Lossy compression reveals attacks in federated learning updates

Compression Footprints as Security Signals for Model-Poisoning Defense in Federated Learning

Machine Learning

Summary

Federated learning allows many devices to train a shared model without sharing raw data, but bad actors can poison the training by sending harmful updates. Normally, defenses look at the shape of these updates, but the authors found that how updates get changed by compression can signal if they are honest or malicious. They call this pattern a compression footprint and use it to build a new defense called CRAFT. CRAFT improves accuracy against attacks without needing extra information from devices or extra communication.

What this means in practice

  • For machine learning engineers: Improve federated learning model aggregation by detecting poisoned updates using compression patterns without extra client data or communication.
  • For cybersecurity teams: Enhance defenses in distributed AI systems by identifying malicious clients through compression-based behavior to reduce poisoning risk.

Authors

Sachi Shome, William Eiers

Abstract

Lossy compression is widely used in Federated Learning (FL) but is generally treated as an error source, while conventional poisoning defenses inspect update geometry. In this work, we instead treat the compressor's response as a security signal: the input-dependent distortion and payload behavior induced by lossy compression can expose differences between honest and attack-generated updates. We introduce the concept of a \emph{compression footprint}: the low-dimensional collection of reconstruction, directional, sparsity, and payload statistics induced by a lossy compressor. We characterize sufficient conditions under which compression footprints separate honest and malicious updates, and operationalize our findings in the CRAFT (\emph{Compression-guided Robust Aggregation via Footprint Trust}) server-side robust aggregation method. Crucially, under a strict honest-majority assumption, CRAFT uses server-verifiable footprints, requires no client-side metadata nor knowledge of the number of malicious clients, and adds no communication beyond the compressed FL pipeline. Moreover, while CRAFT assumes a strict honest majority, it does not require the number of malicious clients to be known in advance. We observe that error-bounded lossy compressor (EBLC) footprints provide stronger separation than Top-K footprints and that footprint trust suppresses malicious influence. We evaluate CRAFT under IID client data with 36\% malicious participation across six standard model-poisoning attacks, three datasets, and six robust aggregation baselines, finding that CRAFT consistently achieves the best accuracy in 7 out of 18 settings and within 1.7 percentage points of the best in the others. Our results show that lossy compression can serve as both a communication mechanism and a security signal for robust aggregation in FL.