Defending federated learning systems against untargeted sybil attacks in non-IID environments
Ali Abduelmula, Ziad Kobti · Procedia Computer Science · 2025
Federated Learning systems are vulnerable to Sybil attacks, where malicious clients inject multiple fake identities to corrupt the learning process. We propose mitigating untargeted Sybil attacks using a robust aggregation method that integrates FoolsGold with Sinkhorn-enhanced Earth Mover’s Distance (EMD) and a multi-step trust-weighting strategy. FoolsGold assigns trust scores based on client update similarity, while Sinkhorn-enhanced EMD refines Sybil detection by computing transport distances between gradient distributions. These scores are dynamically adjusted using a performance-aware mechanism, incorporating clients’ reported distributed accuracy to penalize unreliable updates. Additionally, mild adaptive trimming filters out the lowest 10% of trust scores, reducing adversarial influence while preserving valuable client contributions. These enhancements make the proposed method resilient to Sybil attacks while ensuring efficient model convergence in non-IID (non-independent and identically distributed) data settings. Empirical evaluations demonstrate that our approach outperforms FoolsGold, reducing false positives and improving model robustness.