{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T04:58:42Z","timestamp":1783745922908,"version":"3.55.0"},"reference-count":26,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"the Key Technology Research and Development Program of Zhejiang Province","award":["No.2024C01211"],"award-info":[{"award-number":["No.2024C01211"]}]},{"name":"the Key Technology Research and Development Program of Zhejiang Province","award":["No.2023C03194"],"award-info":[{"award-number":["No.2023C03194"]}]},{"name":"Zhejiang Provincial Natural Science Foundation of China","award":["No.LTGG24F020007"],"award-info":[{"award-number":["No.LTGG24F020007"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecurity"],"abstract":"<jats:title>Abstract<\/jats:title>\n          <jats:p>Federated learning (FL) is a type of distributed machine learning that enables multiple participants to collaboratively build machine learning models without transferring data outside their local devices, thereby ensuring data privacy and security. However, free-riding (FR) attacks pose significant threats by sending false, erroneous, or malicious model updates to the central server, attempting to extract private information from other devices during the federated learning process. This results in privacy leakage and reduced model accuracy. Traditional defenses measures against FR attacks typically employ auditing methods to identify malicious clients, but these methods are ineffective when multiple FR clients collude to inflate each other\u2019s scores mutually. This paper proposes a novel defense method against collusion-based FR attacks. We first design a grouping mechanism based on gradient norm to group clients and then update the groups using an inter-client audit system. Finally, the correlation analysis of all groups is carried out to eliminate the attack group to ensure the security of the training process. This method defends against standard FR attacks and effectively detects attackers in collusion scenarios. Experimental results demonstrate that our method significantly improves the detection of malicious clients and enhances model accuracy by 10\u201320% compared to existing methods. Moreover, the proposed defense mechanism maintains its efficacy even in large-scale client environments, where more than 50% of the clients may be compromised by attackers.<\/jats:p>","DOI":"10.1186\/s42400-025-00366-5","type":"journal-article","created":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T01:02:14Z","timestamp":1756688534000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["A correlation analysis-based federated learning framework for defending against collusion-free-riding attacks"],"prefix":"10.1186","volume":"8","author":[{"given":"MeiTing","family":"Xue","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hao","family":"Zhong","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yukun","family":"Shi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2026-417X","authenticated-orcid":false,"given":"Yan","family":"Zeng","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jilin","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nailiang","family":"Zhao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,9,1]]},"reference":[{"key":"366_CR1","doi-asserted-by":"crossref","unstructured":"Abadi M, Chu A, Goodfellow I, McMahan HB, Mironov I, Talwar K, Zhang L (2016) Deep learning with differential privacy. In: Proceedings of the 2016 ACM SIGSAC conference on computer and communications security, pp 308\u2013318","DOI":"10.1145\/2976749.2978318"},{"key":"366_CR2","doi-asserted-by":"crossref","unstructured":"Andreina S, Marson GA, M\u00f6llering H, Karame G (2021) Baffle: backdoor detection via feedback-based federated learning. In: 2021 IEEE 41st international conference on distributed computing systems (ICDCS). IEEE, pp 852\u2013863","DOI":"10.1109\/ICDCS51616.2021.00086"},{"key":"366_CR3","unstructured":"Blanchard P, El\u00a0Mhamdi EM, Guerraoui R, Stainer J (2017) Machine learning with adversaries: byzantine tolerant gradient descent. Adv Neural Inf Process Syst 30"},{"key":"366_CR4","doi-asserted-by":"crossref","unstructured":"Cao D, Chang S, Lin Z, Liu G, Sun D (2019) Understanding distributed poisoning attack in federated learning. In: 2019 IEEE 25th international conference on parallel and distributed systems (ICPADS). IEEE, pp 233\u2013239","DOI":"10.1109\/ICPADS47876.2019.00042"},{"key":"366_CR5","doi-asserted-by":"crossref","unstructured":"Cretu GF, Stavrou A, Locasto ME, Stolfo SJ, Keromytis AD (2008) Casting out demons: Sanitizing training data for anomaly sensors. In: 2008 IEEE symposium on security and privacy (sp 2008). IEEE, pp 81\u201395","DOI":"10.1109\/SP.2008.11"},{"issue":"10","key":"366_CR6","doi-asserted-by":"publisher","first-page":"6532","DOI":"10.1109\/TII.2019.2945367","volume":"16","author":"M Hao","year":"2019","unstructured":"Hao M, Li H, Luo X, Xu G, Yang H, Liu S (2019) Efficient and privacy-enhanced federated learning for industrial artificial intelligence. IEEE Trans Ind Inf 16(10):6532\u20136542","journal-title":"IEEE Trans Ind Inf"},{"key":"366_CR8","doi-asserted-by":"crossref","unstructured":"Liu J, Li Y, Zhao M, Liu L, Kumar N (2024) Epffl: Enhancing privacy and fairness in federated learning for distributed e-healthcare data sharing services. IEEE Trans Dependable Secure Comput","DOI":"10.1109\/TDSC.2024.3431542"},{"key":"366_CR9","unstructured":"Li D, Wang J (2019) FedMD: Heterogenous federated learning via model distillation. arXiv:1910.03581"},{"issue":"3","key":"366_CR10","doi-asserted-by":"publisher","first-page":"2134","DOI":"10.1109\/TII.2019.2942179","volume":"16","author":"Y Lu","year":"2019","unstructured":"Lu