Jul 2026· International Conference on Control, Decision and Information Technologies· pp. 360-365· 0 citations· 34 references
Abstract
Federated Learning (FL) enables collaborative model training while preserving data privacy. However, it remains highly vulnerable to poisoning attacks, particularly coordinated label- flipping attacks. In this paper, we propose DualFed, a dual-side defense framework for detecting coordinated poisoning behaviors in FL. DualFed combines client-side adaptive behavioral anomaly detection with a server-side Collective Behavioral Correlation (CBC) mechanism. On the client side, an Adaptive Adversarially Robust Statistics (AARS) mechanism integrates trimmed estimation with Exponential Moving Average (EMA) and Exponential Moving Variance (EMV) to robustly quantify abnormal performance degradation. On the server side, CBC aggregates client anomaly reports over a sliding temporal window to detect coordinated attacks. Once an attack is confirmed, DualFed activates a non-punitive self-recovery mechanism. Under non-IID settings, DualFed achieves benign accuracies exceeding 84.0MNIST, 52.0dataset, while reducing malicious attack accuracy to near zero and outperforming recent defense baselines.
This work employs the novel dimensionality reduction technique UMAP and a stringent filtering mechanism to effectively identify and exclude potential malicious participants without relying on traditional noise addition methods and demonstrates that the proposed method maintains high main task accuracy while effectively mitigating backdoor attacks across various attack scenarios.
Under federated learning, single-threshold norm verification cannot effectively distinguish malicious from benign updates with similar norms, resulting in low detection robustness. This paper proposes a robust detection method featuring a two layer "norm verification + directional consistency" filtering mechanism combined with the Isolation Forest algorithm to remove malicious outliers, a weighted adaptive robust aggregation that dynamically allocates weights based on client accuracy and consistency, updates the global model via weighted geometric median, and introduces learning rate decay for stability, and collaborative clean and triggered dual detection sets linking local and global detection to accurately identify and suppress backdoor attacks. Experiments demonstrate near-perfect ROC performance: at a 0.1 false positive rate, the true positive rate reaches approximately 97%, with AUC approaching the theoretical maximum of 1. Under varying malicious client proportions and increasing sample sizes, the method significantly outperforms comparisons in both detection accuracy and false negative rate, fully demonstrating detection robustness.
Mei-Bin Qi· International Conference on...· 0 citations
FedRGD is a federated risk-guided dynamic defense framework that enables efficient fine-grained protection against backdoor attacks in non-IID environments, and combines feature inconsistency detection with lightweight masking and robust aggregation to achieve both accuracy and efficiency.
Rui-Ying Wang· Poster Volume 0008 The 2026...· 0 citations
Backdoor attacks pose a serious threat to federated learning, particularly when client data are non-IID and the attacker ratio is high. FilterFL is a recent server-side defense that employs two Conditional Generative Adversarial Networks (CGANs) to generate synthetic samples and identify malicious client models without requiring clean server data. However, executing both CGAN stages in every communication round makes the defense robust but computationally expensive. In this paper, we propose SiftFL, a scheduling-based robust backdoor detection method that sifts out malicious client models at a fraction of the original cost. SiftFL decouples the cost of the CGAN stages from the number of communication rounds by executing them periodically rather than every round and complements this schedule with a trust history score that stabilizes client filtering across rounds. This design preserves and, in several settings, improves the robustness of CGAN-based detection while sharply lowering its server-side cost. Experiments using MNIST, CIFAR-10, and GTSRB benchmark dataset show that SiftFL reduces server defense computation by up to 99% while keeping the drop in main accuracy within about 4% in the most challenging non-IID cases compared to the original baseline. At the same time, the attack success rate is reduced by roughly 97–99%, and robustness accuracy improves significantly to 85%, in settings where the original FilterFL becomes unstable. The results indicate that scheduling and trust history make SiftFL a more practical and reliable backdoor detection method under non-IID data distribution and high attacker presence.
BackDFL is presented, a unified benchmark for systematically evaluating DFL under realistic and adaptive backdoor attacks, and demonstrates that both state-of-the-art Byzantine-robust DFL methods and adapted FL backdoor defenses fail under modest malicious participation rates, especially in heterogeneous settings.
M. Bouchiha, Gregory Blanc, Yu-Fei Han· 0 citations
Split Federated Learning (SFL) facilitates privacy-preserving collaborative training with reduced client-side overhead. However, its split architecture introduces unique attack surfaces, rendering it vulnerable to diverse poisoning attacks. Most existing defenses fail to exploit the split paradigm, limiting their ability to detect and contain malicious behaviors at an early stage. To bridge this gap, we propose Target-Oriented Feature Decoupling (TOFD), a unified framework that jointly enables proactive detection and robust optimization against a wide range of poisoning attacks. TOFD operates in three stages: (1) Target Inference, which identifies potential attack targets by refining class-wise safe zones via class-specific Margin Perturbation (MP); (2) Sample Purification, which adaptively filters poisoned smashed data using thresholds calibrated through cross-class min-max normalization of MP; and (3) Decoupling Optimization, which leverages an adversarial guidance model to capture attack-induced patterns and decouple their influence during optimization, thereby suppressing residual adversarial effects. We provide theoretical guarantees for the convergence of TOFD. Extensive experiments on five datasets demonstrate that TOFD consistently outperforms state-of-the-art defenses under diverse attack scenarios, achieving superior robustness with low computational overhead suitable for practical deployment.
Yu-Han Xie, Jing Huang, Chen Lyu· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.