Do We Really Need to Design New Byzantine-robust Aggregation Rules?
Minghong Fang
Network and Distributed System Security (NDSS) Symposium 2025 · Day 3 · Federated Learning 2
Overview
This talk, presented by Minghong Fang at the NDSS Symposium, challenges the prevailing trend in Federated Learning (FL) security research: the continuous development of increasingly complex Byzantine-robust aggregation rules. Fang argues that instead of constantly designing novel defenses, the community should focus on enhancing the robustness of existing, foundational aggregation methods. The core premise is that by strategically manipulating the input distribution to these foundational rules, their efficacy against advanced poisoning attacks can be significantly improved, obviating the need for more intricate and often vulnerable new designs.
Key moments
- 0:00 Introduction and challenges of centralized learning
- 1:15 Federated Learning background and Byzantine attack vulnerability
- 2:30 Limitations of current Byzantine-robust FL defenses
- 3:40 The central question: Are new Byzantine-robust rules necessary?
- 4:15 Understanding foundational aggregation rules: Trimmed Mean and Median
- 5:50 Introducing Foundation-Aware FL: Generating synthetic updates
- 8:00 Effectiveness of Foundation-Aware FL by creating homogeneity
Do We Really Need to Design New Byzantine-robust Aggregation Rules?
Speakers: Minghong Fang
Conference: NDSS Symposium
YouTube: https://www.youtube.com/watch?v=r8v05i5SXu4
Overview
This talk, presented by Minghong Fang at the NDSS Symposium, challenges the prevailing trend in Federated Learning (FL) security research: the continuous development of increasingly complex Byzantine-robust aggregation rules. Fang argues that instead of constantly designing novel defenses, the community should focus on enhancing the robustness of existing, foundational aggregation methods. The core premise is that by strategically manipulating the input distribution to these foundational rules, their efficacy against advanced poisoning attacks can be significantly improved, obviating the need for more intricate and often vulnerable new designs.
The research addresses a critical vulnerability in Federated Learning, where malicious clients can poison the global model, leading to incorrect predictions or targeted backdoors. While FL offers benefits like data privacy and reduced communication costs by keeping training data local, its distributed nature makes it susceptible to such adversarial behaviors. Fang's work proposes a server-side defense mechanism that generates synthetic updates to make the overall set of model updates more homogeneous, thereby bolstering the resilience of simple aggregation rules like trim-mean and median.
This talk is particularly significant for machine learning security practitioners and researchers, as it offers a pragmatic and efficient alternative to the arms race of complex attack and defense strategies. By demonstrating that robust FL can be achieved through a simpler, more foundational approach, it encourages a re-evaluation of current research directions and provides a readily implementable defense that leverages well-understood principles, ultimately contributing to more secure and stable federated learning deployments.
Background
▶ Watch: Introduction and challenges of centralized learning (0:00)
The last decade has seen an exponential rise in machine learning (ML) capabilities, driven by the availability of vast datasets. However, these datasets are often distributed across numerous locations, posing challenges for traditional centralized learning models due to data privacy concerns (e.g., private data linkage) and high communication costs, especially for edge devices like smartphones and IoT. Federated Learning (FL) emerged as a solution, allowing clients to train local models on their private data and send only model updates to a central server. The server then aggregates these updates to produce a global model, which is subsequently distributed back to the clients for the next training round. This iterative process aims to achieve the benefits of collaborative learning without centralizing raw data.
Despite its advantages, FL is highly vulnerable to poisoning attacks, often referred to as Byzantine attacks. In this setting, an attacker controls a subset of clients, either by injecting new malicious clients or compromising existing ones. These malicious clients can poison their local training data or directly manipulate their local model updates before sending them to the server. The ultimate goal is to poison the global model, causing it to make incorrect predictions, either broadly (untargeted attack) or specifically for certain inputs (targeted attack).
To counter these threats, the ML security community has proposed various Byzantine-robust aggregation rules. Early efforts in 2018 introduced methods like trim-mean and median aggregation, which aimed to mitigate the impact of outliers, including those introduced by attackers. However, subsequent research in 2020 demonstrated that these initial "robust" methods were still vulnerable to more advanced local model poisoning attacks. The continuous evolution of attack techniques led to the development of more sophisticated defenses, such as the "EffortTrust" defense in 2021, and numerous others in recent years. This ongoing struggle highlights a persistent "cat-and-mouse" game between attackers and defenders, where new defenses are often quickly bypassed by novel attack strategies.
