REVIEW 3 major objections 4 minor 85 references
Toward Malicious Clients Detection in Federated Learning
T0 review · 3 major / 4 minor · reviewed 2026-08-15 · deepseek-v4-flash
Pith's one-line read SafeFL detects malicious federated-learning clients by scoring their local models on a synthetic dataset generated from the global model trajectory.
desk verdict The detection results in Table 1 are arithmetically impossible under SafeFL-ML's own median-loss rule, so the paper's empirical claims cannot be trusted as written—but the trajectory-condensation idea is new enough to warrant refereeing. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The central object is a synthetic dataset produced by trajectory matching. The server treats pairs $(w_\alpha, w_{\alpha+\Delta})$ from the collected global-model trajectory as input-output targets and trains synthetic data so that starting from $w_\alpha$ and training for $\Delta$ steps on the synthetic set reproduces $w_{\alpha+\Delta}$. The resulting synthetic set $D_{\mathrm{syn}}$ is then the evaluation instrument: the loss of each local model on $D_{\mathrm{syn}}$ is what separates malicious from benign behavior. The machinery also includes the largest-cluster aggregation used during trajectory collection, plus the two detection rules, median-loss weighting and loss clustering.
What would settle it
Run SafeFL with 50 percent or more of clients malicious while keeping the same clustering and loss rules, so the largest-cluster assumption in Eq. (1) is violated; detection accuracy should drop sharply if the mechanism is what the paper claims. A sharper test is to craft malicious local models that carry a backdoor but are explicitly optimized to have loss close to the benign median on $D_{\mathrm{syn}}$, then check whether both SafeFL-ML and SafeFL-CL still flag them.
Extended reading notes
Core claim
SafeFL's central claim is that the trajectory of global models alone, with no access to client data, can be turned into a usable test set for client screening. During the first epsilon rounds the server clusters received local models, aggregates only the largest cluster to form each global model, and then uses those global models as targets in a dataset-condensation optimization that produces synthetic images and labels. Once the synthetic set exists, each client's local model is evaluated on it; benign models are those whose loss falls below the median (SafeFL-ML) or in the largest loss cluster (SafeFL-CL). The paper reports that malicious local models show loss clearly separated from benign ones across all tested attacks, and that SafeFL-CL achieves near-perfect detection while keeping final global-model accuracy comparable to no-attack training.
Load-bearing premise
During the first $\epsilon$ rounds, clustering local models into the largest cluster isolates the benign clients, so the global-model trajectory used to make the synthetic dataset is uncontaminated; if malicious clients form the largest cluster or approach half the participants, the synthetic dataset is poisoned and detection fails.
Editorial extensions
If this is right
- Detection no longer requires the server to hold a clean validation dataset drawn from the clients' distribution, so it applies in highly heterogeneous or data-free settings.
- Because clients are re-assessed every round and only excluded from that round's aggregation, benign clients that occasionally exhibit high loss are not permanently removed from the system.
- SafeFL-CL's loss-clustering rule yields near-perfect detection accuracy and low false-positive rates across the tested attacks, keeping final global-model accuracy close to the no-attack FedAvg baseline.
- The detection filter remains effective when different aggregation rules such as Median, Trimmed Mean, or Krum are applied after filtering, making it compatible with prevention-based defenses.
- Longer global-model trajectories and larger synthetic datasets improve detection, with diminishing returns after roughly 25 trajectory rounds and 100 synthetic samples.
Reading between the lines
- If the loss-separation result generalizes, the same synthetic-trajectory trick could screen for other deviant client behavior, such as buggy or stale local models, using only the model updates themselves.
- A direct stress test of the mechanism would be an attack that explicitly optimizes malicious local models to keep their loss inside the benign cluster on $D_{\mathrm{syn}}$ while still implanting a backdoor; the paper's adaptive attack is full-knowledge, but this specific objective is not reported.
