DDFL: A Robust Clustering-Based Defense Against Poisoning Attacks in Decentralized Federated Learning
Asanka Amarasinghe, Yushan Siriwardhana, Tharaka Mawanane Hewa, Mika Ylianttila · 2025
Federated Learning (FL) is a privacy-preserving decentralized Machine Learning (ML) paradigm where the users are massively distributed and coordinated by a central server during the training process. The FL server is a single point of failure, therefore, an absence or a delay with the server severely affects the training process. This leads to further extending FL into Decentralized Federated Learning (DFL) where the learning happens in a peer-to-peer manner without the involvement of a central server. The peer-to-peer sharing of model updates further increases the threat of poisoning attacks, which is an inherent vulnerability in FL systems. Defenses against poisoning attacks in DFL systems are not extensively discussed in the state-of-the-art research, and the existing algorithms perform poorly when the client data distribution is non-IID. In this work, we extensively evaluate the performance of the existing defenses with non-IID client data distribution, and propose DDFL, a novel clustering-based defense mechanism for DFL systems. DDFL does not rely on empirical parameters but considers model update history for the defense. Moreover, we provide a comprehensive analysis for DDFL's effectiveness with non-IID data under various poisoning attack scenarios. Our results show that DDFL performs better in removing poisoners compared with the state-of-the-art techniques in non-IID scenarios.