AntiFLipper: A Secure and Efficient Defense Against Label-Flipping Attacks in Federated Learning

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Rahman, Aashnan, Hasan, Abid, Arifin, Sherajul, Bappy, Faisal Haque, Hossain, Tahrim, Islam, Tariqul, Kamal, Abu Raihan Mostofa, Hossain, Md. Azam
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866918151351959552
author Rahman, Aashnan
Hasan, Abid
Arifin, Sherajul
Bappy, Faisal Haque
Hossain, Tahrim
Islam, Tariqul
Kamal, Abu Raihan Mostofa
Hossain, Md. Azam
author_facet Rahman, Aashnan
Hasan, Abid
Arifin, Sherajul
Bappy, Faisal Haque
Hossain, Tahrim
Islam, Tariqul
Kamal, Abu Raihan Mostofa
Hossain, Md. Azam
contents Federated learning (FL) enables privacy-preserving model training by keeping data decentralized. However, it remains vulnerable to label-flipping attacks, where malicious clients manipulate labels to poison the global model. Despite their simplicity, these attacks can severely degrade model performance, and defending against them remains challenging. We introduce AntiFLipper, a novel and computationally efficient defense against multi-class label-flipping attacks in FL. Unlike existing methods that ensure security at the cost of high computational overhead, AntiFLipper employs a novel client-side detection strategy, significantly reducing the central server's burden during aggregation. Comprehensive empirical evaluations across multiple datasets under different distributions demonstrate that AntiFLipper achieves accuracy comparable to state-of-the-art defenses while requiring substantially fewer computational resources in server side. By balancing security and efficiency, AntiFLipper addresses a critical gap in existing defenses, making it particularly suitable for resource-constrained FL deployments where both model integrity and operational efficiency are essential.
format Preprint
id arxiv_https___arxiv_org_abs_2509_22873
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle AntiFLipper: A Secure and Efficient Defense Against Label-Flipping Attacks in Federated Learning
Rahman, Aashnan
Hasan, Abid
Arifin, Sherajul
Bappy, Faisal Haque
Hossain, Tahrim
Islam, Tariqul
Kamal, Abu Raihan Mostofa
Hossain, Md. Azam
Cryptography and Security
Federated learning (FL) enables privacy-preserving model training by keeping data decentralized. However, it remains vulnerable to label-flipping attacks, where malicious clients manipulate labels to poison the global model. Despite their simplicity, these attacks can severely degrade model performance, and defending against them remains challenging. We introduce AntiFLipper, a novel and computationally efficient defense against multi-class label-flipping attacks in FL. Unlike existing methods that ensure security at the cost of high computational overhead, AntiFLipper employs a novel client-side detection strategy, significantly reducing the central server's burden during aggregation. Comprehensive empirical evaluations across multiple datasets under different distributions demonstrate that AntiFLipper achieves accuracy comparable to state-of-the-art defenses while requiring substantially fewer computational resources in server side. By balancing security and efficiency, AntiFLipper addresses a critical gap in existing defenses, making it particularly suitable for resource-constrained FL deployments where both model integrity and operational efficiency are essential.
title AntiFLipper: A Secure and Efficient Defense Against Label-Flipping Attacks in Federated Learning
topic Cryptography and Security
url https://arxiv.org/abs/2509.22873