联邦学习中的鲁棒性维护:趋势、新兴策略与研究机会
摘要
本文对联邦学习中的鲁棒性进行了全面综述,涵盖了威胁模型、聚合策略、防御战术以及未来研究方向。
arXiv:2609.28722v1 Announce Type: new
Abstract: While Federated Learning (FL) has been widely adopted for protecting user privacy in machine learning, it remains vulnerable to various robustness challenges, including performance-impairment risks, information-stealing threats, and aggregation vulnerabilities. This work offers a holistic synthesis of FL robustness along three tightly coupled angles: (i) a threat-centric view of robustness that categorizes the multifaceted attack surfaces, (ii) a structured taxonomy of robust aggregation strategies distinguishing outcome-centric approaches from security-centric strategies, and (iii) a layered taxonomy of defensive strategies. We rigorously examine current evaluation practices for FL robustness and identify major applications and open research challenges to guide future research.
查看缓存全文
缓存时间: 2026/09/25 09:35
# Upholding Robustness in Federated Learning: Trends, Emerging Strategies, and Research Opportunities Source: [https://arxiv.org/html/2609.28722](https://arxiv.org/html/2609.28722) DOI:[XXXXXXX\.XXXXXXX](https://doi.org/XXXXXXX.XXXXXXX)Journal:CSURVolume:0000CCS:General and reference Surveys and overviewsCCS:Computing methodologies Distributed artificial intelligenceCCS:Security and privacyPravija Raj P V[https://orcid.org/0000-0002-9286-701X](https://orcid.org/0000-0002-9286-701X)email:[p20230903@dubai\.bits\-pilani\.ac\.in](mailto:[email protected])Affiliation:Department of Computer Science and Engineering, BITS Pilani Dubai Campus,Dubai,UAEAshish Guptaemail:[ashish@dubai\.bits\-pilani\.ac\.in](mailto:[email protected])Affiliation:Department of Computer Science and Engineering, BITS Pilani Dubai Campus,Dubai,UAE,Andrea Augelloemail:[andrea\.augello01@unipa\.it](mailto:[email protected])Affiliation:Department of Engineering, University of Palermo,Palermo,ItalyandSajal K\. Dasemail:[sajal@mst\.edu](mailto:[email protected])Affiliation:Department of Computer Science, Missouri University of Science and Technology,Rolla,USA 0 ###### Abstract\. While Federated Learning \(FL\) has been widely adopted for protecting user privacy in machine learning, it remains vulnerable to various robustness challenges, including performance\-impairment risks, information\-stealing threats, and aggregation vulnerabilities\. This work offers a holistic synthesis of FL robustness along three tightly coupled angles: \(i\) a threat\-centric view of robustness that categorizes the multifaceted attack surfaces, \(ii\) a structured taxonomy of robust aggregation strategies distinguishing outcome\-centric approaches from security\-centric strategies, and \(iii\) a layered taxonomy of defensive strategies\. We rigorously examine current evaluation practices for FL robustness and identify major applications and open research challenges to guide future research\. ###### Keywords: Aggregation, Defenses, Federated learning, Robustness, Robust FL Survey, Threats\. ## 1\.Introduction Federated Learning \(FL\) is causing a paradigm shift in the field of Artificial Intelligence \(AI\) by enabling decentralized model training across numerous devices while keeping data local\([Wang et al\., 2024b](https://arxiv.org/html/2609.28722#bib.bib43);[Zhang et al\., 2026](https://arxiv.org/html/2609.28722#bib.bib42);[Gupta et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib1)\)\. The proliferation of intelligent devices and applications that generate vast, decentralized, and heterogeneous data presents tremendous opportunities for scientific and technological innovation\. FL offers substantial advantages over traditional centralized architectures by facilitating real\-time analytics and collaborative knowledge aggregation without centralizing sensitive information\([Javeed et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib171);[Hamouda et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib185);[Jiang et al\., 2020b](https://arxiv.org/html/2609.28722#bib.bib61);[Zhu et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib103)\)\. Consequently, the framework is rapidly gaining traction across diverse sectors, including finance, healthcare, Internet of Things \(IoT\), and smart cities\([Mothukuri et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib33)\)\. The decentralized nature of FL makes it prone to threats that compromise collaborative training\([Hao et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib7);[Fang and Ye, 2022](https://arxiv.org/html/2609.28722#bib.bib19);[Ranjan et al\., 2022a](https://arxiv.org/html/2609.28722#bib.bib14)\)\. Real\-world deployments face adversarial and heterogeneous environments, characterized by diverse participant devices with varying computational and communication resources, and Non\-Independent and Identically Distributed \(Non\-IID\) and imbalanced data distributions\([De Alwis et al\., 2026](https://arxiv.org/html/2609.28722#bib.bib41)\)\. Further, either some clients or the server may act covertly or maliciously, and communication channels may leak sensitive information\. Under these circumstances, ensuring FL robustness involves addressing potential threats; therefore, it is vital to continuously assess the model for vulnerabilities\([Wan et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib190);[Jeong et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib184)\)\. Tackling these challenges necessitates multi\-faceted solutions that extend beyond discrete defenses\. In practice, robust FL demands careful and effective handling of multiple aspects, including threats, aggregation robustness, and defensive measures\. Furthermore, the inconsistency in evaluation trends for robust FL with research using different datasets, partitioning choices, attack settings, mitigation strategies, and metrics makes it complicated to assess methods or verify their particular relevance in real\-life circumstances\. In this paper,we review and systematically analyze the challenges facing FL and assess the current solutions from diverse perspectives, including threats, aggregation strategies, and defenses, which a researcher should contemplate for upholding robustness\.To facilitate an easy understanding, we begin by outlining the crucial factors for robustness in FL\.∙\\bulletCrucial Factors for Robustness:Unlike conventional distributed optimization, federated models demand a heavy focus on reliability and robustness\. Key factors that have a substantial impact on the FL robustness can be assessed from multiple angles\.∙\\bulletAdversarial threats:Malicious participants may manipulate data, alter model updates, or initiate backdoor attacks during training to undermine the global model\([Xie et al\., 2020a](https://arxiv.org/html/2609.28722#bib.bib116)\)\. Detection and mitigation of adversarial threats at the server side can greatly reduce malicious impact\([Gong et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib117);[Yang et al\., 2023b](https://arxiv.org/html/2609.28722#bib.bib142)\)\. Resilience is the key to strong FL frameworks; they should be capable of resisting malevolent attacks\([Gupta et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib18)\)and greedy participants\([Augello et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib4)\)\.∙\\bulletAggregation process:Traditional FL aggregation solutions, such as FedAvg\([McMahan et al\., 2017](https://arxiv.org/html/2609.28722#bib.bib191)\), are vulnerable to deceitful updates, uneven data, and outliers\([Wang et al\., 2024c](https://arxiv.org/html/2609.28722#bib.bib129);[Guo et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib17);[Tang et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib59)\)\. Furthermore, a fragile aggregation approach on the server, if faced by adversaries, could detrimentally affect the whole training process\. In contrast, adaptive and customized approaches can achieve robust models\([Li et al\., 2019](https://arxiv.org/html/2609.28722#bib.bib95);[Tan et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib80);[Wu et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib159)\)\.∙\\bulletDefensive mechanisms:Detecting the presence of adversaries and excluding them from the aggregation process is vital to developing a reliable FL model; consequently, different defensive strategies\([Gupta et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib18);[Wu et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib10);[Yu et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib47)\)have been devised, which demand consolidated discussion and comparative analysis to steer future research toward robust FL\. ### 1\.1\.Motivation The widespread adoption of FL has resulted in many survey papers to handle inherent challenges and diverse threats, and devise appropriate mitigative measures and defenses\([Li et al\., 2024a](https://arxiv.org/html/2609.28722#bib.bib58);[De Alwis et al\., 2026](https://arxiv.org/html/2609.28722#bib.bib41);[Tang et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib59)\)\. This section inspects these efforts through a critical lens, discussing their major insights and gaps, underscoring the need for our work in this area\. To begin with,\([Lianga et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib54)\)provides an analysis of client\-side threats, with a key focus on how model and data poisoning can disrupt the system\. Meanwhile, a thorough discussion of attack vectors, such as evasion, model inversion, and backdoor tactics, is provided in\([Sikandar et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib55)\)\. These studies also critically assess the efficacy of countermeasures such as adversarial training and Differential Privacy \(DP\) against these serious threats\. While the studies\([Mothukuri et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib33);[Han et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib6)\)examine security, privacy, and deployment risks, the authors in\([Lyu et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib8)\)present a taxonomy that primarily includes threat models and two main attack types \(poisoning and inference\)\. In addition to a taxonomy of attacks, the work in\([Liu et al\., 2022a](https://arxiv.org/html/2609.28722#bib.bib9)\)analyzed the potential defenses and summarized their shortcomings\. A survey analyzing the FL from the differential privacy aspect is presented in\([Fu et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib198)\)In\([Zhang et al\., 2023b](https://arxiv.org/html/2609.28722#bib.bib13)\), the authors noted that an adversary’s access levels are crucial for fully understanding the impact of rule exposure\. The work\([Wu et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib10)\)reviewed different attack types based on the potential roles attackers might play in FL\. From a security perspective, a categorization is proposed in\([Chen et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib16)\)based on the security properties: integrity, confidentiality, and availability\. A categorization framework that differentiates between vertical, horizontal, and transfer learning\-based FL is proposed in\([Yang et al\., 2019](https://arxiv.org/html/2609.28722#bib.bib11)\)\. The study in\([Lim et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib15)\)focused on enhancing deployments in distributed computing frameworks by highlighting the challenges of FL implementation in mobile edge computing\. A detailed review of state\-of\-the\-art attacks that compromise privacy using membership attacks and utility, and their defenses, is given in\([Li et al\., 2024b](https://arxiv.org/html/2609.28722#bib.bib12);[Bai et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib199)\)\. In addition, the systematic review\([Uddin et al\., 2025](https://arxiv.org/html/2609.28722#bib.bib196)\)provides a categorical analysis of state\-of\-the\-art FL defenses, based on their underlying principles and techniques\. ∙\\bulletMajor gaps in the prior surveys:After a thorough study, we discovered the following gaps: Despite rapid progress, past studies generally inspect robustness from a single dominant angle, such as security, non\-IID data, privacy, or aggregation challenges, resulting in afragmented insight on robustnessin practical FL systems\. Most existing reviews primarily focus on specific adversary types,inspecting each category in isolation, which restricts their ability to deliver a holistic view of robustness across the crucial factors of FL\. While prior works have devised valuable taxonomies, they didn’t go much beyond conventional security threats and thus oftenfall short of delivering a detailed analysisover diverse robustness perspectives\. To the best of our knowledge, most existing surveys do not adequately orchestrate and assess the multifaceted constituents of robustness over the whole FL pipeline under a unified perspective\. This highlights the pressing need to unite these research strands and systematically examine FL through thelens of robustness, enabling a holistic review that can deliver a coherent reference for upholding FL robustness\. ### 1\.2\.Survey Scope While addressing the above\-mentioned gaps, this paper offers a deeper, more insightful, and end\-to\-end understanding of FL robustness along three tightly coupled angles\. The major contributions are: - •This study presents a unified, multi\-layer, threat\-centric view of FL robustness by categorizing performance\-impairment and information\-stealing attacks across different layers of the FL pipeline\. We expose and discuss the multifaceted attack surfaces affecting FL robustness that previous studies handled separately\. - •We propose an innovative multi\-level taxonomy of robust aggregation strategies that distinguishes outcome\-centric from security\-centric approaches, emphasizes their robustness assumptions, demonstrates their interactions with defensive mechanisms, and offers a holistic design space for robust aggregation\. - •This work introduces a layered taxonomy of defensive strategies categorized by their stage of action \(e\.g\., training data, local updates, global model, and server/coordination\)\. - •Finally, we review current evaluation trends, covering commonly used data\-partitioning schemes, benchmark datasets, and attack configurations; identify robustness gaps in the existing literature; outline key application scenarios; and highlight open research challenges to guide future research on developing robust FL systems\. Figure 1\.Research protocol steps\.The structured approach for the survey\. ### 1\.3\.Research Protocol To ensure comprehensive coverage of the literature on robust FL, we follow a structured approach as shown in Fig\.[1](https://arxiv.org/html/2609.28722#S1.F1)\.∙\\bulletArticles search process:We start by filtering papers from key digital libraries such as IEEE Xplore, ResearchGate, Scopus, and Google Scholar\. The search and selection process employed research\-specific keywords such as:Federated Learning,Robust FL,FL Robustness,Robust Aggregation,Threats to Robustness,FL Attacks, andFL Security\. Search queries are constructed using carefully selected keywords and brief phrases, along with Boolean operators, such as AND and OR\. A detailed search was performed across the chosen databases, focusing on titles, abstracts, and keywords spanning from 2017 to 2026\. The primary studies are selected based on quality and after screening their abstracts or full\-length papers\. Duplicates, irrelevant research, and poor\-quality papers are eliminated\. The selected papers are systematically categorized, enabling a more focused review to identify key insights and trends\.∙\\bulletSelection and inclusion criteria:To guarantee relevance, quality, and impact, the research papers are carefully screened using a structured evaluation checklist\. Major selection and inclusion criteria includes: \(i\) high\-impact journals or conferences with significant citations indicating influence; \(ii\) concise problem formulations with precise explanations; \(iii\) understandable and well\-articulated presentation and discussions; \(iv\) technical depth in terms of detailed algorithms and implementations; \(v\) novel solutions addressing FL threats while maintaining viable robustness guarantees; \(vi\) detailed comparative discussion with state\-of\-the\-art; and \(vii\) evidence\-based conclusions, to ensure the inclusion of the most relevant literature\.Survey organization:Section[2](https://arxiv.org/html/2609.28722#S2)dives into the diverse threats to FL robustness\. We start with an overview of robustness challenges and then classify attacks\. Section[3](https://arxiv.org/html/2609.28722#S3)introduces a taxonomy of robust aggregation strategies, categorizing and analyzing research approaches to ensure model integrity and robust performance\. Section[4](https://arxiv.org/html/2609.28722#S4)details defensive strategies for FL robustness using an insightful taxonomy\. Section[5](https://arxiv.org/html/2609.28722#S5)delivers the experimental evaluation trends\. Section[6](https://arxiv.org/html/2609.28722#S6)offers a summary discussion, sharing insights into emerging trends, major application scenarios, and outlining open challenges and future research directions\. ## 2\.Threats to Robustness in FL This section critically reviews the threats to FL robustness identified in existing studies\. In FL, robustness refers to the system’s ability to eitherremain unaffected by threats and adversarial conditionsorrecover automaticallyfrom them while maintaining reliable performance\. Prior works\([Gupta et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib18);[Li et al\., 2024b](https://arxiv.org/html/2609.28722#bib.bib12);[Yu et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib47);[Bagdasaryan et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib48);[Jere et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib51);[Sun et al\., 2021a](https://arxiv.org/html/2609.28722#bib.bib56);[Chen et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib16);[Arevalo et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib77);[Wei et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib35);[Zhou et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib31);[Wang et al\., 2020b](https://arxiv.org/html/2609.28722#bib.bib38);[Lyu et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib60);[Jeong et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib184);[Zhang et al\., 2023a](https://arxiv.org/html/2609.28722#bib.bib64);[Sun et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib78);[Tolpegin et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib66);[Jiang et al\., 2020b](https://arxiv.org/html/2609.28722#bib.bib61)\)highlighted FL’s vulnerability to a variety of underexplored threats\. After presenting the essentials of FL training, we divide potential threats into two insightful categories: \(i\)performance\-impairment threats– that cause model performance to drop \(either due to a malicious actor or structural conditions\), affecting the FL robustness, and \(ii\)information\-stealing threats– that aim to extract sensitive information, posing risks to privacy and security\. ### 2\.1\.FL Training: The Essentials Fig\.[2](https://arxiv.org/html/2609.28722#acmlabel2)portrays a typical FL setup\. Collaborative model training across multiple participants enables the creation of a global model while protecting data privacy\. FL involves two main entities: participants \(often called clients\) who train ML models using their personal data, and an aggregator server that combines the local models into a global model\. The key phases include:training phase, where clients collaboratively train the model by exchanging local updates without disclosing their data, andinference phase, where clients apply the trained global model to new data samples\. Figure 2\.Typical FL operational process\.Working of a general FL system\.The training process is decentralized, implying that the central server \(aggregator\) has no access to or control over clients’ data\. LetP=\{p1,p2,…,pn\}P=\\\{p\_\{1\},p\_\{2\},\\ldots,p\_\{n\}\\\}represent the set ofnnparticipants, who download parameters \(model\) from the server\. Each participantpip\_\{i\}utilizes its private local datasetDiD\_\{i\}to train a local modelζir\\zeta^\{r\}\_\{i\}during each communication roundrr\. In particular, each client performsτ\\taulocal epochs, and then the updated parameters are uploaded to the server for aggregation to refine the global modelζGr\\zeta^\{r\}\_\{G\}\. Following the aggregation, the global modelζGr\\zeta\_\{G\}^\{r\}is sent to all participants\. Letnndenote the total number of participants, and the weight coefficients satisfy∑p=1nϱp=1\\sum\_\{p=1\}^\{n\}\\varrho\_\{p\}=1withϱp≥0\\varrho\_\{p\}\\geq 0\. The local objective function of participantppis defined as:Flp\(φ\)=1np∑q=1npflq\(φ,xq,yq\)Fl\_\{p\}\(\\varphi\)=\\frac\{1\}\{n\_\{p\}\}\\sum\_\{q=1\}^\{n\_\{p\}\}fl\_\{q\}\(\\varphi;x\_\{q\},y\_\{q\}\), wherenpn\_\{p\}represents the number of local data samples, andflq\(φ,xq,yq\)fl\_\{q\}\(\\varphi;x\_\{q\},y\_\{q\}\)is the corresponding loss function\. And, the server aims to:minφFG\(φ\),whereFG\(φ\):=∑p=1nϱpFlp\(φ\)\.\\min\_\{\\varphi\}F\_\{G\}\(\\varphi\),\\text\{where \}F\_\{G\}\(\\varphi\):=\\sum\_\{p=1\}^\{n\}\\varrho\_\{p\}Fl\_\{p\}\(\\varphi\)\. Table 1\.Adversarial roles and involvements in FL\.Involvement of adversaries and their roles in FL ### 2\.2\.Security Challenges in FL Adversaries can infiltrate the FL framework and pose serious security challenges by exploiting vulnerabilities, such as manipulating training parameters, altering the aggregated model, and distorting learning outcomes\. While localized models and raw training data represent major vulnerabilities on the client side, the integrity of aggregated parameters or gradients can become targets on the server side, particularly in the deployment/inference stages\([Yu et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib47);[Bagdasaryan et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib48);[Jere et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib51);[Sun et al\., 2021a](https://arxiv.org/html/2609.28722#bib.bib56);[Jiang et al\., 2020b](https://arxiv.org/html/2609.28722#bib.bib61)\)\. An adversary can get involved in the FL process by either compromising a participant or the server, or even acting externally, as discussed in Table[1](https://arxiv.org/html/2609.28722#S2.T1)\. The adversary’s capabilities depend on their role in the learning process\. Adversaries can have different levels of knowledge \(null, partial, complete\) and access to the model based on their role\. This knowledge can include training data, feature space, learning methods, parameters, and even the cost function\. Fig\.[3](https://arxiv.org/html/2609.28722#acmlabel4)illustrates the levels of access adversaries might possess\. Through an iterative learning process, an adversary can evolve from a black\-box \(limited knowledge\) to a white\-box \(complete knowledge\) scenario\. Figure 3\.Attack strength based on adversarial knowledge levels\.Shows how attack strength varies based on adversarial knowledge levelsFurther, based on the adversary’s role and its target, we summarize the general classes of attacks in Table[2](https://arxiv.org/html/2609.28722#S2.T2)\. Attacks can be broadly categorized into four types based on their objectives and targets:\(i\) Targeted attack:It aims to degrade the model’s performance on a specific task while leaving other tasks unaffected\([Mothukuri et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib33)\)\.\(ii\) Untargeted attack:It reduces the model’s overall performance or disrupts the model’s convergence\.\(iii\) Inference attack:It aims to extract sensitive information from the model, such as properties of the training data, membership of specific data points, or class information\.\(iv\) Reconstruction attack:It attempts to recover the actual training samples by analyzing the model’s parameters or outputs, causing a serious threat to data privacy\. Table 2\.Overview of Adversarial Attacks\.- •AK \(Additional Knowledge\), \(P\) Properties, \(M\) Membership, and \(C\) Class ### 2\.3\.Performance\-Impairment Threats The threats to disrupt global model performance, either directly or indirectly, mostly occur during the training phase and are categorized based on adversarial objectives\([Wei et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib35);[Zhou et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib31);[Wang et al\., 2020b](https://arxiv.org/html/2609.28722#bib.bib38);[Gupta et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib1)\)\. They are often implemented by poisoning the data or model\([Lyu et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib60);[Jeong et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib184);[Zhang et al\., 2023a](https://arxiv.org/html/2609.28722#bib.bib64)\), as shown in Fig\.[4](https://arxiv.org/html/2609.28722#acmlabel5)\. Data poisoning involves training or inference data manipulation to indirectly compromise a model, whereas model poisoning directly alters the learning process to corrupt it\. Additionally, free\-riders, attacks on the communication channel, and denial\-of\-service attacks significantly impact FL performance\. Figure 4\.Poisoning\-induced attacks in FL\. An adversary can poison either the training data or the local model\.Example of attacks induced by poisoning data or model in FL#### 2\.3\.1\.Poisoning Attacks As mentioned earlier, these attacks are caused by intentional poisoning and can be broadly divided into data or model poisoning\.