address these challenges holistically, this paper proposes a dual-layer detection scheme (EDDFL). It combines norm-based filtering and isolation forest detection to effectively filter out malicious gradients, thereby preserving model accuracy even in adversarial environments. Furthermore, we incorporate a gradient quantization method that not only protects gradient privacy but also improves communication efficiency. Compared with existing approaches, the proposed method effectively addresses the challenges of model poisoning, gradient leakage, and data heterogeneity under non-IID settings. Experimental results demonstrate that our scheme significantly reduces both computational and communication overhead while maintaining privacy guarantees.
KW - Poison attacks
KW - federated learning
KW - gradient quantization
KW - privacy-preserving
UR - https://www.scopus.com/pages/publications/105036272656
UR - https://www.scopus.com/pages/publications/105036272656#tab=citedBy
U2 - 10.1109/GLOBECOM59602.2025.11432262
DO - 10.1109/GLOBECOM59602.2025.11432262
M3 - Conference contribution
AN - SCOPUS:105036272656
T3 - Proceedings - IEEE Global Communications Conference, GLOBECOM
SP - 2300
EP - 2305
BT - GLOBECOM 2025 - 2025 IEEE Global Communications Conference
T2 - 2025 IEEE Global Communications Conference, GLOBECOM 2025
Y2 - 8 December 2025 through 12 December 2025
ER -