Runtime Backdoor Detection for Federated Learning via Representational Dissimilarity Analysis

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Zhang, Xiyue, Xue, Xiaoyong, Du, Xiaoning, Xie, Xiaofei, Liu, Yang, Sun, Meng
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866916645260230656
author Zhang, Xiyue
Xue, Xiaoyong
Du, Xiaoning
Xie, Xiaofei
Liu, Yang
Sun, Meng
author_facet Zhang, Xiyue
Xue, Xiaoyong
Du, Xiaoning
Xie, Xiaofei
Liu, Yang
Sun, Meng
contents Federated learning (FL), as a powerful learning paradigm, trains a shared model by aggregating model updates from distributed clients. However, the decoupling of model learning from local data makes FL highly vulnerable to backdoor attacks, where a single compromised client can poison the shared model. While recent progress has been made in backdoor detection, existing methods face challenges with detection accuracy and runtime effectiveness, particularly when dealing with complex model architectures. In this work, we propose a novel approach to detecting malicious clients in an accurate, stable, and efficient manner. Our method utilizes a sampling-based network representation method to quantify dissimilarities between clients, identifying model deviations caused by backdoor injections. We also propose an iterative algorithm to progressively detect and exclude malicious clients as outliers based on these dissimilarity measurements. Evaluations across a range of benchmark tasks demonstrate that our approach outperforms state-of-the-art methods in detection accuracy and defense effectiveness. When deployed for runtime protection, our approach effectively eliminates backdoor injections with marginal overheads.
format Preprint
id arxiv_https___arxiv_org_abs_2503_04473
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Runtime Backdoor Detection for Federated Learning via Representational Dissimilarity Analysis
Zhang, Xiyue
Xue, Xiaoyong
Du, Xiaoning
Xie, Xiaofei
Liu, Yang
Sun, Meng
Cryptography and Security
Federated learning (FL), as a powerful learning paradigm, trains a shared model by aggregating model updates from distributed clients. However, the decoupling of model learning from local data makes FL highly vulnerable to backdoor attacks, where a single compromised client can poison the shared model. While recent progress has been made in backdoor detection, existing methods face challenges with detection accuracy and runtime effectiveness, particularly when dealing with complex model architectures. In this work, we propose a novel approach to detecting malicious clients in an accurate, stable, and efficient manner. Our method utilizes a sampling-based network representation method to quantify dissimilarities between clients, identifying model deviations caused by backdoor injections. We also propose an iterative algorithm to progressively detect and exclude malicious clients as outliers based on these dissimilarity measurements. Evaluations across a range of benchmark tasks demonstrate that our approach outperforms state-of-the-art methods in detection accuracy and defense effectiveness. When deployed for runtime protection, our approach effectively eliminates backdoor injections with marginal overheads.
title Runtime Backdoor Detection for Federated Learning via Representational Dissimilarity Analysis
topic Cryptography and Security
url https://arxiv.org/abs/2503.04473