∙\\bulletData poisoning attacks:Assuming that an attacker has access to and can modify the training data of multiple clients, data poisoning attacks become a significant concern\. These attacks are further categorized by their nature as follows:\(i\)\(i\)Label\-oriented attacks:They involve altering the labels of a subset of the training data\([Tolpegin et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib66)\)\. Specific labels are purposefully swapped \(targeted\), or labels are shuffled randomly \(untargeted\)\. Label flipping is a typical Dirty Label Poisoning \(DLP\) attack to create malicious gradients\([Xu et al\., 2022b](https://arxiv.org/html/2609.28722#bib.bib65)\)\. A distance\-aware attack in\([Sun et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib78)\)selects the most vulnerable class for label flipping by calculating the mean feature vector of each class as:ψl=1\|Da\(l\)\|∑i∈Da\(l\)Ψ\(i\),\\psi\_\{l\}=\\frac\{1\}\{\|D\_\{\\text\{a\}\}\(l\)\|\}\\sum\_\{i\\in D\_\{\\text\{a\}\}\(l\)\}\\Psi\(i\),whereψl\\psi\_\{l\}denotes the mean of feature vectors in classll,\|Da\(l\)\|\|D\_\{\\text\{a\}\}\(l\)\|is the number of samples in the infected dataset, andΨ\\Psiis the feature extraction function\. To strengthen the attack, the least distant class is chosen based on the distances between classes:Dm\(l,l′\)=‖ψl−ψl′‖2\.D\_\{m\}\(l,l^\{\\prime\}\)=\|\|\\psi\_\{l\}\-\\psi\_\{l^\{\\prime\}\}\|\|\_\{2\}\.Another scenario is where the adversary cannot alter the training data labels due to a certification process that ensures label accuracy and demands that any changes be imperceptible \(Clean\-label poisoning \(CLP\)\-induced attacks\)\([Rong et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib74);[Yang et al\., 2023a](https://arxiv.org/html/2609.28722#bib.bib73);[Peri et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib75);[Xia et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib92)\)\. For instance, the samples are modified to render the poisoned instance \(msm\_\{s\}\) to resemble the base instance as:ms=argminx\(‖δ\(i\)−δ\(s\)‖22\+η‖i−s‖22\),m\_\{s\}=\\arg\\min\_\{x\}\\left\(\\\|\\delta\(i\)\-\\delta\(s\)\\\|\_\{2\}^\{2\}\+\\eta\\\|i\-s\\\|\_\{2\}^\{2\}\\right\),where the functionδ\(i\)\\delta\(i\)corresponds to the inputiipropagating through the network,ssdenotes the base instance, andη\\etacontrols the extent of this similarity to achieve the poisoning effect on the global model\. Such attacks often leave the labels unaffected, making it more appealing and unnoticeable\([Yang et al\., 2023a](https://arxiv.org/html/2609.28722#bib.bib73)\), but unfeasible in non\-IID scenarios\.\(ii\)\(ii\)Poisoned Samples Generation \(PSG\):Data poisoning attacks can also be carried out using Generative Adversarial Networks \(GANs\)\([Sun et al\., 2024a](https://arxiv.org/html/2609.28722#bib.bib68);[Alsereidi et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib69);[Jere et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib51)\)\. Here, an attacker needs to train a GAN to replicate other participants’ training samples\([Sun et al\., 2024a](https://arxiv.org/html/2609.28722#bib.bib68)\), which are then used to craft scaled poisoning updates as their local updates, aiming to compromise the global model \(Fig\.[5](https://arxiv.org/html/2609.28722#acmlabel6)\)\. This method of attack is particularly effective and general since the generated data is realistic, making it difficult to detect and counter\. In\([Zhang et al\., 2021a](https://arxiv.org/html/2609.28722#bib.bib52)\), a poison data generation approach \(Data\_GenData\\\_Gen\) is introduced that relies on iteratively updated global model parameters to regenerate samples for the targeted victims\. Stepping beyond, the work\([Psychogyios et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib53)\)introduced a more sophisticated attack that can go unnoticed for several rounds\. Figure 5\.GAN\-based poisoning attack\. The adversary trains a GAN to generate synthetic poisoned samples\.Synthetic sample generation using GAN for causing poisoning attack\(iii\)\(iii\)External Data Poisoning \(EDP\):It resembles standard poisoning attacks but differs in that the poisoned samples originate from outside the original input distribution\([Winkens et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib70);[Ren et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib71);[Sastry and Oore, 2020](https://arxiv.org/html/2609.28722#bib.bib72)\)\. They use data from entirely different domains with similar characteristics, or even random noise\. Exploiting foreign data potentially impairs the model’s integrity\.\(iv\)\(iv\)Colluding attack:This intense threat arises from the increased influence an attacker gains by controlling multiple clients within the FL framework\([Ranjan et al\., 2022a](https://arxiv.org/html/2609.28722#bib.bib14)\)\. They are mainly of two types, server\-participant and participant\-participant collusion\([Ranjan et al\., 2022b](https://arxiv.org/html/2609.28722#bib.bib36);[Lyu et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib60)\), and can exploit the cooperative interactions to gain unauthorized insights or degrade model performance\. A Sybil attack is a prominent example in which a single or small group of attackers creates multiple colluding identities to amplify the adversarial impact\([Tuor et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib82);[Cao et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib83);[Sun et al\., 2021a](https://arxiv.org/html/2609.28722#bib.bib56)\)\.∙\\bulletModel poisoning attacks:By targeting the manipulation of local model parameters or gradient updates directly, the attackers can deviate the model from the optimal update direction, as depicted in Fig\.[6](https://arxiv.org/html/2609.28722#acmlabel7)\. Attackers attempt to increase stealthiness by ensuring their model updates closely resemble benign updates\([Shejwalkar et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib57);[Zhou et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib31)\)\. They might play random noise injection \(RNI attack\)\([Hossain et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib44);[Fang et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib168)\), manipulate their local updates, or replace the global model with a malicious one \(model replacement \(MR attack\)\)\([Sun et al\., 2019](https://arxiv.org/html/2609.28722#bib.bib141)\), to disrupt the convergence of the global model, misclassify specific data samples, or increase energy consumption\([Cinà et al\., 2025](https://arxiv.org/html/2609.28722#bib.bib192)\)\. Mathematically, a model poisoning attacker aims to replace the global modelζG\(t\+1\)\\zeta\_\{G\}^\{\(t\+1\)\}with a malicious modelζ~G\(t\+1\)\\tilde\{\\zeta\}\_\{G\}^\{\(t\+1\)\}\. To do so, when the global model converges such that∑j∈St\(ζjt−ζGt\)≈0\\sum\_\{j\\in S\_\{t\}\}\(\\zeta\_\{j\}^\{t\}\-\\zeta\_\{G\}^\{t\}\)\\approx 0, the attacker crafts its local model to cancel out the benign updates and steer the global model towards the malicious one\. They may even scale their parameters to amplify their influence\([Rong et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib74);[Bagdasaryan et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib48)\)\. Partial model replacement has been used by selfish clients to make the global model prioritize their local distribution\([Augello et al\., 2026](https://arxiv.org/html/2609.28722#bib.bib5)\)Targeted Model Poisoning \(TMP\), where the adversary enhances their updates to have a significant impact on the global model while avoiding detection\([Bhagoji et al\., 2019](https://arxiv.org/html/2609.28722#bib.bib167)\), remains effective even against Byzantine\-resilient aggregation methods\. Figure 6\.Illustrating model poisoning attack, whereζt\\zeta^\{t\}denote the local model update inttht^\{th\}round\.ζ∗\\zeta^\{\*\}represents the optimal model\.Illustration of model poisoning attackTable 3\.Summary of recent poisoning attacks in FL\. An attack isPersistentif it is carried out in every round\.Some Byzantine\-robust methods \(Krum, Trimmed\-mean, and Median\) can be compromised by directly manipulating local parameters even in a partial\-knowledge setting\([Fang et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib168)\)\. An Optimization\-based Model Poisoning \(OMP\) in\([Zhou et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib31)\)injects malicious neurons into the neural network’s redundant space by leveraging the regularization term\. Reverse and Random attacks \(RRA\)\([El\-Mhamdi et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib32)\)create adversarial gradients by reversing or randomly substituting the benign gradients\. However, because the adversarial gradients deviate greatly from the benign ones, Byzantine\-resilient FL methods can easily identify and eliminate them\. Additionally, Dynamic Poisoning Methods \(DMPs\) that use flexible tactics to circumvent defenses\([Wei et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib35)\)and create malicious models using inner\-product alteration\([Xie et al\., 2020b](https://arxiv.org/html/2609.28722#bib.bib34)\)also exist\. For quick reference, Table[3](https://arxiv.org/html/2609.28722#S2.T3)delivers an insightful summary of major poisoning attacks in FL\. Table 4\.Summary of backdoor attacks and Free\-riders participation in FL\. #### 2\.3\.2\.Backdoor Attacks Adversaries perform backdoor attacks by injecting hidden trigger patterns into data to impair performance on particular class instances\. Such attacks manifest during both training and inference phases\([Bagdasaryan et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib48)\)\. Their stealthy and selective behavior, which compromises model performance only when the trigger is active, has critical consequences for FL\([Wang et al\., 2020b](https://arxiv.org/html/2609.28722#bib.bib38)\)\. Detecting hidden triggers is highly complex, particularly in unexpected scenarios\([Bhagoji et al\., 2019](https://arxiv.org/html/2609.28722#bib.bib167);[Wang et al\., 2024b](https://arxiv.org/html/2609.28722#bib.bib43)\)\. Backdoor attacks can be classified into:\(i\)\(i\)Single\-pattern attack:All backdoor clients inject the same trigger, which makes their detection easier regardless of the attack’s potency\([Huynh et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib93)\)\. The study in\([Bagdasaryan et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib48)\)attempted to alter model weights to create hidden functionalities to influence specific tasks without reducing main accuracy\. Moving beyond simple data poisoning, joint data and model poisoning are employed\([Abad et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib164);[Wang et al\., 2020b](https://arxiv.org/html/2609.28722#bib.bib38)\)\.\(ii\)\(ii\)Coordinated attack:Numerous coordinated adversaries injecting patterns or segments of a common pattern are typically harder to detect\([Xie et al\., 2020a](https://arxiv.org/html/2609.28722#bib.bib116)\)for the variation and spread of the embedded patterns\. The study\([Xie et al\., 2020a](https://arxiv.org/html/2609.28722#bib.bib116)\)introduced a distributed variant where adversaries cooperate to embed various segments of a chosen trigger, while\([Gong et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib117)\)considered the use of model\-specific triggers\.\(iii\)\(iii\)Evolving attacks:The adversarial strength has evolved beyond typical scenarios to more intricate settings\. In feature\-partitioned FL\([Liu et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib166)\), adversaries inject triggers without altering the label, although gradient aggregation helps to alleviate them\. In federated meta\-learning\([Chen et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib165)\), backdoor attacks endure despite fine\-tuning on clean data\. Edge\-case backdoors\([Wang et al\., 2020b](https://arxiv.org/html/2609.28722#bib.bib38)\)target sporadic samples, scaling parameters through Projected Gradient Descent \(PGD\)\. #### 2\.3\.3\.Free\-riders Free\-riders are deceptive participants who do not provide meaningful updates to the global model but rely on other participants to perform most of the training work\([Sagduyu, 2022](https://arxiv.org/html/2609.28722#bib.bib104);[Cao and Gong, 2022](https://arxiv.org/html/2609.28722#bib.bib45);[Mozaffari et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib176);[Pejó and Biczók, 2023](https://arxiv.org/html/2609.28722#bib.bib108)\)\. They typically use only a limited portion of their dataset for training or introduce random noise or arbitrary model updates to conserve computational resources\([Sagduyu, 2022](https://arxiv.org/html/2609.28722#bib.bib104);[Wang et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib109);[Fraboni et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib105);[Wan et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib79)\), ultimately compromising the overall model due to inferior data quality\. A random\-weights technique in\([Pejó and Biczók, 2023](https://arxiv.org/html/2609.28722#bib.bib108)\)challenges detection by generating gradient updates via parameter sampling from a uniform distribution\. Table[4](https://arxiv.org/html/2609.28722#S2.T4)provides a summary discussion of free\-riders and backdoor attacks\. #### 2\.3\.4\.Channel Attack This section explores two FL channel attack scenarios\.First,we examine susceptibilities and communication bottlenecks spawned from periodic updates and frequent interactions between the server and participants\([Ye et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib118)\)\. An example is the man\-in\-the\-middle \(MITM\) attack\([Wang et al\., 2020a](https://arxiv.org/html/2609.28722#bib.bib121);[Vangala et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib119)\)\. Since FL relies on the server to manage the learning process and aggregate updates, such attacks can intercept and alter communication, posing a critical vulnerability\. The study in\([Yao et al\., 2018](https://arxiv.org/html/2609.28722#bib.bib122)\)highlighted how adversaries can exploit the training process by causing delays, cutting bandwidth, aggravating interference, and undermining model convergence\.Second, we discuss the risk of exploiting FL as a secret channel for stealthy interaction, where an intruder utilizes its features to enable concealed data exchanges, compromising the robustness\. More covert attacks\([Hitaj et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib112);[Costa et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib113)\)can even turn the FL systems to covert channels of their desire\. FedComm introduced in\([Hitaj et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib112)\)encodes disguised messages into weights using advanced synchronization methods while adjusting updates to stay stealthy\. Table 5\.Summary of recent works on channel, DoS, and evasion attacks on FL frameworks\. #### 2\.3\.5\.Denial\-of\-Service \(DoS\) Attack Traditional FL is vulnerable to DoS attacks, which substantially disrupt model convergence and affect output accuracy\. Distributed DoS \(DDoS\) attacks targeting the FL servers, resource allocation, and network traffic can often go undetected\([Zhang et al\., 2023a](https://arxiv.org/html/2609.28722#bib.bib64);[Fung et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib85)\)\. Consequently, clients experience difficulty connecting to servers, disrupting communication and functionality\. The study by\([Cao et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib83)\)categorizes and labels untargeted attacks initiated by Sybils as DoS\. The utilization of historical data in\([Zhang et al\., 2023a](https://arxiv.org/html/2609.28722#bib.bib64)\)to iteratively tune the malicious model via neuron perturbations enhances DoS effectiveness\. #### 2\.3\.6\.Evasion Attack The adversary intentionally introduces minor malicious perturbations to input samples during the inference or deployment phase, leading the classifier to misclassify the samples with high probability\([Kurakin et al\., 2017](https://arxiv.org/html/2609.28722#bib.bib136)\)\. They are categorized into white\-box and black\-box attacks based on the adversary’s knowledge\. In a white\-box attack, the adversary has complete access to the learning algorithm and model parameters, allowing the formulation of adversarial samples using these details\([Mothukuri et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib33)\)\. In contrast, the black\-box attackers lack this information\. They create adversarial samples through system interaction or by querying the system\. A zeroth\-order optimization\([Chen et al\., 2017](https://arxiv.org/html/2609.28722#bib.bib138)\)estimates model updates and generates adversarial samples\. Internal evasion attacks, where the adversary clients execute an attack internally at test time to deceive other clients, are discussed in\([Kim et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib137)\)\. At a glance, Table[5](https://arxiv.org/html/2609.28722#S2.T5)summarizes recent works related to channel, DoS, and evasion attacks\. Table 6\.Summary of information stealing threats on FL systems\. ### 2\.4\.Information Stealing Threats While FL is designed to prevent direct data sharing, research has shown that gradient exchanges can expose sensitive details, such as class representations and data membership, to attackers \(both passive and active\)\([Moriai, 2019](https://arxiv.org/html/2609.28722#bib.bib132);[Lyu et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib126);[Liu et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib124);[Le et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib177)\)\. Since models reflect high\-level data statistics, attackers can exploit them to infer private information\. In extreme scenarios, attackers might even recover actual training samples or extract the labels solely from the update gradients\. #### 2\.4\.1\.Inference Attacks During the training stage, the model can unintentionally expose sensitive private information or user data\([Zhang and Li, 2024](https://arxiv.org/html/2609.28722#bib.bib111);[Gu et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib180);[Hu et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib181);[Suri et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib182)\)\. An honest but curious server or user may infer information on the training data without prior knowledge\([Le et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib177);[Hu et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib179)\)\. Inference attacks can be classified into four major types:\(i\)\(i\)Membership inference:Attackers aim to determine whether a specific data sample has been used in the training\. The attack can either be active or passive\([He et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib183)\)and typically leverages a shadow model to mimic the target model’s behavior, enabling the attacker to analyze the model’s outputs and infer membership status, as illustrated in Fig\.[7](https://arxiv.org/html/2609.28722#acmlabel8)\. In a passive attack, the adversary observes updated model parameters and infers membership without altering the learning process\. In contrast, an active attack directly tampers with model training to gain more insights into the data of other participants\. The attacker can apply a gradient ascent attack, in which it checks the loss over subsequent communication rounds in FL to determine whether the sample is likely part of the training set\([Gu et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib180)\)\.\(ii\)\(ii\)Source inference:This attack goes beyond general membership inference by focusing on identifying the specific FL participants\. The exposure of source information can indeed raise substantial concerns about information protection and confidentiality\([Hu et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib181);[Hu et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib179)\)\. The work\([Suri et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib182)\)introduced two novel black\-box attacks that identify multiple participants collectively, without requiring access to the model’s parameters at every training round\.\(iii\)\(iii\)Attribute inference:This attack attempts to infer particular attributes or properties that participants do not intend to disclose, focusing on dataset subsets rather than the entire collection\([Arevalo et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib77);[Mothukuri et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib33)\)\. Unlike general attributes associated with the main task, these properties are specific to individual participants, making such attacks effective even if secure aggregation techniques are employed\. Attackers can analyze the global model to uncover such attributes without affecting the overall performance on the primary task\([Shen et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib97)\)\.\(iv\)\(iv\)Label inference:With a capability to bypass secure aggregation and recover private labels post\-aggregation\([Wang et al\., 2024d](https://arxiv.org/html/2609.28722#bib.bib131)\), label inference is stronger than other inference\-based attacks\. Client\-specific fishing models extract client gradients, enabling large\-scale label inference with 100% accuracy, emphasizing the increased risk from leaked gradients\. Further, GAN\-based inference attacks\([Song et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib130)\)have also been explored in both passive and active modes\. Passive mode enables an attacker to analyze user inputs at the server level, whereas active mode involves sending global updates to a specific client\. According to\([Song et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib130)\), even with a small percentage of gradients, attackers can infer training data\. Figure 7\.In a membership inference attack, through a shadow model, the adversary can infer whether a specific data sample was part of the training set by analyzing the model outputs\.membership inference attack example #### 2\.4\.2\.Model Extraction Attacks This attack captures model predictions by querying the trained model with diverse inputs, enabling attackers to recreate a functionally equivalent model\. Through iterative refinement, the recreated model’s outputs are adjusted to better match the original model’s predictions\. While clients typically have model access, attackers may attempt to steal models to claim ownership of the aggregated model\([Lyu et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib126)\)\. Further, an internal adversary\([Zhang et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib127)\)can also play an attack aiming to deprive other participants of their model ownership rights, enabling the attacker to deceptively claim the model as their intellectual property\. Direct analysis can reconstruct models with high precision, focusing on critical points where derivatives are mostly zero\([Li et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib98)\)\. #### 2\.4\.3\.Reconstruction and Inversion Attacks In these attacks, an adversary aims to reconstruct training samples from a learning model’s parameters, across both black\-box and white\-box scenarios\([Qiu et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib99);[Chen et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib100)\)\. Within the context of inference task distribution, a malicious client can reconstruct random inputs without direct access to the data or computations of other participants\([Chen et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib100)\)\. This threat scales with model architecture, as demonstrated by the potential to recover entire training sets in infinite\-width models\([Loo et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib67)\)\. Even with moderate DP, the attacker can still infer stored data, although increased privacy controls lower accuracy\([Mothukuri et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib33);[Zhang et al\., 2023b](https://arxiv.org/html/2609.28722#bib.bib13)\)\. Importantly, strong predictive frameworks are more vulnerable because they form tight connections across data features and labels\. Participant\-side attacks can masquerade as typical FL participants while stealthily recreating the data, posing a major harm\. Inversion techniques, specifically gradient and model inversion, represent a critical subset of these threats that occur at both the client and server levels\([Liu et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib62);[Wang et al\., 2024d](https://arxiv.org/html/2609.28722#bib.bib131);[Gupta et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib18)\)\. In a gradient inversion attack, an adversary intercepts shared gradients and uses an auxiliary model to iteratively create data samples that mirror the client’s actual data\([Sun et al\., 2024b](https://arxiv.org/html/2609.28722#bib.bib63)\)\. These attacks differ significantly in extent depending on the adversary’s position\. Server\-side attacks pose a systemic threat by potentially exposing data from all the participants\([Geiping et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib94)\)\. Instead, client\-side model inversion infers features of another client’s data by observing model outputs and iteratively adjusting inputs to match observed outputs\([Issa et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib128);[Wang et al\., 2024c](https://arxiv.org/html/2609.28722#bib.bib129)\)\. #### 2\.4\.4\.Eavesdropping Eavesdropping is an attack in which adversaries exploit inadequate client security to intercept and monitor client\-server interactions in FL\. With this, attackers can obtain confidential details about clients and their engagements\. These assaults generally go unnoticed as they involve a passive approach or re\-encryption tricks that mask the break\-in\. Although normally untargeted, it can be targeted by an intruder seeking specific information\([Xu and Neglia, 2021](https://arxiv.org/html/2609.28722#bib.bib120)\)\. A summary of different information\-stealing threats is provided in Table[6](https://arxiv.org/html/2609.28722#S2.T6)\. We present the key insights into the above\-mentioned threats to robustness through the following aspects: type of threat, its target, vulnerable component of FL, and threat complexity, in Table[7](https://arxiv.org/html/2609.28722#S2.T7)\. Table 7\.Insights into threats to robustness in FL\.AttacksAttack TargetVulnerable ComponentComplexityTypeCSMDCommClean\-Label PoisoningTraining Data✓\\checkmarkHADirty\-Label PoisoningTraining Data✓\\checkmarkMAPoisoned Samples GenerationTraining Data✓\\checkmarkHAModel PoisoningGlobal Model✓\\checkmark✓\\checkmarkHABackdoor AttacksGlobal Model✓\\checkmarkHAEvasion AttacksModel Prediction✓\\checkmark✓\\checkmarkMATraining Rules ManipulationLearning Process✓\\checkmark✓\\checkmarkHAFree\-Riding AttacksFL Participation✓\\checkmarkLPInference AttacksPrivate Data✓\\checkmarkMPGAN ReconstructionPrivate Data✓\\checkmark✓\\checkmarkHPNon\-Robust AggregationAggregation Process✓\\checkmarkMPMalicious ServerGlobal Model✓\\checkmarkHAModel Replacement AttackGlobal Model✓\\checkmark✓\\checkmarkHAModel Inversion AttackPrivate Data✓\\checkmark✓\\checkmarkHPModel Extraction AttackModel Parameters✓\\checkmark✓\\checkmarkMPModel Ownership AttackModel Ownership✓\\checkmark✓\\checkmarkMAFL Channel attacksFL Process✓\\checkmark✓\\checkmarkMPMan\-in\-the\-Middle AttacksModel Updates✓\\checkmarkHASybil AttacksFL Integrity✓\\checkmarkHAEavesdropping AttacksCommunication Data✓\\checkmarkMP - •C: Client, S: Server, M: Model, D: Distributed FL nature, Comm: Communication, L: Low, M: Medium, H: High, A: Active, and P: Passive attacks ## 3\.Robust Aggregation Strategies Safeguarding the integrity of the aggregation process is imperative, particularly when faced with potentially corrupted model updates from participating clients of the FL framework\([Li et al\., 2019](https://arxiv.org/html/2609.28722#bib.bib95);[Andrew et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib96)\)\. FL aggregation algorithms are still in the early phases of development, and their robustness is an area demanding active ongoing research and advancement\([Chen et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib100);[Liu et al\., 2022b](https://arxiv.org/html/2609.28722#bib.bib101);[Du et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib90)\)\. In a decentralized FL scheme, the key issue lies in filtering out anomalous or malicious contributions while retaining the authenticity of legitimate contributions during aggregation\([Wan et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib79)\)\. To solve this, several solutions have been developed, attempting to reinforce the aggregation phase and enhance the robustness of FL frameworks\([Zhang et al\., 2026](https://arxiv.org/html/2609.28722#bib.bib42);[Wang et al\., 2024a](https://arxiv.org/html/2609.28722#bib.bib84);[Pejó and Biczók, 2023](https://arxiv.org/html/2609.28722#bib.bib108)\)\. This section critically reviews robust aggregation strategies that enhance the resilience and effectiveness of combining locally trained models into a cohesive global model, and later introduces a taxonomy to classify them\. ### 3\.1\.Aggregation Robustness Challenges Models can be combined using either parameter\-based or output\-based methods\. The parameter\-based approach is the most common\. It brings together trainable parameters, like weights or gradients, from local models\([Liu and Shang, 2022](https://arxiv.org/html/2609.28722#bib.bib123)\)\. The output\-based approach uses representations from the models, such as output logits or compressed sketches\. For example, Fedmask\([Huang et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib3)\)helps mobile devices with limited computing power by having them learn binary masks, which are then combined by the server\. Studies suggest that incorporating cryptographic techniques such as Homomorphic Encryption \(HE\), which enables computations over encrypted data, to safeguard sensitive information, and DP, which adds random noise to outputs, can enhance robustness against information\-stealing threats\([Andrew et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib96)\)\. The assumption followed in centralized FL that the server is reliable yet curious, and the clients are trustworthy, is easily undermined in the presence of adversaries\. Recent developments in robust aggregation place more emphasis on enabling clients to confirm that the server has completed the aggregation correctly, in addition to safeguarding local updates\([Brunetta et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib151)\)\. Decentralized aggregation solutions, such as gossip mechanisms and blockchain technology, are advised to eliminate single points of failure by removing the need for a central server\. Other options are centered on optimizing contract mechanisms, employing robust stochastic model aggregation, and organizing small committees to successfully handle model updates\([Li et al\., 2019](https://arxiv.org/html/2609.28722#bib.bib95)\)\. Solutions such as Trusted execution environments \(TEE\) and Multi\-party computation \(MPC\) further reveal the ongoing efforts to boost security and robustness of FL frameworks\([Sotthiwat et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib147);[Zhao et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib86);[Kadhe et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib148);[Zhang et al\., 2021c](https://arxiv.org/html/2609.28722#bib.bib87)\)\. On the other hand, other vital aspects, such as enhancing training quality and handling heterogeneity, remain underexplored\. The efficacy and scalability in large\-scale FL frameworks also demand deeper investigation\([Kuznetsov et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib89)\)\. Figure 8\.Taxonomy of the robust aggregation strategies along with the relative proportion \(%\) of reviewed publications\.Robust aggregation strategies taxonomy ### 3\.2\.Proposed Taxonomy of Aggregation Strategies This section proposes a new taxonomy, shown in Fig\.