SpaceTime: A Deep Similarity Defense Against Poisoning Attacks in Federated Learning
Abstract
1. Introduction
2. Related Work
3. Assumptions and Attack Model
3.1. Poison Attacks Shift Towards Multiple or Distributed Attackers
3.2. Multiple or Distributed Attackers Create Clustered Signatures
3.3. Poisoning Defenses for Federated IoT IDS Are a Spacetime Problem
3.4. Attack Model
4. Proposed SpaceTime Defense Model
4.1. Defense Architecture
4.2. Similarity Metrics
4.2.1. Cosine Similarity
4.2.2. Triangle Area Similarity (TS)
4.2.3. Sector Area Similarity (SS)
4.2.4. Area Similarity FoolsGold (ASF)
4.2.5. Jaccard Distance (JD)
4.3. Defense Methodology
| Algorithm 1: SpaceTime Deep Similarity Defense Algorithm |
![]() |
- Let =
- Let = 3
- 1 =
- 2 =
- 3 =
- 4 =
- 5 =
5. Implementation Details
5.1. Dataset
5.2. Attack Methodology
5.3. IDS Architecture and Experiment Setup
6. Evaluation Results
6.1. Evaluation Metrics
- Convergence: Convergence is defined as the model’s loss per epoch (or training round), convergence reflects the model’s ability to learn under varying attack rates. A consistent downward trend in loss indicates that the model has reached its learning capacity. This metric also helps diagnose overfitting or underfitting when comparing training and validation losses. In the context of adversarial attacks, convergence reflects the resilience of the model. We define poison resilience as successful convergence even with 50% of the participants being attackers.
- Precision: We calculate Precision separately for honest clients and poison attackers. Client precision measures the proportion of honest clients correctly identified, while attacker precision measures the proportion of attackers correctly classified. High precision in both categories is critical, as misclassifying honest clients or failing to exclude attackers degrades federated learning performance. This metric helps explain the strengths and weaknesses of each defense mechanism.
- Poison Rate: The poison rate quantifies the percentage of model updates originating from attackers. It differs from the attack rate, which refers to the proportion of attackers in the system. A robust defense may result in a high attack rate but a low poison rate by effectively excluding malicious contributions. Poison rate directly reflects the extent to which an attack influences model performance.
6.2. IDS Baseline Evaluation
6.3. SpaceTime Model Convergence
6.4. Poisoning Attacks
6.5. Model Convergence
6.6. Poison Rate
6.7. Poisoning Defense
7. Discussions and Limitations
8. Conclusions
Author Contributions
Funding
Institutional Review Board Statement
Informed Consent Statement
Data Availability Statement
Conflicts of Interest
References
- Konečný, J.; McMahan, H.B.; Ramage, D.; Richtárik, P. Federated Optimization: Distributed Machine Learning for On-Device Intelligence. arXiv 2016, arXiv:1610.02527. [Google Scholar] [CrossRef] [Scilit]
- Saadat, H.; Aboumadi, A.; Mohamed, A.; Erbad, A.; Guizani, M. Hierarchical Federated Learning for Collaborative IDS in IoT Applications. In Proceedings of the 2021 10th Mediterranean Conference on Embedded Computing (MECO), Budva, Montenegro, 7–10 June 2021; pp. 1–6. [Google Scholar] [CrossRef] [Scilit]
- Anthi, E.; Williams, L.; Slowinska, M.; Theodorakopoulos, G.; Burnap, P. A Supervised Intrusion Detection System for Smart Home IoT Devices. IEEE Internet Things J. 2019, 6, 9042–9053. [Google Scholar] [CrossRef] [Scilit]
- Chen, X.; Liu, C.; Li, B.; Lu, K.; Song, D. Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning. arXiv 2017, arXiv:1712.05526. [Google Scholar] [CrossRef] [Scilit]
- Baracaldo, N.; Chen, B.; Ludwig, H.; Safavi, J.A. Mitigating Poisoning Attacks on Machine Learning Models: A Data Provenance Based Approach. In Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security, Dallas, TX, USA, 3 November 2017; pp. 103–110. [Google Scholar] [CrossRef] [Scilit]
- Liu, X.; Li, H.; Xu, G.; Chen, Z.; Huang, X.; Lu, R. Privacy-Enhanced Federated Learning Against Poisoning Adversaries. IEEE Trans. Inf. Forensics Secur. 2021, 16, 4574–4588. [Google Scholar] [CrossRef] [Scilit]
- Singh, A.K.; Blanco-Justicia, A.; Domingo-Ferrer, J.; Sanchez, D.; Rebollo-Monedero, D. Fair Detection of Poisoning Attacks in Federated Learning. In Proceedings of the 2020 IEEE 32nd International Conference on Tools with Artificial Intelligence (ICTAI), Baltimore, MD, USA, 9–11 November 2020; pp. 224–229. [Google Scholar] [CrossRef] [Scilit]
- Sun, G.; Cong, Y.; Dong, J.; Wang, Q.; Lyu, L.; Liu, J. Data Poisoning Attacks on Federated Machine Learning. IEEE Internet Things J. 2021, 14, 1–8. [Google Scholar] [CrossRef] [Scilit]
- Zhang, J.; Chen, B.; Cheng, X.; Binh, H.T.T.; Yu, S. PoisonGAN: Generative Poisoning Attacks Against Federated Learning in Edge Computing Systems. IEEE Internet Things J. 2021, 8, 3310–3322. [Google Scholar] [CrossRef] [Scilit]
- Fung, C.; Yoon, C.J.M.; Beschastnikh, I. Mitigating Sybils in Federated Learning Poisoning. arXiv 2018, arXiv:1808.04866. [Google Scholar]
- Lyu, L. Privacy and Robustness in Federated Learning: Attacks and Defenses. 2022. Available online: http://arxiv.org/abs/2012.06337 (accessed on 4 May 2022).
