← all papers · overview

Fedmid: A Data-free Method For Using Intermediate Outputs As A Defense Mechanism Against Poisoning Attacks In Federated Learning

Abstract

Federated learning combines local updates from clients to produce a global model, which is susceptible to poisoning attacks. Most previous defense strategies relied on vectors derived from projections of local updates on a Euclidean space; however, these methods fail to accurately represent the functionality and structure of local models, resulting in inconsistent performance. Here, we present a new paradigm to defend against poisoning attacks in federated learning using functional mappings of local models based on intermediate outputs. Experiments show that our mechanism is robust under a broad range of computing conditions and advanced attack scenarios, enabling safer collaboration among data-sensitive participants via federated learning.

Related papers

Ranked by semantic similarity — how closely each paper's abstract matches this one (100% = near-identical topic).