Reducing Defense Vulnerabilities in Federated Learning: A Neuron-Centric ApproachShow others and affiliations
2025 (English)In: Applied Sciences, E-ISSN 2076-3417, Vol. 15, no 11, article id 6007Article in journal (Refereed) Published
Abstract [en]
Federated learning is a distributed machine learning approach where end users train local models with their own data and combine model updates on a reliable server to create a global model. Despite its advantages, this distributed structure is vulnerable to attacks as end users keep their data and training process private. Current defense mechanisms often fail when facing different attack types or high percentages of malicious participants. This paper proposes a new defense algorithm called Neuron-Centric Federated Learning Defense (NC-FLD), a novel approach that dynamically identifies and analyzes the most significant neurons across model layers rather than examining entire gradient spaces. Unlike existing methods that analyze all parameters equally, NC-FLD creates feature vectors from specifically selected neurons that show the highest training impact, then applies dimensionality reduction to enhance their discriminative features. We conduct experiments with various attack scenarios and different malicious participant rates across multiple datasets (CIFAR-10, F-MNIST, and MNIST). Additionally, we perform simulations on the GTSR dataset as a real-world application. Experimental results demonstrate that NC-FLD successfully defends against diverse attack scenarios in both IID and non-IID dataset distributions, maintaining accuracy above 70% with 40% malicious participation, a 5–15% improvement over the state-of-the-art method, showing enhanced robustness across diverse data distributions while effectively mitigating the impacts of both data and model poisoning attacks.
Place, publisher, year, edition, pages
Multidisciplinary Digital Publishing Institute (MDPI) , 2025. Vol. 15, no 11, article id 6007
Keywords [en]
data poisoning, deep learning security, federated learning, model poisoning, poisoning attacks, Deep learning, Dimensionality reduction, Attacks scenarios, Distributed machine learning, End-users, Local model, Machine learning approaches, Malicious participant
National Category
Computer Sciences
Identifiers
URN: urn:nbn:se:ri:diva-79449DOI: 10.3390/app15116007Scopus ID: 2-s2.0-105007777327OAI: oai:DiVA.org:ri-79449DiVA, id: diva2:2017815
Note
Article; Granskad
2025-12-012025-12-012025-12-01Bibliographically approved