- Gu, Z.; Shi, J.; Yang, Y.; He, L. Defending against Poisoning Attacks in Federated Learning from a Spatial-temporal Perspective. In Proceedings of the 2023 42nd International Symposium on Reliable Distributed Systems (SRDS), Marrakesh, Morocco, 25–29 September 2023; pp. 25–34, ISSN 2575-8462. [Google Scholar]
- Shen, X.; Liu, Y.; Li, F.; Li, C. Privacy-Preserving Federated Learning Against Label-Flipping Attacks on Non-IID Data. IEEE Internet Things J. 2024, 11, 1241–1255. [Google Scholar] [CrossRef] [Scilit]
- Ma, W.; Zhao, Q.; Tian, W. A defense method against multi-label poisoning attacks in federated learning. Sci. Rep. 2025, 15, 26197. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Sharma, A.; Chen, W.; Zhao, J.; Qiu, Q.; Bagchi, S.; Chaterji, S. FLAIR: Defense against Model Poisoning Attack in Federated Learning. In Proceedings of the 2023 ACM Asia Conference on Computer and Communications Security (ASIA CCS’23), Melbourne, Australia, 10–14 July 2023; pp. 553–566. [Google Scholar]
- Lai, Y.C.; Lin, J.Y.; Lin, Y.D.; Hwang, R.H.; Lin, P.C.; Wu, H.K.; Chen, C.K. Two-phase Defense Against Poisoning Attacks on Federated Learning-based Intrusion Detection. Comput. Secur. 2023, 129, 103205. [Google Scholar] [CrossRef] [Scilit]
- Yang, R.; He, H.; Wang, Y.; Qu, Y.; Zhang, W. Dependable federated learning for IoT intrusion detection against poisoning attacks. Comput. Secur. 2023, 132, 103381. [Google Scholar] [CrossRef] [Scilit]
- Ding, Z.; Wang, W.; Li, X.; Wang, X.; Jeon, G.; Zhao, J.; Mu, C. Identifying alternately poisoning attacks in federated learning online using trajectory anomaly detection method. Sci. Rep. 2024, 14. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Zheng, J.; Yuan, X.; Li, K.; Ni, W.; Tovar, E.; Crowcroft, J. A Novel Defense Against Poisoning Attacks on Federated Learning: LayerCAM Augmented with Autoencoder. arXiv 2024, arXiv:2406.02605. [Google Scholar] [CrossRef] [Scilit]
- Liu, Y.; Zhang, H.; Wang, M.; Xie, Q.; Sun, Z. AntidoteFL: Enhancing defense against poisoning attacks in federated learning. Comput. Netw. 2025, 269, 111427. [Google Scholar] [CrossRef] [Scilit]
- Kim, Y.; Yoon, S. Similarity-based Filtering for Defending Against Malicious Clients in Federated Learning. In Proceedings of the 2024 IEEE International Conference on Big Data (BigData), Washington, DC, USA, 15–18 December 2024; pp. 8728–8730, ISSN 2573-2978. [Google Scholar]
- Hammoudeh, Z.; Lowd, D. Simple, Attack-Agnostic Defense Against Targeted Training Set Attacks Using Cosine Similarity. In Proceedings of the International Conference on Machine Learning (ICML) Workshop, Virtual, 18–24 July 2021. [Google Scholar]
- Xie, C.; Huang, K.; Chen, P.Y.; Li, B. DBA: Distributed backdoor attacks against federated learning. In Proceedings of the International Conference on Learning Representations, ICLR 2020, Addis Ababa, Ethiopia, 26–30 April 2020; p. 19. [Google Scholar]
- Heidarian, A.; Dinneen, M.J. A Hybrid Geometric Approach for Measuring Similarity Level Among Documents and Document Clustering. In Proceedings of the 2016 IEEE Second International Conference on Big Data Computing Service and Applications (BigDataService), Oxford, UK, 29 March–1 April 2016; pp. 142–151. [Google Scholar]
- Birchman, B.; Thamilarasu, G. Securing Federated Learning: Enhancing Defense Mechanisms against Poisoning Attacks. In Proceedings of the 2024 33rd International Conference on Computer Communications and Networks (ICCCN), Kailua-Kona, HI, USA, 29–31 July 2024; pp. 1–6. [Google Scholar]
