Compression Footprints as Security Signals for Model-Poisoning Defense in Federated Learning

📅 2026-09-30
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
In federated learning, lossy compression is conventionally regarded as a source of error that undermines system resilience against model poisoning attacks. This work proposes CRAFT, a robust aggregation method that introduces the concept of "compression footprints" to transform compression responses into security signals. By exploiting the statistical properties of compression distortion and payloads—including reconstruction, directional, and sparsity features—CRAFT enables server-side detection of malicious updates and robust aggregation with zero additional communication overhead. Experimental results demonstrate that CRAFT significantly outperforms existing baselines in model accuracy across diverse poisoning attack scenarios. It effectively mitigates the influence of malicious clients, thereby providing efficient security guarantees for bandwidth-constrained federated learning systems.
📝 Abstract
Lossy compression is widely used in Federated Learning (FL) but is generally treated as an error source, while conventional poisoning defenses inspect update geometry. In this work, we instead treat the compressor's response as a security signal: the input-dependent distortion and payload behavior induced by lossy compression can expose differences between honest and attack-generated updates. We introduce the concept of a \emph{compression footprint}: the low-dimensional collection of reconstruction, directional, sparsity, and payload statistics induced by a lossy compressor. We characterize sufficient conditions under which compression footprints separate honest and malicious updates, and operationalize our findings in the CRAFT (\emph{Compression-guided Robust Aggregation via Footprint Trust}) server-side robust aggregation method. Crucially, under a strict honest-majority assumption, CRAFT uses server-verifiable footprints, requires no client-side metadata nor knowledge of the number of malicious clients, and adds no communication beyond the compressed FL pipeline. Moreover, while CRAFT assumes a strict honest majority, it does not require the number of malicious clients to be known in advance. We observe that error-bounded lossy compressor (EBLC) footprints provide stronger separation than Top-K footprints and that footprint trust suppresses malicious influence. We evaluate CRAFT under IID client data with 36\% malicious participation across six standard model-poisoning attacks, three datasets, and six robust aggregation baselines, finding that CRAFT consistently achieves the best accuracy in 7 out of 18 settings and within 1.7 percentage points of the best in the others. Our results show that lossy compression can serve as both a communication mechanism and a security signal for robust aggregation in FL.
Problem

Research questions and friction points this paper is trying to address.

Federated Learning
Model Poisoning
Lossy Compression
Robust Aggregation
Security
Innovation

Methods, ideas, or system contributions that make the work stand out.

Federated Learning
Model Poisoning Defense
Compression Footprint
Lossy Compression
Robust Aggregation