- Because the synthetic set is built from the largest cluster in the first $\epsilon$ rounds, the method has a natural threshold near 50 percent malicious clients; adding a small trusted anchor set during trajectory collection could push that threshold higher and is a testable extension.
- The paper's privacy discussion suggests a concrete follow-up: measuring how much the synthetic dataset leaks about client data, and whether differentially private global models still separate malicious from benign losses.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper proposes SafeFL, a server-side detection method for malicious clients in federated learning. The server records the first epsilon global models (aggregated from the largest cluster of local models), synthesizes a dataset D_syn from this trajectory via the SynGen algorithm, and then in each subsequent round evaluates every client's local model on D_syn. SafeFL-ML aggregates only clients whose loss is at or below the median loss; SafeFL-CL instead keeps clients in the largest loss cluster. Experiments compare SafeFL with seven detection-based and three prevention-based baselines on five datasets under six attack types, plus ablations and additional attacks in the appendix, and report near-perfect detection accuracy for SafeFL.
Significance. The core idea of replacing a clean server-side validation set with a synthetic dataset distilled from the global-model trajectory is original and potentially useful, since one of the main criticisms of existing defenses such as FLTrust is the unrealistic assumption that the server holds a representative clean dataset. The paper also provides a broad evaluation grid covering five datasets, several attacks, and numerous ablations. However, the central empirical claim is invalidated by an internal arithmetic inconsistency in SafeFL-ML's decision rule, and the paper's 'adaptive attack' evaluation does not exercise the full-knowledge threat model stated in Section 3. The positive contributions are the synthetic-dataset formulation and the breadth of the experimental design, but the manuscript in its current form does not support its headline detection results.
major comments (3)
- [§4.4, Eq. (4) and Table 1] The reported SafeFL-ML metrics are arithmetically inconsistent with the stated decision rule. Eq. (4) sets r_i^t = 0 for every client whose loss is strictly greater than the median l_Med^t, and the text and Algorithm 2 confirm that such clients are treated as malicious. For n = 100 clients, at most 50 clients can have loss above the median, so at most 50 clients can be flagged in any round. In the default setting with 30% malicious and 70% benign clients, even if the 30 malicious clients are exactly the 30 highest losses, 20 benign clients must also be flagged; this gives DACC = (30 + 50) / 100 = 0.80, FPR = 20 / 70 ≈ 0.286, and FNR = 0 as the best possible outcome. With no attack, the rule flags half the benign clients, giving DACC = 0.50. Table 1 reports SafeFL-ML no-attack DACC values of 0.92–0.99 and attack-row DACC values up to 1.00 with FPR as low as 0.00; for example, the CIFAR-10 Trim attack row reports DACC 0.90, FPR 0.03, and FNR 0.13. These numbers are impossible under Eq. (4): the reported FPR/FNR pair implies only about 28 flagged clients (26.1 true positives plus 2.1 false positives), whereas the median rule forces about 50 flagged clients. The same discrepancy appears in Tables 13 and 15 and in the SafeFL-ML curves of Figures 1–2. Either a different, unspecified threshold rule produced the tables, or the metrics were computed differently from the stated procedure; as written, the method cannot produce the headline detection results.
- [§5.1.2 and Appendix A.2] The Adaptive attack, which the contributions describe as a 'strong adaptive attack,' is not adaptive to SafeFL. Section 3 states that the full-knowledge attacker knows the aggregation rule and designs an attack to deceive the FL process, and Section 5.1.2 says the attacker 'designs an adaptive attack to disrupt and deceive the FL process' with SafeFL as the target. However, Appendix A.2 says only that the attack is implemented 'following the methodology outlined in [60]'; reference [60] (Shejwalkar and Houmansadr) constructs attacks against robust aggregation rules such as median and trimmed mean, not against a defense that evaluates local models on a synthetic dataset. The Adaptive-attack rows in Tables 1–3, 10, and 12 therefore do not test the full-knowledge threat model stated in Section 3, and the claim that SafeFL resists a worst-case adversary that knows SafeFL's detection mechanism is unsupported by the reported experiments.
