SecureFed: A Two-Phase Framework for Detecting Malicious Clients in Federated Learning

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Kavuri, Likhitha Annapurna, Mhatre, Akshay, Nair, Akarsh K, Gupta, Deepti
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866909653976219648
author Kavuri, Likhitha Annapurna
Mhatre, Akshay
Nair, Akarsh K
Gupta, Deepti
author_facet Kavuri, Likhitha Annapurna
Mhatre, Akshay
Nair, Akarsh K
Gupta, Deepti
contents Federated Learning (FL) protects data privacy while providing a decentralized method for training models. However, because of the distributed schema, it is susceptible to adversarial clients that could alter results or sabotage model performance. This study presents SecureFed, a two-phase FL framework for identifying and reducing the impact of such attackers. Phase 1 involves collecting model updates from participating clients and applying a dimensionality reduction approach to identify outlier patterns frequently associated with malicious behavior. Temporary models constructed from the client updates are evaluated on synthetic datasets to compute validation losses and support anomaly scoring. The idea of learning zones is presented in Phase 2, where weights are dynamically routed according to their contribution scores and gradient magnitudes. High-value gradient zones are given greater weight in aggregation and contribute more significantly to the global model, while lower-value gradient zones, which may indicate possible adversarial activity, are gradually removed from training. Until the model converges and a strong defense against poisoning attacks is possible, this training cycle continues Based on the experimental findings, SecureFed considerably improves model resilience without compromising model performance.
format Preprint
id arxiv_https___arxiv_org_abs_2506_16458
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle SecureFed: A Two-Phase Framework for Detecting Malicious Clients in Federated Learning
Kavuri, Likhitha Annapurna
Mhatre, Akshay
Nair, Akarsh K
Gupta, Deepti
Cryptography and Security
Federated Learning (FL) protects data privacy while providing a decentralized method for training models. However, because of the distributed schema, it is susceptible to adversarial clients that could alter results or sabotage model performance. This study presents SecureFed, a two-phase FL framework for identifying and reducing the impact of such attackers. Phase 1 involves collecting model updates from participating clients and applying a dimensionality reduction approach to identify outlier patterns frequently associated with malicious behavior. Temporary models constructed from the client updates are evaluated on synthetic datasets to compute validation losses and support anomaly scoring. The idea of learning zones is presented in Phase 2, where weights are dynamically routed according to their contribution scores and gradient magnitudes. High-value gradient zones are given greater weight in aggregation and contribute more significantly to the global model, while lower-value gradient zones, which may indicate possible adversarial activity, are gradually removed from training. Until the model converges and a strong defense against poisoning attacks is possible, this training cycle continues Based on the experimental findings, SecureFed considerably improves model resilience without compromising model performance.
title SecureFed: A Two-Phase Framework for Detecting Malicious Clients in Federated Learning
topic Cryptography and Security
url https://arxiv.org/abs/2506.16458