Related Experiment Video
Updated: May 31, 2026

05:47
Evidence-based Knowledge Synthesis and Hypothesis Validation: Navigating Biomedical Knowledge Bases via Explainable AI and Agentic Systems
Published on: June 13, 2025
Adaptive trust evaluation and representation-based robust aggregation against poisoning attacks in federated learning
1School of Petroleum, China University of Petroleum Beijing at Karamay, Karamay, 834000, China. 2022016879@st.cupk.edu.cn.
Scientific Reports
|April 28, 2026
Summary
Federated Learning (FL) defenses against backdoor attacks are improved by FLAURA. This framework uses adaptive trust evaluation and hybrid aggregation to enhance model security and accuracy in non-IID settings.
Area of Science:
- Artificial Intelligence
- Machine Learning
- Cybersecurity
Background:
- Federated Learning (FL) enables privacy-preserving distributed training but is vulnerable to backdoor attacks, especially in non-IID and open settings.
- Current defenses struggle against sophisticated adversaries, leading to performance degradation and malicious update propagation.
Purpose of the Study:
- To introduce FLAURA, a robust defense framework for Federated Learning against model poisoning and backdoor attacks.
- To enhance FL security and performance in challenging non-IID and open-participation environments.
Main Methods:
- FLAURA operates in the penultimate-layer representation (PLR) space with dual-level trust evaluation.
- Global trust estimation uses the geometric median of PLRs to counter malicious clusters.
- Local trust evaluation employs Maximum Mean Discrepancy (MMD) and curvature-based knee point detection for adaptive boundary setting.
- A hybrid aggregation mechanism combines hard filtering and soft weighting to manage model updates.
Main Results:
- FLAURA significantly outperforms state-of-the-art baselines in experiments on FMNIST, CIFAR-10, and CIFAR-100 datasets.
- The framework effectively reduces attack success rates and target-label confidence.
- FLAURA maintains high accuracy on clean data while mitigating malicious perturbations.
Conclusions:
- FLAURA provides a robust defense against backdoor attacks in Federated Learning.
- The adaptive trust evaluation and hybrid aggregation effectively distinguish benign heterogeneity from malicious attacks.
- FLAURA enhances FL security without prior knowledge of adversary fractions, preserving model diversity and accuracy.