COMBAT MODEL AGAINST POISONING ATTACKS ON FEDERATED LEARNING: A TWO-PHASE DEFENCE MODEL WITH COMPRESSION APPROACH
DOI:
https://doi.org/10.62643/ijerst.2025.v21.n2.pp2961-2970Keywords:
Federated Learning, Data Poisoning Attacks, Convolutional Neural Networks, Model Compression, Secure Machine Learning, Distributed Learning, Adversarial Defense, Privacy PreservationAbstract
Data poisoning attacks pose a serious threat to federated learning (FL) systems, where even a small fraction of malicious participants can significantly degrade global model performance. Studies indicate that up to 30% of real-world federated deployments have experienced such attacks, leading to accuracy reductions of nearly 50%, thereby limiting the adoption of FL in security-critical domains such as healthcare and finance. In addition, centralized learning approaches remain vulnerable due to single-point data storage and manual data handling inconsistencies. To mitigate these challenges, this work proposes a two-stage defense framework that integrates data preprocessing, model compression, and a Convolutional Neural Network (CNN)–based federated learning architecture. Initially, the dataset is cleansed by handling missing values, separating features and labels, applying standard scaling, and partitioning the data into training and testing sets. Subsequently, model compression is employed to reduce communication overhead while obfuscating malicious update patterns from adversarial clients. The proposed CNN-based federated framework demonstrates substantial robustness against poisoning attacks and achieves a significant improvement in predictive performance. Experimental results show an accuracy increase from 87% using a conventional Deep Neural Network (DNN) to 99% with the proposed CNN-based federated approach, validating its effectiveness and reliability
Downloads
Published
Issue
Section
License

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.













