Federated Learning (FL) enables collaborativemodel training without exposing raw data, yet remains vulnerable to malicious clients injecting poisoned datasets. Existing defenses are typically reactive (operating during training) or supervised (requiring prior knowledge of attack types)—assumptions that rarely hold in open-ended IoT deployments. We propose WaSA, a fully unsupervised, offline framework for malicious client detection. Before training, each client transmits a single, privacy-preserving spectral summary of its data to the server. A denoising autoencoder, trained solely on clean auxiliary data, scores clients based on their deviation from the learned benign manifold, identifying corruptions regardless of the attack type. WaSA requires no attack labels, generalizes to unseen anomalies, and introduces a Boltzmann sampling strategy for client selection that smoothly interpolates between hard exclusion and standard aggregation. Experiments on MNIST, CIFAR-10, and CIFAR- 100 under diverse attack scenarios (up to 90% malicious clients) demonstrate consistent improvements over supervised baselines and robust aggregation methods, with negligible communication overhead.

WASA: Wavelet Scattering Autoencoders for Unsupervised Offline Detection of Malicious Clients in Federated Learning / Licciardi, A.. - ELETTRONICO. - (2026). (IEEE International Conference on Omni-layer Intelligent Systems (COINS) 2026 Bologna 7 - 9 Settembre 2026).

WASA: Wavelet Scattering Autoencoders for Unsupervised Offline Detection of Malicious Clients in Federated Learning

Alessandro Licciardi
2026

Abstract

Federated Learning (FL) enables collaborativemodel training without exposing raw data, yet remains vulnerable to malicious clients injecting poisoned datasets. Existing defenses are typically reactive (operating during training) or supervised (requiring prior knowledge of attack types)—assumptions that rarely hold in open-ended IoT deployments. We propose WaSA, a fully unsupervised, offline framework for malicious client detection. Before training, each client transmits a single, privacy-preserving spectral summary of its data to the server. A denoising autoencoder, trained solely on clean auxiliary data, scores clients based on their deviation from the learned benign manifold, identifying corruptions regardless of the attack type. WaSA requires no attack labels, generalizes to unseen anomalies, and introduces a Boltzmann sampling strategy for client selection that smoothly interpolates between hard exclusion and standard aggregation. Experiments on MNIST, CIFAR-10, and CIFAR- 100 under diverse attack scenarios (up to 90% malicious clients) demonstrate consistent improvements over supervised baselines and robust aggregation methods, with negligible communication overhead.
File in questo prodotto:
File Dimensione Formato  
paper_8653-3.pdf

accesso riservato

Tipologia: 2a Post-print versione editoriale / Version of Record
Licenza: Non Pubblico - Accesso privato/ristretto
Dimensione 349.88 kB
Formato Adobe PDF
349.88 kB Adobe PDF   Visualizza/Apri   Richiedi una copia
Pubblicazioni consigliate

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11583/3013914