- [§4.2, Eq. (1), and Algorithm 2, lines 14–17] The global model trajectory used for synthetic data generation is collected by aggregating only the largest cluster of local models for the first epsilon rounds, but the paper provides no correctness argument and no dedicated experiment establishing that this cluster is benign. Because the threat model in Section 3 lets malicious clients transmit arbitrary local models, an adversary that knows the clustering mechanism could attempt to place malicious updates inside the largest cluster during the trajectory-collection phase; the default 30% malicious setting and the tested attacks do not rule this out. Since D_syn is generated from this trajectory, poisoning the trajectory would poison the synthetic dataset and invalidate the subsequent loss-based separation. The paper should either prove a separation condition under which the largest cluster is guaranteed to be benign, or empirically evaluate trajectory poisoning by an adversary that is actually adaptive to SafeFL.
minor comments (4)
- [Appendix A.2] The bullet numbering in Appendix A.2 uses the label 'e)' twice, first for the Scaling+DBA attack and then for the Adaptive attack; the numbering should be corrected.
- [Table 10(b)] The rows for Scaling+DBA and Trim+DBA in Table 10(b) are identical for every defense and every client count, which appears to be a copy-paste error and should be verified.
- [Figures 10(c)–(f)] Figures 10(c)–(f) in the appendix appear to be empty, with only captions and no plotted data or axes; these subfigures should be filled in or removed.
- [§4.2] The first sentence of Section 4.2 says 'the server possesses its own distinct dataset' before explaining that the server will generate a synthetic dataset; this wording is confusing and should be revised to avoid implying the server has a clean validation set.
Circularity Check
No circularity found: SafeFL's synthetic dataset is fitted to the model trajectory, not to the detection labels, and its reported detection is benchmarked externally; the median-rule metrics raise a reproducibility concern, not a circularity one.
full rationale
I walked the derivation chain: Eq. (2) and Algorithm 1 optimize the synthetic dataset D_syn to minimize the squared distance between a model trained on D_syn and a target global model from the trajectory, with no term involving the benign/malicious labels of clients, so there is no fitted-input-called-prediction loop. Detection in Section 4.4 then compares client losses on this fixed D_syn against ground-truth attack membership from external attack implementations (Trim, Scaling, DBA, hybrid, Neurotoxin, and others), and the reported DACC/FPR/FNR are direct confusion-matrix quantities rather than restatements of the optimization objective. The trajectory itself is built under the stated benign-majority clustering assumption in Eq. (1) of Section 4.2; that assumption is an input threat-model premise, not a result SafeFL derives, so it is not circular. The authors' own FedREDefense [69] appears only as a comparison baseline, and the threat model cites prior attacks including the authors' [24] only as benchmark definitions; neither citation carries the derivation. Separately, the paper's own text says SafeFL-ML 'identifies half of the clients as suspicious in each round' (Section 4.4, after Eq. (4)), which is arithmetically incompatible with Table 1's near-zero FPR and DACC near 1.00 under 30% malicious clients; this is an internal-consistency or reproducibility defect, not a reduction of a prediction to its inputs, so it does not increase the circularity score.
Assumptions & free parameters
free parameters (6)
- Trajectory length epsilon =
25 for MNIST/CIFAR-10/FEMNIST, 30 for STL-10/Tiny-ImageNet
- SynGen iterations Psi =
5000 (CIFAR-10/STL-10/MNIST), 8500 (FEMNIST), 10000 (Tiny-ImageNet)
- Step parameter Delta =
15
- Synthetic dataset size =
100
- Learning rate gamma for SynGen =
0.1
- Clustering algorithm pair =
K-means for trajectory, Mean-shift for loss clustering
assumptions (5)
- domain assumption The majority of clients are honest and their local models cluster together in parameter space.
- domain assumption Malicious local models incur higher loss on the synthetic dataset than benign models.
- domain assumption Dataset condensation from a global-model trajectory produces a synthetic dataset that separates malicious from benign behavior.
