Detecting Model Poisoning Attacks in Federated Learning via Joint Spatio-Temporal Inspection
Abstract
Detecting model poisoning attacks in federated learning (FL) remains challenging under heterogeneous data distributions and coordinated adversarial behavior. Non-IID data can induce substantial variation among benign updates, leading detectors to misclassify them as malicious, whereas coordinated attackers can submit mutually similar updates to conceal their collective attack behavior. To address these limitations, we propose TSDetector, a joint spatio-temporal model poisoning detection framework that characterizes client behavior from two complementary perspectives. Specifically, from the spatial perspective, TSDetector characterizes the relationships among clients by adaptively fusing an update distance graph which captures discrepancies among client updates with a knowledge discrepancy graph that reflects their similarities in learned knowledge on a reference dataset, from the temporal perspective, TSDetector models client specific update trajectories across communication rounds to identify cross round poisoned attack behaviors compared with normal training dynamics. Extensive experiments across five benchmark datasets and five representative untargeted attacks show that TSDetector reduces average attack impact to 1.16%, with maximum attack induced performance degradation limited to 4.6%. TSDetector avoids severe performance degradation observed in multiple baseline defenses, demonstrating broader applicability across diverse datasets and poisoning strategies.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.