[8](https://arxiv.org/html/2609.28722#acmlabel9), for analyzing and classifying robust aggregation solutions\. They are divided into two macro\-categories according to their key design focus: \(i\)outcome\-centric: enhances robustness by boosting the learning outcome of the global model under potentially falsified client updates, and \(ii\)security\-centric: reinforces robustness by safeguarding the integrity, verifiability, and confidentiality of the aggregation phase itself\. #### 3\.2\.1\.Outcome\-centric Aggregation This category includes client\-oriented methods, which enhance robustness by selectively prioritizing high\-quality and trustworthy clients through adaptive selection and client evaluation strategies; fusion\-oriented methods redesign the way local models are merged via dynamic fusion, contextual aggregation, and clustering\-based strategies; and objective\-oriented methods, which mold the training objective using statistical feature\-based aggregators and customized loss or regularization designs to lessen attackers’ impact\.\(i\) Adaptive selection of clients:To enhance robustness during aggregation\([Du et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib90)\), it is crucial to prioritize participants with better communication abilities, higher prediction outcomes, or models that better align with the global model\. Clients are chosen in frameworks such as Eiffel\([Sultana et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib91)\)based on update frequency, processing ability, and data size\. The robustness of FL framework is further strengthened by sophisticated solutions like Lyapunov optimization\([Perazzone et al\., 2025](https://arxiv.org/html/2609.28722#bib.bib193)\), sequential Kalman filters\([Yan et al\., 2025](https://arxiv.org/html/2609.28722#bib.bib194)\), and bandit learning methods\([Wan et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib79)\), which use clients likely to deliver high\-quality updates and alleviate bad contributions\. In\([Wang et al\., 2024a](https://arxiv.org/html/2609.28722#bib.bib84)\), an SVM\-based aggregation process is introduced for lazy clients in cross\-device FL, accelerating convergence without burdening clients\.\(ii\) Client evaluation mechanisms:Discovering the appropriate weight per client and recognizing adversaries can be accomplished by evaluating the local updates\. Maintaining a server\-specific model\([Cao et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib146)\)is one innovative approach\. Before the start of the collaborative training process, the server uses a carefully selected mini dataset to train a baseline server\-version of the model\. The cosine similarity between client updates and the server\-version is assessed to understand how well they align\. The higher score updates are given more weight\. In a different study\([Park et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib106)\), weights assignment to clients followed an approach based on the entropy of each gradient received on an evaluation dataset\.\(iii\) Dynamic fusion approaches:A reliable way to reduce training times without compromising model accuracy is dynamic local model fusion approaches\([Lee et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib160);[Wu et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib159);[Sun et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib162)\)\. The issue of low\-accuracy models caused by traditional fully asynchronous aggregation has been addressed by methods using client numbers or interval time windows\. The trade\-off between model performance and training time can be effectively balanced by dynamically selecting the number of aggregations per round\([Lee et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib160)\)\. To enhance robustness, techniques for handling stale models have also been suggested, such as avoiding out\-of\-date local models from the aggregation process\([Wu et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib159)\)and temporal weight decay methods\([Zhang et al\., 2021b](https://arxiv.org/html/2609.28722#bib.bib161)\)\.\(iv\) Contextual model aggregation:By adapting the model aggregation process to fit a particular context, contextual aggregation methods solve slow convergence issues\([Liu et al\., 2022b](https://arxiv.org/html/2609.28722#bib.bib101);[Nguyen et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib140)\)\. The study\([Nguyen et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib140)\)sought to ensure consistent loss reduction at each optimization round by imposing a context\-based bound on loss reduction specific to the participants and assuming smoothness of the overall loss function\. The results demonstrated significant gains in robustness and convergence speed, outperforming conventional techniques\.\(v\) Clustering\-based solutions:In hierarchical FL, clustering has emerged as a robust strategy to improve both model performance and resource usage, solving key challenges related to non\-IID data and communication efficacy\([Xiao et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib152)\)\. Clients with similar characteristics or data distributions are grouped into clusters to enable effective model aggregation within each cluster\. This improves the robustness of the FL process\. Different clustering\-based strategies, including those that use communication capabilities and device\-to\-device interactions within clusters, have been investigated\([Lin et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib156)\)\. One such framework is the FedSim\([Palihawadana et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib158)\), which employs k\-means clustering to guide the aggregation process\. This approach is further extended using diverse distance metrics, such as Manhattan and cosine distances\([Wang et al\., 2021a](https://arxiv.org/html/2609.28722#bib.bib153)\)and hybrid metrics\([Augello et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib195)\)\. Beyond distance metrics, studies have explored clustering in terms of data distribution to support the training of personalized models, designed for specific environmental contexts\([Li et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib155)\)\. This approach can be extended using data\-similarity\-based client partitioning approaches to promote collaboration and disincentivize selfish behavior\.\(vi\) Statistical\-feature\-based aggregators:To prioritize the gradients from the most reliable clients, some studies formulate statistical\-feature\-based aggregators that protect the global model from potentially poisonous updates\([Huang et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib3)\)\. Some of the existing approaches, such as Trimmed Mean, Krum, Median, and Multi\-Krum\([Peng et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib37);[Wang et al\., 2024b](https://arxiv.org/html/2609.28722#bib.bib43)\), use robust estimators either individually or jointly to mitigate the influence of outliers and adversarial updates\. For instance, by employing the geometric median to aggregate local updates via a Weiszfeld\-type algorithm, the study in\([Pillutla et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib115)\)introduced a robust aggregation solution that safeguards against compromised participants without revealing local contributions and performs well under severe corruption\.\(vii\) Training function optimization:Researchers have examined approaches for optimizing the distributed training loss function to improve robustness, intending to refine the learning process itself\. Certain studies have introduced appealing techniques\([Li et al\., 2019](https://arxiv.org/html/2609.28722#bib.bib95);[Andrew et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib96);[Zhao et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib139)\), though they are still in the early stages of development\. For example,\([Li et al\., 2019](https://arxiv.org/html/2609.28722#bib.bib95)\)applies regularization to the loss function to reduce the local model deviations from the global model during training, thereby enhancing the resilience of the learning process\. Moreover,\([Andrew et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib96)\)presented a dynamic clipping value estimated online to adapt to various situations\. In\([Zhao et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib139)\), an extension of the Huber loss function is provided to devise an optimal loss structure, delivering theoretical guarantees in IID and slightly heterogeneous scenarios\. #### 3\.2\.2\.Security\-centric Aggregation This group includes ledger\-based methods that employ decentralized models such as blockchain to provide tamper\-resistant logging, reputation, and auditability for the aggregation process, hardware\-assisted methods that employ TEEs to perform aggregation within safe enclaves, and cryptographical techniques such as MPC, HE, and Quantum Secure Aggregation \(QSA\) that safeguard the confidentiality and verifiability of model updates and aggregation outcomes\. They are reviewed as follows\.\(i\) MPC\-based aggregators:Secure Multi\-Party Computation has been researched to improve both privacy and robustness in federated aggregation\([Sotthiwat et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib147)\)\. These approaches reduce the chances of information leakage by enabling the global model to be computed without disclosing specific local models\. While the studies such as\([Brunetta et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib151)\)prioritize verifiable sharing schemes and a dual\-stage aggregation, where a committee is initially selected for aggregating the models, the research in\([Kadhe et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib148)\)utilizes Fast Fourier Transform \(FFT\) based confidential sharing as a substitute to the standard Shamir confidential sharing method\. By lowering the risk of one\-point failure and boosting security, sharing secret\-shared local updates over several aggregation servers can also strengthen robustness\.\(ii\) HE\-based aggregators:FL frameworks that rely on HE\-based aggregators typically adopt a shared public key\-based encryption approach to protect the local models, allowing the server to use the additive homomorphic property of the encryption system to aggregate the encrypted models, without decrypting them\([Xu et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib163);[Liu et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib124)\)\. For the system to be reliable and robust\([Liu et al\., 2022b](https://arxiv.org/html/2609.28722#bib.bib101)\), the secret key management is vital\. Three main secret key handling choices are covered in the literature, and each has a distinct influence on robustness and privacy in FL systems\([Zhu et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib103)\)\. The three key handling practices are discussed as follows: \(1\) Secret key sharing among users – this approach distributes the secret key to all users but kept concealed from the server\. Each participant has access to the global model\. Even though this configuration permits aggregation using cryptographic systems like Paillier, RSA, lattice\-based, ElGamal, and BGN\([Fang et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib102)\), its robustness is constrained by potential flaws in key dissemination\. \(2\) Central server holds the key – only the server holds the secret key, protecting the privacy of the global model\. However, because the server can decrypt encrypted models, this centralization can undermine robustness and risk client model privacy\. Additional strategies, such as model masking or using a trusted party to handle the secret key, are required to improve robustness and privacy\. \(3\) Threshold\-based key handling – this enhances the shared key management by mandating a certain number of users to collaborate to perform decryption utilizing techniques such as ElGamal and threshold Paillier\([Zhu et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib103)\)\. Table 8\.Summary of robust aggregation approaches\.CategoryPaperMethodsKey FeaturesAdvantagesDrawbacksClient model evaluationCosine similarity based evaluation of gradients, Geometric median aggregation, Entropy\-based client weighting\.Prioritizes gradients with higher cosine similarity, Robust aggregation via geometric median, Personalization via entropy\-based weighting\.Enhances robustness against malicious clients, Reduces impact of outliers\.Computational overhead in gradient similarity calculations, Requires additional validation metrics, May not generalize to all non\-IID settings\.Quantum secure aggregationQuantum bit representation of model parameters, Entangled qubits for model aggregation, Post\-quantum secure protocol using homomorphic pseudorandom generator\.Secure aggregation using qubits, Low computational complexity, Post\-quantum security, Compatible with different model architectures\.High resilience against attacks, Ensures privacy without sacrificing efficiency\.Requires specialized quantum hardware, Limited scalability in classical systems, Not widely adopted due to early\-stage development\.Dynamic fusion of local modelsDynamic fusion of local models based on time windows, Adaptive aggregation strategies, Temporal weight decay strategies\.Excludes stale models, Implements deadline\-based aggregation\.Handles stale model updates effectively, Improves aggregation efficiency\.Performance depends on accurate time\-window selection, High communication overhead for frequent updates, Increased computation for temporal decay management\.Statistical featuresTrimmed Mean, Median\-Krum, Multi\-Krum aggregation\.Median\-Krum joint method, Robust aggregation under adversarial conditions, Effective accuracy and convergence under malicious conditions\.Robust against adversarial manipulations, Convergence under malicious attacks, Effective under non\-IID settingsMay discard useful model updates, computationally expensive, May not perform well in extreme data heterogeneity scenarios\.Adaptive client selectionMulti\-armed bandit strategy, Gradient update norms, Radial\-basis functions, Adaptive client selection based on communication capacity\.Multi\-armed bandit approach, Dynamic client evaluation, Balancing exploration vs\. exploitation, Focus on gradient norms and model alignment\.Dynamic selection based on exploration\-exploitation trade\-off, Efficient client evaluation to reduce communication overhead\.Selection bias may impact global model accuracy\.Training function optimizationRegularization in loss function, Dynamic clipping value, Huber loss function\.Loss function regularization, Dynamic adaptation for non\-IID scenarios, Huber loss extension for optimal robustness\.Adaptive to non\-IID scenarios, Improves robustness of convergence\.Requires careful tuning of regularization parameters\.Contextual model aggregationContext\-dependent aggregation bounds, Smooth loss function assumptionContext\-dependent aggregation, Smoothness assumption for loss functions, Robust optimization per device context\.Optimizes aggregation based on device context\.Complexity increases with diverse contexts\.MPC\-based approachesFast Fourier Transform\-based secret sharing, Two\-step aggregation process, Verifiable sharing schemesFast Fourier Transform for secret sharing, Verifiable MPC schemes, Use of multiple servers for improved security and privacy\.Improved privacy via MPC, Supports collaborative computation, Resilience against single point of failure\.High computational and communication costs, Requires careful protocol design, Limited efficiency for large models\.Blockchain\-based approachesReputation\-based reward systems, Blockchain for secure model aggregation, Model encryption during uploadDecentralized aggregation, Reputation\-based model evaluation, Ensure model integrity and prevent tampering using blockchain\.Ensures transparency and traceability, Prevents model manipulation\.Slower convergence due to blockchain verification, High communication and storage overhead\.TEE\-based approachesTrust execution environment for secure aggregation, DP techniques with TEEs, Model shuffling for additional security\.Secure model aggregation via TEEs, DP\-enhanced privacy, Randomization via model shuffling, ML in TEEs for enhanced security\.Efficient computation, lower communication overhead, stronger protection against insider attacks\.Hardware dependency and trust assumption on hardware vendors, Memory and execution constraints, Vulnerable to side\-channel attacks\.HE approachesAdditive HE, Secret key management methods \(shared, centralized, threshold\-based\)\.Privacy\-preserving aggregation, various key management strategies, Additive HE for model aggregation\.Strong privacy guarantees, Compatible with different FL frameworksIncreased computational overhead with large\-scale models, Demands careful key management\.Clustering\-based approaches\([Xiao et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib152)\),\([Lin et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib156)\),\([Palihawadana et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib158)\),\([Wang et al\., 2021a](https://arxiv.org/html/2609.28722#bib.bib153)\),\([Li et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib155)\),\([Augello et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib195)\)K\-means clustering, Client similarity metrics \(Manhattan, cosine distances\), Data distribution\-based clustering\.Improved aggregation efficiency, Targeted model aggregation within clusters, Enhanced collaboration among similar clients\.Reduces aggregation overhead, Improves accuracy over diverse datasets\.Performance drops with incorrect clustering, requires accurate clustering criteria\. \(iii\) Quantum secure aggregation:Quantum Secure Aggregation \(QSA\) schemes are receiving popularity\([Chehimi and Saad, 2022](https://arxiv.org/html/2609.28722#bib.bib173);[Javeed et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib171);[Yang et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib175)\)since they can be used to strengthen robustness against evolving challenges\. By encoding local model parameters in quantum bits \(qubits\), QSA can boost security and efficiency in aggregating them\([Zhang et al\., 2022b](https://arxiv.org/html/2609.28722#bib.bib174)\), guaranteeing strong resilience against exposure to semi\-honest adversaries\. Eavesdropping can be discovered and eliminated by QSA’s robust security settings\. A 3\-round post\-QSA mechanism is devised by\([Yang et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib175)\)to deal with quantum threat contexts\. It employs an additive homomorphic decryption that relies on Shamir secret sharing and a homomorphic pseudorandom generator based on single\-masking to guarantee robust functionality even when participants drop out\. This mechanism is a promising strategy for reliable and robust aggregation in quantum\-inspired FL since it exhibits impressive run\-time efficiency and preserves privacy under a semi\-honest threat model\.\(iv\) Blockchain\-based aggregators:Blockchain technology, with its decentralized and tamper\-resistant features, is increasingly being utilized to enhance FL robustness and security\([Shen et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib97);[Vangala et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib119);[Hamouda et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib185)\)\. In such a setup, clients download the global model from the blockchain, then train and encrypt their models before uploading them back\([Chen et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib110);[Kalapaaking et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib188)\)\. Miner servers aggregate these models and update the global model, which is then distributed to other nodes \(See Fig\.[9](https://arxiv.org/html/2609.28722#acmlabel10)\)\. Figure 9\.Blockchain\-based FL: encrypted updates and aggregated results are safely recorded; miner servers perform model aggregation\.blockchain\-based FL for aggregation robustnessRecent developments include reputation\-based reward systems where each aggregation node evaluates and reports the quality of local models to the blockchain\. Integrating reputation with blockchain’s inherent security helps enhance FL robustness and quality by validating and rewarding model contributions based on performance and reputation\([Ranathunga et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib189)\)\.