- domain assumption Attack implementations from cited papers behave as described when transplanted into this evaluation.
- ad hoc to paper The server can run K-means and Mean-shift clustering without knowing the number of clusters in advance.
Cite this review
Pith. "Pith review of Toward Malicious Clients Detection in Federated Learning." pith.science (2026). https://pith.science/paper/YCNTSINV
@misc{pith2026250509110,
author = {Pith},
title = {Pith review of: Toward Malicious Clients Detection in Federated Learning},
year = {2026},
howpublished = {\url{https://pith.science/paper/YCNTSINV}},
note = {Machine review of arXiv:2505.09110}
}
read the original abstract
Federated learning (FL) enables multiple clients to collaboratively train a global machine learning model without sharing their raw data. However, the decentralized nature of FL introduces vulnerabilities, particularly to poisoning attacks, where malicious clients manipulate their local models to disrupt the training process. While Byzantine-robust aggregation rules have been developed to mitigate such attacks, they remain inadequate against more advanced threats. In response, recent advancements have focused on FL detection techniques to identify potentially malicious participants. Unfortunately, these methods often misclassify numerous benign clients as threats or rely on unrealistic assumptions about the server's capabilities. In this paper, we propose a novel algorithm, SafeFL, specifically designed to accurately identify malicious clients in FL. The SafeFL approach involves the server collecting a series of global models to generate a synthetic dataset, which is then used to distinguish between malicious and benign models based on their behavior. Extensive testing demonstrates that SafeFL outperforms existing methods, offering superior efficiency and accuracy in detecting malicious clients.
Figures
Figures from the paper (9 more)
Reference graph
Works this paper leans on
-
[60]
Virat Shejwalkar and Amir Houmansadr. 2021. Manipulating the byzantine: Optimizing model poisoning attacks and defenses for federated learning. In NDSS
2021
-
[1]
d.].Federated Learning: Collaborative Machine Learning without Central- ized Training Data
[n. d.].Federated Learning: Collaborative Machine Learning without Central- ized Training Data. https://ai.googleblog.com/2017/04/federated-learning- collaborative.html
2017
-
[2]
d.].Utilization of FATE in Risk Management of Credit in Small and Micro Enter- prises
[n. d.].Utilization of FATE in Risk Management of Credit in Small and Micro Enter- prises. https://www.fedai.org/cases/utilization-of-fate-in-risk-management-of- credit-in-small-and-micro-\enterprises/
-
[3]
Martin Abadi, Andy Chu, Ian Goodfellow, H Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang. 2016. Deep learning with differential privacy. In CCS
2016
-
[4]
Maryam Badar, Sandipan Sikdar, Wolfgang Nejdl, and Marco Fisichella. 2024. Fairtrade: Achieving pareto-optimal trade-offs between balanced accuracy and fairness in federated learning. InAAAI
2024
-
[5]
Eugene Bagdasaryan, Andreas Veit, Yiqing Hua, Deborah Estrin, and Vitaly Shmatikov. 2020. How to backdoor federated learning. InAISTATS
2020
-
[6]