- Fung, C.; Yoon, C.J.M.; Beschastnikh, I. The Limitations of Federated Learning in Sybil Settings. In Proceedings of the 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2020), San Sebastian, Spain, 14–15 October 2020; pp. 301–316. [Google Scholar]
- Blanchard, P.; Mhamdi, E.M.E.; Guerraoui, R.; Stainer, J. Machine Learning with Adversaries: Byzantine Tolerant Gradient Descent. In Proceedings of the 31st International Conference on Neural Information Processing Systems, Long Beach, CA, USA, 4–9 December 2017; p. 11. [Google Scholar]
- Cao, D.; Chang, S.; Lin, Z.; Liu, G.; Sun, D. Understanding Distributed Poisoning Attack in Federated Learning. In Proceedings of the 2019 IEEE 25th International Conference on Parallel and Distributed Systems (ICPADS), Tianjin, China, 4–6 December 2019; pp. 233–239. [Google Scholar] [CrossRef] [Scilit]
- Zhang, J.; Chunpeng, G.; Hu, F.; Chen, B. RobustFL: Robust Federated Learning Against Poisoning Attacks in Industrial IoT Systems. IEEE Trans. Ind. Inform. 2021, 18, 6388–6397. [Google Scholar] [CrossRef] [Scilit]
- Wang, Q.; Peng, R.Q.; Wang, J.Q.; Li, Z.; Qu, H.B. NEWLSTM: An Optimized Long Short-Term Memory Language Model for Sequence Prediction. IEEE Access 2020, 8, 65395–65401. [Google Scholar] [CrossRef] [Scilit]
- Alomari, D.; Anis, F.; Alabdullatif, M.; Aljamaan, H. A Survey on Botnets Attack Detection Utilizing Machine and Deep Learning Models. In Proceedings of the 27th International Conference on Evaluation and Assessment in Software Engineering (EASE’23), New York, NY, USA, 14–16 June 2023; pp. 493–498. [Google Scholar]















| Anomaly-Based IoT IDS | ||
|---|---|---|
| Layer Type | Output Shape | Number of Parameters |
| Dense | (None, 256, 256) | 7680 |
| LSTM | (None, 256, 256) | 525,312 |
| Dense | (None, 256, 512) | 131,584 |
| LSTM | (None, 512) | 2,099,200 |
| Dense | (None, 1024) | 525,312 |
| Dense | (None, 1) | 1025 |
| Total | 3,290,113 | |
| IDS Accuracy Impacts from Various Attacks | ||||
|---|---|---|---|---|
| Attack Rate | Byzantine | Label Flip | Backdoor | DBA |
| 5% | 74.5% | 83.3% | 98.3% | 99% |
| 10% | 64.4% | 78.4% | 98.2% | 93.2% |
| 50% | 59.1% | 64.1% | 97.1% | 89.1% |
| Poison Rate Effects on Accuracy | |||
|---|---|---|---|
| Defense | Attack Rate | Poison Rate | IDS Accuracy |
| FoolsGold | 50 | 33 | 87 |
| Spacetime | 50 | 0 | 96 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2025 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (https://creativecommons.org/licenses/by/4.0/).
Share and Cite
Thamilarasu, G.; Dunham, C. SpaceTime: A Deep Similarity Defense Against Poisoning Attacks in Federated Learning. Big Data Cogn. Comput. 2025, 9, 313. https://doi.org/10.3390/bdcc9120313
Thamilarasu G, Dunham C. SpaceTime: A Deep Similarity Defense Against Poisoning Attacks in Federated Learning. Big Data and Cognitive Computing. 2025; 9(12):313. https://doi.org/10.3390/bdcc9120313
Chicago/Turabian StyleThamilarasu, Geethapriya, and Christian Dunham. 2025. "SpaceTime: A Deep Similarity Defense Against Poisoning Attacks in Federated Learning" Big Data and Cognitive Computing 9, no. 12: 313. https://doi.org/10.3390/bdcc9120313
APA StyleThamilarasu, G., & Dunham, C. (2025). SpaceTime: A Deep Similarity Defense Against Poisoning Attacks in Federated Learning. Big Data and Cognitive Computing, 9(12), 313. https://doi.org/10.3390/bdcc9120313