Existing defenses, despite their increasing complexity, often suffer from significant limitations. Some rely on strong assumptions, such as the server having access to a separate, clean dataset for validation, which is often not feasible in real-world FL scenarios. More critically, many advanced defenses remain vulnerable to sophisticated poisoning attacks, necessitating further rounds of complex design and implementation. This continuous cycle raises a fundamental question: do we truly need to keep designing entirely new Byzantine-robust aggregation rules, or is there a more efficient and sustainable approach to securing Federated Learning? This talk addresses this open question by proposing an alternative perspective.
Key Findings
▶ Watch: Limitations of current Byzantine-robust FL defenses (2:30)
The central finding of this research is that the Federated Learning ecosystem does not necessarily require the continuous invention of new, complex Byzantine-robust aggregation rules to defend against poisoning attacks. Instead, the talk demonstrates that the security of FL can be significantly enhanced by improving the robustness of existing, foundational aggregation rules, specifically trim-mean and median aggregation.
The key insight is that the effectiveness of these foundational rules can be amplified by strategically manipulating the distribution of model updates that they process. The proposed "Foundation-Aware" defense achieves this by having the central server generate synthetic updates. These synthetic updates are carefully constructed to reduce the heterogeneity of the overall set of client updates, creating a more uniform distribution. By feeding this more homogeneous set—comprising both legitimate client updates and the server-generated synthetic updates—into the simple trim-mean or median aggregation rule, the defense effectively mitigates the impact of malicious updates. This approach counters the attacker's ability to exploit the inherent heterogeneity of client training data (non-IID distribution) to launch effective poisoning attacks, thereby making simple, well-understood rules significantly more resilient.
Technical Deep Dive
▶ Watch: The central question: Are new Byzantine-robust rules necessary? (3:40)
The core of the proposed solution, termed Foundation-Aware, lies in enhancing the robustness of established, foundational aggregation rules rather than inventing new ones. The two foundational rules discussed are trim-mean and median aggregation, both introduced in 2018.
- Trim-Mean Aggregation: For each dimension (or parameter) of the model updates, the trim-mean method first identifies and removes a predefined fraction of the largest values and the smallest values. After discarding these extreme values, it computes the average of the remaining values. This process is applied independently to each dimension of the model updates.
- Median Aggregation: This rule directly computes the component-wise median of the clients' local model updates. For each dimension, it finds the median value among all client updates for that specific dimension.
These two methods are chosen for their ease of implementation and their role as backbones for many existing Byzantine-robust aggregation rules.
Threat Model:
The research considers a comprehensive threat model to evaluate the defense's efficacy:
- Attacker Objective: Can be either untargeted (aiming to degrade overall model performance) or targeted (aiming to cause incorrect predictions for specific inputs).
- Attacker Access: The attacker controls a subset of malicious clients. These clients have the capability to send arbitrary local model updates to the central server, meaning they can deviate significantly from honest updates.
- Attacker Knowledge: The attacker is assumed to operate under a worst-case, yet realistic, scenario. They possess knowledge of the local model updates from all clients (including honest ones) and, crucially, know the specific aggregation rule employed by the server. This high level of knowledge allows attackers to craft highly effective poisoning strategies.
- Defender Objective: The proposed defense (Foundation-Aware) must maintain competitive performance (accuracy) for the global model, demonstrate Byzantine robustness against poisoning attacks, and remain efficient in terms of computational and communication overhead.
- Defender Knowledge: The server (defender) observes all local model updates sent by the clients. However, it has no knowledge about the attacker's strategy or which specific clients are malicious.
Foundation-Aware Defense Mechanism:
The Foundation-Aware defense operates in two primary steps after the server receives local model updates from clients:
- Generate Synthetic Updates: This is the novel component. The server generates a set of synthetic model updates.
- Aggregate with Foundational Rule: The server then uses one of the foundational aggregation rules (trim-mean or median) to combine both the received client local model updates and the newly generated synthetic updates.
