Defense against local model poisoning attacks to byzantine-robust federated learning