Skip to content
Open access

MAD-Based Update Filtering for Non-IID Federated Learning: Robustness Analysis Under Poisoning Attacks

2026 · IEEE Access · Vol 14, pp. 118452-118463 · 0 citations · 26 references
Computer Science

TL;DR

A ablation indicates that removing MAD filtering substantially reduces class-balanced performance on HAM10000 under noise injection, and a diagnostic analysis shows that the cosine-distance signal separates benign and malicious updates strongly under noise injection but weakly under sign flipping.

Abstract

Federated Learning enables collaborative model training without sharing raw client data, making it attractive for privacy-sensitive domains. However, its performance degrades when local data are non-independent and identically distributed (non-IID) and when malicious clients inject adversarial updates; robust aggregation alone can be insufficient, especially for imbalanced medical datasets where minority-class degradation is masked by overall accuracy. This paper proposes a Median Absolute Deviation (MAD)-based malicious-update filtering framework for non-IID federated learning. The server flags and excludes abnormal client updates before aggregation, using a coordinate-wise median reference and a modified Z-score over cosine distances. Unlike trust-based defenses, it requires no clean server-side dataset and provides an interpretable, per-round diagnostic. We evaluate it on CIFAR-10 and HAM10000 under noise injection and sign flipping against eight robust aggregation baselines, under a unified protocol that reports Accuracy and Macro-F1 at the same validation-selected checkpoint, averaged over three seeds. On CIFAR-10, the proposed method attains a mean Macro-F1 comparable to or better than the strongest baselines under both attacks (75.9% and 67.6%). On HAM10000 under noise injection it achieves the highest mean accuracy (74.0%) with a competitive Macro-F1, whereas under sign flipping it is only mid-ranked. An ablation indicates that removing MAD filtering substantially reduces class-balanced performance on HAM10000 under noise injection, and a diagnostic analysis shows that the cosine-distance signal separates benign and malicious updates strongly under noise injection but weakly under sign flipping. These results characterize both the robustness potential and the boundary conditions of update-level median filtering in non-IID federated learning.

Read PDF

Similar papers

Conference Aug 2026

URP-FL: Robust and Personalized Federated Learning under Heterogeneous and Adversarial Conditions

Federated learning is appealing for privacy-sensitive network systems, yet its practical deployment remains hindered by the following three recurring challenges: (1) client drift under non-IID data, (2) vulnerability to corrupted updates, and (3) the communication cost of repeated model exchange. Most existing approaches address these issues in isolation. While analytically convenient, this separation often fails to reflect real-world conditions. For instance, defenses against poisoning may suppress useful updates, while personalization and compression can alter the aggregation geometry itself. In this paper, we study these effects jointly and propose URP-FL, a compact training framework that integrates reliability-aware aggregation, local regularization for drift control, and sparse client uploads. We provide theoretical analysis establishing a convergence bound with distinct terms capturing optimization error, data heterogeneity, and adversarial impact. Experiments on a non-IID image classification benchmark with sign-flip and label-flip attacks demonstrate the benefits of the unified design. Compared to FedAvg and FedProx, this URP-FL maintains accuracy under attack while reducing transmitted parameters by approximately 75%. Rather than presenting a production ready system, it offers a reproducible and technically coherent step toward federated learning that is more robust under realistic conditions.

Hua Kun, Wei Wang · 0 citations
Open access Aug 2026

TGSFL: Trustworthy group-signature-based federated learning for LLMs in healthcare

Federated learning (FL) enables collaborative model training without sharing raw data, making it well suited to privacy-sensitive healthcare applications. However, malicious model updates and anonymous participation abuse can disrupt optimization and undermine the reliability of downstream medical AI systems. Existing defenses often address robustness or privacy separately, with limited support for accountable authentication and client revocation. To address these limitations, we propose TGSFL, a Trustworthy Group-Signature-Based Federated Learning framework for healthcare large language models (LLMs). The proposed framework integrates dynamic group-signature authentication, per-client local differential privacy, and dual-layer malicious-update detection to identify and suppress adversarial updates before aggregation. It further supports anonymous yet traceable participation and dynamic revocation of persistently malicious clients. Theoretical analysis establishes conditional traceability, dynamic revocation, and per-client local differential privacy. Experiments under multiple Byzantine attack scenarios show that TGSFL improves robustness and training stability over existing baselines while introducing only modest computational overhead, demonstrating its practicality for secure and privacy-preserving medical AI training.

Xinying Liu, Chunhua Jin, Yu-Peng Wu et al. · 0 citations
Conference Open access 2026

Activation-Level Privacy and Certified Robustness in Federated Split Learning for IoT Intrusion Detection

SplittingFed-DP relocates the Gaussian DP mechanism from the high-dimensional gradient to the low-dimensional activation space at the cut layer, audited under Rényi differential privacy and proves that this same Gaussian release coincides with the randomised-smoothing operator of Cohen et al. at the cut layer.

Rguibi Arjdal, Y. Asimi, Ahmed Asimi et al. · 0 citations
Open access Jul 2026

A Comprehensive Defense Framework Against Poisoning Backdoor Attacks in Federated Learning

This work employs the novel dimensionality reduction technique UMAP and a stringent filtering mechanism to effectively identify and exclude potential malicious participants without relying on traditional noise addition methods and demonstrates that the proposed method maintains high main task accuracy while effectively mitigating backdoor attacks across various attack scenarios.

Chun-I Fan, Hsin-Yen Wang, Tomohiro Morikawa · 0 citations
Preprint Aug 2026

FL-OA: A Byzantine-Robust Federated Learning Framework with Outsourced Auditing for Intelligent Devices

In FL-OA, the server collaborates with third-party organization that holds an additional root dataset to perform outsourced auditing, thereby enabling the server to achieve robust aggregation without strong assumptions, demonstrating that FL-OA outperforms existing defense methods against Byzantine attacks.

Hongliang Zhang, Zhongyuan Yu, Fenghua Xu et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.