Gilad Baruch, Moran Baruch, and Yoav Goldberg. 2019. A little is enough: Circumventing defenses for distributed learning. InNeurIPS
work page 2019
-
[7]
Enrique Tomás Martínez Beltrán, Mario Quiles Pérez, Pedro Miguel Sánchez Sánchez, Sergio López Bernal, Gérôme Bovet, Manuel Gil Pérez, Grego- rio Martínez Pérez, and Alberto Huertas Celdrán. 2022. Decentralized Federated Learning: Fundamentals, State-of-the-art, Frameworks, Trends, and Challenges. InarXiv preprint arXiv:2211.08413
work page Pith review arXiv 2022
Show all 85 references
-
[8]
Arjun Nitin Bhagoji, Supriyo Chakraborty, Prateek Mittal, and Seraphin Calo
-
[9]
Peva Blanchard, El Mahdi El Mhamdi, Rachid Guerraoui, and Julien Stainer
-
[10]
Keith Bonawitz. 2019. Towards federated learning at scale: System design. In SysML
2019
-
[11]
Beyza Bozdemir, Sébastien Canard, Orhan Ermis, Helen Möllering, Melek Önen, and Thomas Schneider. 2021. Privacy-preserving density-based clustering. In ASIACCS
2021
-
[12]
Brendan Mcmahan, Virginia Smith, and Ameet Talwalkar
Sebastian Caldas, Sai Meher Karthik Duddu, Peter Wu, Tian Li, Jakub Konen, H. Brendan Mcmahan, Virginia Smith, and Ameet Talwalkar. 2019. LEAF: A Benchmark for Federated Settings. InNeurIPS
2019
-
[13]
Ricardo JGB Campello, Davoud Moulavi, and Jörg Sander. 2013. Density-based clustering based on hierarchical density estimates. InPAKDD
2013
-
[14]
Xiaoyu Cao, Minghong Fang, Jia Liu, and Neil Zhenqiang Gong. 2021. FLTrust: Byzantine-robust Federated Learning via Trust Bootstrapping. InNDSS
2021
-
[15]
Xiaoyu Cao and Neil Zhenqiang Gong. 2022. Mpaf: Model poisoning attacks to federated learning based on fake clients. InCVPR Workshops
2022
-
[16]
George Cazenavette, Tongzhou Wang, Antonio Torralba, Alexei A Efros, and Jun-Yan Zhu. 2022. Dataset distillation by matching training trajectories. In CVPR
2022
-
[17]
Hongyan Chang and Reza Shokri. 2023. Bias propagation in federated learning. InICLR
2023
-
[18]
Min Chen, Yang Xu, Hongli Xu, and Liusheng Huang. 2023. Enhancing de- centralized federated learning for non-iid data on heterogeneous devices. In ICDE
2023
-
[19]
Yizong Cheng. 1995. Mean shift, mode seeking, and clustering. InIEEE transac- tions on pattern analysis and machine intelligence
1995
-
[20]
Adam Coates, Andrew Ng, and Honglak Lee. 2011. An analysis of single-layer networks in unsupervised feature learning. InAISTATS
2011
-
[21]
Jia Deng, Wei Dong, Richard Socher, Li-Jia Li, Kai Li, and Li Fei-Fei. 2009. Imagenet: A large-scale hierarchical image database. InCVPR
2009
-
[22]
Cynthia Dwork, Moritz Hardt, Toniann Pitassi, Omer Reingold, and Richard Zemel. 2012. Fairness through awareness. InITCS
2012
-
[23]
El Mahdi El-Mhamdi, Sadegh Farhadkhani, Rachid Guerraoui, Arsany Guirguis, Lê-Nguyên Hoang, and Sébastien Rouault. 2021. Collaborative learning in the jungle (decentralized, byzantine, heterogeneous, asynchronous and nonconvex learning). InNeurIPS
2021
-
[24]
Minghong Fang, Xiaoyu Cao, Jinyuan Jia, and Neil Gong. 2020. Local model poisoning attacks to Byzantine-robust federated learning. InUSENIX Security Symposium
2020
-
[25]
Minghong Fang, Jia Liu, Neil Zhenqiang Gong, and Elizabeth S Bentley. 2022. Aflguard: Byzantine-robust asynchronous federated learning. InACSASC
2022
-
[26]