How Synthetic Updates are Generated:
The process for generating synthetic updates is critical to the defense's effectiveness:
- Identify Extreme Updates: The server first computes two "extreme" updates:
- Gmax: For each parameter dimension, Gmax takes the maximum value observed across all client local model updates for that dimension. For example, if there are three clients with updates (g1_x, g1_y), (g2_x, g2_y), and (g3_x, g3_y), then Gmax would be (max(g1_x, g2_x, g3_x), max(g1_y, g2_y, g3_y)).
- Gminima: Similarly, for each parameter dimension, Gminima takes the minimum value observed across all client local model updates for that dimension.
- Select Deviating Client Update: After computing Gmax and Gminima, the server identifies the client local model update that deviates the most from these extreme updates. This is typically done by calculating a distance metric (e.g., Euclidean distance) from Gmax and Gminima, and selecting the update whose distance is largest from both or from the "center" defined by these extremes. The speaker provides an example: if G2 deviates the most from the extreme updates, then G2 is chosen.
- Generate Copies: Once the most deviating client update (e.g., G2) is identified, the server generates multiple copies of this specific update. These copies constitute the synthetic updates.
Why Foundation-Aware is Effective:
The effectiveness of this approach stems from addressing a fundamental vulnerability in FL: the heterogeneity of client training data. In real-world FL, client data is often non-IID (non-independent and identically distributed). This heterogeneity leads to diverse local model updates from honest clients, which attackers can exploit to camouflage their malicious updates. Attackers often craft updates that blend into the "noise" of legitimate updates, making them hard to detect by simple outlier removal.
By generating synthetic updates, the Foundation-Aware defense artificially creates a more homogeneous set of updates. The speaker illustrates this with a conceptual plot: legitimate (blue) and malicious (red) updates are initially scattered. The synthetic updates (green) are strategically placed to "fill in" gaps or reinforce the distribution of honest updates. This process effectively increases the mean and reduces the standard deviation of the overall update distribution. This homogenization makes the foundational aggregation rules (trim-mean, median) more robust because malicious outliers become more distinct and easier to filter out, even if they were designed to be subtle within a heterogeneous distribution. The server's control over synthetic update generation ensures that attackers cannot directly poison them unless the server itself is compromised.
Demo / Proof of Concept
▶ Watch: Introducing Foundation-Aware FL: Generating synthetic updates (5:50)
While the talk did not feature a live, interactive demo, it presented extensive experimental results to validate the effectiveness of the Foundation-Aware defense. These results serve as the empirical proof of concept, demonstrating its practical utility against various poisoning attacks.
The experimental setup was designed to simulate realistic Federated Learning scenarios:
- Client Configuration: By default, experiments involved 100 clients in total, with 20% of these clients (20 clients) designated as malicious. The impact of varying the fraction of malicious clients was also investigated.
- Data Distribution: Crucially, client training data was set to be non-independent and identically distributed (non-IID), reflecting the real-world heterogeneity that attackers often exploit.
- Datasets: Experiments were conducted on six different datasets spanning various domains, ensuring a broad evaluation of the defense's applicability.
- Synthetic Update Generation: The server was configured to generate 15 synthetic updates by default, a parameter that could be tuned.
- Attack Scenarios: The defense was tested against 12 different poisoning attacks, encompassing a wide range of attack strategies, both targeted and untargeted.
- Baselines: The Foundation-Aware defense was rigorously compared against 10 different existing Byzantine-robust FL baselines to contextualize its performance.
The primary metrics used to evaluate the defense were the test error rate or the attack success rate on the global model. A lower value for these metrics indicates a more effective defense.
Key Experimental Findings:
- Overall Effectiveness: The results, presented in a comprehensive table, consistently showed that the Foundation-Aware defense (using either median or trim-mean for aggregation) could effectively reduce the impact of poisoning attacks across all six datasets and 12 attack types. For instance, a row in the results table specifically highlighted the performance of "Foundation-Aware (Median)," indicating its superior resilience compared to other baselines.
- Resilience to Malicious Client Fraction: A critical aspect of the evaluation was understanding the defense's performance when a large fraction of clients were malicious. A figure presented in the talk plotted the test error rate against the fraction of malicious clients. This graph demonstrated that the Foundation-Aware defense (both with median and trim-mean aggregation) remained effective even when a substantial proportion of clients were malicious, significantly outperforming baseline FL under attack scenarios. This indicates its robustness in highly adversarial environments.
