Search papers, labs, and topics across Lattice.
This paper introduces R2CFL, a robust reputation-driven framework for Crowdsourced Federated Learning (CrowdFL) that addresses the vulnerabilities of existing reputation mechanisms against stealthy adversaries. By integrating a robust reputation model with a nearest neighbor mixing defense mechanism, R2CFL effectively filters updates during aggregation, preventing adversaries from accumulating trust and influencing the learning process. Experimental results show that R2-NNM outperforms state-of-the-art defenses against adaptive attackers while maintaining accurate reputation scoring that reflects true performance metrics of the defenses used.
Stealthy attackers can no longer manipulate federated learning systems unnoticed, thanks to a novel reputation model that ties trust to actual performance in R2CFL.
Crowdsourced Federated Learning (CrowdFL) extends traditional federated learning by enabling open and heterogeneous participation through a crowdsourcing paradigm. In this setting, reputation-driven incentive mechanisms are commonly employed to guide worker selection and enhance trustworthiness. While such approaches improve participant reliability, existing frameworks largely overlook the quantification of their robustness against stealthy adversaries, particularly those capable of evading standard detection mechanisms. To fill this gap, this paper proposes R2CFL, a robust reputation-driven CrowdFL framework. R2CFL introduces a robust reputation model coupled with a nearest neighbor mixing (R2-NNM) defense mechanism that links reputation evolution with the filtering of updates during aggregation. The proposed mechanism prevents stealthy attackers from gradually accumulating trust and influencing future tasks. Experimental results demonstrate that R2-NNM matches or surpasses state-of-the-art Byzantine-robust and backdoor defense mechanisms against adaptive attackers. Furthermore, when integrated with existing detect-and-filter defenses, the proposed reputation model faithfully captures the statistical robustness of the underlying defense by producing reputation scores that closely reflect its true positive and false positive characteristics.