Detection of Poisoning Attacks in Federated Learning with Non-IID data
Divya Bhatt, Le Gruenwald · 2025
Federated Learning (FL) is a decentralized approach to training machine learning models while preserving the privacy of training data. In FL, the training data remains on local clients, and only model updates are shared with a central server to collaboratively learn a global model. However, this decentralized nature makes FL vulnerable to poisoning attacks, where malicious clients can compromise the integrity of the model by submitting manipulated updates. To defend against such attacks, we propose a new defense algorithm called RBF, based on Radial Basis Functions. The RBF defense algorithm constructs a similarity matrix between client model updates and then analyzes this matrix to detect anomalous patterns that may indicate malicious behavior. Identified malicious clients are excluded from the aggregation process to enhance the robustness and prediction accuracy of the global model. We evaluate RBF on three real-world datasets using four different learning models. Its performance is compared against two existing kernel-based defense algorithms: KPCA with KMeans (Kernel Principal Component Analysis with clustering) and LoMar (Local Malicious Factor using Kernel Density Estimation). Experimental results demonstrate that RBF outperforms both baselines across standard evaluation metrics, including Precision, Recall, F1-Score, Attack Success Rate, and Global Prediction Accuracy. Additionally, RBF achieves the lowest execution time with two models and comparable performance with the other two models. Further experiments varying the number of clients, the proportion of malicious participants, and data heterogeneity (IID vs Non-IID) show that RBF maintains stable and competitive performance under diverse conditions. These findings establish RBF as an effective and efficient defense against poisoning attacks in federated learning systems.