Aug 2026· Proceedings of the 32nd ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.2· pp. 5891-5902· 0 citations· 16 references
Abstract
Federated Learning (FL) facilitates distributed training while preserving privacy, yet remains highly vulnerable to backdoor attacks. Existing defenses primarily address these threats via robust aggregation, which reduces the influence of malicious contributions (e.g., pruning, reweighting), or through detection-based filtering that discards anomalous updates prior to aggregation. Nevertheless, existing defenses primarily suppress or discard malicious updates, inevitably sacrificing task-relevant knowledge and leading to reduced clean-task accuracy. To this end, we propose FedPurify, a framework that performs post-training data-free purification to remove malicious backdoors while preserving task-relevant knowledge. Specifically, following global convergence without loss of task-relevant knowledge, FedPurify proposes a fully data-free sample synthesis scheme to generate diverse and representative samples from the converged global model, thereby inherently preserving client privacy in FL. Building upon these synthetic samples, FedPurify further leverages data-free trigger inversion to effectively expose latent backdoor behaviors. Finally, FedPurify combines contrastive feature alignment with knowledge-preserving self-distillation to remove backdoor effects while preserving benign task performance. Extensive experiments verify that FedPurify effectively removes backdoors from the global model with negligible impact on clean performance, outperforming existing defense methods.
Federated Learning (FL) inherently preserves privacy but remains highly vulnerable to backdoor attacks due to its open participation architecture. Existing defenses face two fundamental limitations: first, screening-based aggregation strategies prove ineffective against advanced cross-round attacks where adversaries progressively poison model parameters through multi-round collaboration; second, mitigation techniques often cause significant accuracy degradation due to the deep entanglement between backdoor and primary task parameters. To address these challenges, we propose Fed-CBE, a novel client-side defense algorithm that eliminates backdoors through three synergistic mechanisms: 1) periodic alternating layer resetting disrupts deep parameters to dismantle cross-round backdoor accumulation; 2) indiscriminate forgetting employs entropy maximization on non-ground-truth classes to decouple backdoor associations without prior trigger knowledge; and 3) knowledge distillation with historical local models restores primary task performance. Extensive evaluations on three benchmark datasets and model architectures demonstrate that Fed-CBE achieves highly competitive robustness, limiting attack success rates to near-zero levels in most settings and keeping them exceptionally low even under high malicious-client ratios without compromising primary task performance, significantly outperforming existing defenses.
Chun-Hai Li, Yun-Hui Shen, Ming Xie et al.· IEEE Transactions on Informa...· 0 citations
This work proposes CAEBA (Conditional AutoEncoder Backdoor Attack), a dynamic hidden backdoor framework that uses a conditional autoencoder to generate target-aware and visually stealthy triggers while progressively implanting the backdoor through federated optimization.
Federated Learning (FL) has emerged as a leading paradigm for privacy-preserving machine learning, yet the distributed nature of FL introduces unique security challenges, notably the threat of backdoor attacks. However, existing attack strategies face a critical limitation: reliance on end-to-end supervision creates a task-divergence that produces detectable model updates, while the use of fixed triggers is poorly aligned with FL’s evolving global model, leading to limited persistence. To address this limitation, we propose Spa, a novel framework for stealthy and persistent backdoors. Instead of creating a conflicting secondary task, Spa leverages feature-space alignment to seamlessly integrate backdoor features into the primary collaborative objective, thus ensuring stealth. Furthermore, to overcome the fixed-trigger challenge, Spa introduces an adversarial dynamic trigger optimization that mines the current global model for intrinsic vulnerabilities. This creates an adaptive trigger that co-evolves with the learning process, ensuring both efficacy and persistence. Extensive experiments demonstrate that Spa achieves high attack success rates (nearly 100%) with minimal impact on model utility, maintains robustness under data heterogeneity, and exhibits persistence (remains effective around 900 FL rounds after stop attacking), outperforming conventional techniques. Our results highlight the importance of further investigation into this new class of emerging threats and emphasize the need for advanced, feature-level defense techniques.
Chengcheng Zhu, Ye Li, Bosen Rao et al.· IEEE Transactions on Informa...· 0 citations
FedRGD is a federated risk-guided dynamic defense framework that enables efficient fine-grained protection against backdoor attacks in non-IID environments, and combines feature inconsistency detection with lightweight masking and robust aggregation to achieve both accuracy and efficiency.
Rui-Ying Wang· Poster Volume 0008 The 2026...· 0 citations
This work employs the novel dimensionality reduction technique UMAP and a stringent filtering mechanism to effectively identify and exclude potential malicious participants without relying on traditional noise addition methods and demonstrates that the proposed method maintains high main task accuracy while effectively mitigating backdoor attacks across various attack scenarios.
This article proposes a novel adaptive obfuscation mechanism, coined FedAdOb, to protect private data without yielding original model performances, and utilizes passport-based adaptive obfuscation to ensure data privacy in both horizontal and vertical federated learning settings.
Hanlin Gu, Jiahuan Luo, Yan Kang et al.· IEEE Transactions on Pattern...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.