\(v\) TEE\-based aggregation:The TEEs provide a hardware\-isolated enclave within a processor, shielding sensitive code and data from the potentially compromised host operating system or Rich Execution Environment \(REE\)\([Zhao et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib86);[Zhang et al\., 2021c](https://arxiv.org/html/2609.28722#bib.bib87)\)\. In a robust FL framework, participants transmit encrypted local models to the REE, which serves as a gateway to the TEE, which securely decrypts and aggregates these updates, ensuring that raw model parameters remain inaccessible to the central server before the finalized global update is returned to the REE for distribution\([Zhao et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib86)\)\. Furthermore, executing the entire training process within the TEE environment has emerged as a comprehensive strategy to maintain end\-to\-end confidentiality of both algorithmic logic and data throughout the lifecycle of the aggregation process\([Kuznetsov et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib89)\)\. Table[8](https://arxiv.org/html/2609.28722#S3.T8)provides a quick view on robust aggregators focusing on key features, advantages, and drawbacks\. Table 9\.Key insights on robust aggregation strategies\.Key ChallengeUnderlying CausesImpact on AggregationExisting SolutionsEvaluation MetricsTrade\-offs InvolvedGaps in ResearchStatistical heterogeneityNon\-IID data distribution, Device diversity, Varying client participation, Variability in local datasets\.Divergence in local models affects global model convergence and performance\.Bayesian non\-parametric methods, Neuron matching, Probabilistic federated neural matching\.Accuracy, Model convergence rate, Gradient similarity\.Increased computation for better adaptability requires careful tuning\.Generalizing methods for complex neural networks, Adaptive sampling, Meta\-learning, Federated transfer learning, Hybrid approaches for improved convergence\.Fairness and bias mitigationDemographic biases in models, Disproportionate impact of non\-IID data\.Biased model updates, reducing overall model fairness and generalization\.FairFL, Adaptive sampling, Bias\-aware aggregation strategies\.Model fairness metrics \(e\.g\., demographic parity, equal opportunity\)\.Increased computational costs and require additional fairness constraints in optimization\.Advances in Federated debiasing techniques, Fairness\-aware aggregation\.Bottlenecks in communicationHigh number of clients, Limited bandwidth and connectivity constraints, Frequent communication rounds, Latency Constraints, Communication Overhead\.Slows down model updates and convergenceAirComp\-based FL \(Over\-the\-air computation\), Intelligent reflective surfaces \(IRS\), Multi\-relay techniques, Gradient sparsification, Quantization, Local update compression, 6G integration\.Latency, Communication overhead, Model convergence speed\.Accuracy loss, Higher infrastructure cost\.6G for higher efficiency and scalability, AI\-driven network optimization, Edge caching\.Secure aggregationModel poisoning, Inference attacks, Sybil attacks, Data poisoning, Backdoor attacks\.Risk of poisoning and inference attacks compromise FL security\.Robust aggregation, Anomaly detection TEE, Cryptographic filtering, Blockchain\.Attack resistance, Privacy preservation, Adversarial robustness\.Trade\-offs in model utility, Higher computational and storage costs for improved security\.Enhancing blockchain security for decentralized FL, Secure multi\-party computation \(SMC\), Decentralized consensus mechanisms\.Robustness and efficiency tradeoffHigh computational and communication costs, Resource\-constrained edge devices\.Balancing security, accuracy, and resource constraints, Delay in model convergence\.Adaptive aggregation techniques, Sparsification and quantization, Cryptographic solutions\.Accuracy loss, Model convergence time, Computational cost, Computational overhead\.Model robustness and computational overhead, Security, and aggregation speed\.Dynamic aggregation methods that optimize performance under varying conditions, Trade\-off\-aware federated optimization strategies, lightweight security mechanisms, and robustness under real\-time FL conditions\.Quantum aggregationInstability due to quantum errors, Quantum noise, error correction, and limited availability of quantum hardware\.Faster aggregation, Higher security via quantum cryptographic techniques\.Quantum secure multi\-party computation, Quantum\-enhanced HE, Hybrid quantum\-classical FL aggregation models\.Aggregation speed, Computational complexity, Noise resilience in quantum operations, Robustness against quantum attacks\.Quantum and classical processing, Stability and computational speed, Scalability\.Stable quantum aggregation, PQC\- methods, Error mitigation techniques, Hybrid quantum\-classical models\. ### 3\.3\.Key Insights on Robust Aggregators Despite progress in robust aggregation, several challenges persist and remain crucial to the continued advancement of FL systems\.Statistical heterogeneityremains a major challenge due to non\-IID data, affecting global model convergence\.Fairness and biasmitigation demands attention towards addressing demographic imbalances in FL through bias\-aware aggregation approaches with reduced computational costs\.Communication challengesarising from limited bandwidth and high client numbers hinder model convergence, demanding future improvements in technologies such as over\-the\-air computation and gradient sparsification\. The use of blockchain\-based solutions and cryptographic verifications for decentralized FL has strengthened the aggregation robustness against inference and poisoning assaults\. While adaptive and dynamic techniques improve aggregation performance, reliability, and accuracy, resource limits must be balanced to ensure thetrade\-off between robustness and efficiency\. More efficient and secure aggregation provided by QSA makes it a viable future path\. However, hardware constraints and quantum noise lead to stability and scalability challenges\. Table[9](https://arxiv.org/html/2609.28722#S3.T9)presents the key insights for a quick understanding of the research gaps in the robust aggregation methodologies\. The table summarizes the root causes, impacts on aggregation, reported solutions, assessment approaches, trade\-offs, and research gaps for each challenge, rendering a thorough summary of the current literature to support future plans for boosting aggregation robustness in FL\. ## 4\.Robustness via Defensive Strategies Given FL’s susceptibility to diverse threats, robust defensive strategies are critical to protect local updates and aggregation results against established and evolving threats\.∙\\bulletLimitations of conventional defenses:Classical centralized defensive measures, such as anomaly detection and robust loss functions, rely on direct inspection of training data or regulating participants\([Jiang and Borcea, 2023](https://arxiv.org/html/2609.28722#bib.bib46);[Ozfatura et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib39)\)\. Such approaches, however, are not directly viable to FL, as the centralized server has confined capabilities to monitor the local updates or parameters during the training stage\([Zhao et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib139);[Liu and Shang, 2022](https://arxiv.org/html/2609.28722#bib.bib123)\)\. Local updates generated by the participants are vulnerable to different challenges, demanding early\-phase security measures\. Protecting training data is equally important, as it supports the development of robust models\([Yu et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib47);[Marnissi et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib2);[Wang et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib154)\)\. Figure 10\.Taxonomy: Robustness through defensive strategies along with the relative proportion \(%\) of reviewed publications\.Taxonomy of defensive strategies for upholding robustness### 4\.1\.Proposed Taxonomy of Defensive Strategies With the growing complexity of adversarial threats, new defensive measures are evolving to thwart the attacks\([Lyu et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib126);[Liu et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib166)\)\. The protection of client data and the integrity of local updates are guaranteed by client\-level protective measures\([Wan et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib190)\)\. New vulnerabilities could appear during the aggregation stage, when the server combines local model updates\. Aggregated updates could expose personal information or tilt the global model if rigorous security measures aren’t enforced\([Fung et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib85);[Pillutla et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib115);[Fraboni et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib105);[Li et al\., 2019](https://arxiv.org/html/2609.28722#bib.bib95)\)\. For this reason, strategic countermeasures are vital\. In order to guarantee the availability, confidentiality, and integrity of model components and training data, a thorough methodology that takes into consideration both local and global levels is important\([Xu et al\., 2022a](https://arxiv.org/html/2609.28722#bib.bib114)\)\. In contrast to current surveys, which categorize defenses by attack type, we prefer a more comprehensive strategy because many mechanisms are known to handle multiple attacks\. Fig\.[10](https://arxiv.org/html/2609.28722#acmlabel11)gives the proposed taxonomy of defensive strategies for achieving robustness against hostile threats\. #### 4\.1\.1\.Defenses against Training Data Manipulation Advanced preprocessing approaches to safeguard training data have been investigated recently\([Xia et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib92)\)\. This strengthens data security by preventing data poisoning and property inference attacks\([Gupta et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib1)\)\. An interesting example is provided in\([Xu et al\., 2024a](https://arxiv.org/html/2609.28722#bib.bib88)\), which employs an enhanced variational autoencoder \(VAE\) for property split and property variance management to circumvent inference attacks while maintaining model accuracy\. This strategy successfully reduces the success rates of poisoning and inference attacks, advancing FL security\. In addition,DP techniquesare utilized to protect confidential data, further enhancing the security measures available for FL systems\([Andrew et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib96)\)\. Empirical evidence reveals that these methods can successfully mitigate the potency of reconstruction attacks\. The significance ofKnowledge distillation \(KD\)in boosting security and robustness of FL is highlighted in recent studies\. The utility of global KD for retrieving useful knowledge while removing malicious inputs from infected clients is discussed in\([Park et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib107)\)\.Adversarial distillationas a defense mechanism is also investigated to enhance the robustness of the FL model against backdoor attacks by altering the distillation process during federated communication\([Zhu et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib125)\)\. These advancements demonstrate the effectiveness and adaptability in addressing privacy concerns, client\-side attacks, and backdoors, promoting the field of FL toward stronger security and robustness\([Liu et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib124)\)\. #### 4\.1\.2\.Defenses against Malicious Model Updates Robust aggregation, which does not necessitate the explicit identification of hostile clients, is considered a common defensive measure against a variety of poisoning attacks\([Peng et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib37);[Wang et al\., 2024b](https://arxiv.org/html/2609.28722#bib.bib43);[Pillutla et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib115)\)\. However, the most successful defenses against malicious model updates include a variety of methods intended to identify and reduce detrimental effects from hostile clients\([Mozaffari et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib176);[Ma et al\., 2022b](https://arxiv.org/html/2609.28722#bib.bib133)\)\. A common approach issimilarity\-based detection, which assumes that benign updates, though unique, will typically align a particular reference model or pattern\([Cao et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib146);[Wang et al\., 2021a](https://arxiv.org/html/2609.28722#bib.bib153)\)\. Malicious updates, on the other hand, are likely to break such assumptions\. To find deviations, each update is compared to an aggregated model or a known best model, using criteria such as Euclidean distance or cosine similarity\. Local models are assessed usingsimilarity\-based recognition and trust scoring, which assign ratings based on validation datasets or similarity factors\. Clients exhibiting consistent, benign\-like updates gain more weights via adaptive mechanisms, whereas distrustful updates are scaled\-down or omitted from the aggregation process\([Cao et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib146);[Wang et al\., 2021a](https://arxiv.org/html/2609.28722#bib.bib153);[Wang et al\., 2020b](https://arxiv.org/html/2609.28722#bib.bib38);[Zhang et al\., 2023b](https://arxiv.org/html/2609.28722#bib.bib13);[Zhang and Li, 2024](https://arxiv.org/html/2609.28722#bib.bib111)\)\. When an attack has already contaminated the global model, mitigation measures prioritize identification of the parameter space where the attack’s long\-term impact resides and perturbing it during the training process\([Sun et al\., 2021b](https://arxiv.org/html/2609.28722#bib.bib178)\)\. With this, residual effects can be neutralized to provide robustness against such risks\. Moreover, the use of single\-masking approaches helps to conceal actual client data, while cloud\-stored data inhibits malevolent participants from initiating DoS behaviors, boosting FL system resilience\([Zhang and Li, 2024](https://arxiv.org/html/2609.28722#bib.bib111)\)\. One of the main drawbacks of such methods is that they often need extra datasets or TEEs to verify the integrity of updates, which is not always practical\. Furthermore, these tactics can often tolerate only a certain number of malicious users and may not be robust against multiple types of poisoning scenarios\([Xu et al\., 2022a](https://arxiv.org/html/2609.28722#bib.bib114);[Zhang et al\., 2021c](https://arxiv.org/html/2609.28722#bib.bib87)\)\. The paper\([Xu et al\., 2022a](https://arxiv.org/html/2609.28722#bib.bib114)\)addresses this concern using a truth\-discovering method that defends against multiple poisoning attacks without needing additional datasets, even when the proportion of adversaries exceeds half of the total users\. Other sophisticated methods to develop robust FL frameworks includeVariance reduction and DPmethods\([Zhang and Hu, 2023](https://arxiv.org/html/2609.28722#bib.bib40);[Jiang and Borcea, 2023](https://arxiv.org/html/2609.28722#bib.bib46);[Marnissi et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib2)\)\. These enhancements strengthen security while maintaining a better balance between utility, privacy, and efficiency\. In addition to enabling effective preprocessing,autoencoder\-based solutionshave evolved as powerful defenses against deceptive model updates\. With the ability to learn compressed representations, autoencoders can effectively distinguish benign from deceptive updates, eliminating corrupted contributions prior to aggregation\([Xu et al\., 2024a](https://arxiv.org/html/2609.28722#bib.bib88)\)\.Sparsificationas a defense mechanism also exhibits its excellence in both boosting communication efficacy and robust security\([Jiang and Borcea, 2023](https://arxiv.org/html/2609.28722#bib.bib46);[Ozfatura et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib39);[Marnissi et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib2);[Wang et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib154)\)\. For instance, a peer\-to\-peer FL approach in\([Wang et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib154)\)optimizes performance while providing robust defenses against multiple attacks\.Watermarkinghas also been employed as a defense strategy to ensure model integrity and ownership by including distinctive patterns during the training phase\([Yang et al\., 2023b](https://arxiv.org/html/2609.28722#bib.bib142)\)\. Watermarks can be revealed to establish ownership and stop unauthorized duplication of the model, despite the fact that they remain hidden during regular operations\. But preserving model functionality and privacy while maintaining watermark robustness is still difficult\([Xu et al\., 2024b](https://arxiv.org/html/2609.28722#bib.bib143)\)\. In addition, blockchain technology provides options to use smart contracts for model integrity verification, guaranteeing that submitted models fulfill specifications\([Ranathunga et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib189);[Shen et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib97);[Chen et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib110);[Kalapaaking et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib188)\)\. Table 10\.Summary on robustness via defensive strategies\.CategoryPaperMethodsKey featuresEvaluation metricsDatasetsAdvantagesDrawbacksAgainst training\-data manipulationAdvanced preprocessing, local data filtering, enhanced VAE for property division or variation control, DP on data or gradients, global KD to filter malicious client knowledge, adversarial distillation against backdoors\.Reduces poisoning and inference risk, provides noise\-based privacy, and filters poisoned samples before aggregation\.ASR, property inference AUC, reconstruction success, and clean accuracy\.MNIST,CIFAR\-10/100,EMNISTProtects data and intermediate representations, reduces attack surface before aggregation, preserves utility via KD/distillation\.DP/KD/VAEs add overhead, utility loss if over\-tuned, need auxiliary data, hyperparameter sensitivity\.Against malicious model updates\([Wang et al\., 2024b](https://arxiv.org/html/2609.28722#bib.bib43)\)\([Wang et al\., 2021a](https://arxiv.org/html/2609.28722#bib.bib153)\),\([Cao et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib146)\),\([Peng et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib37)\),\([Wang et al\., 2020b](https://arxiv.org/html/2609.28722#bib.bib38)\),\([Yang et al\., 2023b](https://arxiv.org/html/2609.28722#bib.bib142)\),\([Zhang et al\., 2021c](https://arxiv.org/html/2609.28722#bib.bib87)\),\([Zhang and Li, 2024](https://arxiv.org/html/2609.28722#bib.bib111)\),\([Chen et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib110)\),\([Kalapaaking et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib188)\),\([Ranathunga et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib189)\),\([Ozfatura et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib39)\),\([Marnissi et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib2)\),\([Wang et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib154)\),\([Jiang and Borcea, 2023](https://arxiv.org/html/2609.28722#bib.bib46)\),\([Xu et al\., 2024a](https://arxiv.org/html/2609.28722#bib.bib88)\),\([Xu et al\., 2022a](https://arxiv.org/html/2609.28722#bib.bib114)\)\([Xu et al\., 2024b](https://arxiv.org/html/2609.28722#bib.bib143)\),\([Sun et al\., 2021b](https://arxiv.org/html/2609.28722#bib.bib178)\),\([Ma et al\., 2022b](https://arxiv.org/html/2609.28722#bib.bib133)\),\([Zhang and Hu, 2023](https://arxiv.org/html/2609.28722#bib.bib40)\)Robust aggregation rules, similarity or trust\-based filtering, truth\-discovery, HE\-based, variance\-reduced \+ DP, autoencoder\-based anomaly filtering, sparsification, watermarking, blockchain/smart\-contracts\.Server or client\-side update inspection, down\-weight or drop suspicious gradients, and cryptographic traceability for updates\.Accuracy under attack, ASR, detection precision/recall, convergence, watermark detection rate, and blockchain latency\.MNIST,CIFAR\-10/100,EMNIST,FEMNIST,synthetic datasetsBroad coverage of model\-poisoning and byzantine behaviors, tolerate high malicious ratios, can recover from polluted rounds; reduces single point of failure, integrity, and ownership guarantees\.Bounded assumption on adversarial strength, demand extra validation data/ TEE, autoencoders, AEs/watermarks/blockchain overheads, sensitivity to non\-IID, and hyperparameter tuning\.Preserving global model integrity\([Sultana et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib91)\),\([Liu et al\., 2022b](https://arxiv.org/html/2609.28722#bib.bib101)\),\([Du et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib90)\),\([Cao et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib83)\),\([Uprety and Rawat, 2021](https://arxiv.org/html/2609.28722#bib.bib144)\),\([Andreina et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib145)\),\([Issa et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib128)\)Global integrity assessment across training rounds, decentralized multi\-model aggregation with voting, trust scores via global / client validation, and privacy\-aware and personalized encoders\.Post\-aggregation checking, detect and neutralize persistent poisoning effects, majority voting across models, maintain privacy while preserving utility\.Global accuracy under strong poisoning; integrity or trust scores; fraction of compromised updates detected and discarded; privacy\-utility trade\-off metrics\.EMNIST,FEMNIST,MNIST,CIFAR\-10,synthetic datasets\.Adds a global sanity check layer beyond local defenses, can recover from polluted rounds, and reduces a single point of failure via multiple globals\.Depends on representative validation sets/clients, higher coordination/computation overhead, and personalized encoders have extra complexity\.Against malicious servers\([Le et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib177)\),\([Mothukuri et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib33)\),\([Jeter et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib157)\),\([Huang et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib3)\),\([Han et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib6)\),\([Hao et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib7)\),\([Guo et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib17)\),\([Zhou et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib186)\),\([Ma et al\., 2022a](https://arxiv.org/html/2609.28722#bib.bib187)\),\([Ye et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib118)\),\([Liu and Shang, 2022](https://arxiv.org/html/2609.28722#bib.bib123)\),\([Tang et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib59)\)Server\-side threat analyses, image augmentation, enhanced ciphertext schemes, decentralized / blockchain FL, auditing and monitoring, limit or detect client identification by the server\.Limit gradient inversion, server\-side reconstruction, client identification, protect against server model manipulation, and accountability for server operations using decentralization and auditing\.Privacy leakage metrics \(e\.g\., inversion success\), identification success, global accuracy under a malicious server, audit, and consensus performance\.CIFAR\-10/100,MNIST,synthetic datasets\.Targets the strongest adversary \(the server\) explicitly, preserves utility, and increases transparency and accountability\.Blockchain/auditing introduces latency, storage, and system complexity, tailored to specific modalities \(e\.g\., images\), and cryptography demands careful key and protocol management\.Adversarial\-resilient aggregationStatistical robust aggregation, byzantine\-resilient aggregation, similarity/distance\-based methods, reputation\-based methods, cryptography\-enhanced methodsTolerate adversarial or corrupted gradients, detect and suppress abnormal updates and outliers during aggregation, account for reliable participants, protect update confidentiality and integrity\.Global accuracy under attack, ASR, Byzantine tolerance level, convergence stability, computation and communication overhead\.MNIST,CIFAR\-10/100,EMNIST,FEMNISTImageNetEnhances robustness against adversarial behaviors, tolerates a fraction of malicious clients, enhances stability and reliability of global model updates\.Assumes bounded adversaries, performance may get affected under highly non\-IID data, similarity and reputation mechanisms introduce additional computation, cryptography\-enhanced methods increase overhead\.Advanced cryptographic strategies\([Xia et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib92)\),\([Sotthiwat et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib147)\),\([Zhu et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib103)\),\([Ma et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib134)\),\([Javeed et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib171)\),\([Chehimi and Saad, 2022](https://arxiv.org/html/2609.28722#bib.bib173)\),\([Gurung et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib172)\),\([Ma et al\., 2022d](https://arxiv.org/html/2609.28722#bib.bib135)\),\([Moriai, 2019](https://arxiv.org/html/2609.28722#bib.bib132)\),\([Moshawrab et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib170)\)HE, partial HE, two\-trapdoor HE with secure cosine similarity, ZKPs for verifiable training, PQC, quantum\-resistant signatures \+ blockchain, PE for SVM\-based FL\.Guarantee confidentiality and integrity of updates and aggregation, public verifiability, and quantum\-resistant security\.Byzantine tolerance level, runtime and memory overhead, proof generation/verification time/size, comm\. cost, task accuracy under encrypted/PQC/PE\.MNIST,CIFAR\-10,synthetic datasets\.Offer strong, provable security guarantees, can be combined with other defenses, higher tolerance in heterogeneous environments\.Higher overhead, especially for deep models, polynomial approximations needed for deep non\-linear models, complex key management, large\-scale deployment challenges\. #### 4\.1\.3\.Preserving Global Model Integrity Evaluating the integrity and performance of the updated global model is essential to improve FL’s robustness to model poisoning threats\([Sultana et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib91)\)\. Despite the existence of many robust aggregation techniques, these measures may not fully guarantee FL robustness in the face of highly potent adversaries\. As a result, even in the absence of further attacks, the negative consequences induced by the attack can persist through the later rounds if the global model is poisoned\([Andrew et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib96);[Liu et al\., 2022b](https://arxiv.org/html/2609.28722#bib.bib101);[Du et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib90)\)\. Additionally, the framework is susceptible to adversarial manipulation due to its reliance on a single global model\. This has been tackled with the emergence ofdecentralized aggregation schemes, where clients collectively train the global model, each of which contributes to the ultimate prediction through majority voting\([Cao et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib83)\)\. Although it is still tricky to recognize specific attackers, this approach increases robustness against poisoning attempts\. Devising effectivetrust measures for clientsis vital for accurate assessment\. A global validation set can evaluate the global model after each client submission, updating client trustworthiness based on model performance\([Uprety and Rawat, 2021](https://arxiv.org/html/2609.28722#bib.bib144)\)\. However, the effectiveness of this defense depends on the quality of the test set, prompting the exploration of alternatives\. For e\.g\., instead of centralized testing, a modified global model can be evaluated by selecting validation clients using their local data\([Andreina et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib145)\)\. If flagged as compromised by a majority of these clients, the server discards the update, ensuring the global integrity and reinforcing overall robustness\.