Skip to main navigation Skip to search Skip to main content

Defending Federated Learning Against Model Poisoning Attacks via Eliminating Malicious Features

  • Weiqi Qiu
  • , Qinbo Liu
  • , Ziqian Zeng
  • , Yuchen Tian
  • , Zoe L. Jiang
  • , Yang Liu*
  • *Corresponding author for this work
  • Harbin Institute of Technology
  • State Grid Shaanxi Electric Power Company
  • Swansea University
  • Tencent

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Federated learning (FL) is susceptible to model poisoning attacks, in which malicious clients compromise the global model by sending manipulated model updates to the server. While numerous studies have proposed defenses against such attacks, these defenses often struggle to handle complex attack patterns or heterogeneous data distributions in practical scenarios. Moreover, existing defenses face significant limitations in efficiency and applicability, particularly when dealing with large-scale or highly sophisticated attacks. This article studies model poisoning attacks in FL, showing the effectiveness of such attacks and the difficulties of defending against them via a theoretical foundation. To address the above challenges, we introduce a novel defense method designed to mitigate model poisoning attacks more effectively by eliminating malicious features, and design differential privacy-based defense (DPD) and selective aggregation-based defense (SAD), respectively. Empirical evidence from experiments with public datasets verifies their effectiveness. In particular, SAD outperforms all baseline defense methods in defending against Min-Max attacks. Additionally, SAD effectively defends against other attack types, achieving optimal or near-optimal defense performance in our experiments.

Original languageEnglish
Title of host publication2026 4th International Conference on Big Data and Privacy Computing, BDPC 2026
PublisherInstitute of Electrical and Electronics Engineers Inc.
Pages40-48
Number of pages9
ISBN (Electronic)9798319519450
DOIs
StatePublished - 2026
Externally publishedYes
Event4th International Conference on Big Data and Privacy Computing, BDPC 2026 - Beijing, China
Duration: 29 May 202631 May 2026

Publication series

Name2026 4th International Conference on Big Data and Privacy Computing, BDPC 2026

Conference

Conference4th International Conference on Big Data and Privacy Computing, BDPC 2026
Country/TerritoryChina
CityBeijing
Period29/05/2631/05/26

Keywords

  • AI security
  • Federated learning
  • Model poisoning attacks

Fingerprint

Dive into the research topics of 'Defending Federated Learning Against Model Poisoning Attacks via Eliminating Malicious Features'. Together they form a unique fingerprint.

Cite this