Y, Huang X, Dai Y, Maharjan S, Zhang Y (2019) Differentially private asynchronous federated learning for mobile edge computing in urban informatics. IEEE Trans Ind Inf 16(3):2134\u20132143","journal-title":"IEEE Trans Ind Inf"},{"key":"366_CR11","doi-asserted-by":"crossref","unstructured":"Lu R, Zhang W, He H, Li Q, Zhong X, Yang H, Wang D, Lu S, Guo Y, Wang Z (2024) Two-stage client selection for federated learning against free-riding attack: a multi-armed bandits and auction-based approach. IEEE Internet Things J","DOI":"10.1109\/JIOT.2024.3431555"},{"key":"366_CR12","unstructured":"Lyu L, Yu H, Ma X, Chen C, Sun L, Zhao J, Yang Q, Philip SY (2022) Privacy and robustness in federated learning: attacks and defenses. IEEE Trans Neural Netw Learn Syst"},{"key":"366_CR13","unstructured":"McMahan B, Moore E, Ramage D, Hampson S, Arcas BA (2017) Communication-efficient learning of deep networks from decentralized data. In: Artificial intelligence and statistics. PMLR, pp 1273\u20131282"},{"key":"366_CR14","unstructured":"Paudice A, Mu\u00f1oz-Gonz\u00e1lez L, Gyorgy A, Lupu EC (2018) Detection of adversarial training examples in poisoning attacks through anomaly detection. arXiv:1802.03041"},{"key":"366_CR15","unstructured":"Phuong M, Lampert C (2019) Towards understanding knowledge distillation. In: International conference on machine learning. PMLR, pp 5142\u20135151"},{"issue":"8","key":"366_CR16","doi-asserted-by":"publisher","first-page":"3710","DOI":"10.1109\/TNNLS.2020.3015958","volume":"32","author":"F Sattler","year":"2020","unstructured":"Sattler F, M\u00fcller K-R, Samek W (2020) Clustered federated learning: model-agnostic distributed multitask optimization under privacy constraints. IEEE Trans Neural Netw Learn Syst 32(8):3710\u20133722","journal-title":"IEEE Trans Neural Netw Learn Syst"},{"key":"366_CR17","unstructured":"Shah D, Dube P, Chakraborty S, Verma A (2021) Adversarial training in communication constrained federated learning. arXiv:2103.01319"},{"key":"366_CR18","unstructured":"Wang J (2022) Pass: parameters audit-based secure and fair federated learning scheme against free rider. arXiv:2207.07292"},{"key":"366_CR19","doi-asserted-by":"crossref","unstructured":"Wang B, Li H, Liu X, Guo Y (2023) Frad: free-rider attacks detection mechanism for federated learning in aiot. IEEE Internet of Things J","DOI":"10.1109\/JIOT.2023.3298606"},{"key":"366_CR20","doi-asserted-by":"crossref","unstructured":"Wan W, Hu S, Li M, Lu J, Zhang L, Zhang LY, Jin H (2023) A four-pronged defense against byzantine attacks in federated learning. In: Proceedings of the 31st ACM international conference on multimedia, pp 7394\u20137402","DOI":"10.1145\/3581783.3612474"},{"issue":"3","key":"366_CR21","doi-asserted-by":"publisher","first-page":"2608","DOI":"10.1109\/TII.2022.3172310","volume":"19","author":"X Xiao","year":"2022","unstructured":"Xiao X, Tang Z, Li C, Xiao B, Li K (2022) SCA: Sybil-based collusion attacks of IIoT data poisoning in federated learning. IEEE Trans Ind Inf 19(3):2608\u20132618","journal-title":"IEEE Trans Ind Inf"},{"key":"366_CR22","doi-asserted-by":"crossref","unstructured":"Xu X, Lyu L (2020) A reputation mechanism is all you need: collaborative fairness and adversarial robustness in federated learning. arXiv:2011.10464","DOI":"10.1007\/978-3-030-63076-8_14"},{"key":"366_CR23","unstructured":"Yin D, Chen Y, Kannan R, Bartlett P (2018) Byzantine-robust distributed learning: towards optimal statistical rates. In: International conference on machine learning. PMLR, pp 5650\u20135659"},{"key":"366_CR24","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s11704-021-0598-z","volume":"16","author":"K Zhang","year":"2022","unstructured":"Zhang K, Song X, Zhang C, Yu S (2022) Challenges and future directions of secure federated learning: a survey. Front Comput Sci 16:1\u20138","journal-title":"Front Comput Sci"},{"key":"366_CR25","doi-asserted-by":"crossref","unstructured":"Zhang Z, Li Y (2024) NSPFL: a novel secure and privacy-preserving federated learning with data integrity auditing. IEEE Trans Inf Forensics Sec","DOI":"10.1109\/TIFS.2024.3379852"},{"issue":"11","key":"366_CR26","doi-asserted-by":"publisher","first-page":"10782","DOI":"10.1109\/JIOT.2020.2987958","volume":"7","author":"C Zhou","year":"2020","unstructured":"Zhou C, Fu A, Yu S, Yang W, Wang H, Zhang Y (2020) Privacy-preserving federated learning in fog computing. IEEE Internet Things J 7(11):10782\u201310793","journal-title":"IEEE Internet Things J"},{"key":"366_CR27","unstructured":"Zhu L, Liu Z, Han S (2019) Deep leakage from gradients. Adv Neural Inf Process Syst 32"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-025-00366-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-025-00366-5\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-025-00366-5.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T01:02:23Z","timestamp":1756688543000},"score":1,"resource":{"primary":{"URL":"https:\/\/cybersecurity.springeropen.com\/articles\/10.1186\/s42400-025-00366-5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9,1]]},"references-count":26,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["366"],"URL":"https:\/\/doi.org\/10.1186\/s42400-025-00366-5","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,9,1]]},"assertion":[{"value":"7 November 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"12 January 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"1 September 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no known competing financial interests or personal relationships that could have appeared to influence the work reported in this paper.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"65"}}