GAISSF / D1 / D1-CTL-04

Federated Learning Poisoning Prevention

Objective

Protect multi-party models from malicious clients.

Control / requirement

Gradient anomaly detection + robust aggregation.

Business impact

Failure to implement this control creates risk of global model poisoning via compromised federated learning clients, with estimated financial exposure of $2M-$10M for multi-organisation federated models.

Validation approach

Test ID: D1-CTL-04-VTS-001 Test Type: Hybrid (Automated + Manual Review) Test Design: Simulate malicious client submitting poisoned gradients in federated learning simulation environment Execution Steps: 1. Deploy GAISSF™ federated learning test harness 2. Configure with 10 client nodes, 1 malicious 3. Execute: pytest tests/d1_model_integrity/test_federated_poisoning.py -v # oda3-gaissf-vts 4. Review output for detection_rate and aggregation_audit Pass Criteria: malicious_gradient_detection_rate >= 95%; poisoned_gradients_excluded_from_aggregation = True Independent Verification: Auditor re-runs federated learning simulation with GAISSF™ test harness using auditor-controlled attack parameters.

Expected evidence

Not separately specified in the available source.

Mapping and source

Not separately specified in the available source.

Implementation guidance

Translate the requirement into system-specific procedures, responsible roles, technical configurations and review conditions. Retain evidence showing both design and operating performance. Where the source provides no separate implementation instruction, do not infer that a single technical mechanism is sufficient.

Assessment considerations

  • Confirm scope and applicability.
  • Inspect control design and responsible ownership.
  • Test representative operation and adverse conditions where appropriate.
  • Evaluate evidence provenance, completeness and contradictory evidence.
  • Record limitations and notably absent outcomes.