MARS: A Malignity-Aware Backdoor Defense in Federated Learning

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Wan, Wei, Ning, Yuxuan, Huang, Zhicong, Hong, Cheng, Hu, Shengshan, Zhou, Ziqi, Zhang, Yechao, Zhu, Tianqing, Zhou, Wanlei, Zhang, Leo Yu
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908556991660032
author Wan, Wei
Ning, Yuxuan
Huang, Zhicong
Hong, Cheng
Hu, Shengshan
Zhou, Ziqi
Zhang, Yechao
Zhu, Tianqing
Zhou, Wanlei
Zhang, Leo Yu
author_facet Wan, Wei
Ning, Yuxuan
Huang, Zhicong
Hong, Cheng
Hu, Shengshan
Zhou, Ziqi
Zhang, Yechao
Zhu, Tianqing
Zhou, Wanlei
Zhang, Leo Yu
contents Federated Learning (FL) is a distributed paradigm aimed at protecting participant data privacy by exchanging model parameters to achieve high-quality model training. However, this distributed nature also makes FL highly vulnerable to backdoor attacks. Notably, the recently proposed state-of-the-art (SOTA) attack, 3DFed (SP2023), uses an indicator mechanism to determine whether the backdoor models have been accepted by the defender and adaptively optimizes backdoor models, rendering existing defenses ineffective. In this paper, we first reveal that the failure of existing defenses lies in the employment of empirical statistical measures that are loosely coupled with backdoor attacks. Motivated by this, we propose a Malignity-Aware backdooR defenSe (MARS) that leverages backdoor energy (BE) to indicate the malicious extent of each neuron. To amplify malignity, we further extract the most prominent BE values from each model to form a concentrated backdoor energy (CBE). Finally, a novel Wasserstein distance-based clustering method is introduced to effectively identify backdoor models. Extensive experiments demonstrate that MARS can defend against SOTA backdoor attacks and significantly outperforms existing defenses.
format Preprint
id arxiv_https___arxiv_org_abs_2509_20383
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle MARS: A Malignity-Aware Backdoor Defense in Federated Learning
Wan, Wei
Ning, Yuxuan
Huang, Zhicong
Hong, Cheng
Hu, Shengshan
Zhou, Ziqi
Zhang, Yechao
Zhu, Tianqing
Zhou, Wanlei
Zhang, Leo Yu
Cryptography and Security
Artificial Intelligence
Federated Learning (FL) is a distributed paradigm aimed at protecting participant data privacy by exchanging model parameters to achieve high-quality model training. However, this distributed nature also makes FL highly vulnerable to backdoor attacks. Notably, the recently proposed state-of-the-art (SOTA) attack, 3DFed (SP2023), uses an indicator mechanism to determine whether the backdoor models have been accepted by the defender and adaptively optimizes backdoor models, rendering existing defenses ineffective. In this paper, we first reveal that the failure of existing defenses lies in the employment of empirical statistical measures that are loosely coupled with backdoor attacks. Motivated by this, we propose a Malignity-Aware backdooR defenSe (MARS) that leverages backdoor energy (BE) to indicate the malicious extent of each neuron. To amplify malignity, we further extract the most prominent BE values from each model to form a concentrated backdoor energy (CBE). Finally, a novel Wasserstein distance-based clustering method is introduced to effectively identify backdoor models. Extensive experiments demonstrate that MARS can defend against SOTA backdoor attacks and significantly outperforms existing defenses.
title MARS: A Malignity-Aware Backdoor Defense in Federated Learning
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2509.20383