Skip to content
Conference

Dual-side Control for Coordinated Attack Detection in Federated Learning

Jul 2026 · International Conference on Control, Decision and Information Technologies · pp. 360-365 · 0 citations · 34 references

Abstract

Federated Learning (FL) enables collaborative model training while preserving data privacy. However, it remains highly vulnerable to poisoning attacks, particularly coordinated label- flipping attacks. In this paper, we propose DualFed, a dual-side defense framework for detecting coordinated poisoning behaviors in FL. DualFed combines client-side adaptive behavioral anomaly detection with a server-side Collective Behavioral Correlation (CBC) mechanism. On the client side, an Adaptive Adversarially Robust Statistics (AARS) mechanism integrates trimmed estimation with Exponential Moving Average (EMA) and Exponential Moving Variance (EMV) to robustly quantify abnormal performance degradation. On the server side, CBC aggregates client anomaly reports over a sliding temporal window to detect coordinated attacks. Once an attack is confirmed, DualFed activates a non-punitive self-recovery mechanism. Under non-IID settings, DualFed achieves benign accuracies exceeding 84.0MNIST, 52.0dataset, while reducing malicious attack accuracy to near zero and outperforming recent defense baselines.

View source

Similar papers

Open access Jul 2026

A Comprehensive Defense Framework Against Poisoning Backdoor Attacks in Federated Learning

This work employs the novel dimensionality reduction technique UMAP and a stringent filtering mechanism to effectively identify and exclude potential malicious participants without relying on traditional noise addition methods and demonstrates that the proposed method maintains high main task accuracy while effectively mitigating backdoor attacks across various attack scenarios.

Chun-I Fan, Hsin-Yen Wang, Tomohiro Morikawa · 0 citations
#federated learning Conference Sep 2026

Robust detection method for adversarial backdoor attacks under federated learning architecture

Under federated learning, single-threshold norm verification cannot effectively distinguish malicious from benign updates with similar norms, resulting in low detection robustness. This paper proposes a robust detection method featuring a two layer "norm verification + directional consistency" filtering mechanism combined with the Isolation Forest algorithm to remove malicious outliers, a weighted adaptive robust aggregation that dynamically allocates weights based on client accuracy and consistency, updates the global model via weighted geometric median, and introduces learning rate decay for stability, and collaborative clean and triggered dual detection sets linking local and global detection to accurately identify and suppress backdoor attacks. Experiments demonstrate near-perfect ROC performance: at a 0.1 false positive rate, the true positive rate reaches approximately 97%, with AUC approaching the theoretical maximum of 1. Under varying malicious client proportions and increasing sample sizes, the method significantly outperforms comparisons in both detection accuracy and false negative rate, fully demonstrating detection robustness.

Mei-Bin Qi · 0 citations
Conference 2026

FedRGD: Risk-Guided Dynamic Defense against Federated Backdoors

FedRGD is a federated risk-guided dynamic defense framework that enables efficient fine-grained protection against backdoor attacks in non-IID environments, and combines feature inconsistency detection with lightweight masking and robust aggregation to achieve both accuracy and efficiency.

Rui-Ying Wang · 0 citations
Open access 2026

SiftFL: Scheduling-Based Robust Backdoor Detection in Federated Learning

Backdoor attacks pose a serious threat to federated learning, particularly when client data are non-IID and the attacker ratio is high. FilterFL is a recent server-side defense that employs two Conditional Generative Adversarial Networks (CGANs) to generate synthetic samples and identify malicious client models without requiring clean server data. However, executing both CGAN stages in every communication round makes the defense robust but computationally expensive. In this paper, we propose SiftFL, a scheduling-based robust backdoor detection method that sifts out malicious client models at a fraction of the original cost. SiftFL decouples the cost of the CGAN stages from the number of communication rounds by executing them periodically rather than every round and complements this schedule with a trust history score that stabilizes client filtering across rounds. This design preserves and, in several settings, improves the robustness of CGAN-based detection while sharply lowering its server-side cost. Experiments using MNIST, CIFAR-10, and GTSRB benchmark dataset show that SiftFL reduces server defense computation by up to 99% while keeping the drop in main accuracy within about 4% in the most challenging non-IID cases compared to the original baseline. At the same time, the attack success rate is reduced by roughly 97–99%, and robustness accuracy improves significantly to 85%, in settings where the original FilterFL becomes unstable. The results indicate that scheduling and trust history make SiftFL a more practical and reliable backdoor detection method under non-IID data distribution and high attacker presence.

Ekhlas Hashem, Muhamad Felemban, Sajjad Mahmood et al. · 0 citations
Preprint Aug 2026

BackDFL: A Unified Benchmark For Backdoor Attacks and Defenses In Decentralized Federated Learning

BackDFL is presented, a unified benchmark for systematically evaluating DFL under realistic and adaptive backdoor attacks, and demonstrates that both state-of-the-art Byzantine-robust DFL methods and adapted FL backdoor defenses fail under modest malicious participation rates, especially in heterogeneous settings.

M. Bouchiha, Gregory Blanc, Yu-Fei Han · 0 citations
Preprint Aug 2026

TOFD: Target-Oriented Feature Decoupling against Poisoning Attacks in Split Federated Learning

Split Federated Learning (SFL) facilitates privacy-preserving collaborative training with reduced client-side overhead. However, its split architecture introduces unique attack surfaces, rendering it vulnerable to diverse poisoning attacks. Most existing defenses fail to exploit the split paradigm, limiting their ability to detect and contain malicious behaviors at an early stage. To bridge this gap, we propose Target-Oriented Feature Decoupling (TOFD), a unified framework that jointly enables proactive detection and robust optimization against a wide range of poisoning attacks. TOFD operates in three stages: (1) Target Inference, which identifies potential attack targets by refining class-wise safe zones via class-specific Margin Perturbation (MP); (2) Sample Purification, which adaptively filters poisoned smashed data using thresholds calibrated through cross-class min-max normalization of MP; and (3) Decoupling Optimization, which leverages an adversarial guidance model to capture attack-induced patterns and decouple their influence during optimization, thereby suppressing residual adversarial effects. We provide theoretical guarantees for the convergence of TOFD. Extensive experiments on five datasets demonstrate that TOFD consistently outperforms state-of-the-art defenses under diverse attack scenarios, achieving superior robustness with low computational overhead suitable for practical deployment.

Yu-Han Xie, Jing Huang, Chen Lyu · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.