Defending against adversarial attacks in federated learning
A computer-implemented method, a computer program product, and a computer system for defending against adversarial attacks in federated learning. In the federated learning comprising an aggregator and parties, the aggregator receives weights sent from the respective parties. The aggregator computes values of a performance metric for weight arrays obtained by the respective parties, using a validation dataset. The aggregator ranks the values of the performance metric in a list. The aggregator recursively splits the list in half until one or more adversary updates of the weights are isolated. The aggregator excludes one or more parties that send the one or more adversary updates from participating in a current round of training in the federated learning.