FedNIA: Noise-Induced Activation Analysis for Mitigating Data Poisoning in FL

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Hallaji, Ehsan, Razavi-Far, Roozbeh, Saif, Mehrdad
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866913703325073408
author Hallaji, Ehsan
Razavi-Far, Roozbeh
Saif, Mehrdad
author_facet Hallaji, Ehsan
Razavi-Far, Roozbeh
Saif, Mehrdad
contents Federated learning systems are increasingly threatened by data poisoning attacks, where malicious clients compromise global models by contributing tampered updates. Existing defenses often rely on impractical assumptions, such as access to a central test dataset, or fail to generalize across diverse attack types, particularly those involving multiple malicious clients working collaboratively. To address this, we propose Federated Noise-Induced Activation Analysis (FedNIA), a novel defense framework to identify and exclude adversarial clients without relying on any central test dataset. FedNIA injects random noise inputs to analyze the layerwise activation patterns in client models leveraging an autoencoder that detects abnormal behaviors indicative of data poisoning. FedNIA can defend against diverse attack types, including sample poisoning, label flipping, and backdoors, even in scenarios with multiple attacking nodes. Experimental results on non-iid federated datasets demonstrate its effectiveness and robustness, underscoring its potential as a foundational approach for enhancing the security of federated learning systems.
format Preprint
id arxiv_https___arxiv_org_abs_2502_16396
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle FedNIA: Noise-Induced Activation Analysis for Mitigating Data Poisoning in FL
Hallaji, Ehsan
Razavi-Far, Roozbeh
Saif, Mehrdad
Machine Learning
Artificial Intelligence
Cryptography and Security
Federated learning systems are increasingly threatened by data poisoning attacks, where malicious clients compromise global models by contributing tampered updates. Existing defenses often rely on impractical assumptions, such as access to a central test dataset, or fail to generalize across diverse attack types, particularly those involving multiple malicious clients working collaboratively. To address this, we propose Federated Noise-Induced Activation Analysis (FedNIA), a novel defense framework to identify and exclude adversarial clients without relying on any central test dataset. FedNIA injects random noise inputs to analyze the layerwise activation patterns in client models leveraging an autoencoder that detects abnormal behaviors indicative of data poisoning. FedNIA can defend against diverse attack types, including sample poisoning, label flipping, and backdoors, even in scenarios with multiple attacking nodes. Experimental results on non-iid federated datasets demonstrate its effectiveness and robustness, underscoring its potential as a foundational approach for enhancing the security of federated learning systems.
title FedNIA: Noise-Induced Activation Analysis for Mitigating Data Poisoning in FL
topic Machine Learning
Artificial Intelligence
Cryptography and Security
url https://arxiv.org/abs/2502.16396