CARAT: Class-Aware Robust Aggregation for Model-Poisoning-Resilient Federated Learning
Abstract
Federated learning is vulnerable to model-poisoning attacks because the server must aggregate client updates without inspecting client data. Existing robust aggregation rules often rely on update geometry, coordinate-wise robust statistics, or a single trusted reference direction, but these signals can confuse malicious behavior with benign client heterogeneity under non-i.i.d. data. We propose CARAT, a class-aware robust aggregation rule that uses a small labeled server reference set to sample hidden, class-balanced tasks and score each candidate update by its task-level loss reduction. CARAT combines these hidden-task certificates with robust clipping, common-radius evaluation, coordinate-rank anomaly penalties, and capped-simplex weight optimization to favor updates that remain useful across semantic slices while limiting structurally extreme updates. On CIFAR-100/ResNet18 with malicious clients, two non-i.i.d. regimes, and four untargeted model-poisoning attacks, CARAT achieves the best average rank among the reported public baselines and improves final accuracy by – percentage points over the strongest non-CARAT baseline in each attack/heterogeneity setting. Within this scoped evaluation, the results support task-conditioned validation as a practical alternative to purely geometric or single-anchor trust signals when a modest labeled server reference set is available.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.