\([Issa et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib128)\)focuses on mitigating such threats while maintaining the model utility and ensuring data privacy, contributing to the overall system integrity\. #### 4\.1\.4\.Defenses against Malicious Servers Malicious servers represent a dual threat to client privacy and overall system robustness\([Hao et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib7);[Han et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib6)\)\. They may engage in both passive and active attacks, often analyzing individual client updates or isolating shared models to compromise the underlying security model\([Jeter et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib157);[Huang et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib3)\)\. In addition to typical snooping, servers can utilize advanced multitasking strategies to create adversarial networks intended for client identification, which directly infringe user privacy\([Le et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib177);[Mothukuri et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib33)\)\. The server’s ability to intercept personal data and deduce confidential information by closely analyzing model predictions or gradients\([Guo et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib17)\)further exacerbates this risk\. Furthermore, by introducing malevolent parameters, crafted gradients, or corrupted updates to undermine accuracy\([Han et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib6)\), a compromised server can intentionally impair the global model’s performance\. Such manipulation extends beyond performance measures; a malevolent server can add systemic bias and compromise the fairness of the global model by actively altering model weights or parameters\([Tang et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib59)\)\. Studies that rely on decentralized and traceable blockchain\([Zhou et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib186);[Ma et al\., 2022a](https://arxiv.org/html/2609.28722#bib.bib187)\)have shown remarkable performance in handling these threats\. To prevent malicious servers from manipulating global model parameters to infer private data,\([Jeter et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib157)\)developed animage augmentation\- based defense that preserves model performance while showing strong resilience against such attacks\.Enhanced ciphertext strategiesalso provide defense against malicious server and client threats\([Huang et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib3)\)\. #### 4\.1\.5\.Adversarial\-resistant Aggregation Several techniques have been proposed to combine model updates from multiple participants while mitigating the impact of malicious or deceptive inputs\. We dedicated the entire Section[3](https://arxiv.org/html/2609.28722#S3)to discussing the robust aggregation strategies\. #### 4\.1\.6\.Advanced Cryptographic Strategies In addition to ensuring the integrity and confidentiality of the aggregation process, the integration of cryptographic strategies has also emerged as a valuable tool to enhance both security and robustness against sophisticated threats such as poisoning attacks\([Xia et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib92);[Sotthiwat et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib147);[Zhu et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib103);[Ma et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib134)\)\. The lack of transparency in the FL training process, due to its localized nature, makes it difficult for third parties, such as model users or auditors, to verify the model’s integrity and correctness\.Zero\-knowledge proofs\(ZKPs\) address this issue by allowing public verification of the learning process without disclosing confidential information about the model or the data\([Ma et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib134)\)\. Moreover,Post\-Quantum Cryptography \(PQC\)\([Javeed et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib171)\),quantum cryptographic approachesare becoming increasingly popular\. In contrast to conventional RSA and ECDSA, which are susceptible to Shor’s algorithm, PQC is based on a mathematical foundation that can resist quantum\-scale attacks\([Javeed et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib171);[Chehimi and Saad, 2022](https://arxiv.org/html/2609.28722#bib.bib173)\)\. To resist emerging quantum threats,\([Gurung et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib172)\)integrated PQC withinblockchain\-based FLby using a combination of stateful and stateless hash\-based signature mechanisms\. Similarly,HEhas been used as a defense mechanism against poisoning threats\. For instance, thetwo\-trapdoor HEmechanism devised in\([Ma et al\., 2022d](https://arxiv.org/html/2609.28722#bib.bib135)\)successfully identifies and eliminates malicious updates by estimating distances between encrypted gradients using secure cosine similarity\. This ensures robustness while preserving privacy\. This method is particularly effective in heterogeneous scenarios and can withstand up to 50% adversarial users\. Even though popular schemes such as El Gamal, RSA, and Paillier exhibit homomorphic characteristics\([Zhu et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib103)\), applying them to FL faces a number of trade\-offs, such as increased memory overhead, latency, and polynomial approximations for non\-linear models\([Moriai, 2019](https://arxiv.org/html/2609.28722#bib.bib132)\)\.polymorphic encryption\(PE\) has also been experimented in this context to resist inference and poisoning attacks\([Moshawrab et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib170)\)\. ### 4\.2\.Key Insights on Defensive Strategies We present Table[10](https://arxiv.org/html/2609.28722#S4.T10)to provide a quick summary of robustness through defensive mechanisms, and Table[11](https://arxiv.org/html/2609.28722#S4.T11)to deliver the key insights\. The analysis demonstrates that upholding robustness demands layered defenses covering data, updates, adversarial aggregation, global model verification, server behavior analysis, and cryptographic safeguards\. AEs, DP, KD, and client\-side preprocessing work together to reduce*inference risk and poisoning*while maintaining accuracy in the face of training data manipulation\. Although they often come at the expense of additional computation, validation data, or protocol complexity,*robust aggregation, similarity/trust mechanisms, truth discovery, sparsification, autoencoders, watermarking, and blockchain*provide additional protection against malicious model updates\. Vital sanity\-checks should be performed to*ensure global integrity*\(such as Eiffel, decentralized aggregation, trust\-validation, and personalized encoders\) to preserve or restore a clean global model in the face of severe attacks\. By reducing reconstruction, client identification, and biased aggregation, defenses against*malicious servers*, such as image augmentation, enhanced ciphertext, and blockchain\-based auditing, specifically target the most powerful adversary\. Moreover, strong confidentiality and verifiability are provided by*sophisticated cryptographic techniques*, but these techniques can also incur additional overhead\. Thus, practical robust FL deployments should consider*carefully selected hybrids*rather than relying solely on a single defense mechanism\. Table 11\.Key insights on robustness via defensive strategiesInsightCore ideaDefended threatsTypical design patternAdvantagesDrawbacksConventional defenses fail in FLClassical centralized defenses that assume direct access to training data and full control over the pipeline conflict with FL’s distributed approach\.Data poisoning in raw data, data\-level outliers, and direct anomaly detection at the sample level\.Assume the server sees the full dataset; reweight or discard suspicious samples using robust losses or feature statistics\.Well\-understood in centralized ML; strong guarantees only when data is pooled\.Incompatible with FL’s update\-only interface, violates privacy constraints, and cannot inspect raw local data or intermediate features\.Multi\-attack coverageDefenses that simultaneously address multiple threats appear more appealing than mechanisms tailored to a single attack type, motivating taxonomies organized by phase or location rather than by attack\.Label\-flipping, gradient poisoning, backdoors, inference or reconstruction attacks\.A combination of robust aggregation with DP noise, KD, autoencoder\-based update scoring, or sparsification\.One mechanism spans multiple stages \(local, aggregation, global\) and minimizes attack\-specific tuning, making it convenient in mixed\-threat environments\.Difficult to ensure the best protection for any single attack, covert and adaptive adversaries can still circumvent generic rules, DP noise, and robustness interaction is non\-trivial\.Layered client\-server protectionCombined protection across local training, aggregation, and system layer for increased effectiveness than any isolated component\.Local poisoning; gradient leakage; compromised servers; integrity of global model and logs\.Client \(preprocessing, DP, VAE, KD, etc\.\), server \(similarity or trust scoring, robust aggregation\), system \(blockchain, auditing, watermarking\)\.Suppress attacks early at the client, preserve long\-term traceability and accountability of updates, and model lineage\.Increased overall complexity, difficulty in coordinating thresholds and hyperparameters across layers, and overhead on resource\-constrained devices\.Cryptography boosts robustnessStrong cryptography enables confidentiality and verifiability, but is resource\-intensive\.Inference attacks, model or gradient inversion, leakage, poisoning, and replay attacks\.Secure aggregation, ZKP, PE, and PQC techniquesSecurely fetch individual updates from the server and peers, allow validation during aggregation and training, tolerate stronger threat models \(e\.g\., curious or semi\-malicious servers\)\.Encrypted computation is slow \(high runtime\), nonlinear networks require polynomial approximations, and protocols are complex and involve key management issues\.Fragile defensive assumptionsSimple assumptions that may break under sophisticated or more realistic conditions\.High\-Byzantine poisoning, adaptive and covert adversaries that target defense logic, highly non\-IID clients\.Assume a maximum fraction of suspicious clients, need good validation data or honest clients, threshold tuning for specific non\-IID levels\.Offer provable bounds or strong empirical robustness under an assumed context, easy to analyze and implement for targeted scenarios\.Bound on malicious fraction; need auxiliary data or TEE; degrade under extreme non\-IID\.Robustness through personalizationClient or cluster\-specific models to reduce the impact of poisoned or biased updates\.Client\-targeted poisoning; non\-IID amplified attacks; fairness/bias issues\.Clustered aggregation, personalized layers, trust\-weighted personalization, KD\-based refinement, representation or prototype\-level adaptation\.Reduces cross\-client poisoning; isolates malicious clusters, better fits local data, improves accuracy and robustness on non\-IID data\.More models to manage, difficulty in global guarantees, and misassignment of clusters strengthen attacks\.Ownership and auditabilityVerify training integrity and prevent theft, copying, or claiming ownership of the model\.Model theft, unauthorized model re\-use, disputes about training data or protocol\.Watermarking, blockchain \(append\-only logs for updates\), signed update histories, ZKPs for verifiable training\.Enables model origin verification and tamper checks, easier detection of adversarial modifications, and supports audit requirements\.May not prevent attacks in real time; a delicate trade\-off between watermark robustness and accuracy; a blockchain or logging approach incurs an operational burden\.Future\-guarantees with PQC and hybrid designsAgainst future quantum attackers while staying practical via hybridization tactics\.Update confidentiality, key compromise, signature forgery, and long\-term model poisoning\.PQC\-based signatures, PQC \+ blockchain, PQC\-secured aggregation, lightweight crypto integration with statistical defenses \(DP, robust aggregation, sparsification\)\.Security against emerging cryptanalytic capabilities, verifiable logs, and secure channels, integration with existing FL pipelines\.PQC tooling is in nascent stages, larger keys and signatures, hybrid design and deployment remain complex\. ## 5\.Experimental Evaluation Trends This section analyzes current trends in the experimental evaluation of robust FL systems, focusing on data partitioning approaches and the datasets commonly used for robustness testing\. The analysis highlights the strengths and weaknesses of current methodologies and provides insights into potential areas that demand more robust evaluations\. ### 5\.1\.Data Partitioning Approaches Evaluating FL algorithms often involves simulating non\-IID data distributions across clients, even when the main focus is on handling heterogeneity rather than treating it as an additional source of noise\. Meanwhile, for IID data partitioning, the data is randomly and evenly distributed across clients, ensuring each client has a similar distribution\. The most common approach to simulate non\-IID conditions is theClass\-based approach\. Each client typically receives data corresponding to a limited number of classes, with uneven sample counts, reflecting a highly skewed distribution\. For instance, in\([Jeong et al\., 2018](https://arxiv.org/html/2609.28722#bib.bib29)\), 2000 samples are selected randomly and divided into 10 subsets based on their true labels\. Each client is then assigned a fixed number of target labels\. On the other hand, in\([Briggs et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib22)\), clients are given samples with only two labels, with each client receiving 600 instances\. Another common strategy is the Dirichlet distribution\-based approach, where data is allocated to clients based on a Dirichlet distribution, allowing for varying degrees of non\-IIDness\. TheCategory\-based approach, instead, performs distribution followed by local classification\. The data slices are distributed across clients, and classification is performed on the client side\. For instance, in\([Zhao et al\., 2018](https://arxiv.org/html/2609.28722#bib.bib30)\), the data is sorted by category into 20 partitions, and each client randomly receives two partitions from the 2 categories\. Although these approaches are commonly considered standard, the majority of studies typically consider a single non\-IID setting and rely on relatively simple varieties of label skew on vision benchmarks, overlooking stronger versions of volume, label, and feature skews\. For instance, the same defense can behave very differently depending on the partition choice\. Assessing robustness under dynamic or time\-varying trends that more accurately reflect real deployments, combining multiple skew types, and systematically varying distribution skew \(e\.g\., varying Dirichlet concentration\) are potential areas that warrant further attention\. Table 12\.Summary of commonly used datasets in FL research\.Common datasets used by researchers in FLDatasetTypeDescriptionIIDNon\-IIDApplied ScenarioCIFAR\-10Image Classification60,000 32x32 color images across 10 classes✓\\checkmark✓\\checkmarkObject recognition, autonomous systems\.CIFAR\-100Image Classification60,000 32×32 color images across 100 classes×\\times✓\\checkmarkFine\-grained classification, FL model evaluation purposes\.MNISTHandwritten Digits70,000 28×28 grayscale images \(digits 0\-9\)✓\\checkmark✓\\checkmarkHandwritten digit recognition, basic FL benchmarking\.Extended MNISTHandwritten CharactersIncludes handwritten letters and digits×\\times✓\\checkmarkReal\-world non\-IID settings for character recognition tasks\.Fashion\-MNISTFashion Image Classification70,000 28×28 grayscale images across 10 fashion categories✓\\checkmark✓\\checkmarkRetail analytics, product categorization\.ShakespeareText \(NLP\)Complete works of Shakespeare divided by characters×\\times✓\\checkmarkPersonalized language modeling, and text generation tasks\.Google’s GboardKeystroke Data \(NLP\)Text input data from Google’s Gboard keyboard×\\times✓\\checkmarkNext\-word prediction, language modeling\.Application\-specificApplication\-related Data \(e\.g\., Medical, Speech, IoT\)Domain\-specific datasets for various real\-world applications×\\times✓\\checkmarkHealthcare, IoT, Speech recognition\.SyntheticSimulated DataArtificially generated datasets for algorithm testing✓\\checkmark✓\\checkmarkExperimenting FL model validation under controlled conditions and contexts\.OthersMiscellaneousOther miscellaneous datasets✓\\checkmark✓\\checkmarkFL research on custom datasets\. ### 5\.2\.Common Datasets in FL Research Unless an application\-specific dataset is used, researchers in FL typically rely on a set of commonly used datasets to evaluate the performance and robustness of their algorithms\. The most commonly used datasets are summarized in Table[12](https://arxiv.org/html/2609.28722#S5.T12), along with their type, description, suitability for data distribution, and real\-world application scenarios\. Fig\.[11\(a\)](https://arxiv.org/html/2609.28722#acmlabel13)represents the distribution of commonly used datasets in FL research\. CIFAR\-10 and MNIST remain foundational, demonstrating their continued relevance in collaborative model training scenarios\. Recently, the number of works using Fashion\-MNIST for image classification has increased\. \(a\)Commonly used datasets in FL research\.FL datasets used by researchers\. \(b\)Research focus across FL attack categories\.Fl research focus in terms of attacks Figure 11\.Current Research Trends in Robust FL\. ### 5\.3\.Research Trends in Robust FL According to the threat modeling literature, researchers have mostly focused on a few well\-known attack types, including backdoor attacks, model poisoning, and data poisoning\. Given their direct impact on the model’s integrity, they have been extensively explored by researchers\. Other key adversarial threats include inference attacks, free\-riding and malicious behavior, FL\-channel attacks, evasion strategies, and network\-level threats such as eavesdropping and DoS attacks\. Fig\.[11\(b\)](https://arxiv.org/html/2609.28722#acmlabel14)portrays the major research focus across various FL attack categories\. The current literature is dominated by works that either analyze the attack surface or design concrete defense mechanisms\. While defense mechanism focuses on countering diverse threats with customized protective strategies at the client or server side, attack surface analysis primarily focuses on methodically characterizing threats to robustness in FL\. In comparison, the researchers paid less attention to aggregation reliability and heterogeneity\. This indicates that FL robustness is still largely influenced by sophisticated adversarial circumstances, necessitating increased focus\. ## 6\.Discussion and Future Directions This section discusses key insights into emerging trends to robustness in FL, followed by the major application scenarios of robust FL, challenges faced, and future research directions\. ### 6\.1\.Emerging Robustness Trends in FL FL is still evolving, with a number of new trends reshaping its overall robustness in dynamic environments, deployment efficiency, and design concept\. The demand to improve scalability, communication efficacy, privacy, and model robustness in heterogeneous and dynamic environments is driving innovations\. A summary analysis of emerging research trends in robust FL is presented in Table[13](https://arxiv.org/html/2609.28722#S6.T13)\. The goal of new methods, such as communication scheduling, model pruning, and asynchronous updates, is to reduce communication costs, especially in devices with constrained resources\([Jiang and Borcea, 2023](https://arxiv.org/html/2609.28722#bib.bib46);[Huang et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib3)\)\. In order to improve data privacy and guard against potential quantum threats, sophisticated cryptographic solutions like HE and PQC are being incorporated as well\([Javeed et al\., 2024](https://arxiv.org/html/2609.28722#bib.bib171);[Gurung et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib172)\)\. Hierarchical and clustered architectures and lightweight learners further support scalability, and personalization techniques guarantee that client\-based requirements are guaranteed without undermining global performance\([Jiang et al\., 2020c](https://arxiv.org/html/2609.28722#bib.bib21);[Li and Wang, 2022](https://arxiv.org/html/2609.28722#bib.bib24);[Caldarola et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib23);[Briggs et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib22);[Collins et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib81)\)\. Recently, investigations into Quantum ML and quantum\-influenced optimization have opened innovative avenues to advance model training and resilience\([Chehimi and Saad, 2022](https://arxiv.org/html/2609.28722#bib.bib173);[Zhang et al\., 2022b](https://arxiv.org/html/2609.28722#bib.bib174);[Yang et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib175)\)\. Altogether, these rising trends indicate a positive shift toward more robust, flexible, and future\-ready FL frameworks\. Table 13\.Emerging research trends toward Robust FL\. ### 6\.2\.Major Application Scenarios for Robust FL This section explores major real\-world FL application scenarios across different sectors, where robustness remain critical yet underexplored challenge\. #### 6\.2\.1\.Intelligent Healthcare In healthcare, safeguarding patient privacy is paramount, but this should be achieved without sacrificing the robustness and dependability of clinical models\. FL enables multiple hospitals and clinics to collaboratively train models without sharing patient data externally\. To guarantee reliable decision support in safety\-critical workflows, robust FL must also withstand noisy labels, diverse patient populations, and local updates poisoning, among others\. To improve robustness against data manipulation and single points of failure, decentralized aggregation and coordination components \(e\.g\., committee\-based or blockchain\-assisted aggregation\) are used\. The healthcare\-FL model in\([Ye et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib49)\)predicts oxygen requirements using vital signs, laboratory reports, and chest X\-rays to improve clinical outcomes A diagnostic model using FL in\([Ma et al\., 2022c](https://arxiv.org/html/2609.28722#bib.bib50)\)supports cancer patients by letting physicians to design personalized nutrition and treatment plans, support longer life expectancy, and offer guidance in rehabilitation\. #### 6\.2\.2\.Recommender Systems Robust federated recommendation offloads computation to user devices while shielding the learning and aggregation pipeline against such risks\. Recent advances include anomaly\-resilient aggregation, client trust scoring, and privacy\-preserving protections to prevent adversaries from extracting sensitive preferences or influencing recommendations\. Different approaches include: \(i\) Robust collaborative filtering: Utilizing user\-item interaction data while preserving privacy by handling user\-item factors under adversarial ratings and sparse or skewed interaction graphs, often using outlier\-resistant aggregators, \(ii\) Deep learning\-based robust FL: Employing neural networks trained across distributed clients, while using robust aggregation, gradient masking, or client selection approaches to mitigate adversarial risks, \(iii\) Meta\-learning based robust FL: Personalizing models for individual users through experience\-based adaptations to mitigate malicious or low\-quality clients\. A distributed matrix decomposition approach\([Du et al\., 2021](https://arxiv.org/html/2609.28722#bib.bib76)\)helps learning global latent factors via gradient sharing, and integrating matrix factorization with quantization helps minimize communication overhead\. FL\-driven recommender systems support a variety of sectors, including e\-commerce and social media, in providing customized services while adhering to data regulations and privacy issues\. However, overlooking robustness could allow malevolent alterations of recommendations, leading to reduced user confidence, user discontent, and monetary losses\([Nguyen et al\., 2026](https://arxiv.org/html/2609.28722#bib.bib197)\)\. #### 6\.2\.3\.Finance and Banking Collaboration between financial institutions to enhance services such as fraud detection, credit risk analysis, and financial recommendations is made possible by robust FL\. Confidentiality challenges and competitive interests, however, limit explicit data exchange between institutions\. The initial results are encouraging and reveal FL’s potential to improve data\-driven choices for decision\-making across financial networks, even though the majority of FL\-driven financial applications are currently in their infancy\. Robustness preserves confidentiality and integrity of the model and is guaranteed through threat\-resilient optimization, secure aggregation, and cryptography\-oriented defenses\. Notable robust applications include: \(i\) WeBank’s credit risk assessment\([Li and Wen, 2023](https://arxiv.org/html/2609.28722#bib.bib149)\)uses FL for small business lending and personal credit scoring, supporting credit risk management, mitigating single\-institution bias, and limiting the impact of corrupted or low\-quality clients, \(ii\) FL for Internet banking in\([Luo et al\., 2023](https://arxiv.org/html/2609.28722#bib.bib150)\)integrated DP, SMC, and collaborative modeling for improving credit approval rates and loan performance while ensuring data confidentiality\. #### 6\.2\.4\.Smart Cities Smart cities require integrating and analyzing data generated by diverse entities, including governments, private enterprises, and individual users\. Robust FL enables decentralized training of AI models across urban stakeholders while mitigating malicious clients, corrupted sensor devices, and unreliable communication, thereby supporting safety\-critical decision\-making\. This supports various urban applications, such as traffic prediction, pollution monitoring, and infrastructure management\([Que and Khan, 2025](https://arxiv.org/html/2609.28722#bib.bib169);[Li and Wang, 2022](https://arxiv.org/html/2609.28722#bib.bib24)\)\. For instance, the urban traffic prediction framework in\([Li and Wang, 2022](https://arxiv.org/html/2609.28722#bib.bib24)\)employs a global spatial\-temporal pattern graph under a data federation, ensuring data privacy using personalized FL methods based on meta\-learning while mitigating the impact of heterogeneous and noisy data sources\. Historical traffic statistics is employed in\([Yuan et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib25)\)for congestion prediction, while ensuring privacy\. #### 6\.2\.5\.IoT and Edge Computing FL and edge computing combination enables distributed model training directly on edge devices, such as smartphones, smart meters, surveillance cameras, and industrial IoT nodes, without transferring raw data to a central cloud\. This preserves data privacy and strengthens security while reducing communication overhead and latency\([Que and Khan, 2025](https://arxiv.org/html/2609.28722#bib.bib169);[Zhang et al\., 2022a](https://arxiv.org/html/2609.28722#bib.bib20);[Yuan et al\., 2022](https://arxiv.org/html/2609.28722#bib.bib25)\)\. Handling malevolent updates, heterogeneity of devices, and unstable connectivity is vital for applications such as industrial supervision and surveillance, where compromised models can have serious consequences\. Numerous studies have looked at different aspects of this integration\. For instance, local training on mobile devices is enabled by an edge FL framework in\([Ye et al\., 2020](https://arxiv.org/html/2609.28722#bib.bib26)\), which allows for robust server\-side inspection of anomalous updates and periodically aggregates model updates to enhance learning efficiency and reduce overhead\. A fair aggregation strategy can ensure balanced accuracy among clients and reduce the dominance of low\-resource or unreliable clients\. An FL model with adaptive learning rates\([Jiang et al\., 2020a](https://arxiv.org/html/2609.28722#bib.bib27)\)addresses the various accuracy needs of heterogeneous edge devices\. By down\-weighting distrustful contributions, an asynchronous FL model in\([Wang et al\., 2021b](https://arxiv.org/html/2609.28722#bib.bib28)\)improves communication efficiency through selective model updates based on device capacity and data quality\. ### 6\.3\.Challenges and Future Research Directions While current robust mechanisms have addressed fundamental threats and challenges facing FL, the evolution of adversarial tactics necessitates more sophisticated, flexible, scalable, and domain\-aware solutions\. The next frontier for robustness in FL is discussed along the following directions:∙\\bulletCausality\-driven attack attribution:Current detection measures typically struggle to distinguish between malicious model poisoning and benign statistical heterogeneity\. Future studies should adopt the use of causal inference to distinguish spurious correlations from adversaries, allowing for more precise detection and reliable source attribution\.