MaEA: A Secure Aggregation Defense Method Against Poisoning Attacks in Federated Learning
Zheyi Chen, Yujie Xue, Yunjing Ren, Hongting Zheng, Hansong Xu, Kun Hua, Dongfeng Fang, Hailin Feng · 2025
Federated learning is a collaborative training paradigm designed to protect private data and is widely used in the cooperative training of Internet of Things (IoT) devices. However, despite its focus on privacy protection, federated learning remains susceptible to poisoning attacks from malicious clients. These attacks can degrade system performance and potentially lead to data privacy breaches. Moreover, real-world IoT datasets are often heterogeneous, further increasing the difficulty of detecting malicious clients. Existing defense mechanisms often struggle to effectively identify malicious clients while maintaining high model performance. To address this issue, we propose a defense mechanism called Malicious client exclusion aggregation (MaEA). This method utilizes KL divergence to preliminarily filter out anomalous clients, aggregates the remaining (preliminarily filtered) clients to obtain a pre-center model, and then identifies and excludes malicious clients by measuring their deviations from this pre-center model. We executed a series of extensive experiments on the CIFAR-10 dataset to demonstrate the effectiveness of MaEA. The results demonstrate that our approach can efficiently detect and identify malicious clients while correcting model performance.