Minghong Fang, Zhuqing Liu, Xuecen Zhao, and Jia Liu. 2025. Byzantine-Robust Federated Learning over Ring-All-Reduce Distributed Computing. InThe Web Conference
2025
-
[27]
Minghong Fang, Seyedsina Nabavirazavi, Zhuqing Liu, Wei Sun, Sun- dararaja Sitharama Iyengar, and Haibo Yang. 2025. Do We Really Need to Design New Byzantine-robust Aggregation Rules?. InNDSS
2025
-
[28]
Minghong Fang, Xilong Wang, and Neil Zhenqiang Gong. 2025. Provably Robust Federated Reinforcement Learning. InThe Web Conference
2025
-
[29]
Minghong Fang, Zifan Zhang, Hairi, Prashant Khanduri, Jia Liu, Songtao Lu, Yuchen Liu, and Neil Gong. 2024. Byzantine-robust decentralized federated learning. InCCS
2024
-
[30]
Hossein Fereidooni, Alessandro Pegoraro, Phillip Rieger, Alexandra Dmitrienko, and Ahmad-Reza Sadeghi. 2024. FreqFed: A Frequency Analysis-Based Approach for Mitigating Poisoning Attacks in Federated Learning. InNDSS
2024
-
[31]
Moritz Hardt, Eric Price, and Nati Srebro. 2016. Equality of opportunity in supervised learning. InNeurIPS
2016
-
[32]
John A Hartigan and Manchek A Wong. 1979. Algorithm AS 136: A k-means clustering algorithm. InJournal of the royal statistical society. series c (applied statistics)
1979
-
[33]
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. 2016. Deep Residual Learning for Image Recognition. InCVPR
2016
-
[34]
Shivam Kalra, Junfeng Wen, Jesse C Cresswell, Maksims Volkovs, and HR Tizhoosh. 2023. Decentralized federated learning through proxy model sharing. InNature Communications
2023
-
[35]
Sai Praneeth Karimireddy, Lie He, and Martin Jaggi. 2022. Byzantine-robust learning on heterogeneous datasets via bucketing. InICLR
2022
-
[36]
Sai Praneeth Karimireddy, Satyen Kale, Mehryar Mohri, Sashank Reddi, Sebas- tian Stich, and Ananda Theertha Suresh. 2020. Scaffold: Stochastic controlled averaging for federated learning. InICML
2020
-
[37]
Jang-Hyun Kim, Jinuk Kim, Seong Joon Oh, Sangdoo Yun, Hwanjun Song, Joon- hyun Jeong, Jung-Woo Ha, and Hyun Oh Song. 2022. Dataset condensation via efficient synthetic-data parameterization. InICML
2022
-
[38]
Krizhevsky and G
A. Krizhevsky and G. Hinton. 2009. Learning multiple layers of features from tiny images.Handbook of Systemic Autoimmune Diseases(2009)
2009
-
[39]
Kavita Kumari, Phillip Rieger, Hossein Fereidooni, Murtuza Jadliwala, and Ahmad- Reza Sadeghi. 2023. BayBFed: Bayesian Backdoor Defense for Federated Learning. InIEEE Symposium on Security and Privacy
2023
-
[40]
Yann LeCun, Corinna Cortes, and CJ Burges. 1998. MNIST handwritten digit database.A vailable: http://yann. lecun. com/exdb/mnist(1998)
1998
-
[41]
Liping Li, Wei Xu, Tianyi Chen, Georgios B Giannakis, and Qing Ling. 2019. RSA: Byzantine-robust stochastic aggregation methods for distributed learning from heterogeneous datasets. InAAAI
2019
-
[42]
Songze Li and Yanbo Dai. 2024. BackdoorIndicator: Leveraging OOD Data for Proactive Backdoor Detection in Federated Learning. InUSENIX Security Sympo- sium
2024
-
[43]
Tian Li, Shengyuan Hu, Ahmad Beirami, and Virginia Smith. 2021. Ditto: Fair and robust federated learning through personalization. InICML
2021
-
[44]
Tian Li, Anit Kumar Sahu, Manzil Zaheer, Maziar Sanjabi, Ameet Talwalkar, and Virginia Smith. 2020. Federated optimization in heterogeneous networks. In MLSys