∙\\bulletContext\-aware and flexible defenses:The adoption of fixed or static parameters for defenses \(e\.g\., preset clipping thresholds\) is often unreliable\. Robust FL demands adaptive frameworks that incorporate temporal, environmental, and contextual factors, tweaking the level of defenses in real\-time according to the shifting threat landscape, client behavior trends, and application\-based priorities\.∙\\bulletSelf\-healing and resilient frameworks:Apart from mere detection strategies, FL frameworks must have self\-healing capabilities\. Drawing motivation from biological immunity, subsequent research should focus on innovative solutions that enable the models to behave automatically according to any recognized degradation in performance, separate infected sub\-modules, and activate automated recovery appropriately without needing a system reset\.∙\\bulletNeuro\-symbolic FL for verifiable robustness:Adversarial examples often affect purely neural approaches\. To address this, integrating symbolic\-AI with neural models that can provide verifiable reasoning and logical constraints is essential\. It is particularly critical for robustness in high\-stakes environments such as healthcare or autonomous navigation, where model decisions must adhere to strict safety logic\.∙\\bulletCross\-domain and modality\-specific defenses:Image classification is the subject of a large portion of the existing literature\. However, there are significant differences in the robustness requirements for different forms of data\. Future research must devise robustness primitives specifically designed to address the distinct structural weaknesses of non\-vision sectors as well\.∙\\bulletQuantum\-enhanced and quantum\-resilient FL:\(i\)Quantum FL \(QFL\):Effective estimation and addressing gradient vanishing in deep quantum circuits is vital\. Future studies should explore quantum\-based compression to reduce communication overhead and personalized QFL for resource\-limited edge devices, which adversaries commonly exploit\. \(ii\)Multimodal QFL:Creating QFL systems that can accommodate the integration of different kinds of data will broaden their use in major applications, such as smart healthcare and finance\. \(iii\)Quantum\-Resilient security:Many of the standard encryption solutions will turn obsolete as quantum computing advances\. Transition of FL towards PQC is therefore crucial to ensure long\-term data protection and integrity against adversaries with quantum capabilities\. We presented a multifaceted review and analysis of robust FL from diverse perspectives\. Given the increasing sophistication of adversarial threats and the inherent challenges presented by the heterogeneous and decentralized characteristics of FL, the analysis has emphasized the critical relevance of upholding robustness in FL systems\. ## References - Abadet al\.\(2023\)G\. Abad, S\. Paguada, O\. Ersoy, S\. Picek, V\. J\. Ramírez\-Durán, and A\. UrbietaSniper backdoor: single client targeted backdoor attack in federated learning\.In2023 IEEE Conference on Secure and Trustworthy Machine Learning \(SaTML\),pp\. 377–391\.Cited by:[§2\.3\.2](https://arxiv.org/html/2609.28722#S2.SS3.SSS2.p1.1),[Table 4](https://arxiv.org/html/2609.28722#S2.T4.5.1.3.1.1.2.1)\. - Alsereidiet al\.\(2024\)M\. Alsereidi, A\. Awadallah, A\. Alkaabi, S\. Yoon, and C\. Y\. YeunData poisoning against federated learning: comparative analysis under label\-flipping attacks and gan\-generated eeg data\.In2024 2nd Int\. Conf\. on Cyber Resilience \(ICCR\),pp\. 1–5\.Cited by:[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p1.1),[Table 3](https://arxiv.org/html/2609.28722#S2.T3.8.1.4.1.1.1.1)\. - Andreinaet al\.\(2021\)S\. Andreina, G\. A\. Marson, H\. Möllering, and G\. KarameBaffle: backdoor detection via feedback\-based federated learning\.In2021 IEEE 41st Int\. Conf\. on Distrib\. Comput\. Syst\. \(ICDCS\),pp\. 852–863\.Cited by:[§4\.1\.3](https://arxiv.org/html/2609.28722#S4.SS1.SSS3.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.4.2.1.3.1)\. - Andrewet al\.\(2021\)G\. Andrew, O\. Thakkar, B\. McMahan, and S\. RamaswamyDifferentially private learning with adaptive clipping\.Advances in Neural Inf\. Process\. Syst\.34,pp\. 17455–17466\.Cited by:[§3\.1](https://arxiv.org/html/2609.28722#S3.SS1.p1.1),[§3\.2\.1](https://arxiv.org/html/2609.28722#S3.SS2.SSS1.p1.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.7.2.1.1.1),[§3](https://arxiv.org/html/2609.28722#S3.p1.1),[§4\.1\.1](https://arxiv.org/html/2609.28722#S4.SS1.SSS1.p1.1),[§4\.1\.3](https://arxiv.org/html/2609.28722#S4.SS1.SSS3.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.2.2.1.2.1)\. - Arevaloet al\.\(2024\)C\. A\. Arevalo, S\. L\. Noorbakhsh, Y\. Dong, Y\. Hong, and B\. WangTask\-agnostic privacy\-preserving representation learning for federated learning against attribute inference attacks\.InProc\. of the AAAI Conf\. on Artif\. Intell\.,Vol\.38,pp\. 10909–10917\.Cited by:[§2\.4\.1](https://arxiv.org/html/2609.28722#S2.SS4.SSS1.p1.1),[Table 6](https://arxiv.org/html/2609.28722#S2.T6.5.1.7.1.1.1.1),[§2](https://arxiv.org/html/2609.28722#S2.p1.1)\. - Augelloet al\.\(2023\)A\. Augello, G\. Falzone, and G\. Lo ReDCFL: dynamic clustered federated learning under differential privacy settings\.In2023 IEEE Int\. Conf\. on pervasive Comput\. and Comm\. Wkshp\. and other affiliated events \(PerCom Wkshp\.\),pp\. 614–619\.Cited by:[§3\.2\.1](https://arxiv.org/html/2609.28722#S3.SS2.SSS1.p1.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.13.2.1.3.1)\. - Augelloet al\.\(2024\)A\. Augello, A\. Gupta, G\. Lo Re, and S\. K\. DasTackling selfish clients in federated learning\.InECAI 2024,pp\. 1888–1895\.Cited by:[§1](https://arxiv.org/html/2609.28722#S1.p1.1)\. - Augelloet al\.\(2026\)A\. Augello, A\. Gupta, G\. Lo Re, and S\. K\. DasFairRFL: fair and robust federated learning in the presence of selfish clients\.IEEE Trans\. on Emerging Topics in Comput\.\.Cited by:[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p2.1)\. - Bagdasaryanet al\.\(2020\)E\. Bagdasaryan, A\. Veit, Y\. Hua, D\. Estrin, and V\. ShmatikovHow to backdoor federated learning\.InInt\. Conf\. on Artif\. Intell\. and Statistics,pp\. 2938–2948\.Cited by:[§2\.2](https://arxiv.org/html/2609.28722#S2.SS2.p1.1),[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p2.1),[§2\.3\.2](https://arxiv.org/html/2609.28722#S2.SS3.SSS2.p1.1),[Table 4](https://arxiv.org/html/2609.28722#S2.T4.5.1.3.1.1.1.1),[§2](https://arxiv.org/html/2609.28722#S2.p1.1)\. - Baiet al\.\(2024\)L\. Bai, H\. Hu, Q\. Ye, H\. Li, L\. Wang, and J\. XuMembership inference attacks and defenses in federated learning: a survey\.ACM Computing Surveys57\(4\),pp\. 1–35\.Cited by:[§1\.1](https://arxiv.org/html/2609.28722#S1.SS1.p1.1)\. - Bhagojiet al\.\(2019\)A\. N\. Bhagoji, S\. Chakraborty, P\. Mittal, and S\. CaloAnalyzing federated learning through an adversarial lens\.InInt\. Conf\. on machine learning,pp\. 634–643\.Cited by:[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p2.1),[§2\.3\.2](https://arxiv.org/html/2609.28722#S2.SS3.SSS2.p1.1),[Table 3](https://arxiv.org/html/2609.28722#S2.T3.8.1.9.1.1.1.1)\. - Briggset al\.\(2020\)C\. Briggs, Z\. Fan, and P\. AndrasFederated learning with hierarchical clustering of local updates to improve training on non\-iid data\.In2020 Int\. Joint Conf\. on Neural Networks \(IJCNN\),pp\. 1–9\.Cited by:[§5\.1](https://arxiv.org/html/2609.28722#S5.SS1.p1.1),[§6\.1](https://arxiv.org/html/2609.28722#S6.SS1.p1.1)\. - Brunettaet al\.\(2021\)C\. Brunetta, G\. Tsaloli, B\. Liang, G\. Banegas, and A\. MitrokotsaNon\-interactive, secure verifiable aggregation for decentralized, privacy\-preserving learning\.InAustralasian Conf\. on Inf\. Security and Privacy,pp\. 510–528\.Cited by:[§3\.1](https://arxiv.org/html/2609.28722#S3.SS1.p1.1),[§3\.2\.2](https://arxiv.org/html/2609.28722#S3.SS2.SSS2.p1.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.9.2.1.1.1)\. - Caldarolaet al\.\(2021\)D\. Caldarola, M\. Mancini, F\. Galasso, M\. Ciccone, E\. Rodolà, and B\. CaputoCluster\-driven graph federated learning over multiple domains\.InProc\. of the IEEE/CVF Conf\. on Computer Vision and Pattern Recognition,pp\. 2749–2758\.Cited by:[§6\.1](https://arxiv.org/html/2609.28722#S6.SS1.p1.1)\. - Caoet al\.\(2021\)X\. Cao, M\. Fang, J\. Liu, and N\. Z\. GongFLTrust: byzantine\-robust federated learning via trust bootstrapping\.InISOC Netw\. and Distrib\. System Security Symp\. \(NDSS\),Cited by:[§3\.2\.1](https://arxiv.org/html/2609.28722#S3.SS2.SSS1.p1.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.2.2.1.1.1),[§4\.1\.2](https://arxiv.org/html/2609.28722#S4.SS1.SSS2.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.3.2.1.1.1)\. - Cao and Gong \(2022\)X\. Cao and N\. Z\. GongMpaf: model poisoning attacks to federated learning based on fake clients\.InProc\. of the IEEE/CVF Conf\. on Computer Vision and Pattern Recognition,pp\. 3396–3404\.Cited by:[§2\.3\.3](https://arxiv.org/html/2609.28722#S2.SS3.SSS3.p1.1),[Table 4](https://arxiv.org/html/2609.28722#S2.T4.5.1.8.1.1.2.1)\. - Caoet al\.\(2022\)X\. Cao, Z\. Zhang, J\. Jia, and N\. Z\. GongFlcert: provably secure federated learning against poisoning attacks\.IEEE Trans\. on Inf\. Forensics and Security17,pp\. 3691–3705\.Cited by:[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p2.1),[§2\.3\.5](https://arxiv.org/html/2609.28722#S2.SS3.SSS5.p1.1),[Table 3](https://arxiv.org/html/2609.28722#S2.T3.8.1.6.1.1.2.1),[Table 5](https://arxiv.org/html/2609.28722#S2.T5.5.1.7.1.1.1.1),[§4\.1\.3](https://arxiv.org/html/2609.28722#S4.SS1.SSS3.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.4.2.1.2.1)\. - Chehimi and Saad \(2022\)M\. Chehimi and W\. SaadQuantum federated learning with quantum data\.InICASSP 2022\-2022 IEEE Int\. Conf\. on Acoustics, Speech and Signal Process\. \(ICASSP\),pp\. 8617–8621\.Cited by:[§3\.2\.2](https://arxiv.org/html/2609.28722#S3.SS2.SSS2.p2.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.3.2.1.1.1),[§4\.1\.6](https://arxiv.org/html/2609.28722#S4.SS1.SSS6.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.7.2.1.3.1),[§6\.1](https://arxiv.org/html/2609.28722#S6.SS1.p1.1)\. - Chenet al\.\(2020\)C\. Chen, L\. Golubchik, and M\. PaolieriBackdoor attacks on federated meta\-learning\.arXiv preprint arXiv:2006\.07026\.Cited by:[§2\.3\.2](https://arxiv.org/html/2609.28722#S2.SS3.SSS2.p1.1),[Table 4](https://arxiv.org/html/2609.28722#S2.T4.5.1.6.1.1.1.1)\. - Chenet al\.\(2023\)H\. Chen, T\. Zhu, T\. Zhang, W\. Zhou, and P\. S\. YuPrivacy and fairness in federated learning: on the perspective of tradeoff\.ACM Comput\. Surveys56\(2\),pp\. 1–37\.Cited by:[§2\.4\.3](https://arxiv.org/html/2609.28722#S2.SS4.SSS3.p1.1),[Table 6](https://arxiv.org/html/2609.28722#S2.T6.5.1.13.1.1.1.1),[§3](https://arxiv.org/html/2609.28722#S3.p1.1)\. - Chenet al\.\(2024\)L\. Chen, D\. Zhao, L\. Tao, K\. Wang, S\. Qiao, X\. Zeng, and C\. W\. TanA credible and fair federated learning framework based on blockchain\.IEEE Trans\. on Artif\. Intell\.\.Cited by:[§3\.2\.2](https://arxiv.org/html/2609.28722#S3.SS2.SSS2.p2.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.10.2.1.2.1),[§4\.1\.2](https://arxiv.org/html/2609.28722#S4.SS1.SSS2.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.3.2.1.3.1)\. - Chenet al\.\(2017\)P\. Chen, H\. Zhang, Y\. Sharma, J\. Yi, and C\. HsiehZoo: zeroth order optimization based black\-box attacks to deep neural networks without training substitute models\.InProc\. of the 10th ACM workshop on Artif\. Intell\. and security,pp\. 15–26\.Cited by:[§2\.3\.6](https://arxiv.org/html/2609.28722#S2.SS3.SSS6.p1.1),[Table 5](https://arxiv.org/html/2609.28722#S2.T5.5.1.9.1.1.1.1)\. - Chenet al\.\(2022\)Y\. Chen, Y\. Gui, H\. Lin, W\. Gan, and Y\. WuFederated learning attacks and defenses: a survey\.In2022 IEEE Int\. Conf\. on Big Data \(Big Data\),pp\. 4256–4265\.Cited by:[§1\.1](https://arxiv.org/html/2609.28722#S1.SS1.p1.1),[§2](https://arxiv.org/html/2609.28722#S2.p1.1)\. - Cinàet al\.\(2025\)A\. E\. Cinà, A\. Demontis, B\. Biggio, F\. Roli, and M\. PelilloEnergy\-latency attacks via sponge poisoning\.Inf\. Sciences702,pp\. 121905\.Cited by:[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p2.1)\. - Collinset al\.\(2021\)L\. Collins, H\. Hassani, A\. Mokhtari, and S\. ShakkottaiExploiting shared representations for personalized federated learning\.InInt\. Conf\. on machine learning,pp\. 2089–2099\.Cited by:[§6\.1](https://arxiv.org/html/2609.28722#S6.SS1.p1.1)\. - Costaet al\.\(2022\)G\. Costa, F\. Pinelli, S\. Soderi, and G\. TolomeiTurning federated learning systems into covert channels\.IEEE Access10,pp\. 130642–130656\.Cited by:[§2\.3\.4](https://arxiv.org/html/2609.28722#S2.SS3.SSS4.p1.1),[Table 5](https://arxiv.org/html/2609.28722#S2.T5.5.1.5.1.1.1.1)\. - De Alwiset al\.\(2026\)C\. De Alwis, O\. Aouedi, J\. Xu, S\. Wang, Y\. Siriwardhana, T\. Hewa, E\. Zeydan, C\. Sandeepa, and M\. LiyanageFederated learning for 6g security: a survey on threats, solutions and research directions\.IEEE Commun\. Surveys & Tutorials\.Cited by:[§1\.1](https://arxiv.org/html/2609.28722#S1.SS1.p1.1),[§1](https://arxiv.org/html/2609.28722#S1.p1.1)\. - Duet al\.\(2023\)J\. Du, N\. Qin, D\. Huang, Y\. Zhang, and X\. JiaAn efficient federated learning framework for machinery fault diagnosis with improved model aggregation and local model training\.IEEE Trans\. on Neural Netw\. and Learning Syst\.\.Cited by:[§3\.2\.1](https://arxiv.org/html/2609.28722#S3.SS2.SSS1.p1.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.6.2.1.1.1),[§3](https://arxiv.org/html/2609.28722#S3.p1.1),[§4\.1\.3](https://arxiv.org/html/2609.28722#S4.SS1.SSS3.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.4.2.1.2.1)\. - Duet al\.\(2021\)Y\. Du, D\. Zhou, Y\. Xie, J\. Shi, and M\. GongFederated matrix factorization for privacy\-preserving recommender systems\.Applied soft comput\.111,pp\. 107700\.Cited by:[§6\.2\.2](https://arxiv.org/html/2609.28722#S6.SS2.SSS2.p1.1)\. - El\-Mhamdiet al\.\(2020\)E\. El\-Mhamdi, R\. Guerraoui, A\. Guirguis, L\. N\. Hoang, and S\. RouaultGenuinely distributed byzantine machine learning\.InProc\. of the 39th Symp\. on Principles of Distrib\. Comput\.,pp\. 355–364\.Cited by:[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p3.1),[Table 3](https://arxiv.org/html/2609.28722#S2.T3.8.1.11.1.1.1.1)\. - Fanget al\.\(2021\)C\. Fang, Y\. Guo, Y\. Hu, B\. Ma, L\. Feng, and A\. YinPrivacy\-preserving and communication\-efficient federated learning in internet of things\.Computers & Security103,pp\. 102199\.Cited by:[§3\.2\.2](https://arxiv.org/html/2609.28722#S3.SS2.SSS2.p1.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.12.2.1.2.1)\. - Fanget al\.\(2020\)M\. Fang, X\. Cao, J\. Jia, and N\. GongLocal model poisoning attacks to\{\\\{byzantine\-robust\}\\\}federated learning\.In29th USENIX security symposium \(USENIX Security 20\),pp\. 1605–1622\.Cited by:[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p2.1),[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p3.1),[Table 3](https://arxiv.org/html/2609.28722#S2.T3.8.1.7.1.1.2.1)\. - Fang and Ye \(2022\)X\. Fang and M\. YeRobust federated learning with noisy and heterogeneous clients\.In2022 IEEE/CVF Conf\. on Comput\. Vision and Pattern Recognition \(CVPR\),pp\. 10062–10071\.Cited by:[§1](https://arxiv.org/html/2609.28722#S1.p1.1)\. - Fraboniet al\.\(2021\)Y\. Fraboni, R\. Vidal, and M\. LorenziFree\-rider attacks on model aggregation in federated learning\.InInt\. Conf\. on Artif\. Intell\. and Statistics,pp\. 1846–1854\.Cited by:[§2\.3\.3](https://arxiv.org/html/2609.28722#S2.SS3.SSS3.p1.1),[Table 4](https://arxiv.org/html/2609.28722#S2.T4.5.1.9.1.1.2.1),[§4\.1](https://arxiv.org/html/2609.28722#S4.SS1.p1.1)\. - Fuet al\.\(2024\)J\. Fu, Y\. Hong, X\. Ling, L\. Wang, X\. Ran, Z\. Sun, H\. Wang, Z\. Chen, and Y\. CaoDifferentially private federated learning: a systematic review\.ACM Computing Surveys\.Cited by:[§1\.1](https://arxiv.org/html/2609.28722#S1.SS1.p1.1)\. - Funget al\.\(2020\)C\. Fung, C\. J\. Yoon, and I\. BeschastnikhThe limitations of federated learning in sybil settings\.In23rd Int\. Symp\. on Research in Attacks, Intrusions and Defenses \(RAID 2020\),pp\. 301–316\.Cited by:[§2\.3\.5](https://arxiv.org/html/2609.28722#S2.SS3.SSS5.p1.1),[Table 5](https://arxiv.org/html/2609.28722#S2.T5.5.1.7.1.1.2.1),[§4\.1](https://arxiv.org/html/2609.28722#S4.SS1.p1.1)\. - Geipinget al\.\(2020\)J\. Geiping, H\. Bauermeister, H\. Dröge, and M\. MoellerInverting gradients\-how easy is it to break privacy in federated learning?\.Advances in neural Inf\. Process\. Syst\.33,pp\. 16937–16947\.Cited by:[§2\.4\.3](https://arxiv.org/html/2609.28722#S2.SS4.SSS3.p1.1),[Table 6](https://arxiv.org/html/2609.28722#S2.T6.5.1.14.1.1.3.1)\. - Gonget al\.\(2022\)X\. Gong, Y\. Chen, H\. Huang, Y\. Liao, S\. Wang, and Q\. WangCoordinated backdoor attacks against federated learning with model\-dependent triggers\.IEEE network36\(1\),pp\. 84–90\.Cited by:[§1](https://arxiv.org/html/2609.28722#S1.p1.1),[§2\.3\.2](https://arxiv.org/html/2609.28722#S2.SS3.SSS2.p1.1),[Table 4](https://arxiv.org/html/2609.28722#S2.T4.5.1.4.1.1.2.1)\. - Guet al\.\(2022\)Y\. Gu, Y\. Bai, and S\. XuCS\-mia: membership inference attack based on prediction confidence series in federated learning\.J\. of Inf\. Secur\. and Appl\.67,pp\. 103201\.Cited by:[§2\.4\.1](https://arxiv.org/html/2609.28722#S2.SS4.SSS1.p1.1),[Table 6](https://arxiv.org/html/2609.28722#S2.T6.5.1.3.1.1.1.1)\. - Guoet al\.\(2023\)X\. Guo, P\. Wang, S\. Qiu, W\. Song, Q\. Zhang, X\. Wei, and D\. ZhouFast: adopting federated unlearning to eliminating malicious terminals at server side\.IEEE Trans\. on Netw\. Science and Eng\.\.Cited by:[§1](https://arxiv.org/html/2609.28722#S1.p1.1),[§4\.1\.4](https://arxiv.org/html/2609.28722#S4.SS1.SSS4.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.5.2.1.4.1)\. - Guptaet al\.\(2022\)A\. Gupta, T\. Luo, M\. V\. Ngo, and S\. K\. DasLong\-short history of gradients is all you need: detecting malicious and unreliable clients in federated learning\.InEur\. Symp\. on Research in Comput\. Secur\.,pp\. 445–465\.Cited by:[§1](https://arxiv.org/html/2609.28722#S1.p1.1),[§2\.4\.3](https://arxiv.org/html/2609.28722#S2.SS4.SSS3.p1.1),[Table 6](https://arxiv.org/html/2609.28722#S2.T6.5.1.14.1.1.3.1),[§2](https://arxiv.org/html/2609.28722#S2.p1.1)\. - Guptaet al\.\(2023\)A\. Gupta, G\. Markowsky, and S\. K\. DasIs performance fairness achievable in presence of attackers under federated learning?\.InECAI 2023,pp\. 948–955\.Cited by:[§1](https://arxiv.org/html/2609.28722#S1.p1.1),[§2\.3](https://arxiv.org/html/2609.28722#S2.SS3.p1.1),[§4\.1\.1](https://arxiv.org/html/2609.28722#S4.SS1.SSS1.p1.1)\. - Gurunget al\.\(2023\)D\. Gurung, S\. R\. Pokhrel, and G\. LiPerformance analysis and evaluation of post quantum secure blockchain federated learning\.arXiv preprint arXiv:2306\.14772\.Cited by:[§4\.1\.6](https://arxiv.org/html/2609.28722#S4.SS1.SSS6.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.7.2.1.4.1),[§6\.1](https://arxiv.org/html/2609.28722#S6.SS1.p1.1)\. - Hamoudaet al\.\(2023\)D\. Hamouda, M\. A\. Ferrag, N\. Benhamida, and H\. SeridiPPSS: a privacy\-preserving secure framework using blockchain\-enabled federated deep learning for industrial iots\.Pervasive and Mobile Comput\.88,pp\. 101738\.Cited by:[§1](https://arxiv.org/html/2609.28722#S1.p1.1),[§3\.2\.2](https://arxiv.org/html/2609.28722#S3.SS2.SSS2.p2.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.10.2.1.2.1)\. - Hanet al\.\(2024\)Q\. Han, S\. Lu, W\. Wang, H\. Qu, J\. Li, and Y\. GaoPrivacy preserving and secure robust federated learning: a survey\.Concurrency and Comput\.: Practice and Experience,pp\. e8084\.Cited by:[§1\.1](https://arxiv.org/html/2609.28722#S1.SS1.p1.1),[§4\.1\.4](https://arxiv.org/html/2609.28722#S4.SS1.SSS4.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.5.2.1.3.1)\. - Haoet al\.\(2023\)X\. Hao, C\. Lin, W\. Dong, X\. Huang, and H\. XiongRobust and secure federated learning against hybrid attacks: a generic architecture\.IEEE Trans\. on Inf\. Forensics and Secur\.\.Cited by:[§1](https://arxiv.org/html/2609.28722#S1.p1.1),[§4\.1\.4](https://arxiv.org/html/2609.28722#S4.SS1.SSS4.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.5.2.1.3.1)\. - Heet al\.\(2024\)X\. He, Y\. Xu, S\. Zhang, W\. Xu, and J\. YanEnhance membership inference attacks in federated learning\.Computers & Security136,pp\. 103535\.Cited by:[§2\.4\.1](https://arxiv.org/html/2609.28722#S2.SS4.SSS1.p1.1),[Table 6](https://arxiv.org/html/2609.28722#S2.T6.5.1.2.1.1.1.1)\. - Hitajet al\.\(2023\)D\. Hitaj, G\. Pagnotta, B\. Hitaj, F\. Perez\-Cruz, and L\. V\. ManciniFedcomm: federated learning as a medium for covert communication\.IEEE Trans\. on Dependable and Secure Comput\.\.Cited by:[§2\.3\.4](https://arxiv.org/html/2609.28722#S2.SS3.SSS4.p1.1),[Table 5](https://arxiv.org/html/2609.28722#S2.T5.5.1.4.1.1.1.1)\. - Hossainet al\.\(2021\)M\. T\. Hossain, S\. Islam, S\. Badsha, and H\. ShenDesmp: differential privacy\-exploited stealthy model poisoning attacks in federated learning\.In2021 17th Int\. Conf\. on Mobility, Sensing and Netw\. \(MSN\),pp\. 167–174\.Cited by:[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p2.1),[Table 3](https://arxiv.org/html/2609.28722#S2.T3.8.1.7.1.1.1.1)\. - Huet al\.\(2021\)H\. Hu, Z\. Salcic, L\. Sun, G\. Dobbie, and X\. ZhangSource inference attacks in federated learning\.In2021 IEEE Int\. Conf\. on Data Mining \(ICDM\),Vol\.,pp\. 1102–1107\.Cited by:[§2\.4\.1](https://arxiv.org/html/2609.28722#S2.SS4.SSS1.p1.1),[Table 6](https://arxiv.org/html/2609.28722#S2.T6.5.1.4.1.1.2.1)\. - Huet al\.\(2024\)H\. Hu, X\. Zhang, Z\. Salcic, L\. Sun, K\. R\. Choo, and G\. DobbieSource inference attacks: beyond membership inference attacks in federated learning\.IEEE Trans\. on Dependable and Secure Comput\.21\(4\),pp\. 3012–3029\.Cited by:[§2\.4\.1](https://arxiv.org/html/2609.28722#S2.SS4.SSS1.p1.1),[Table 6](https://arxiv.org/html/2609.28722#S2.T6.5.1.4.1.1.1.1)\. - Huanget al\.\(2024\)W\. Huang, M\. Ye, Z\. Shi, G\. Wan, H\. Li, B\. Du, and Q\. YangFederated learning for generalization, robustness, fairness: a survey and benchmark\.IEEE Trans\. on Pattern Anal\. and Mach\. Intell\.\(\),pp\. 1–20\.Cited by:[§3\.1](https://arxiv.org/html/2609.28722#S3.SS1.p1.1),[§3\.2\.1](https://arxiv.org/html/2609.28722#S3.SS2.SSS1.p1.1),[§4\.1\.4](https://arxiv.org/html/2609.28722#S4.SS1.SSS4.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.5.2.1.2.1),[§6\.1](https://arxiv.org/html/2609.28722#S6.SS1.p1.1)\. - Huynhet al\.\(2024\)T\. Huynh, D\. Nguyen, T\. Pham, and A\. TranCOMBAT: alternated training for effective clean\-label backdoor attacks\.InProc\. of the AAAI Conf\. on Artif\. Intell\.,Vol\.38,pp\. 2436–2444\.Cited by:[§2\.3\.2](https://arxiv.org/html/2609.28722#S2.SS3.SSS2.p1.1),[Table 4](https://arxiv.org/html/2609.28722#S2.T4.5.1.2.1.1.1.1)\. - Issaet al\.\(2024\)W\. Issa, N\. Moustafa, B\. Turnbull, and K\. R\. ChooRVE\-pfl: robust variational encoder\-based personalised federated learning against model inversion attacks\.IEEE Trans\. on Inf\. Forensics and Security\.Cited by:[§2\.4\.3](https://arxiv.org/html/2609.28722#S2.SS4.SSS3.p1.1),[Table 6](https://arxiv.org/html/2609.28722#S2.T6.5.1.14.1.1.4.1),[§4\.1\.3](https://arxiv.org/html/2609.28722#S4.SS1.SSS3.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.4.2.1.4.1)\. - Javeedet al\.\(2024\)D\. Javeed, M\. S\. Saeed, I\. Ahmad, M\. Adil, P\. Kumar, and A\. N\. IslamQuantum\-empowered federated learning and 6g wireless networks for iot security: concept, challenges and future directions\.Future Gen\. Computer Syst\.\.Cited by:[§1](https://arxiv.org/html/2609.28722#S1.p1.1),[§3\.2\.2](https://arxiv.org/html/2609.28722#S3.SS2.SSS2.p2.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.3.2.1.1.1),[§4\.1\.6](https://arxiv.org/html/2609.28722#S4.SS1.SSS6.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.7.2.1.3.1),[§6\.1](https://arxiv.org/html/2609.28722#S6.SS1.p1.1)\. - Jeonget al\.\(2018\)E\. Jeong, S\. Oh, H\. Kim, J\. Park, M\. Bennis, and S\. KimCommunication\-efficient on\-device machine learning: federated distillation and augmentation under non\-iid private data\.arXiv preprint arXiv:1811\.11479\.Cited by:[§5\.1](https://arxiv.org/html/2609.28722#S5.SS1.p1.1)\. - Jeonget al\.\(2024\)H\. Jeong, H\. Son, S\. Lee, J\. Hyun, and T\. ChungFedCC: robust federated learning against model poisoning attacks\.External Links:2212\.01976Cited by:[§1](https://arxiv.org/html/2609.28722#S1.p1.1),[§2\.3](https://arxiv.org/html/2609.28722#S2.SS3.p1.1),[§2](https://arxiv.org/html/2609.28722#S2.p1.1)\. - Jereet al\.\(2020\)M\. S\. Jere, T\. Farnan, and F\. KoushanfarA taxonomy of attacks on federated learning\.IEEE Secur\. & Privacy19\(2\),pp\. 20–28\.Cited by:[§2\.2](https://arxiv.org/html/2609.28722#S2.SS2.p1.1),[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p1.1),[Table 3](https://arxiv.org/html/2609.28722#S2.T3.8.1.4.1.1.2.1),[§2](https://arxiv.org/html/2609.28722#S2.p1.1)\. - Jeteret al\.\(2023\)T\. R\. Jeter, T\. Nguyen, R\. Alharbi, and M\. T\. ThaiOASIS: offsetting active reconstruction attacks in federated learning\.arXiv preprint arXiv:2311\.13739\.Cited by:[§4\.1\.4](https://arxiv.org/html/2609.28722#S4.SS1.SSS4.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.5.2.1.2.1)\. - Jianget al\.