TY - GEN
T1 - Defending Against Malicious Clients in Robust Heterogeneous Federated Learning
AU - Wang, Zijun
AU - Gai, Keke
AU - Yu, Jing
AU - Zhu, Liehuang
N1 - Publisher Copyright:
© ICST Institute for Computer Sciences, Social Informatics and Telecommunications Engineering 2026.
PY - 2026
Y1 - 2026
N2 - Federated Learning (FL) is a technical alternative for achieving collaboration-aware privacy-preserving Machine Learning (ML); however, modeling heterogeneous FL is a challenging issue as clients often encounter the scenario of training various local ML models due to varied data and tasks. To be specific, unexpected behaviors of malicious clients, e.g., sending erroneous updates data to the server, may threaten the training effectiveness of FL systems. In this paper, we propose a heterogeneous FL approach to defend against malicious clients from the perspective of strengthening robustness. We directly align the public data with the model feedback and re-distribute the contribution of mutual learning from the collaborative training process, in order to improve the adaptability in various contexts and eliminate the negative impacts on the accuracy from malicious clients. Our experiments have demonstrated that the proposed approach has a superior performance in both model alignment and data heterogeneity. The impact from malicious data during the training process can be effectively eliminated and the model accuracy of benign clients can be successfully maintained.
AB - Federated Learning (FL) is a technical alternative for achieving collaboration-aware privacy-preserving Machine Learning (ML); however, modeling heterogeneous FL is a challenging issue as clients often encounter the scenario of training various local ML models due to varied data and tasks. To be specific, unexpected behaviors of malicious clients, e.g., sending erroneous updates data to the server, may threaten the training effectiveness of FL systems. In this paper, we propose a heterogeneous FL approach to defend against malicious clients from the perspective of strengthening robustness. We directly align the public data with the model feedback and re-distribute the contribution of mutual learning from the collaborative training process, in order to improve the adaptability in various contexts and eliminate the negative impacts on the accuracy from malicious clients. Our experiments have demonstrated that the proposed approach has a superior performance in both model alignment and data heterogeneity. The impact from malicious data during the training process can be effectively eliminated and the model accuracy of benign clients can be successfully maintained.
KW - Data Heterogeneity
KW - Federated Learning
KW - Knowledge Distillation
KW - Malicious Client
UR - https://www.scopus.com/pages/publications/105040509889
U2 - 10.1007/978-3-032-23450-6_15
DO - 10.1007/978-3-032-23450-6_15
M3 - Conference contribution
AN - SCOPUS:105040509889
SN - 9783032234490
T3 - Lecture Notes of the Institute for Computer Sciences, Social-Informatics and Telecommunications Engineering, LNICST
SP - 290
EP - 303
BT - Security and Privacy in Communication Networks - 21st EAI International Conference, SecureComm 2025, Proceedings
A2 - Liang, Wei
A2 - Kung, Sun-Yuan
A2 - Qiu, Meikang
PB - Springer Science and Business Media Deutschland GmbH
T2 - 21st EAI International Conference on Security and Privacy in Communication Networks, SecureComm 2025
Y2 - 4 July 2025 through 6 July 2025
ER -