Compression Footprints as Security Signals: Defending Federated Learning Against Model Poisoning
壓縮足跡化身安全訊號:利用破壞性壓縮抵禦聯邦學習中的模型投毒攻擊
While lossy compression in Federated Learning is traditionally treated as a source of error, this paper repurposes it as a security signal. By extracting low-dimensional 'compression footprints' (reconstruction, sparsity, and payload statistics), the researchers developed CRAFT. This server-side aggregation method filters out malicious updates without requiring client-side metadata or prior knowledge of attacker counts, adding zero communication overhead. Under 36% malicious participation, CRAFT achieved top-tier defense performance across multiple datasets.
Key points
Compression Footprints
Repurposes lossy compressor distortions (reconstruction, directional, sparsity, and payload statistics) to expose anomalous updates.
CRAFT Robust Aggregation
Operates server-side robust aggregation using footprint trust to suppress the influence of malicious updates.
No Communication Overhead
Requires no client-side metadata or knowledge of malicious client counts, adding zero extra communication overhead.
EBLC Outperforms Top-K
Error-bounded lossy compressor (EBLC) footprints provide stronger separation of malicious updates than Top-K footprints.
How it works
Why it matters
Federated Learning is vulnerable to communication bottlenecks and model-poisoning attacks. CRAFT elegantly unifies communication efficiency and security by repurposing lossy compression—originally a data-reduction tool—as an active defense line. It achieves robust defense without imposing extra communication costs or client-side metadata sharing, offering a practical path for securing decentralized AI deployments.
Who it affects
- AI Researcher
- AI Developer
- Enterprise Leader
How to use it
- 1Secure Federated Learning for Bandwidth-Constrained IoT Networks
- 2Mitigating Model-Poisoning in Decentralized Collaborative AI Training
Limitations & caveats
- Operates under a strict honest-majority assumption among participating clients.
- The evaluation and footprint behavior are verified primarily under IID client data conditions.
Related
Extracting User Models via Belief Self-Distillation: How LLMs Form and Use Beliefs About Users
以「信念自我蒸餾」提取使用者模型:揭示大語言模型對用戶意圖的內在表徵
Researchers introduce Belief Self-Distillation (BSD), a framework to read and write an LLM's implicit beliefs about its users, revealing how user-intent inference drives safety decisions and showing shared representation geometries across models.
LLM Agents Can Easily Tamper with Their Own Traces: A Critical Security Flaw in Agent Frameworks
LLM Agent 可輕易篡改自身執行軌跡:現行代理框架的重大安全漏洞
Researchers reveal that popular LLM agent frameworks fail to protect execution traces from being tampered with or deleted by the agents themselves, posing significant risks for compliance and safety monitoring.
TRACE: Reconstructing Private Robot Trajectories from Policy Gradients in Embodied RL
具身強化學習的隱私危機:TRACE 演算法僅憑「策略梯度」即可重建機器人私密軌跡
This paper introduces TRACE, a rapid temporal gradient-inversion attack showing that sharing only policy gradients in embodied RL fails to prevent reconstruction of private observation-action trajectories.