\(2020a\)H\. Jiang, M\. Liu, B\. Yang, Q\. Liu, J\. Li, and X\. GuoCustomized federated learning for accelerated edge computing with heterogeneous task targets\.Computer Netw\.183,pp\. 107569\.Cited by:[§6\.2\.5](https://arxiv.org/html/2609.28722#S6.SS2.SSS5.p1.1)\. - Jianget al\.\(2020b\)W\. Jiang, H\. Li, S\. Liu, X\. Luo, and R\. LuPoisoning and evasion attacks against deep learning algorithms in autonomous vehicles\.IEEE trans\. on vehicular technol\.69\(4\),pp\. 4439–4449\.Cited by:[§1](https://arxiv.org/html/2609.28722#S1.p1.1),[§2\.2](https://arxiv.org/html/2609.28722#S2.SS2.p1.1),[§2](https://arxiv.org/html/2609.28722#S2.p1.1)\. - Jiang and Borcea \(2023\)X\. Jiang and C\. BorceaComplement sparsification: low\-overhead model pruning for federated learning\.InProc\. of the AAAI Conf\. on Artif\. Intell\.,Vol\.37,pp\. 8087–8095\.Cited by:[§4\.1\.2](https://arxiv.org/html/2609.28722#S4.SS1.SSS2.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.3.2.1.5.1),[§4](https://arxiv.org/html/2609.28722#S4.p1.1),[§6\.1](https://arxiv.org/html/2609.28722#S6.SS1.p1.1)\. - Jianget al\.\(2020c\)Y\. Jiang, J\. Konečnỳ, K\. Rush, and S\. KannanImproving federated learning personalization via model agnostic meta learning\.arXiv preprint arXiv:1909\.12488\.Cited by:[§6\.1](https://arxiv.org/html/2609.28722#S6.SS1.p1.1)\. - Kadheet al\.\(2020\)S\. Kadhe, N\. Rajaraman, O\. O\. Koyluoglu, and K\. RamchandranFastsecagg: scalable secure aggregation for privacy\-preserving federated learning\.arXiv preprint arXiv:2009\.11248\.Cited by:[§3\.1](https://arxiv.org/html/2609.28722#S3.SS1.p1.1),[§3\.2\.2](https://arxiv.org/html/2609.28722#S3.SS2.SSS2.p1.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.9.2.1.2.1)\. - Kalapaakinget al\.\(2022\)A\. P\. Kalapaaking, I\. Khalil, M\. S\. Rahman, M\. Atiquzzaman, X\. Yi, and M\. AlmashorBlockchain\-based federated learning with secure aggregation in trusted execution environment for internet\-of\-things\.IEEE Trans\. on Industrial Inform\.19\(2\),pp\. 1703–1714\.Cited by:[§3\.2\.2](https://arxiv.org/html/2609.28722#S3.SS2.SSS2.p2.1),[§4\.1\.2](https://arxiv.org/html/2609.28722#S4.SS1.SSS2.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.3.2.1.4.1)\. - Kimet al\.\(2023\)T\. Kim, S\. Singh, N\. Madaan, and C\. Joe\-WongCharacterizing internal evasion attacks in federated learning\.InInt\. Conf\. on Artif\. Intell\. and Statistics,pp\. 907–921\.Cited by:[§2\.3\.6](https://arxiv.org/html/2609.28722#S2.SS3.SSS6.p1.1),[Table 5](https://arxiv.org/html/2609.28722#S2.T5.5.1.10.1.1.1.1)\. - Kurakinet al\.\(2017\)A\. Kurakin, I\. Goodfellow, and S\. BengioAdversarial machine learning at scale\.arXiv preprint arXiv:1611\.01236\.Cited by:[§2\.3\.6](https://arxiv.org/html/2609.28722#S2.SS3.SSS6.p1.1),[Table 5](https://arxiv.org/html/2609.28722#S2.T5.5.1.8.1.1.2.1)\. - Kuznetsovet al\.\(2021\)E\. Kuznetsov, Y\. Chen, and M\. ZhaoSecurefl: privacy preserving federated learning with sgx and trustzone\.In2021 IEEE/ACM Symp\. on Edge Comput\. \(SEC\),pp\. 55–67\.Cited by:[§3\.1](https://arxiv.org/html/2609.28722#S3.SS1.p1.1),[§3\.2\.2](https://arxiv.org/html/2609.28722#S3.SS2.SSS2.p3.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.11.2.1.2.1)\. - Leet al\.\(2023\)J\. Le, D\. Zhang, X\. Lei, L\. Jiao, K\. Zeng, and X\. LiaoPrivacy\-preserving federated learning with malicious clients and honest\-but\-curious servers\.IEEE Trans\. on Inf\. Forensics and Secur\.18\(\),pp\. 4329–4344\.Cited by:[§2\.4\.1](https://arxiv.org/html/2609.28722#S2.SS4.SSS1.p1.1),[§2\.4](https://arxiv.org/html/2609.28722#S2.SS4.p1.1),[§4\.1\.4](https://arxiv.org/html/2609.28722#S4.SS1.SSS4.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.5.2.1.1.1)\. - Leeet al\.\(2021\)J\. Lee, H\. Ko, and S\. PackAdaptive deadline determination for mobile device selection in federated learning\.IEEE Trans\. on Vehicular Technol\.71\(3\),pp\. 3367–3371\.Cited by:[§3\.2\.1](https://arxiv.org/html/2609.28722#S3.SS2.SSS1.p1.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.4.2.1.1.1)\. - Liet al\.\(2023\)J\. Li, A\. S\. Rakin, X\. Chen, L\. Yang, Z\. He, D\. Fan, and C\. ChakrabartiModel extraction attacks on split federated learning\.arXiv preprint arXiv:2303\.08581\.Cited by:[§2\.4\.2](https://arxiv.org/html/2609.28722#S2.SS4.SSS2.p1.1),[Table 6](https://arxiv.org/html/2609.28722#S2.T6.5.1.12.1.1.1.1)\. - Liet al\.\(2019\)L\. Li, W\. Xu, T\. Chen, G\. B\. Giannakis, and Q\. LingRSA: byzantine\-robust stochastic aggregation methods for distributed learning from heterogeneous datasets\.InProc\. of the AAAI Conf\. on Artif\. Intell\.,Vol\.33,pp\. 1544–1551\.Cited by:[§1](https://arxiv.org/html/2609.28722#S1.p1.1),[§3\.1](https://arxiv.org/html/2609.28722#S3.SS1.p1.1),[§3\.2\.1](https://arxiv.org/html/2609.28722#S3.SS2.SSS1.p1.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.7.2.1.1.1),[§3](https://arxiv.org/html/2609.28722#S3.p1.1),[§4\.1](https://arxiv.org/html/2609.28722#S4.SS1.p1.1)\. - Li and Wang \(2022\)W\. Li and S\. WangFederated meta\-learning for spatial\-temporal prediction\.Neural Comput\. and Appl\.34\(13\),pp\. 10355–10374\.Cited by:[§6\.1](https://arxiv.org/html/2609.28722#S6.SS1.p1.1),[§6\.2\.4](https://arxiv.org/html/2609.28722#S6.SS2.SSS4.p1.1)\. - Li and Wen \(2023\)Y\. Li and G\. WenResearch and practice of financial credit risk management based on federated learning\.\.Eng\. Lett\.31\(1\)\.Cited by:[§6\.2\.3](https://arxiv.org/html/2609.28722#S6.SS2.SSS3.p1.1)\. - Liet al\.\(2024a\)Y\. Li, W\. Ding, H\. Chen, W\. Bao, and D\. YuanContribution\-wise byzantine\-robust aggregation for class\-balanced federated learning\.Inf\. Sciences667,pp\. 120475\.Cited by:[§1\.1](https://arxiv.org/html/2609.28722#S1.SS1.p1.1),[Table 3](https://arxiv.org/html/2609.28722#S2.T3.8.1.6.1.1.4.1)\. - Liet al\.\(2024b\)Y\. Li, Z\. Guo, N\. Yang, H\. Chen, D\. Yuan, and W\. DingThreats and defenses in federated learning life cycle: a comprehensive survey and challenges\.arXiv preprint arXiv:2407\.06754\.Cited by:[§1\.1](https://arxiv.org/html/2609.28722#S1.SS1.p1.1),[§2](https://arxiv.org/html/2609.28722#S2.p1.1)\. - Liet al\.\(2022\)Z\. Li, Z\. Chen, X\. Wei, S\. Gao, C\. Ren, and T\. Q\. QuekHPFL\-cn: communication\-efficient hierarchical personalized federated edge learning via complex network feature clustering\.InProc\. of the 2022 19th Annual IEEE Int\. Conf\. on Sensing, Commun\., and Netw\. \(SECON\),pp\. 325–333\.Cited by:[§3\.2\.1](https://arxiv.org/html/2609.28722#S3.SS2.SSS1.p1.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.13.2.1.3.1)\. - Liangaet al\.\(2023\)J\. Lianga, R\. Wang, C\. Feng, and C\. ChangA survey on federated learning poisoning attacks and defenses\.arXiv preprint arXiv:2306\.03397\.Cited by:[§1\.1](https://arxiv.org/html/2609.28722#S1.SS1.p1.1)\. - Limet al\.\(2020\)W\. Y\. B\. Lim, N\. C\. Luong, D\. T\. Hoang, Y\. Jiao, Y\. Liang, Q\. Yang, D\. Niyato, and C\. MiaoFederated learning in mobile edge networks: a comprehensive survey\.IEEE Commun\. Surveys & Tutorials22\(3\),pp\. 2031–2063\.Cited by:[§1\.1](https://arxiv.org/html/2609.28722#S1.SS1.p1.1)\. - Linet al\.\(2021\)F\. P\. Lin, S\. Hosseinalipour, S\. S\. Azam, C\. G\. Brinton, and N\. MichelusiSemi\-decentralized federated learning with cooperative d2d local model aggregations\.IEEE J\. on Selected Areas in Commun\.39\(12\),pp\. 3851–3869\.Cited by:[§3\.2\.1](https://arxiv.org/html/2609.28722#S3.SS2.SSS1.p1.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.13.2.1.1.1)\. - Liuet al\.\(2022a\)P\. Liu, X\. Xu, and W\. WangThreats, attacks and defenses to federated learning: issues, taxonomy and perspectives\.Cybersecurity5\(1\),pp\. 4\.Cited by:[§1\.1](https://arxiv.org/html/2609.28722#S1.SS1.p1.1)\. - Liu and Shang \(2022\)S\. Liu and Y\. ShangFederated learning with anomaly client detection and decentralized parameter aggregation\.In2022 52nd Annual IEEE/IFIP Int\. Conf\. on Dependable Syst\. and Netw\. Wkshp\. \(DSN\-W\),Vol\.,pp\. 37–43\.Cited by:[§3\.1](https://arxiv.org/html/2609.28722#S3.SS1.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.5.2.1.6.1),[§4](https://arxiv.org/html/2609.28722#S4.p1.1)\. - Liuet al\.\(2021\)X\. Liu, H\. Li, G\. Xu, Z\. Chen, X\. Huang, and R\. LuPrivacy\-enhanced federated learning against poisoning adversaries\.IEEE Trans\. on Inf\. Forensics and Security16\(\),pp\. 4574–4588\.External Links:[Document](https://dx.doi.org/10.1109/TIFS.2021.3108434)Cited by:[§2\.4](https://arxiv.org/html/2609.28722#S2.SS4.p1.1),[§3\.2\.2](https://arxiv.org/html/2609.28722#S3.SS2.SSS2.p1.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.12.2.1.1.1),[§4\.1\.1](https://arxiv.org/html/2609.28722#S4.SS1.SSS1.p1.1)\. - Liuet al\.\(2023\)X\. Liu, S\. Cai, L\. Li, R\. Zhang, and S\. GuoMGIA: mutual gradient inversion attack in multi\-modal federated learning\.InProc\. of the AAAI Conf\. on Artif\. Intell\.,Vol\.37,pp\. 16270–16271\.Cited by:[§2\.4\.3](https://arxiv.org/html/2609.28722#S2.SS4.SSS3.p1.1),[Table 6](https://arxiv.org/html/2609.28722#S2.T6.5.1.14.1.1.1.1)\. - Liuet al\.\(2020\)Y\. Liu, Z\. Yi, and T\. ChenBackdoor attacks and defenses in feature\-partitioned collaborative learning\.arXiv preprint arXiv:2007\.03608\.Cited by:[§2\.3\.2](https://arxiv.org/html/2609.28722#S2.SS3.SSS2.p1.1),[Table 4](https://arxiv.org/html/2609.28722#S2.T4.5.1.5.1.1.1.1),[§4\.1](https://arxiv.org/html/2609.28722#S4.SS1.p1.1)\. - Liuet al\.\(2022b\)Z\. Liu, J\. Guo, W\. Yang, J\. Fan, K\. Lam, and J\. ZhaoPrivacy\-preserving aggregation in federated learning: a survey\.IEEE Trans\. on Big Data\.Cited by:[§3\.2\.1](https://arxiv.org/html/2609.28722#S3.SS2.SSS1.p1.1),[§3\.2\.2](https://arxiv.org/html/2609.28722#S3.SS2.SSS2.p1.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.12.2.1.1.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.8.2.1.1.1),[§3](https://arxiv.org/html/2609.28722#S3.p1.1),[§4\.1\.3](https://arxiv.org/html/2609.28722#S4.SS1.SSS3.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.4.2.1.1.1)\. - Looet al\.\(2023\)N\. Loo, R\. Hasani, M\. Lechner, A\. Amini, and D\. RusUnderstanding reconstruction attacks with the neural tangent kernel and dataset distillation\.arXiv preprint arXiv:2302\.01428\.Cited by:[§2\.4\.3](https://arxiv.org/html/2609.28722#S2.SS4.SSS3.p1.1),[Table 6](https://arxiv.org/html/2609.28722#S2.T6.5.1.13.1.1.2.1)\. - Luoet al\.\(2023\)Y\. Luo, Z\. Lu, X\. Yin, S\. Lu, and Y\. WengApplication research of vertical federated learning technol\. in banking risk control model strategy\.In2023 IEEE Intl Conf on Parallel & Distrib\. Process\. with Appl\., Big Data & Cloud Comput\., Sust\. Comput\. & Commun\., Social Comput\. & Netw\.,pp\. 545–552\.Cited by:[§6\.2\.3](https://arxiv.org/html/2609.28722#S6.SS2.SSS3.p1.1)\. - Lyuet al\.\(2024\)L\. Lyu, H\. Yu, X\. Ma, C\. Chen, L\. Sun, J\. Zhao, Q\. Yang, and P\. S\. YuPrivacy and robustness in federated learning: attacks and defenses\.IEEE Trans\. on Neural Netw\. and Learning Syst\.35\(7\),pp\. 8726–8746\.Cited by:[§2\.4\.2](https://arxiv.org/html/2609.28722#S2.SS4.SSS2.p1.1),[§2\.4](https://arxiv.org/html/2609.28722#S2.SS4.p1.1),[Table 6](https://arxiv.org/html/2609.28722#S2.T6.5.1.12.1.1.1.1),[§4\.1](https://arxiv.org/html/2609.28722#S4.SS1.p1.1)\. - Lyuet al\.\(2020\)L\. Lyu, H\. Yu, and Q\. YangThreats to federated learning: a survey\.arXiv preprint arXiv:2003\.02133\.Cited by:[§1\.1](https://arxiv.org/html/2609.28722#S1.SS1.p1.1)\. - Lyuet al\.\(2023\)X\. Lyu, Y\. Han, W\. Wang, J\. Liu, B\. Wang, J\. Liu, and X\. ZhangPoisoning with cerberus: stealthy and colluded backdoor attack against federated learning\.InProc\. of the AAAI Conf\. on Artif\. Intell\.,Vol\.37,pp\. 9020–9028\.Cited by:[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p2.1),[§2\.3](https://arxiv.org/html/2609.28722#S2.SS3.p1.1),[§2](https://arxiv.org/html/2609.28722#S2.p1.1)\. - Maet al\.\(2022a\)C\. Ma, J\. Li, L\. Shi, M\. Ding, T\. Wang, Z\. Han, and H\. V\. PoorWhen federated learning meets blockchain: a new distributed learning paradigm\.IEEE Comput\. Intell\. Magazine17\(3\),pp\. 26–33\.Cited by:[§4\.1\.4](https://arxiv.org/html/2609.28722#S4.SS1.SSS4.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.5.2.1.5.1)\. - Maet al\.\(2022b\)J\. Ma, S\. Naas, S\. Sigg, and X\. LyuPrivacy\-preserving federated learning based on multi\-key homomorphic encryption\.Int\. J\. of Intell\. Syst\.37\(9\),pp\. 5880–5901\.Cited by:[§4\.1\.2](https://arxiv.org/html/2609.28722#S4.SS1.SSS2.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.3.2.1.7.1)\. - Maet al\.\(2024\)J\. Ma, H\. Liu, M\. Zhang, and Z\. LiuVPFL: enabling verifiability and privacy in federated learning with zero\-knowledge proofs\.Knowl\.\-Based Syst\.,pp\. 112115\.Cited by:[§4\.1\.6](https://arxiv.org/html/2609.28722#S4.SS1.SSS6.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.7.2.1.2.1)\. - Maet al\.\(2022c\)Z\. Ma, M\. Zhang, J\. Liu, A\. Yang, H\. Li, J\. Wang, D\. Hua, and M\. LiAn assisted diagnosis model for cancer patients based on federated learning\.Frontiers in Oncol\.12,pp\. 860532\.Cited by:[§6\.2\.1](https://arxiv.org/html/2609.28722#S6.SS2.SSS1.p1.1)\. - Maet al\.\(2022d\)Z\. Ma, J\. Ma, Y\. Miao, Y\. Li, and R\. H\. DengShieldFL: mitigating model poisoning attacks in privacy\-preserving federated learning\.IEEE Trans\. on Inf\. Forensics and Security17,pp\. 1639–1654\.Cited by:[§4\.1\.6](https://arxiv.org/html/2609.28722#S4.SS1.SSS6.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.7.2.1.4.1)\. - Marnissiet al\.\(2024\)O\. Marnissi, H\. El Hammouti, and E\. H\. BergouAdaptive sparsification and quantization for enhanced energy efficiency in federated learning\.IEEE Open J\. of the Commun\. Soc\.5\(\),pp\. 4307–4321\.External Links:[Document](https://dx.doi.org/10.1109/OJCOMS.2024.3425531)Cited by:[§4\.1\.2](https://arxiv.org/html/2609.28722#S4.SS1.SSS2.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.3.2.1.5.1),[§4](https://arxiv.org/html/2609.28722#S4.p1.1)\. - McMahanet al\.\(2017\)B\. McMahan, E\. Moore, D\. Ramage, S\. Hampson, and B\. A\. y ArcasCommunication\-efficient learning of deep networks from decentralized data\.InArtif\. Intell\. and statistics,pp\. 1273–1282\.Cited by:[§1](https://arxiv.org/html/2609.28722#S1.p1.1)\. - Moriai \(2019\)S\. MoriaiPrivacy\-preserving deep learning via additively homomorphic encryption\.In2019 IEEE 26th Symp\. on Computer Arithmetic \(ARITH\),pp\. 198–198\.Cited by:[§2\.4](https://arxiv.org/html/2609.28722#S2.SS4.p1.1),[§4\.1\.6](https://arxiv.org/html/2609.28722#S4.SS1.SSS6.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.7.2.1.5.1)\. - Moshawrabet al\.\(2023\)M\. Moshawrab, M\. Adda, A\. Bouzouane, H\. Ibrahim, and A\. RaadPolyFLAG\_SVM: a polymorphic federated learning aggregation of gradients support vector machines framework\.Procedia Computer Science224,pp\. 139–146\.Cited by:[§4\.1\.6](https://arxiv.org/html/2609.28722#S4.SS1.SSS6.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.7.2.1.5.1)\. - Mothukuriet al\.\(2021\)V\. Mothukuri, R\. M\. Parizi, S\. Pouriyeh, Y\. Huang, A\. Dehghantanha, and G\. SrivastavaA survey on security and privacy of federated learning\.Future Generation Computer Syst\.115,pp\. 619–640\.Cited by:[§1\.1](https://arxiv.org/html/2609.28722#S1.SS1.p1.1),[§1](https://arxiv.org/html/2609.28722#S1.p1.1),[§2\.2](https://arxiv.org/html/2609.28722#S2.SS2.p2.1),[§2\.3\.6](https://arxiv.org/html/2609.28722#S2.SS3.SSS6.p1.1),[§2\.4\.1](https://arxiv.org/html/2609.28722#S2.SS4.SSS1.p1.1),[§2\.4\.3](https://arxiv.org/html/2609.28722#S2.SS4.SSS3.p1.1),[Table 5](https://arxiv.org/html/2609.28722#S2.T5.5.1.8.1.1.1.1),[Table 6](https://arxiv.org/html/2609.28722#S2.T6.5.1.7.1.1.2.1),[§4\.1\.4](https://arxiv.org/html/2609.28722#S4.SS1.SSS4.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.5.2.1.1.1)\. - Mozaffariet al\.\(2024\)H\. Mozaffari, S\. Choudhary, and A\. HoumansadrFake or compromised? making sense of malicious clients in federated learning\.External Links:2403\.06319Cited by:[§2\.3\.3](https://arxiv.org/html/2609.28722#S2.SS3.SSS3.p1.1),[Table 4](https://arxiv.org/html/2609.28722#S2.T4.5.1.8.1.1.1.1),[§4\.1\.2](https://arxiv.org/html/2609.28722#S4.SS1.SSS2.p1.1)\. - Nguyenet al\.\(2022\)H\. T\. Nguyen, H\. V\. Poor, and M\. ChiangContextual model aggregation for fast and robust federated learning in edge computing\.arXiv preprint arXiv:2203\.12738\.Cited by:[§3\.2\.1](https://arxiv.org/html/2609.28722#S3.SS2.SSS1.p1.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.8.2.1.1.1)\. - Nguyenet al\.\(2026\)M\. H\. Nguyen, T\. T\. Nguyen, J\. Jo, D\. A\. Nguyen, H\. Yin, and Q\. V\. H\. NguyenHandling data sparsity and model poisoning attacks in federated sequential recommender systems\.Knowl\.\-Based Syst\.,pp\. 115545\.Cited by:[§6\.2\.2](https://arxiv.org/html/2609.28722#S6.SS2.SSS2.p1.1)\. - Ozfaturaet al\.\(2021\)E\. Ozfatura, K\. Ozfatura, and D\. GündüzTime\-correlated sparsification for communication\-efficient federated learning\.In2021 IEEE Int\. Symp\. on Inf\. Theory \(ISIT\),pp\. 461–466\.Cited by:[§4\.1\.2](https://arxiv.org/html/2609.28722#S4.SS1.SSS2.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.3.2.1.4.1),[§4](https://arxiv.org/html/2609.28722#S4.p1.1)\. - Palihawadanaet al\.\(2022\)C\. Palihawadana, N\. Wiratunga, A\. Wijekoon, and H\. KalutarageFedsim: similarity guided model aggregation for federated learning\.Neurocomputing483,pp\. 432–445\.Cited by:[§3\.2\.1](https://arxiv.org/html/2609.28722#S3.SS2.SSS1.p1.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.13.2.1.2.1)\. - Parket al\.\(2021\)J\. Park, D\. Han, M\. Choi, and J\. MoonSageflow: robust federated learning against both stragglers and adversaries\.Advances in neural Inf\. Process\. Sys\.34,pp\. 840–851\.Cited by:[§3\.2\.1](https://arxiv.org/html/2609.28722#S3.SS2.SSS1.p1.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.2.2.1.2.1)\. - Parket al\.\(2023\)S\. Park, S\. Han, F\. Wu, S\. Kim, B\. Zhu, X\. Xie, and M\. ChaFedDefender: client\-side attack\-tolerant federated learning\.InProc\. of the 29th ACM SIGKDD Conf\. on Knowl\. Discovery and Data Mining,KDD ’23,pp\. 1850–1861\.External Links:ISBN 9798400701030Cited by:[§4\.1\.1](https://arxiv.org/html/2609.28722#S4.SS1.SSS1.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.2.2.1.2.1)\. - Pejó and Biczók \(2023\)B\. Pejó and G\. BiczókQuality inference in federated learning with secure aggregation\.IEEE Trans\. on Big Data9\(5\),pp\. 1430–1437\.Cited by:[§2\.3\.3](https://arxiv.org/html/2609.28722#S2.SS3.SSS3.p1.1),[Table 4](https://arxiv.org/html/2609.28722#S2.T4.5.1.11.1.1.1.1),[§3](https://arxiv.org/html/2609.28722#S3.p1.1)\. - Penget al\.\(2024\)J\. Peng, W\. Li, and Q\. LingMean aggregator is more robust than robust aggregators under label poisoning attacks\.arXiv preprint arXiv:2404\.13647\.Cited by:[§3\.2\.1](https://arxiv.org/html/2609.28722#S3.SS2.SSS1.p1.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.5.2.1.1.1),[§4\.1\.2](https://arxiv.org/html/2609.28722#S4.SS1.SSS2.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.3.2.1.2.1)\. - Perazzoneet al\.\(2025\)J\. B\. Perazzone, S\. Wang, M\. Ji, and K\. ChanCommunication\-efficient device scheduling for federated learning using lyapunov optimization\.IEEE Trans\. on Netw\.\.Cited by:[§3\.2\.1](https://arxiv.org/html/2609.28722#S3.SS2.SSS1.p1.1)\. - Periet al\.\(2020\)N\. Peri, N\. Gupta, W\. R\. Huang, L\. Fowl, C\. Zhu, S\. Feizi, T\. Goldstein, and J\. P\. DickersonDeep k\-nn defense against clean\-label data poisoning attacks\.InComputer Vision–ECCV 2020 Wkshp\.: Glasgow, UK, August 23–28, 2020, Proc\., Part I 16,pp\. 55–70\.Cited by:[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p1.1),[Table 3](https://arxiv.org/html/2609.28722#S2.T3.8.1.2.1.1.1.1)\. - Pillutlaet al\.\(2022\)K\. Pillutla, S\. M\. Kakade, and Z\. HarchaouiRobust aggregation for federated learning\.IEEE Trans\. on Signal Process\.70\(\),pp\. 1142–1154\.External Links:[Document](https://dx.doi.org/10.1109/TSP.2022.3153135)Cited by:[§3\.2\.1](https://arxiv.org/html/2609.28722#S3.SS2.SSS1.p1.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.2.2.1.1.1),[§4\.1\.2](https://arxiv.org/html/2609.28722#S4.SS1.SSS2.p1.1),[§4\.1](https://arxiv.org/html/2609.28722#S4.SS1.p1.1)\. - Psychogyioset al\.\(2023\)K\. Psychogyios, T\. Velivassaki, S\. Bourou, A\. Voulkidis, D\. Skias, and T\. ZahariadisGAN\-driven data poisoning attacks and their mitigation in federated learning systems\.Electronics12\(8\),pp\. 1805\.Cited by:[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p1.1),[Table 3](https://arxiv.org/html/2609.28722#S2.T3.8.1.4.1.1.3.1)\. - Qiuet al\.\(2024\)P\. Qiu, X\. Zhang, S\. Ji, C\. Fu, X\. Yang, and T\. WangHashvfl: defending against data reconstruction attacks in vertical federated learning\.IEEE Trans\. on Inf\. Forensics and Security\.Cited by:[§2\.4\.3](https://arxiv.org/html/2609.28722#S2.SS4.SSS3.p1.1),[Table 6](https://arxiv.org/html/2609.28722#S2.T6.5.1.13.1.1.1.1)\. - Que and Khan \(2025\)C\. Que and F\. N\. KhanA scalable federated learning\-based approach for accurate traffic prediction in edge computing\-enable metro optical networks\.Computers & Industrial Eng\.203,pp\. 111004\.Cited by:[§6\.2\.4](https://arxiv.org/html/2609.28722#S6.SS2.SSS4.p1.1),[§6\.2\.5](https://arxiv.org/html/2609.28722#S6.SS2.SSS5.p1.1)\. - Ranathungaet al\.\(2022\)T\. Ranathunga, A\. McGibney, S\. Rea, and S\. BhartiBlockchain\-based decentralized model aggregation for cross\-silo federated learning in industry 4\.0\.IEEE Internet of Things J\.10\(5\),pp\. 4449–4461\.Cited by:[§3\.2\.2](https://arxiv.org/html/2609.28722#S3.SS2.SSS2.p3.1),[§4\.1\.2](https://arxiv.org/html/2609.28722#S4.SS1.SSS2.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.3.2.1.4.1)\. - Ranjanet al\.\(2022a\)P\. Ranjan, F\. Corò, A\. Gupta, and S\. K\. DasLeveraging spanning tree to detect colluding attackers in federated learning\.InIEEE INFOCOM 2022 \- IEEE Conf\. on Comput\. Commun\. Wkshp\. \(INFOCOM WKSHPS\),pp\. 1–2\.Cited by:[§1](https://arxiv.org/html/2609.28722#S1.p1.1),[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p2.1),[Table 3](https://arxiv.org/html/2609.28722#S2.T3.8.1.6.1.1.1.1)\. - Ranjanet al\.\(2022b\)P\. Ranjan, A\. Gupta, F\. Coro, and S\. K\. DasSecuring federated learning against overwhelming collusive attackers\.InGLOBECOM 2022\-2022 IEEE Global Commun\. Conf\.,pp\. 1448–1453\.Cited by:[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p2.1),[Table 3](https://arxiv.org/html/2609.28722#S2.T3.8.1.6.1.1.1.1)\. - Renet al\.\(2020\)J\. Ren, P\. J\. Liu, E\. Fertig, J\. Snoek, R\. Poplin, M\. Depristo, J\. Dillon, and B\. LakshminarayananLikelihood ratios for out\-of\-distribution detection\.Advances in neural Inf\. processing systems32\.Cited by:[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p2.1),[Table 3](https://arxiv.org/html/2609.28722#S2.T3.8.1.5.1.1.2.1)\. - Ronget al\.\(2022\)D\. Rong, S\. Ye, R\. Zhao, H\. N\. Yuen, J\. Chen, and Q\. HeFedRecAttack: model poisoning attack to federated recommendation\.In2022 IEEE 38th Int\. Conf\. on Data Eng\. \(ICDE\),Vol\.,pp\. 2643–2655\.External Links:[Document](https://dx.doi.org/10.1109/ICDE53745.2022.00243)Cited by:[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p1.1),[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p2.1),[Table 3](https://arxiv.org/html/2609.28722#S2.T3.8.1.2.1.1.2.1),[Table 3](https://arxiv.org/html/2609.28722#S2.T3.8.1.8.1.1.2.1)\. - Sagduyu \(2022\)Y\. E\. SagduyuFree\-rider games for federated learning with selfish clients in nextg wireless networks\.In2022 IEEE Conf\. on Commun\. and Netw\. Security \(CNS\),pp\. 365–370\.Cited by:[§2\.3\.3](https://arxiv.org/html/2609.28722#S2.SS3.SSS3.p1.1),[Table 4](https://arxiv.org/html/2609.28722#S2.T4.5.1.8.1.1.3.1)\. - Sastry and Oore \(2020\)C\. S\. Sastry and S\. OoreDetecting out\-of\-distribution examples with gram matrices\.InInt\. Conf\. on Mach\. Learning,pp\. 8491–8501\.Cited by:[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p2.1),[Table 3](https://arxiv.org/html/2609.28722#S2.T3.8.1.5.1.1.1.1)\. - Shejwalkaret al\.\(2022\)V\. Shejwalkar, A\. Houmansadr, P\. Kairouz, and D\. RamageBack to the drawing board: a critical evaluation of poisoning attacks on production federated learning\.In2022 IEEE Symp\. on Security and Privacy \(SP\),pp\. 1354–1371\.Cited by:[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p2.1)\. - Shenet al\.\(2021\)M\. Shen, H\. Wang, B\. Zhang, L\. Zhu, K\. Xu, Q\. Li, and X\. DuExploiting unintended property leakage in blockchain\-assisted federated learning for intelligent edge computing\.IEEE Internet of Things J\.8\(4\),pp\. 2265–2275\.External Links:[Document](https://dx.doi.org/10.1109/JIOT.2020.3028110)Cited by:[§2\.4\.1](https://arxiv.org/html/2609.28722#S2.SS4.SSS1.p1.1),[Table 6](https://arxiv.org/html/2609.28722#S2.T6.5.1.8.1.1.1.1),[§3\.2\.2](https://arxiv.org/html/2609.28722#S3.SS2.SSS2.p2.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.10.2.1.1.1),[§4\.1\.2](https://arxiv.org/html/2609.28722#S4.SS1.SSS2.p1.1)\. - Sikandaret al\.\(2023\)H\. S\. Sikandar, H\. Waheed, S\. Tahir, S\. U\. Malik, and W\. RafiqueA detailed survey on federated learning attacks and defenses\.Electronics12\(2\),pp\. 260\.Cited by:[§1\.1](https://arxiv.org/html/2609.28722#S1.SS1.p1.1)\. - Songet al\.\(2020\)M\. Song, Z\. Wang, Z\. Zhang, Y\. Song, Q\. Wang, J\. Ren, and H\. QiAnalyzing user\-level privacy attack against federated learning\.IEEE J\. on Selected Areas in Commun\.38\(10\),pp\. 2430–2444\.Cited by:[§2\.4\.1](https://arxiv.org/html/2609.28722#S2.SS4.SSS1.p1.1),[Table 6](https://arxiv.org/html/2609.28722#S2.T6.5.1.9.1.1.1.1)\. - Sotthiwatet al\.\(2021\)E\. Sotthiwat, L\. Zhen, Z\. Li, and C\. ZhangPartially encrypted multi\-party computation for federated learning\.In2021 IEEE/ACM 21st Int\. Symp\. on Cluster, Cloud and Internet Comput\. \(CCGrid\),pp\. 828–835\.Cited by:[§3\.1](https://arxiv.org/html/2609.28722#S3.SS1.p1.1),[§3\.2\.2](https://arxiv.org/html/2609.28722#S3.SS2.SSS2.p1.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.9.2.1.1.1),[§4\.1\.6](https://arxiv.org/html/2609.28722#S4.SS1.SSS6.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.7.2.1.1.1)\. - Sultanaet al\.\(2022\)A\. Sultana, M\. M\. Haque, L\. Chen, F\. Xu, and X\. YuanEiffel: efficient and fair scheduling in adaptive federated learning\.IEEE Trans\. on Parallel and Distrib\. Syst\.33\(12\),pp\. 4282–4294\.Cited by:[§3\.2\.1](https://arxiv.org/html/2609.28722#S3.SS2.SSS1.p1.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.6.2.1.1.1),[§4\.1\.3](https://arxiv.org/html/2609.28722#S4.SS1.SSS3.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.4.2.1.1.1)\. - Sunet al\.\(2021a\)G\. Sun, Y\. Cong, J\. Dong, Q\. Wang, L\. Lyu, and J\. LiuData poisoning attacks on federated machine learning\.IEEE Internet of Things J\.9\(13\),pp\. 11365–11375\.Cited by:[§2\.2](https://arxiv.org/html/2609.28722#S2.SS2.p1.1),[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p2.1),[Table 3](https://arxiv.org/html/2609.28722#S2.T3.8.1.6.1.1.3.1),[§2](https://arxiv.org/html/2609.28722#S2.p1.1)\. - Sunet al\.