MONZA: A Score System for Malicious Clients Detection
DOI:
https://doi.org/10.5753/jisa.2026.7098Keywords:
Federated Learning, GDPR, non-IID, malicious clients, attacksAbstract
Federated Learning (FL) is a machine learning training method that uses a collaborative model for training across a diverse set of clients, while preserving data privacy in accordance with the General Data Protection Regulation (GDPR) for clients' data. The classification and similarity within many clients can become an issue, often leading to decreased model accuracy and slower convergence, or reducing the number of parameters to the point of not learning anything during aggregation. However, the presence of non-IID data and malicious clients poses significant challenges to the significance of generalization models and distribution data. Malicious clients can perform poisoning attacks by sending harmful model updates that degrade the performance of the global model. This article introduces MONZA, a scoring system designed to detect and exclude malicious clients in FL environments. In a scenario where clients can also engage in various attacks, including model poisoning and data poisoning, this can lead to incorrect training. The proposed method uses cosine similarity to calculate client scores. It employs L2 normalization to identify biased models; in some cases, the similarity is not sufficient to classify a client, effectively filtering out malicious participants before aggregation and implementing a penalty with a quarentine method. Our evaluation shows that MONZA achieves an accuracy of 54.5% in a scenario with 30% malicious clients, while zPROBE (i.e., existing resilient methods) only reached an accuracy of 50%. Furthermore, MONZA reduces the simulation execution time by 66% and the computational effort to 83 MFLOP/s compared to zPROBE, which demonstrates to be a more efficient and resilient method. These results confirm that MONZA maintains the integrity of the model, making a security aggregation while minimizing resource consumption in malicious FL settings.
Downloads
References
Ariffin, A., Zaki, F., Hanif, H., and Anuar, N. B. (2025). Adversarial attack and defence of federated learning-based network traffic classification in edge computing environment. Computer Networks, page 111739. DOI: 10.1016/j.comnet.2025.111739.
Barros, A., Veiga, R., Morais, R., Rosário, D., and Cerqueira, E. (2024). Mesfla: Model efficiency through selective federated learning algorithm. Journal of Internet Services and Applications, 15(1):495-507. DOI: 10.5753/jisa.2024.4044.
Cao, X., Zhang, Z., Jia, J., and Gong, N. Z. (2022). Flcert: Provably secure federated learning against poisoning attacks. IEEE Transactions on Information Forensics and Security, 17:3691-3705. DOI: 10.1109/tifs.2022.3212174.
de Souza, A. M., Maciel, F., da Costa, J. B., Bittencourt, L. F., Cerqueira, E., Loureiro, A. A., and Villas, L. A. (2024). Adaptive client selection with personalization for communication efficient federated learning. Ad Hoc Networks, 157:103462. DOI: 10.1016/j.adhoc.2024.103462.
Ghodsi, Z., Javaheripi, M., Sheybani, N., Zhang, X., Huang, K., and Koushanfar, F. (2023). zprobe: Zero peek robustness checks for federated learning. In Proceedings of the IEEE/CVF International Conference on Computer Vision, pages 4860-4870. DOI: 10.48550/arXiv.2206.12100.
Gu, C., Cui, X., Zhu, X., and Hu, D. (2023). Fl2dp: Privacy-preserving federated learning via differential privacy for artificial iot. IEEE Transactions on Industrial Informatics, 20(4):5100-5111. DOI: 10.1109/tii.2023.3331726.
Guo, Y. (2023). A review of machine learning-based zero-day attack detection: Challenges and future directions. Computer communications, 198:175-185. DOI: 10.1016/j.comcom.2022.11.001.
Hasan, N., Alam, M. G. R., Ripon, S. H., Pham, P. H., and Hassan, M. M. (2025). An autoencoder-based confederated clustering leveraging a robust model fusion strategy for federated unsupervised learning. Information Fusion, 115:102751. DOI: 10.1016/j.inffus.2024.102751.
Ma, X., Zhu, J., Lin, Z., Chen, S., and Qin, Y. (2022a). A state-of-the-art survey on solving non-iid data in federated learning. Future Generation Computer Systems, 135:244-258. DOI: 10.1016/j.future.2022.05.003.
