SurroFL: Sketch-Based Defense Against Poisoning in Privacy-Preserving Federated Learning
Yuyang Kuang, Weinan Liu, Longbo Han, Jindong Huang, Peng Cao, Lin You · IEEE Internet of Things Journal · 2025
In privacy-preserving federated learning (PPFL), the local gradient updates are encrypted to protect the privacy of the clients. However, this opacity hinders the effective detection of the poisoning attacks. Although the existing defense methods can offer robust privacy guarantees, they often require additional rounds of interaction, which significantly increase the computational and the communication overhead, thereby limiting the practicality and the scalability of federated learning deployments. To address the trade-off between privacy protection and defense efficiency, we propose SurroFL, a robust and efficient privacy-preserving federated learning framework designed to defend against the poisoning attacks. SurroFL uses the locality sensitive hashing (LSH) to generate the sketches of the encrypted gradients, enabling the detection of malicious behaviors in the plaintext domain without compromising privacy. In addition, SurroFL adopts the sparse batch encryption strategy to reduce the encryption overhead and incorporates a dynamic reputation-based scoring mechanism to adaptively suppress the malicious clients over time. Our extensive experiments, conducted under the IID data partition setting on the multiple benchmark datasets and the various poisoning attack scenarios, demonstrate that SurroFL consistently outperforms the existing approaches in both robustness and efficiency. Notably, SurroFL achieves an improvement of 20%-70% in the model accuracy while substantially reducing both the computational and the communication overhead, making it highly suitable for deployment in the resource-constrained federated learning environments.