Proposing an invariant aggregator to defend against backdoor attacks in federated learning by redirecting aggregated updates to invariant directions.