Ma, Z., Ma, J., Miao, Y., Li, Y., and Deng, R. H. (2022b). Shieldfl: Mitigating model poisoning attacks in privacy-preserving federated learning. IEEE Transactions on Information Forensics and Security, 17:1639-1654. DOI: 10.1109/tifs.2022.3169918.
Rezaei, H., Taheri, R., and Shojafar, M. (2025). Fedllmguard: A federated large language model for anomaly detection in 5g networks. Computer Networks, page 111473. DOI: 10.1016/j.comnet.2025.111473.
Smestad, C. and Li, J. (2023). A systematic literature review on client selection in federated learning. In Proceedings of the 27th International Conference on Evaluation and Assessment in Software Engineering, EASE '23, page 2–11, New York, NY, USA. Association for Computing Machinery. DOI: 10.1145/3593434.3593438.
Song, R., Zhou, L., Lakshminarasimhan, V., Festag, A., and Knoll, A. (2022). Federated Learning Framework Coping with Hierarchical Heterogeneity in Cooperative ITS. In IEEE 25th International Conference on Intelligent Transportation Systems (ITSC). IEEE. DOI: 10.1109/ITSC55140.2022.9922064.
Sun, P., Liu, X., Wang, Z., and Liu, B. (2024). Byzantine-robust decentralized federated learning via dual-domain clustering and trust bootstrapping. In Proceedings of the IEEE/CVF conference on computer vision and pattern recognition, pages 24756-24765. DOI: 10.1109/cvpr52733.2024.02338.
Veiga, R., Morais, R., Bastos, L., Rosário, D., Loureiro, A., and Cerqueira, E. (2025). A resilient and lightweight layer client selection in federated learning. In 2025 21st International Conference on Distributed Computing in Smart Systems and the Internet of Things (DCOSS-IoT), pages 609-616. IEEE. DOI: 10.1109/dcoss-iot65416.2025.00097.
Xia, G., Chen, J., Yu, C., and Ma, J. (2023). Poisoning attacks in federated learning: A survey. Ieee Access, 11:10708-10722. DOI: 10.1109/access.2023.3238823.
Yan, G., Wang, H., Yuan, X., and Li, J. (2023). Defl: defending against model poisoning attacks in federated learning via critical learning periods awareness. In Proceedings of the AAAI Conference on Artificial Intelligence, volume 37, pages 10711-10719. DOI: 10.1609/aaai.v37i9.26271.
Yazdinejad, A., Dehghantanha, A., Karimipour, H., Srivastava, G., and Parizi, R. M. (2024). A robust privacy-preserving federated learning model against model poisoning attacks. IEEE Transactions on Information Forensics and Security, 19:6693-6708. DOI: 10.1109/tifs.2024.3420126.
Ye, M., Fang, X., Du, B., Yuen, P. C., and Tao, D. (2023). Heterogeneous federated learning: State-of-the-art and research challenges. ACM Computing Surveys, 56(3):1-44. DOI: 10.1145/3625558.
Zang, L. and Li, Y. (2024). Detection and mitigation of label-flipping attacks in fl systems with kl divergence. IEEE Internet of Things Journal, 11(19):32221-32233. DOI: 10.1109/jiot.2024.3424188.
Zhang, J., Hua, Y., Wang, H., Song, T., Xue, Z., Ma, R., and Guan, H. (2023). Fedala: Adaptive local aggregation for personalized federated learning. In Proceedings of the AAAI Conference on Artificial Intelligence, volume 37, pages 11237-11244. DOI: 10.1609/aaai.v37i9.26330.
Zhao, K., Wang, L., Yu, F., Zeng, B., and Pang, Z. (2025). Fedmp: A multi-pronged defense algorithm against byzantine poisoning attacks in federated learning. Computer Networks, 257:110990. DOI: 10.1016/j.comnet.2024.110990.
Downloads
Published
How to Cite
Issue
Section
License
Copyright (c) 2026 Journal of Internet Services and Applications

This work is licensed under a Creative Commons Attribution 4.0 International License.

