Data Poisoning Detection for Secure Federated Learning With Dropout-Resilient Aggregation
Abstract
Federated learning (FL) enables multiple clients to train a global model collaboratively without sharing their raw data. However, compromised clients can launch data poisoning attacks by submitting malicious local updates and thereby degrade model accuracy. In addition, unprotected model updates may disclose sensitive information. Moreover, excluding malicious clients reduces the number of available shares and can prevent a conventional secure aggregation protocol from completing. To address these challenges, we propose DPDR, a secure FL framework that combines privacy-preserving, kernel density estimation (KDE)-based poisoning detection with dropout-resilient secure aggregation. DPDR subjects masked local updates to secure <inline-formula><tex-math notation="LaTeX">$k$</tex-math></inline-formula>-nearest-neighbor (<inline-formula><tex-math notation="LaTeX">$k$</tex-math></inline-formula>-NN) computation, KDE-based local-density estimation, maliciousness-score computation, and poisoned-update classification. It then excludes poisoned updates and uses Shamir secret reconstruction to aggregate the retained benign updates before broadcasting the resulting global model. Experiments on three benchmark datasets show that DPDR defends against data poisoning, protects model-update privacy, and tolerates client dropout while maintaining competitive global-model performance.