Compression Footprints as Security Signals for Model-Poisoning Defense in Federated Learning
The paper argues that lossy compression can help spot poisoned federated-learning updates, not just shrink them.
Shome and Eiers define “compression footprints” as reconstruction, direction, sparsity, and payload statistics left by a compressor on client updates. They build CRAFT, a server-side aggregation method that uses those footprints under a strict honest-majority assumption, without client metadata or a known attacker count. In IID experiments with 36% malicious participation, CRAFT led accuracy in 7 of 18 settings and stayed within 1.7 percentage points of the best result in the rest. ArXiv · AI/CL/LG's note
Shome and Eiers define “compression footprints” as reconstruction, direction, sparsity, and payload statistics left by a compressor on client updates. They build CRAFT, a server-side aggregation method that uses those footprints under a strict honest-majority assumption, without client metadata or a known attacker count. In IID experiments with 36% malicious participation, CRAFT led accuracy in 7 of 18 settings and stayed within 1.7 percentage points of the best result in the rest. ArXiv · AI/CL/LG's note
score 3