\(2021b\)J\. Sun, A\. Li, L\. DiValentin, A\. Hassanzadeh, Y\. Chen, and H\. LiFl\-wbc: enhancing robustness against model poisoning attacks in federated learning from a client perspective\.Advances in neural Inf\. Proc\. systems34,pp\. 12613–12624\.Cited by:[§4\.1\.2](https://arxiv.org/html/2609.28722#S4.SS1.SSS2.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.3.2.1.7.1)\. - Sunet al\.\(2024a\)W\. Sun, B\. Gao, K\. Xiong, Y\. Wang, P\. Fan, and K\. B\. LetaiefA gan\-based data poisoning attack against federated learning systems and its countermeasure\.arXiv preprint arXiv:2405\.11440\.Cited by:[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p1.1),[Table 3](https://arxiv.org/html/2609.28722#S2.T3.8.1.4.1.1.1.1)\. - Sunet al\.\(2024b\)Y\. Sun, G\. Xiong, X\. Yao, K\. Ma, and J\. CuiGI\-pip: do we require impractical auxiliary dataset for gradient inversion attacks?\.InICASSP 2024\-2024 IEEE Int\. Conf\. on Acoustics, Speech and Signal Process\. \(ICASSP\),pp\. 4675–4679\.Cited by:[§2\.4\.3](https://arxiv.org/html/2609.28722#S2.SS4.SSS3.p1.1),[Table 6](https://arxiv.org/html/2609.28722#S2.T6.5.1.14.1.1.2.1)\. - Sunet al\.\(2022\)Y\. Sun, J\. Shao, Y\. Mao, and J\. ZhangAsynchronous semi\-decentralized federated edge learning for heterogeneous clients\.InICC 2022\-IEEE Int\. Conf\. on Commun\.,pp\. 5196–5201\.Cited by:[§3\.2\.1](https://arxiv.org/html/2609.28722#S3.SS2.SSS1.p1.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.4.2.1.2.1)\. - Sunet al\.\(2023\)Y\. Sun, H\. Ochiai, and J\. SakumaAttacking\-distance\-aware attack: semi\-targeted model poisoning on federated learning\.IEEE Trans\. on Artif\. Intell\.5\(2\),pp\. 925–939\.Cited by:[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p1.1),[§2](https://arxiv.org/html/2609.28722#S2.p1.1)\. - Sunet al\.\(2019\)Z\. Sun, P\. Kairouz, A\. T\. Suresh, and H\. B\. McMahanCan you really backdoor federated learning?\.arXiv preprint arXiv:1911\.07963\.Cited by:[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p2.1),[Table 3](https://arxiv.org/html/2609.28722#S2.T3.8.1.8.1.1.1.1)\. - Suriet al\.\(2022\)A\. Suri, P\. Kanani, V\. J\. Marathe, and D\. W\. PetersonSubject membership inference attacks in federated learning\.arXiv preprint arXiv:2206\.03317\.Cited by:[§2\.4\.1](https://arxiv.org/html/2609.28722#S2.SS4.SSS1.p1.1),[Table 6](https://arxiv.org/html/2609.28722#S2.T6.5.1.5.1.1.1.1)\. - Tanet al\.\(2022\)Y\. Tan, G\. Long, L\. Liu, T\. Zhou, Q\. Lu, J\. Jiang, and C\. ZhangFedproto: federated prototype learning across heterogeneous clients\.InProc\. of the AAAI Conf\. on Artif\. Intell\.,Vol\.36,pp\. 8432–8440\.Cited by:[§1](https://arxiv.org/html/2609.28722#S1.p1.1)\. - Tanget al\.\(2024\)J\. Tang, H\. Xu, M\. Wang, T\. Tang, C\. Peng, and H\. LiaoA flexible and scalable malicious secure aggregation protocol for federated learning\.IEEE Trans\. on Inf\. Forensics and Security\.Cited by:[§1\.1](https://arxiv.org/html/2609.28722#S1.SS1.p1.1),[§1](https://arxiv.org/html/2609.28722#S1.p1.1),[§4\.1\.4](https://arxiv.org/html/2609.28722#S4.SS1.SSS4.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.5.2.1.6.1)\. - Tolpeginet al\.\(2020\)V\. Tolpegin, S\. Truex, M\. E\. Gursoy, and L\. LiuData poisoning attacks against federated learning systems\.InComputer security–ESORICs 2020: 25th Eur\. Symp\. on research in computer security, Guildford, UK, proceedings, part i 25,pp\. 480–501\.Cited by:[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p1.1),[Table 3](https://arxiv.org/html/2609.28722#S2.T3.8.1.3.1.1.2.1),[§2](https://arxiv.org/html/2609.28722#S2.p1.1)\. - Tuoret al\.\(2021\)T\. Tuor, S\. Wang, B\. J\. Ko, C\. Liu, and K\. K\. LeungOvercoming noisy and irrelevant data in federated learning\.In2020 25th Int\. Conf\. on Pattern Recognition \(ICPR\),pp\. 5020–5027\.Cited by:[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p2.1),[Table 3](https://arxiv.org/html/2609.28722#S2.T3.8.1.6.1.1.2.1)\. - Uddinet al\.\(2025\)M\. P\. Uddin, Y\. Xiang, M\. Hasan, J\. Bai, Y\. Zhao, and L\. GaoA systematic literature review of robust federated learning: issues, solutions, and future research directions\.ACM Comput\. Surveys57\(10\),pp\. 1–62\.Cited by:[§1\.1](https://arxiv.org/html/2609.28722#S1.SS1.p1.1)\. - Uprety and Rawat \(2021\)A\. Uprety and D\. B\. RawatMitigating poisoning attack in federated learning\.In2021 IEEE symposium series on computational Intell\. \(SSCI\),pp\. 01–07\.Cited by:[§4\.1\.3](https://arxiv.org/html/2609.28722#S4.SS1.SSS3.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.4.2.1.3.1)\. - Vangalaet al\.\(2022\)A\. Vangala, A\. K\. Das, A\. Mitra, S\. K\. Das, and Y\. ParkBlockchain\-enabled authenticated key agreement scheme for mobile vehicles\-assisted precision agricultural iot networks\.IEEE Trans\. on Inf\. Forensics and Security18,pp\. 904–919\.Cited by:[§2\.3\.4](https://arxiv.org/html/2609.28722#S2.SS3.SSS4.p1.1),[Table 5](https://arxiv.org/html/2609.28722#S2.T5.5.1.2.1.1.2.1),[§3\.2\.2](https://arxiv.org/html/2609.28722#S3.SS2.SSS2.p2.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.10.2.1.1.1)\. - Wanet al\.\(2023\)W\. Wan, S\. Hu, M\. Li, J\. Lu, L\. Zhang, L\. Y\. Zhang, and H\. JinA four\-pronged defense against byzantine attacks in federated learning\.InProc\. of the 31st ACM Int\. Conf\. on Multimedia,MM ’23\.Cited by:[§1](https://arxiv.org/html/2609.28722#S1.p1.1),[§4\.1](https://arxiv.org/html/2609.28722#S4.SS1.p1.1)\. - Wanet al\.\(2022\)W\. Wan, S\. Hu, J\. Lu, L\. Y\. Zhang, H\. Jin, and Y\. HeShielding federated learning: robust aggregation with adaptive client selection\.arXiv preprint arXiv:2204\.13256\.Cited by:[§2\.3\.3](https://arxiv.org/html/2609.28722#S2.SS3.SSS3.p1.1),[Table 4](https://arxiv.org/html/2609.28722#S2.T4.5.1.10.1.1.1.1),[§3\.2\.1](https://arxiv.org/html/2609.28722#S3.SS2.SSS1.p1.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.6.2.1.2.1),[§3](https://arxiv.org/html/2609.28722#S3.p1.1)\. - Wanget al\.\(2020a\)D\. Wang, C\. Li, S\. Wen, S\. Nepal, and Y\. XiangMan\-in\-the\-middle attacks against machine learning classifiers via malicious generative models\.IEEE Trans\. on Dependable and Secure Comput\.18\(5\),pp\. 2074–2087\.Cited by:[§2\.3\.4](https://arxiv.org/html/2609.28722#S2.SS3.SSS4.p1.1),[Table 5](https://arxiv.org/html/2609.28722#S2.T5.5.1.2.1.1.1.1)\. - Wanget al\.\(2021a\)D\. Wang, N\. Zhang, and M\. TaoAdaptive clustering\-based model aggregation for federated learning with imbalanced data\.In2021 IEEE 22nd Int\. Wkshp\. on Signal Process\. Advances in Wireless Commun\. \(SPAWC\),pp\. 591–595\.Cited by:[§3\.2\.1](https://arxiv.org/html/2609.28722#S3.SS2.SSS1.p1.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.13.2.1.2.1),[§4\.1\.2](https://arxiv.org/html/2609.28722#S4.SS1.SSS2.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.3.2.1.1.1)\. - Wanget al\.\(2023\)H\. Wang, L\. Muñoz\-González, M\. Z\. Hameed, D\. Eklund, and S\. RazaSparSFA: towards robust and communication\-efficient peer\-to\-peer federated learning\.Computers & Security129,pp\. 103182\.Cited by:[§4\.1\.2](https://arxiv.org/html/2609.28722#S4.SS1.SSS2.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.3.2.1.5.1),[§4](https://arxiv.org/html/2609.28722#S4.p1.1)\. - Wanget al\.\(2020b\)H\. Wang, K\. Sreenivasan, S\. Rajput, H\. Vishwakarma, S\. Agarwal, J\. Sohn, K\. Lee, and D\. PapailiopoulosAttack of the tails: yes, you really can backdoor federated learning\.Advances in Neural Inf\. Process\. Syst\.33,pp\. 16070–16084\.Cited by:[§2\.3\.2](https://arxiv.org/html/2609.28722#S2.SS3.SSS2.p1.1),[§2\.3](https://arxiv.org/html/2609.28722#S2.SS3.p1.1),[Table 3](https://arxiv.org/html/2609.28722#S2.T3.8.1.9.1.1.2.1),[Table 4](https://arxiv.org/html/2609.28722#S2.T4.5.1.7.1.1.1.1),[§2](https://arxiv.org/html/2609.28722#S2.p1.1),[§4\.1\.2](https://arxiv.org/html/2609.28722#S4.SS1.SSS2.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.3.2.1.2.1)\. - Wanget al\.\(2022\)J\. Wang, X\. Chang, R\. J\. Rodrìguez, and Y\. WangAssessing anonymous and selfish free\-rider attacks in federated learning\.In2022 IEEE Symp\. on Computers and Commun\. \(ISCC\),pp\. 1–6\.Cited by:[§2\.3\.3](https://arxiv.org/html/2609.28722#S2.SS3.SSS3.p1.1),[Table 4](https://arxiv.org/html/2609.28722#S2.T4.5.1.9.1.1.1.1)\. - Wanget al\.\(2024a\)M\. Wang, A\. Bodonhelyi, E\. Bozkir, and E\. KasneciTurboSVM\-fl: boosting federated learning through svm aggregation for lazy clients\.InProc\. of the AAAI Conf\. on Artif\. Intell\.,Vol\.38,pp\. 15546–15554\.Cited by:[§3\.2\.1](https://arxiv.org/html/2609.28722#S3.SS2.SSS1.p1.1),[§3](https://arxiv.org/html/2609.28722#S3.p1.1)\. - Wanget al\.\(2021b\)Q\. Wang, Q\. Li, K\. Wang, H\. Wang, and P\. ZengEfficient federated learning for fault diagnosis in industrial cloud\-edge computing\.Computing103\(10\),pp\. 2319–2337\.Cited by:[§6\.2\.5](https://arxiv.org/html/2609.28722#S6.SS2.SSS5.p1.1)\. - Wanget al\.\(2024b\)X\. Wang, D\. Dimitriadis, S\. Koyejo, and S\. TopleInvariant aggregator for defending against federated backdoor attacks\.InInt\. Conf\. on Artif\. Intell\. and Statistics,pp\. 2728–2736\.Cited by:[§1](https://arxiv.org/html/2609.28722#S1.p1.1),[§2\.3\.2](https://arxiv.org/html/2609.28722#S2.SS3.SSS2.p1.1),[§3\.2\.1](https://arxiv.org/html/2609.28722#S3.SS2.SSS1.p1.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.5.2.1.2.1),[§4\.1\.2](https://arxiv.org/html/2609.28722#S4.SS1.SSS2.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.3.2.1.1.1)\. - Wanget al\.\(2024c\)Y\. Wang, S\. Guo, Y\. Deng, H\. Zhang, and Y\. FangPrivacy\-preserving task\-oriented semantic communications against model inversion attacks\.IEEE Trans\. on Wireless Commun\.\.Cited by:[§1](https://arxiv.org/html/2609.28722#S1.p1.1),[§2\.4\.3](https://arxiv.org/html/2609.28722#S2.SS4.SSS3.p1.1),[Table 6](https://arxiv.org/html/2609.28722#S2.T6.5.1.14.1.1.1.1)\. - Wanget al\.\(2024d\)Z\. Wang, Z\. Chang, J\. Hu, X\. Pang, J\. Du, Y\. Chen, and K\. RenBreaking secure aggregation: label leakage from aggregated gradients in federated learning\.InIEEE INFOCOM 2024 \- IEEE Conf\. on Computer Commun\.,Vol\.,pp\. 151–160\.External Links:[Document](https://dx.doi.org/10.1109/INFOCOM52122.2024.10621090)Cited by:[§2\.4\.1](https://arxiv.org/html/2609.28722#S2.SS4.SSS1.p1.1),[§2\.4\.3](https://arxiv.org/html/2609.28722#S2.SS4.SSS3.p1.1),[Table 6](https://arxiv.org/html/2609.28722#S2.T6.5.1.11.1.1.1.1),[Table 6](https://arxiv.org/html/2609.28722#S2.T6.5.1.14.1.1.2.1)\. - Weiet al\.\(2023\)K\. Wei, J\. Li, M\. Ding, C\. Ma, Y\. Jeon, and H\. V\. PoorCovert model poisoning against federated learning: algorithm design and optimization\.IEEE Trans\. on Dependable and Secure Comput\.\.Cited by:[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p3.1),[§2\.3](https://arxiv.org/html/2609.28722#S2.SS3.p1.1),[Table 3](https://arxiv.org/html/2609.28722#S2.T3.8.1.12.1.1.1.1),[§2](https://arxiv.org/html/2609.28722#S2.p1.1)\. - Winkenset al\.\(2020\)J\. Winkens, R\. Bunel, A\. G\. Roy, R\. Stanforth, V\. Natarajan, J\. R\. Ledsam, P\. MacWilliams, P\. Kohli, A\. Karthikesalingam, S\. Kohl,et al\.Contrastive training for improved out\-of\-distribution detection\.arXiv preprint arXiv:2007\.05566\.Cited by:[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p2.1),[Table 3](https://arxiv.org/html/2609.28722#S2.T3.8.1.5.1.1.1.1)\. - Wuet al\.\(2022\)J\. Wu, S\. Si, J\. Wang, and J\. XiaoThreats and defenses of federated learning: a survey\.Big Data Research8\(5\),pp\. 12\.Cited by:[§1\.1](https://arxiv.org/html/2609.28722#S1.SS1.p1.1),[§1](https://arxiv.org/html/2609.28722#S1.p1.1)\. - Wuet al\.\(2023\)Q\. Wu, X\. Chen, T\. Ouyang, Z\. Zhou, X\. Zhang, S\. Yang, and J\. ZhangHiFlash: communication\-efficient hierarchical federated learning with adaptive staleness control and heterogeneity\-aware client\-edge association\.IEEE Trans\. on Parallel and Distrib\. Syst\.34\(5\),pp\. 1560–1579\.Cited by:[§1](https://arxiv.org/html/2609.28722#S1.p1.1),[§3\.2\.1](https://arxiv.org/html/2609.28722#S3.SS2.SSS1.p1.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.4.2.1.1.1)\. - Xiaet al\.\(2023\)G\. Xia, J\. Chen, C\. Yu, and J\. MaPoisoning attacks in federated learning: a survey\.IEEE Access11,pp\. 10708–10722\.Cited by:[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p1.1),[Table 3](https://arxiv.org/html/2609.28722#S2.T3.8.1.2.1.1.4.1),[§4\.1\.1](https://arxiv.org/html/2609.28722#S4.SS1.SSS1.p1.1),[§4\.1\.6](https://arxiv.org/html/2609.28722#S4.SS1.SSS6.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.2.2.1.1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.7.2.1.1.1)\. - Xiaoet al\.\(2022\)D\. Xiao, B\. Cao, and W\. WuEfl\-wp: federated learning\-based workload prediction in inter\-cloud environments\.In2022 Int\. Joint Conf\. on Neural Netw\. \(IJCNN\),pp\. 1–10\.Cited by:[§3\.2\.1](https://arxiv.org/html/2609.28722#S3.SS2.SSS1.p1.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.13.2.1.1.1)\. - Xieet al\.\(2020a\)C\. Xie, K\. Huang, P\. Chen, and B\. LiDba: distributed backdoor attacks against federated learning\.InInt\. Conf\. on learning representations,Cited by:[§1](https://arxiv.org/html/2609.28722#S1.p1.1),[§2\.3\.2](https://arxiv.org/html/2609.28722#S2.SS3.SSS2.p1.1),[Table 4](https://arxiv.org/html/2609.28722#S2.T4.5.1.4.1.1.1.1)\. - Xieet al\.\(2020b\)C\. Xie, O\. Koyejo, and I\. GuptaFall of empires: breaking byzantine\-tolerant sgd by inner product manipulation\.InUncertainty in Artif\. Intell\.,pp\. 261–270\.Cited by:[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p3.1),[Table 3](https://arxiv.org/html/2609.28722#S2.T3.8.1.12.1.1.2.1)\. - Xuet al\.\(2022a\)C\. Xu, Y\. Jia, L\. Zhu, C\. Zhang, G\. Jin, and K\. SharifTDFL: truth discovery based byzantine robust federated learning\.IEEE Trans\. on Parallel and Distrib\. Syst\.33\(12\),pp\. 4835–4848\.Cited by:[§4\.1\.2](https://arxiv.org/html/2609.28722#S4.SS1.SSS2.p1.1),[§4\.1](https://arxiv.org/html/2609.28722#S4.SS1.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.3.2.1.6.1)\. - Xu and Neglia \(2021\)C\. Xu and G\. NegliaWhat else is leaked when eavesdropping federated learning?\.InCCS workshop Privacy Preserving Mach\. Learning \(PPML\),Cited by:[§2\.4\.4](https://arxiv.org/html/2609.28722#S2.SS4.SSS4.p1.1),[Table 6](https://arxiv.org/html/2609.28722#S2.T6.5.1.15.1.1.1.1)\. - Xuet al\.\(2020\)G\. Xu, H\. Li, Y\. Zhang, S\. Xu, J\. Ning, and R\. H\. DengPrivacy\-preserving federated deep learning with irregular users\.IEEE Trans\. on Dependable and Secure Comput\.19\(2\),pp\. 1364–1381\.Cited by:[§3\.2\.2](https://arxiv.org/html/2609.28722#S3.SS2.SSS2.p1.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.9.2.1.2.1)\. - Xuet al\.\(2022b\)Q\. Xu, Z\. Yang, Y\. Zhao, X\. Cao, and Q\. HuangRethinking label flipping attack: from sample masking to sample thresholding\.IEEE Trans\. on Pattern Anal\. and Mach\. Intell\.45\(6\),pp\. 7668–85\.Cited by:[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p1.1),[Table 3](https://arxiv.org/html/2609.28722#S2.T3.8.1.3.1.1.1.1)\. - Xuet al\.\(2024a\)S\. Xu, H\. Xia, P\. Liu, R\. Zhang, H\. Chi, and W\. GaoFLPM: a property modification scheme for data protection in federated learning\.Future Generation Computer Syst\.154,pp\. 151–159\.Cited by:[§4\.1\.1](https://arxiv.org/html/2609.28722#S4.SS1.SSS1.p1.1),[§4\.1\.2](https://arxiv.org/html/2609.28722#S4.SS1.SSS2.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.2.2.1.1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.3.2.1.6.1)\. - Xuet al\.\(2024b\)Y\. Xu, Y\. Tan, C\. Zhang, K\. Chi, P\. Sun, W\. Yang, J\. Ren, H\. Jiang, and Y\. ZhangRobWE: robust watermark embedding for personalized federated learning model ownership protection\.External Links:2402\.19054Cited by:[§4\.1\.2](https://arxiv.org/html/2609.28722#S4.SS1.SSS2.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.3.2.1.6.1)\. - Yanet al\.\(2025\)W\. Yan, Q\. Li, and T\. GonsalvesCorrelated dropout\-aware client selection framework for efficient decentralized federated learning systems\.In2025 IEEE Conf\. on Cloud and Big Data Comput\. \(CBDCom\),pp\. 112–119\.Cited by:[§3\.2\.1](https://arxiv.org/html/2609.28722#S3.SS2.SSS1.p1.1)\. - Yanget al\.\(2023a\)J\. Yang, J\. Zheng, T\. Baker, S\. Tang, Y\. Tan, and Q\. ZhangClean\-label poisoning attacks on federated learning for iot\.Expert Syst\.40\(5\),pp\. e13161\.Cited by:[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p1.1),[Table 3](https://arxiv.org/html/2609.28722#S2.T3.8.1.2.1.1.3.1)\. - Yanget al\.\(2019\)Q\. Yang, Y\. Liu, T\. Chen, and Y\. TongFederated machine learning: concept and applications\.ACM Trans\. on Intell\. Syst\. and Technol\. \(TIST\)10\(2\),pp\. 1–19\.Cited by:[§1\.1](https://arxiv.org/html/2609.28722#S1.SS1.p1.1)\. - Yanget al\.\(2022\)S\. Yang, Y\. Chen, S\. Tu, and Z\. YangA post\-quantum secure aggregation for federated learning\.InProc\. of the 2022 12th Int\. Conf\. on Commun\. and Netw\. Secur\.,pp\. 117–124\.Cited by:[§3\.2\.2](https://arxiv.org/html/2609.28722#S3.SS2.SSS2.p2.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.3.2.1.2.1),[§6\.1](https://arxiv.org/html/2609.28722#S6.SS1.p1.1)\. - Yanget al\.\(2023b\)W\. Yang, S\. Shao, Y\. Yang, X\. Liu, X\. Liu, Z\. Xia, G\. Schaefer, and H\. FangWatermarking in secure federated learning: a verification framework based on client\-side backdooring\.ACM Trans\. Intell\. Syst\. Technol\.15\(1\)\.External Links:ISSN 2157\-6904Cited by:[§1](https://arxiv.org/html/2609.28722#S1.p1.1),[§4\.1\.2](https://arxiv.org/html/2609.28722#S4.SS1.SSS2.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.3.2.1.2.1)\. - Yaoet al\.\(2018\)X\. Yao, C\. Huang, and L\. SunTwo\-stream federated learning: reduce the communication costs\.In2018 IEEE Visual Commun\. and Image Process\. \(VCIP\),pp\. 1–4\.Cited by:[§2\.3\.4](https://arxiv.org/html/2609.28722#S2.SS3.SSS4.p1.1),[Table 5](https://arxiv.org/html/2609.28722#S2.T5.5.1.3.1.1.1.1)\. - Yeet al\.\(2022\)H\. Ye, L\. Liang, and G\. Y\. LiDecentralized federated learning with unreliable communications\.IEEE journal of selected topics in signal processing16\(3\),pp\. 487–500\.Cited by:[§2\.3\.4](https://arxiv.org/html/2609.28722#S2.SS3.SSS4.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.5.2.1.5.1)\. - Yeet al\.\(2023\)M\. Ye, X\. Fang, B\. Du, P\. C\. Yuen, and D\. TaoHeterogeneous federated learning: state\-of\-the\-art and research challenges\.ACM Comput\. Surveys56\(3\),pp\. 1–44\.Cited by:[§6\.2\.1](https://arxiv.org/html/2609.28722#S6.SS2.SSS1.p1.1)\. - Yeet al\.\(2020\)Y\. Ye, S\. Li, F\. Liu, Y\. Tang, and W\. HuEdgeFed: optimized federated learning based on edge computing\.IEEE Access8,pp\. 209191–209198\.Cited by:[§6\.2\.5](https://arxiv.org/html/2609.28722#S6.SS2.SSS5.p1.1)\. - Yuet al\.\(2023\)Y\. Yu, Q\. Liu, L\. Wu, R\. Yu, S\. L\. Yu, and Z\. ZhangUntargeted attack against federated recommendation systems via poisonous item embeddings and the defense\.InProc\. of the AAAI Conf\. on Artif\. Intell\.,Vol\.37,pp\. 4854–4863\.Cited by:[§1](https://arxiv.org/html/2609.28722#S1.p1.1),[§2\.2](https://arxiv.org/html/2609.28722#S2.SS2.p1.1),[§2](https://arxiv.org/html/2609.28722#S2.p1.1),[§4](https://arxiv.org/html/2609.28722#S4.p1.1)\. - Yuanet al\.\(2022\)X\. Yuan, J\. Chen, J\. Yang, N\. Zhang, T\. Yang, T\. Han, and A\. TaherkordiFedstn: graph representation driven federated learning for edge computing enabled urban traffic flow prediction\.IEEE Trans\. on Intell\. Transp\. Syst\.24\(8\),pp\. 8738–8748\.Cited by:[§6\.2\.4](https://arxiv.org/html/2609.28722#S6.SS2.SSS4.p1.1),[§6\.2\.5](https://arxiv.org/html/2609.28722#S6.SS2.SSS5.p1.1)\. - Zhanget al\.\(2023a\)H\. Zhang, Z\. Yao, L\. Y\. Zhang, S\. Hu, C\. Chen, A\. Liew, and Z\. LiDenial\-of\-service or fine\-grained control: towards flexible model poisoning attacks on federated learning\.InProc\. of the Thirty\-Second Int\. Joint Conf\. on Artif\. Intell\.,pp\. 4567–4575\.Cited by:[§2\.3\.5](https://arxiv.org/html/2609.28722#S2.SS3.SSS5.p1.1),[§2\.3](https://arxiv.org/html/2609.28722#S2.SS3.p1.1),[Table 5](https://arxiv.org/html/2609.28722#S2.T5.5.1.6.1.1.1.1),[§2](https://arxiv.org/html/2609.28722#S2.p1.1)\. - Zhanget al\.\(2021a\)J\. Zhang, B\. Chen, X\. Cheng, H\. T\. T\. Binh, and S\. YuPoisonGAN: generative poisoning attacks against federated learning in edge computing systems\.IEEE Internet of Things J\.8\(5\),pp\. 3310–3322\.Cited by:[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p1.1),[Table 3](https://arxiv.org/html/2609.28722#S2.T3.8.1.4.1.1.2.1),[Table 6](https://arxiv.org/html/2609.28722#S2.T6.5.1.6.1.1.1.1)\. - Zhanget al\.\(2022a\)J\. Zhang, X\. Cheng, C\. Wang, Y\. Wang, Z\. Shi, J\. Jin, A\. Song, W\. Zhao, L\. Wen, and T\. ZhangFedAda: fast\-convergent adaptive federated learning in heterogeneous mobile edge computing environment\.World Wide Web25\(5\),pp\. 1971–1998\.Cited by:[§6\.2\.5](https://arxiv.org/html/2609.28722#S6.SS2.SSS5.p1.1)\. - Zhanget al\.\(2021b\)W\. Zhang, T\. Zhou, Q\. Lu, X\. Wang, C\. Zhu, H\. Sun, Z\. Wang, S\. K\. Lo, and F\. WangDynamic\-fusion\-based federated learning for covid\-19 detection\.IEEE Internet of Things J\.8\(21\),pp\. 15884–15891\.Cited by:[§3\.2\.1](https://arxiv.org/html/2609.28722#S3.SS2.SSS1.p1.1)\. - Zhanget al\.\(2024\)X\. Zhang, S\. Lin, C\. Chen, and X\. ChenMODA: model ownership deprivation attack in asynchronous federated learning\.IEEE Trans\. on Dependable and Secure Comput\.21\(4\),pp\. 4220–4235\.Cited by:[§2\.4\.2](https://arxiv.org/html/2609.28722#S2.SS4.SSS2.p1.1),[Table 6](https://arxiv.org/html/2609.28722#S2.T6.5.1.12.1.1.2.1)\. - Zhanget al\.\(2022b\)Y\. Zhang, C\. Zhang, C\. Zhang, L\. Fan, B\. Zeng, and Q\. YangFederated learning with quantum secure aggregation\.arXiv preprint arXiv:2207\.07444\.Cited by:[§3\.2\.2](https://arxiv.org/html/2609.28722#S3.SS2.SSS2.p2.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.3.2.1.2.1),[§6\.1](https://arxiv.org/html/2609.28722#S6.SS1.p1.1)\. - Zhanget al\.\(2023b\)Y\. Zhang, D\. Zeng, J\. Luo, Z\. Xu, and I\. KingA survey of trustworthy federated learning with perspectives on security, robustness and privacy\.InCompanion Proc\. of the ACM Web Conf\. 2023,pp\. 1167–1176\.Cited by:[§1\.1](https://arxiv.org/html/2609.28722#S1.SS1.p1.1),[§2\.4\.3](https://arxiv.org/html/2609.28722#S2.SS4.SSS3.p1.1),[§4\.1\.2](https://arxiv.org/html/2609.28722#S4.SS1.SSS2.p1.1)\. - Zhanget al\.\(2026\)Y\. Zhang, Y\. Wang, W\. Liu, G\. Han, J\. Cao, and Y\. TianSecure aggregation with verifiability and robustness for privacy\-preserving federated learning\.Knowl\.\-Based Syst\.,pp\. 115310\.Cited by:[§1](https://arxiv.org/html/2609.28722#S1.p1.1),[§3](https://arxiv.org/html/2609.28722#S3.p1.1)\. - Zhanget al\.\(2021c\)Y\. Zhang, Z\. Wang, J\. Cao, R\. Hou, and D\. MengShuffleFL: gradient\-preserving federated learning using trusted execution environment\.InProc\. of the 18th ACM Int\. Conf\. on Comput\. frontiers,pp\. 161–168\.Cited by:[§3\.1](https://arxiv.org/html/2609.28722#S3.SS1.p1.1),[§3\.2\.2](https://arxiv.org/html/2609.28722#S3.SS2.SSS2.p3.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.11.2.1.1.1),[§4\.1\.2](https://arxiv.org/html/2609.28722#S4.SS1.SSS2.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.3.2.1.3.1)\. - Zhang and Li \(2024\)Z\. Zhang and Y\. LiNSPFL: a novel secure and privacy\-preserving federated learning with data integrity auditing\.IEEE Trans\. on Inf\. Forensics and Security\.Cited by:[§2\.4\.1](https://arxiv.org/html/2609.28722#S2.SS4.SSS1.p1.1),[Table 6](https://arxiv.org/html/2609.28722#S2.T6.5.1.10.1.1.1.1),[§4\.1\.2](https://arxiv.org/html/2609.28722#S4.SS1.SSS2.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.3.2.1.3.1)\. - Zhang and Hu \(2023\)Z\. Zhang and R\. HuByzantine\-robust federated learning with variance reduction and differential privacy\.In2023 IEEE Conf\. on Commun\. and Netw\. Secur\. \(CNS\),pp\. 1–9\.Cited by:[§4\.1\.2](https://arxiv.org/html/2609.28722#S4.SS1.SSS2.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.3.2.1.7.1)\. - Zhaoet al\.\(2021\)L\. Zhao, J\. Jiang, B\. Feng, Q\. Wang, C\. Shen, and Q\. LiSear: secure and efficient aggregation for byzantine\-robust federated learning\.IEEE Trans\. on Dependable and Secure Comput\.19\(5\),pp\. 3329–3342\.Cited by:[§3\.1](https://arxiv.org/html/2609.28722#S3.SS1.p1.1),[§3\.2\.2](https://arxiv.org/html/2609.28722#S3.SS2.SSS2.p3.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.11.2.1.1.1)\. - Zhaoet al\.\(2024\)P\. Zhao, F\. Yu, and Z\. WanA huber loss minimization approach to byzantine robust federated learning\.InProc\. of the AAAI Conf\. on Artif\. Intell\.,Vol\.38,pp\. 21806–21814\.Cited by:[§3\.2\.1](https://arxiv.org/html/2609.28722#S3.SS2.SSS1.p1.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.7.2.1.2.1),[§4](https://arxiv.org/html/2609.28722#S4.p1.1)\. - Zhaoet al\.\(2018\)Y\. Zhao, M\. Li, L\. Lai, N\. Suda, D\. Civin, and V\. ChandraFederated learning with non\-iid data\.arXiv preprint arXiv:1806\.00582\.Cited by:[§5\.1](https://arxiv.org/html/2609.28722#S5.SS1.p1.1)\. - Zhouet al\.\(2020\)S\. Zhou, H\. Huang, W\. Chen, P\. Zhou, Z\. Zheng, and S\. GuoPirate: a blockchain\-based secure framework of distributed machine learning in 5g networks\.IEEE Netw\.34\(6\),pp\. 84–91\.Cited by:[§4\.1\.4](https://arxiv.org/html/2609.28722#S4.SS1.SSS4.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.5.2.1.4.1)\. - Zhouet al\.\(2021\)X\. Zhou, M\. Xu, Y\. Wu, and N\. ZhengDeep model poisoning attack on federated learning\.Future Internet13\(3\),pp\. 73\.Cited by:[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p2.1),[§2\.3\.1](https://arxiv.org/html/2609.28722#S2.SS3.SSS1.p3.1),[§2\.3](https://arxiv.org/html/2609.28722#S2.SS3.p1.1),[Table 3](https://arxiv.org/html/2609.28722#S2.T3.8.1.10.1),[§2](https://arxiv.org/html/2609.28722#S2.p1.1)\. - Zhuet al\.\(2023\)C\. Zhu, J\. Zhang, X\. Sun, B\. Chen, and W\. MengADFL: defending backdoor attacks in federated learning via adversarial distillation\.Computers & Security132,pp\. 103366\.Cited by:[§4\.1\.1](https://arxiv.org/html/2609.28722#S4.SS1.SSS1.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.2.2.1.3.1)\. - Zhuet al\.\(2021\)H\. Zhu, R\. Wang, Y\. Jin, K\. Liang, and J\. NingDistributed additive encryption and quantization for privacy\-preserving federated deep learning\.Neurocomputing463,pp\. 309–327\.Cited by:[§1](https://arxiv.org/html/2609.28722#S1.p1.1),[§3\.2\.2](https://arxiv.org/html/2609.28722#S3.SS2.SSS2.p1.1),[Table 8](https://arxiv.org/html/2609.28722#S3.T8.5.1.12.2.1.2.1),[§4\.1\.6](https://arxiv.org/html/2609.28722#S4.SS1.SSS6.p1.1),[Table 10](https://arxiv.org/html/2609.28722#S4.T10.5.1.7.2.1.2.1)\.
相似文章
重新思考联邦学习中可转移对抗攻击与鲁棒防御
本文分析了联邦学习系统中对抗攻击的可转移性,并提出了一种基于对抗训练的防御机制以增强模型鲁棒性。
同质与异构数据分布下联邦学习聚合策略的比较研究
本文对各种联邦学习聚合策略进行了全面的实验比较,分析了它们在homogeneous和heterogeneous数据分布下的性能和效率。
BackDFL:去中心化联邦学习中后门攻击与防御的统一基准
本文介绍了BackDFL,这是一个用于系统评估去中心化联邦学习中后门攻击和防御的统一基准,揭示了当前鲁棒性方法的关键失效模式。
面向模态异质性下的鲁棒联邦多模态图学习
本文提出FedMPO,一种鲁棒的联邦多模态图学习方法,通过拓扑感知的跨模态生成、缺失感知的专家路由和可靠性感知的聚合来解决模态异质性和缺失模态问题,在多个数据集上实现了性能提升。
良性及对抗性客户端异质性下航空发动机预测的鲁棒与个性化联邦学习
本文针对良性及对抗性客户端异质性下的航空发动机剩余使用寿命预测,对联邦学习进行了受控研究,评估了个性化和拜占庭鲁棒聚合方法。研究发现,共享表示个性化缩小了本地与集中式准确率之间的绝大部分差距;使用Krum的鲁棒聚合能有效缓解后门攻击;将两者结合可形成组合防御,在攻击成功率较低的同时,仅付出较小的准确率代价。