Adaptive Aggregation for Robust Federated Learning Against Label Flipping and Backdoor Attacks

Chaima Lhasnaoui, Oscar Bergling, Addi Ait‐Mlouk, Tarik Agouti · 2025

Federated learning (FL) has emerged as a powerful solution for collaborative model training in domains with strict data privacy requirements, such as medical imaging. However, FL remains vulnerable to data poisoning attacks, which can significantly compromise the integrity of the global model. This study investigates the impact of two representative poisoning strategies-label flipping and backdoor injection-within an FL setup using a convolutional neural network trained on chest X-ray images for pneumonia detection. Our experimental results reveal that both attacks can severely degrade the global model's performance, either by reducing classification accuracy or embedding hidden misclassification behaviors triggered during inference. To address these vulnerabilities, we propose an adaptive aggregation strategy that assigns weights to client updates based on their performance on a clean validation set. This approach enhances robustness against poisoning without requiring modifications on the client side. Experimental results demonstrate that the proposed defense effectively mitigates the impact of both attack types, maintaining high accuracy on clean data while minimizing the influence of poisoned updates. These findings highlight the urgent need for integrated security measures in FL systems, particularly in high-stakes applications such as clinical diagnostics.

Read the paper · More papers on PaperTik