Do We Really Need to Design New Byzantine-robust Aggregation Rules?
In federated learning, Byzantine clients launching poisoning attacks can severely degrade the robustness of existing aggregation rules. To address this, we propose FoundationFL—a framework that preserves standard robust aggregators (e.g., Trimmed-mean, Median) without modifying their logic; instead, the server generates synthetic model updates, which are jointly aggregated with clients’ local updates. We provide the first theoretical proof that enhancing input quality alone—without designing new aggregation rules—significantly improves Byzantine resilience of classical robust aggregators. FoundationFL guarantees convergence under Byzantine threats and empirically demonstrates substantial improvements in poisoning resistance across multiple real-world datasets, while maintaining high model accuracy and low communication overhead. The framework thus achieves strong effectiveness, generalizability, and practicality.