2020
-
[45]
Tian Li, Maziar Sanjabi, Ahmad Beirami, and Virginia Smith. 2020. Fair resource allocation in federated learning. InICLR
2020
-
[46]
Xiang Li, Kaixuan Huang, Wenhao Yang, Shusen Wang, and Zhihua Zhang. 2020. On the convergence of fedavg on non-iid data. InICLR
2020
-
[47]
Songhua Liu, Jingwen Ye, Runpeng Yu, and Xinchao Wang. 2023. Slimmable dataset condensation. InCVPR
2023
-
[48]
Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Agüera y Arcas
H. Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Agüera y Arcas. 2017. Communication-Efficient Learning of Deep Net- works from Decentralized Data. InAISTATS
2017
-
[49]
Mehryar Mohri, Gary Sivek, and Ananda Theertha Suresh. 2019. Agnostic federated learning. InICML
2019
-
[50]
Hamid Mozaffari, Virat Shejwalkar, and Amir Houmansadr. 2023. Every Vote Counts: Ranking-Based Training of Federated Learning to Resist Poisoning At- tacks. InUSENIX Security Symposium
2023
-
[51]
Luis Muñoz-González, Kenneth T Co, and Emil C Lupu. 2019. Byzantine-robust federated machine learning through adaptive model averaging.arXiv preprint arXiv:1909.05125(2019)
2019 arXiv
-
[52]
Mohammad Naseri, Yufei Han, Enrico Mariconti, Yun Shen, Gianluca Stringhini, and Emiliano De Cristofaro. 2022. Cerberus: Exploring Federated Prediction of Security Events. InCCS
2022
-
[53]
Thuy Dung Nguyen, Tuan A Nguyen, Anh Tran, Khoa D Doan, and Kok-Seng Wong. 2023. Iba: Towards irreversible backdoor attacks in federated learning. In NeurIPS
2023
-
[54]
Thien Duc Nguyen, Phillip Rieger, Roberta De Viti, Huili Chen, Björn B Bran- denburg, Hossein Yalame, Helen Möllering, Hossein Fereidooni, Samuel Marchal, Markus Miettinen, et al. 2022. FLAME: Taming backdoors in federated learning. InUSENIX Security Symposium
2022
-
[55]
Mustafa Safa Ozdayi, Murat Kantarcioglu, and Yulia R Gel. 2021. Defending against backdoors in federated learning with robust learning rate. InAAAI
2021
-
[56]
Matthias Paulik, Matt Seigel, Henry Mason, Dominic Telaar, Joris Kluivers, Rogier van Dalen, Chi Wai Lau, Luke Carlson, Filip Granqvist, Chris Vandevelde, et al
-
[57]
Renjie Pi, Weizhong Zhang, Yueqi Xie, Jiahui Gao, Xiaoyu Wang, Sunghun Kim, and Qifeng Chen. 2023. Dynafed: Tackling client data heterogeneity with global dynamics. InCVPR
2023
-
[58]
Shashank Rajput, Hongyi Wang, Zachary Charles, and Dimitris Papailiopoulos
-
[59]
Phillip Rieger, Thien Duc Nguyen, Markus Miettinen, and Ahmad-Reza Sadeghi
-
[61]
Virat Shejwalkar, Amir Houmansadr, Peter Kairouz, and Daniel Ramage. 2022. Back to the drawing board: A critical evaluation of poisoning attacks on produc- tion federated learning. InIEEE Symposium on Security and Privacy
2022
-
[62]
InNeurIPS
DETOX: A redundancy-based framework for faster and more robust gradient aggregation. InNeurIPS. ASIA CCS ’25, August 25–29, 2025, Hanoi, Vietnam Zhihao Dou, Jiaqi Wang, Wei Sun, Zhuqing Liu, and Minghong Fang
2025
-
[63]
Jianyu Wang, Qinghua Liu, Hao Liang, Gauri Joshi, and H Vincent Poor. 2020. Tackling the objective inconsistency problem in heterogeneous federated opti- mization.NeurIPS
2020
-
[64]
