PurifyFL: Non-Interactive Privacy-Preserving Federated Learning Against Poisoning Attacks Based on Single Server
Yanli Ren, Zhe Yang, Guorui Feng, Xinpeng Zhang · IEEE Transactions on Emerging Topics in Computational Intelligence · 2025
Privacy-preserving federated learning (PPFL) allows multiple users to collaboratively train models on local devices without the the risk of privacy leakage. However, PPFL is prone to be disrupted by poisoning attacks for the server being forbbiden from accessing users' updates. The existing protocols focusing on poisoning attacks in PPFL generally use two servers to interactively execute protocols to defend against poisoning attacks, while the other ones using a single server require multiple rounds of server-user interactions, both of which incur significant communication overheads. We propose PurifyFL, a privacy-preserving poisoning attacks defense strategy. PurifyFL only relies on a single server while most of the previous works depend on two non-colluding servers, which are impractical in reality. Moreover, We also achieve non-interactivity between the users and the server. Experiments show that PurifyFL can effectively resist typical poisoning attacks with lower computational and communication overheads compared to existing works.