arXiv AI By Tianhang Zheng, Yanlu Li, Bohan Deng, Baochun Li

FedReview: Review and Dispose Poisoned Updates without Validation Datasets or Historic Knowledge

Read the original on arXiv AI →

FedReview is a review-based mechanism for federated learning that identifies and removes poisoned model updates without needing a server-side validation dataset or historic client knowledge. In each training round, the server randomly selects reviewers who evaluate incoming updates on their own training data, rank them, and estimate how many low-quality updates are likely poisoned. The server then aggregates these rankings via majority voting to filter out suspicious updates during model aggregation, enabling robust global model training even in adversarial settings.

Machine-generated by The Flow from the publisher's headline and feed description — not written or checked by a human. The full article lives at arXiv AI.

arXiv Machine Learning
Sep 23

FedNIA: Noise-Induced Activation Analysis for Mitigating Data Poisoning in Federated Learning

FedNIA is a defense framework for federated learning that identifies and excludes malicious clients without needing a central test dataset. It works by injecting random noise inputs and analyzing layerwise activation patterns with an autoencoder to detect abnormal behaviors caused by data poisoning. The method can counter various attack types—including sample poisoning, label flipping, and backdoors—even when multiple attackers collaborate, and shows strong performance on non‑iid federated datasets.

By Ehsan Hallaji, Roozbeh Razavi-Far, Mehrdad Saif
arXiv Machine Learning
Aug 20

FedLNS: Leverage LayerNorm Signature Modeling to Mitigate Adversarial Manipulation in Federated LLMs

FedLNS is a server‑side framework that screens federated learning updates by representing each client’s contribution through changes in trainable normalization‑layer parameters, creating lightweight signatures that can be compared against a history‑aware cross‑client reference. The method requires no extra client‑to‑server communication, raw data, or labeled attack examples, and after screening, the remaining full‑model updates are aggregated with standard federated learning rules. Experiments on GPT‑style, BERT‑style, and LLaMA‑style models with 200 clients demonstrate that FedLNS achieves lower test perplexity than six baselines even when 40% of the population performs target manipulation under both IID and non‑IID data partitions.

By Kai Li, Jong-Ik Park, Carlee Joe-Wong, Wei Ni, Falko Dressler