Kai Wang, Bo Zhao, Xiangyu Peng, Zheng Zhu, Shuo Yang, Shuo Wang, Guan Huang, Hakan Bilen, Xinchao Wang, and Yang You. 2022. Cafe: Learning to condense dataset by aligning features. InCVPR
2022
-
[65]
Ning Wang, Yang Xiao, Yimin Chen, Yang Hu, Wenjing Lou, and Y Thomas Hou
-
[66]
Wenbin Wang, Qiwen Ma, Zifan Zhang, Yuchen Liu, Zhuqing Liu, and Minghong Fang. 2025. Poisoning Attacks and Defenses to Federated Unlearning. InThe Web Conference
2025
-
[67]
Vale Tolpegin, Stacey Truex, Mehmet Emre Gursoy, and Ling Liu. 2020. Data poisoning attacks against federated learning systems. InESORICS
2020
-
[68]
Cong Xie, Sanmi Koyejo, and Indranil Gupta. 2019. Zeno: Distributed stochastic gradient descent with suspicion-based fault-tolerance. InICML
2019
-
[69]
Yueqi Xie, Minghong Fang, and Neil Zhenqiang Gong. 2024. FedREDefense: Defending against Model Poisoning Attacks for Federated Learning using Model Update Reconstruction Error. InICML
2024
-
[70]
Dong Yin, Yudong Chen, Kannan Ramchandran, and Peter Bartlett. 2018. Byzantine-Robust Distributed Learning: Towards Optimal Statistical Rates. In ICML
2018
-
[71]
InASIACCS
Flare: defending federated learning against model poisoning attacks via latent space representations. InASIACCS
-
[72]
Yi Zeng, Minzhou Pan, Hoang Anh Just, Lingjuan Lyu, Meikang Qiu, and Ruoxi Jia
-
[73]
Chulin Xie, Keli Huang, Pin-Yu Chen, and Bo Li. 2020. Dba: Distributed backdoor attacks against federated learning. InICLR
2020
-
[74]
Zifan Zhang, Minghong Fang, Jiayuan Huang, and Yuchen Liu. 2024. Poisoning attacks on federated learning-based wireless traffic prediction. InIFIP Networking Conference
2024
-
[75]
Zhengming Zhang, Ashwinee Panda, Linyue Song, Yaoqing Yang, Michael Ma- honey, Prateek Mittal, Ramchandran Kannan, and Joseph Gonzalez. 2022. Neuro- toxin: Durable backdoors in federated learning. InICML
2022
-
[76]
Bo Zhao and Hakan Bilen. 2023. Dataset condensation with distribution matching. InW ACV
2023
-
[77]
Ming Yin, Yichang Xu, Minghong Fang, and Neil Zhenqiang Gong. 2024. Poison- ing federated recommender systems with fake users. InThe Web Conference
2024
-
[78]
BDIndicator
Zhuangdi Zhu, Junyuan Hong, and Jiayu Zhou. 2021. Data-free knowledge distillation for heterogeneous federated learning. InICML. Table 8: The CNN architecture. Layer Size Input 28×28×1 Convolution+ReLU 3×3×30 Max Pooling 2×2 Convolution+ReLU 3×3×5 Max Pooling 2×2 Fully Connect...
2021
-
[80]
Zaixi Zhang, Xiaoyu Cao, Jinyuan Jia, and Neil Zhenqiang Gong. 2022. FLDetector: Defending federated learning against model poisoning attacks via detecting malicious clients. InKDD
2022
-
[84]
Bo Zhao, Konda Reddy Mopuri, and Hakan Bilen. 2021. Dataset condensation with gradient matching. InICLR
2021
-
[2017]
In NeurIPS
Machine learning with adversaries: Byzantine tolerant gradient descent. In NeurIPS
-
[2019]
Analyzing federated learning through an adversarial lens. InICML
-
[2021]
Federated evaluation and tuning for on-device personalization: System design & applications.arXiv preprint arXiv:2102.08503(2021)
2021 arXiv
-
[2022]
Deepsight: Mitigating backdoor attacks in federated learning through deep model inspection. InNDSS
-
[2023]
Narcissus: A practical clean-label backdoor attack with limited information. InCCS
Reviewed August 15, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.