Skip to main navigation Skip to search Skip to main content

Privacy-Preserving Federated Learning Scheme With Mitigating Model Poisoning Attacks: Vulnerabilities and Countermeasures

  • Jiahui Wu
  • , Fucai Luo
  • , Tiecheng Sun
  • , Haiyan Wang
  • , Weizhe Zhang*
  • *Corresponding author for this work
  • Peng Cheng Laboratory
  • Zhejiang Gongshang University
  • Harbin Institute of Technology

Research output: Contribution to journalArticlepeer-review

Abstract

The privacy-preserving federated learning schemes based on the setting of two honest-but-curious and non-colluding servers offer promising solutions in terms of security and efficiency. However, our investigation reveals that these schemes still suffer from privacy leakage when considering model poisoning attacks from malicious users. Specifically, we demonstrate that the privacy-preserving computation process for defending against model poisoning attacks inadvertently leaks privacy to one of the honest-but-curious servers, enabling it to access users’ gradients in plaintext. To address this issue, we propose an enhanced privacy-preserving and Byzantine-robust federated learning (PBFL) framework that simultaneously achieves privacy, robustness, and efficiency. Central to our design is a novel Byzantine-tolerant aggregation strategy that defends against both conventional and adaptive poisoning attacks. It integrates normalization judgment, cosine similarity computation, and adaptive user weighting, with a dual-scoring trust mechanism and outlier suppression for stealthy attacks. In addition, we develop two privacy-preserving subroutines, namely secure normalization judgment and secure cosine similarity measurement, which operate over encrypted gradients using a trapdoor fully homomorphic encryption (FHE) scheme, ensuring both confidentiality and robust aggregation correctness. Theoretical analyses confirm that our scheme guarantees security, convergence, and efficiency even with malicious users and one malicious server. Extensive experiments demonstrate that our method effectively breaks prior privacy attacks, maintains high accuracy under diverse poisoning strategies, and significantly reduces computation and communication overhead compared to state-of-the-art PBFL schemes.

Original languageEnglish
Pages (from-to)1421-1438
Number of pages18
JournalIEEE Transactions on Dependable and Secure Computing
Volume23
Issue number1
DOIs
StatePublished - Jan 2026
Externally publishedYes

Keywords

  • Federated learning (FL)
  • homomorphic encryption
  • poisoning attacks
  • privacy protection

Fingerprint

Dive into the research topics of 'Privacy-Preserving Federated Learning Scheme With Mitigating Model Poisoning Attacks: Vulnerabilities and Countermeasures'. Together they form a unique fingerprint.

Cite this