State-of-the-Art Defense Schemes Against Byzantine Attack in Federated Learning

Bingbing Li, Fadoua Abdoulmoulah · 2025

A serious threat faced by federated learning systems is Byzantine attack. The decentralized nature of federated learning, coupled with non-independent identically distribution of data across participants increase the severity of the threat, rendering robust and adaptive defense crucial to maintaining system security and reliability. This paper summarizes state-of-the-art defense mechanisms to mitigate Byzantine attack in federated learning systems. We introduce a structured taxonomy to categorize existing defense schemes according to their underlying approaches, including differential privacy, optimization, distance geometric, and gradient statistics. The defense schemes are discussed and compared in terms of their aggregation criterion, global model calculation method, and data distribution. We aim to clarify and provide a wholistic understanding of these approaches and assess them, highlighting their limitations and practical applicability, particularly within various data distribution scenarios.

Read the paper · More papers on PaperTik