Welcome to Journal of University of Chinese Academy of Sciences,Today is

Journal of University of Chinese Academy of Sciences ›› 2026, Vol. 43 ›› Issue (4): 553-565.DOI: 10.7523/j.ucas.2024.051

• Electronics and Computer Science • Previous Articles     Next Articles

FLShadow:Byzantine-robust federated aggregation based on a trusted shadow model

Chenchen XU1(), Xutong WANG2,3, Taochun WANG1, Fulong CHEN1, Qixu LIU2,3   

  1. 1.School of Computer Information,Anhui Normal University,Wuhu 241000,Anhui,China
    2.Institute of Information Engineering,Chinese Academy of Sciences,Beijing 100085,China
    3.School of Cyber Security,University of Chinese Academy of Sciences,Beijing 100049,China
  • Received:2023-10-08 Revised:2025-05-17 Online:2026-07-15
  • Contact: Chenchen XU

Abstract:

In federated learning, Byzantine nodes can carefully manipulate the model updates of clients. As a result, the central model accuracy decreases or fails to converge after aggregation. The number of communication rounds also increases. Without trusted reference gradients, the central model can not be properly aggregated solely from updates provided by untrustworthy clients. In this paper, we introduce a trusted reference and we regard it as a shadow model. To overcome this challenge, we propose a novel Byzantine robust federated aggregation method. The central server collects the shadow dataset in advance and trains a model called the shadow model. The central server compares the update direction between the client model and the trusted shadow model. Accordingly, the central server computes malicious score and marks the malicious clients. Then, the central model deletes or prunes the updates from the malicious clients. Finally, the central model aggregates the corrected gradients to ensure good convergence and maintain accuracy. The proposed method has been evaluated on a variety of model architectures and real datasets. The results show that the proposed method can effectively defend against six different Byzantine node attacks on three datasets.

Key words: federated learning, Byzantine attack, shadow model, shadow dataset, aggregation rule, privacy security, adversarial attack

CLC Number: