Defending Federated Learning from Collaborative Poisoning Attacks: A Clique-Based Detection Framework

Dimitrios Anastasiadis, Ioannis Refanidis · Electronics · 2025

Federated Learning (FL) systems are increasingly vulnerable to data poisoning attacks, in which malicious clients attempt to manipulate their training data in order to compromise the corresponding machine learning model. Existing detection techniques rely mostly on identifying clients who provide weight updates that significantly diverge from the average across multiple training rounds. In this work, we propose a Clique-Based Detection Framework (CBDF) that focuses on similarity patterns between client updates instead of their deviation. Specifically, we make use of the Euclidean distance to measure similarity between the weight update vectors of different clients over training iterations. Clients that provide consistently similar weight updates and exceed a predefined threshold are flagged as potential adversaries. Therefore, this method detects the coordination patterns of the attackers and uses them to strengthen FL systems against sophisticated, coordinated data poisoning attacks. We validate the effectiveness of this approach through extensive experimental evaluation. Moreover, we provide suggestions regarding fine-tuning hyperparameters to maximize the performance of the detection method. This approach represents a novel advancement in protecting FL models from malicious interference.

Read the paper · More papers on PaperTik