{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/sparsefed-mitigating-model-poisoning-attacks","title":"SparseFed: Mitigating Model Poisoning Attacks in Federated Learning with Sparsification","arxiv_id":"2112.06274","date":"2021-12-12","proceeding":null,"authors":["Ashwinee Panda","Saeed Mahloujifar","Arjun N. Bhagoji","Supriyo Chakraborty","Prateek Mittal"],"abstract":"Federated learning is inherently vulnerable to model poisoning attacks because its decentralized nature allows attackers to participate with compromised devices. In model poisoning attacks, the attacker reduces the model's performance on targeted sub-tasks (e.g. classifying planes as birds) by uploading \"poisoned\" updates. In this report we introduce \\algoname{}, a novel defense that uses global top-k update sparsification and device-level gradient clipping to mitigate model poisoning attacks. We propose a theoretical framework for analyzing the robustness of defenses against poisoning attacks, and provide robustness and convergence analysis of our algorithm. To validate its empirical efficacy we conduct an open-source evaluation at scale across multiple benchmark datasets for computer vision and federated learning.","url_abs":"https://arxiv.org/abs/2112.06274v1","url_pdf":"https://arxiv.org/pdf/2112.06274v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"sparsefed-mitigating-model-poisoning-attacks","repo_url":"https://github.com/sparsefed/sparsefed","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":0,"framework":"pytorch","reach":null}],"tasks":[{"task_slug":"federated-learning","task_name":"Federated Learning"},{"task_slug":"model-poisoning","task_name":"Model Poisoning"}],"methods":[{"method_slug":"gradient-clipping","method_name":"Gradient Clipping"}],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=2112.06274","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2112.06274"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/sparsefed/sparsefed","reach":null}],"summary":{"ran_draft_wrong":2,"ran_fixture":2},"by_repo_kind":{"official":{"samples":4,"ran":4,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":4,"samples":[{"code_sha256_prefix":"e8bae5965a304e39","entry":"compute_loss_mixup","repo":"sparsefed/sparsefed","repo_kind":"official","path":"CommEfficient/cv_train.py","file_url":"https://github.com/sparsefed/sparsefed/blob/HEAD/CommEfficient/cv_train.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"OUTPUT_MISDECLARED","metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"e8bae5965a304e39"}},{"code_sha256_prefix":"dee9116372ec569f","entry":"criterion_helper","repo":"sparsefed/sparsefed","repo_kind":"official","path":"CommEfficient/cv_train.py","file_url":"https://github.com/sparsefed/sparsefed/blob/HEAD/CommEfficient/cv_train.py","link_basis":"first_harvest_node","language":"python","status":"ran_fixture","verification_level":1,"contract_check":"RAISES","metamorphic_tier":"invariant","behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"dee9116372ec569f"}},{"code_sha256_prefix":"62225dd8920c913d","entry":"mixup_criterion","repo":"sparsefed/sparsefed","repo_kind":"official","path":"CommEfficient/cv_train.py","file_url":"https://github.com/sparsefed/sparsefed/blob/HEAD/CommEfficient/cv_train.py","link_basis":"first_harvest_node","language":"python","status":"ran_fixture","verification_level":1,"contract_check":"RAISES","metamorphic_tier":"invariant","behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"62225dd8920c913d"}},{"code_sha256_prefix":"906c2ca68bdb0d2d","entry":"split_results","repo":"sparsefed/sparsefed","repo_kind":"official","path":"CommEfficient/fed_aggregator.py","file_url":"https://github.com/sparsefed/sparsefed/blob/HEAD/CommEfficient/fed_aggregator.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"MISDECLARED","metamorphic_tier":"well_formed","behaviour_fingerprint":true,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"906c2ca68bdb0d2d"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}