Skip to main navigation Skip to search Skip to main content

PFedRobust: A personalized federated learning framework toward robustness against data poisoning attacks in IoT

  • Chunmei Li
  • , Tao Li
  • , Andrea Bracciali
  • , Yilei Wang*
  • , Hongwei Zhou
  • , Daojing He
  • , Zhiquan Liu
  • *Corresponding author for this work
  • Qufu Normal University
  • University of Pisa
  • Jiaxing University
  • Guangzhou University
  • School of Computer Science and Technology, Harbin Institute of Technology
  • Guangdong Provincial Key Laboratory of Novel Security Intelligence Technologies
  • University of Jinan

Research output: Contribution to journalArticlepeer-review

Abstract

Poisoned models are difficult to be detected due to the property of not Independent and Identically Distributed (non-IID) datasets, such as datasets of edge devices, mobile devices, etc. in the Internet of Things (IoT) in Personalized Federated Learning (PFL). Generally, all local models are pre-aggregated as a Pre-aggregated Poisoned Global Model (PPGM) and then local models with high similarities with PPGM are detected as poisoned models. However, the high False Negative Rate (FNR) of poisoned models results in low model accuracy (MA) once the poisoned models are reported as benign ones and aggregated into the global model. In this paper, we propose PFedRobust, a fine-grained PFL framework, where models are trained and aggregated in terms of the classes instead of clients. Specifically, each client divides its non-IID dataset into multiple IID class-based datasets in terms of classes. Then a novel Local Class Model (LCM), a binary classifier, is constructed on each class-based dataset. The LCMs of the same class, for different clients, are little variation since their corresponding class-based datasets are IID. Finally, the server calculates the similarity between each LCM and the Pre-computed Poisoned Global Class Model (PPGCM) using Earth Mover's Distance (EMD). LCMs with high similarities are regarded as Malicious Class Models (MCMs), which are excluded from the real aggregation process. Extensive experiments indicate that PFedRobust performs well in both FNR and MA. That is, excellent performance in MCMs detection and robustness.

Original languageEnglish
Article number115974
JournalKnowledge-Based Systems
Volume343
DOIs
StatePublished - 15 Jun 2026
Externally publishedYes

Keywords

  • Data poisoning attacks
  • Earth Mover's Distance (EMD)
  • Personalized Federated Learning (PFL)
  • Robustness

Fingerprint

Dive into the research topics of 'PFedRobust: A personalized federated learning framework toward robustness against data poisoning attacks in IoT'. Together they form a unique fingerprint.

Cite this