In summary, the experimental results unequivocally demonstrated that the Foundation-Aware defense, by enhancing foundational aggregation rules with synthetic updates, provides a robust and effective countermeasure against advanced poisoning attacks in Federated Learning, without the need for complex, newly designed aggregation rules.
Defensive Implications
▶ Watch: Effectiveness of Foundation-Aware FL by creating homogeneity (8:00)
The findings presented in this talk have profound implications for defenders operating in Federated Learning environments, offering a pragmatic shift in strategy:
- Simplicity Over Complexity: Defenders no longer need to chase the latest, most complex Byzantine-robust aggregation rules. The research strongly suggests that focusing on enhancing simple, well-understood methods like trim-mean and median aggregation can yield superior or comparable results. This reduces the burden of implementing and maintaining intricate algorithms, which often introduce their own vulnerabilities or performance overheads.
- Leverage Foundational Robustness: The core takeaway is to "secure FL by enhancing the robustness of existing foundational aggregation rules." This means defenders should prioritize implementing the Foundation-Aware approach on the server side.
- Server-Side Control: The defense is entirely server-side. This is a significant advantage as it means clients do not need to be modified or updated to incorporate new defense mechanisms. The server generates synthetic updates based on the incoming client updates, maintaining full control over this critical component. This also means that attackers, unless they compromise the server itself, cannot directly influence or poison the synthetic updates, as explicitly stated in the Q&A.
- Address Data Heterogeneity: The defense directly tackles one of the primary enablers of poisoning attacks: the heterogeneity (non-IID nature) of client training data. By making the overall distribution of updates more homogeneous through synthetic updates, the Foundation-Aware defense makes it harder for malicious updates to blend in, thus improving the efficacy of outlier-resistant aggregation rules. Defenders should understand that addressing data distribution characteristics is key to resilience.
- Cost-Effective Security: This approach offers a potentially more cost-effective way to secure FL. Instead of investing resources in developing and validating new, complex aggregation algorithms, efforts can be redirected towards robust implementation of the synthetic update generation process and careful tuning of parameters (e.g., number of synthetic updates, selection criteria).
- Proactive Defense: By continuously generating synthetic updates, the server proactively fortifies the aggregation process in each round, adapting to the dynamic nature of client contributions and potential adversarial actions. This provides a persistent layer of defense against a wide range of poisoning attacks.
In essence, defenders should pivot towards a strategy of fortifying the fundamentals. By implementing the Foundation-Aware mechanism, they can achieve robust Federated Learning security with greater simplicity, efficiency, and resilience against advanced threats, without getting caught in the endless cycle of designing new aggregation rules.
Key Takeaways
- Federated Learning is highly vulnerable to poisoning attacks from malicious clients, which can corrupt the global model.
- While many "Byzantine-robust" aggregation rules have been proposed, existing foundational methods like trim-mean and median aggregation are simple but often insufficient against advanced attacks.
- The research demonstrates that it is not necessary to design new, complex aggregation rules to secure Federated Learning effectively.
- The proposed Foundation-Aware defense enhances the robustness of existing foundational rules by having the server generate synthetic updates.
- These synthetic updates create a more homogeneous distribution of model updates, making it harder for malicious updates to camouflage and easier for foundational rules to filter them out.
- The Foundation-Aware defense is a server-side mechanism, highly effective against various poisoning attacks and even when a large fraction (e.g., 20%) of clients are malicious.
About the Speaker(s)
The talk was presented by Minghong Fang. The transcript and metadata do not provide further details about their title or affiliation at the time of the conference.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Solid academic ML security research that makes a clear, testable argument — stop chasing complexity, fix the fundamentals — and backs it with reasonable empirical breadth (12 attacks, 10 baselines, 6 datasets). Not groundbreaking, but honest and well-scoped work that belongs in an academic venue.
Heather Calloway (CISO) — PASS
Technically credible ML security research on federated learning poisoning defenses, but it sits entirely outside governance, institutional risk, or defender operations at the organizational level. This is academic systems research — rigorous in its lane, irrelevant in mine.
→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025
All talks from Network and Distributed System Security (NDSS) Symposium 2025