TY - GEN
T1 - Defending Federated Learning Against Model Poisoning Attacks via Eliminating Malicious Features
AU - Qiu, Weiqi
AU - Liu, Qinbo
AU - Zeng, Ziqian
AU - Tian, Yuchen
AU - Jiang, Zoe L.
AU - Liu, Yang
N1 - Publisher Copyright:
© 2026 IEEE.
PY - 2026
Y1 - 2026
N2 - Federated learning (FL) is susceptible to model poisoning attacks, in which malicious clients compromise the global model by sending manipulated model updates to the server. While numerous studies have proposed defenses against such attacks, these defenses often struggle to handle complex attack patterns or heterogeneous data distributions in practical scenarios. Moreover, existing defenses face significant limitations in efficiency and applicability, particularly when dealing with large-scale or highly sophisticated attacks. This article studies model poisoning attacks in FL, showing the effectiveness of such attacks and the difficulties of defending against them via a theoretical foundation. To address the above challenges, we introduce a novel defense method designed to mitigate model poisoning attacks more effectively by eliminating malicious features, and design differential privacy-based defense (DPD) and selective aggregation-based defense (SAD), respectively. Empirical evidence from experiments with public datasets verifies their effectiveness. In particular, SAD outperforms all baseline defense methods in defending against Min-Max attacks. Additionally, SAD effectively defends against other attack types, achieving optimal or near-optimal defense performance in our experiments.
AB - Federated learning (FL) is susceptible to model poisoning attacks, in which malicious clients compromise the global model by sending manipulated model updates to the server. While numerous studies have proposed defenses against such attacks, these defenses often struggle to handle complex attack patterns or heterogeneous data distributions in practical scenarios. Moreover, existing defenses face significant limitations in efficiency and applicability, particularly when dealing with large-scale or highly sophisticated attacks. This article studies model poisoning attacks in FL, showing the effectiveness of such attacks and the difficulties of defending against them via a theoretical foundation. To address the above challenges, we introduce a novel defense method designed to mitigate model poisoning attacks more effectively by eliminating malicious features, and design differential privacy-based defense (DPD) and selective aggregation-based defense (SAD), respectively. Empirical evidence from experiments with public datasets verifies their effectiveness. In particular, SAD outperforms all baseline defense methods in defending against Min-Max attacks. Additionally, SAD effectively defends against other attack types, achieving optimal or near-optimal defense performance in our experiments.
KW - AI security
KW - Federated learning
KW - Model poisoning attacks
UR - https://www.scopus.com/pages/publications/105046424430
U2 - 10.1109/BDPC69980.2026.11608099
DO - 10.1109/BDPC69980.2026.11608099
M3 - 会议稿件
AN - SCOPUS:105046424430
T3 - 2026 4th International Conference on Big Data and Privacy Computing, BDPC 2026
SP - 40
EP - 48
BT - 2026 4th International Conference on Big Data and Privacy Computing, BDPC 2026
PB - Institute of Electrical and Electronics Engineers Inc.
T2 - 4th International Conference on Big Data and Privacy Computing, BDPC 2026
Y2 - 29 May 2026 through 31 May 2026
ER -