SecureSplit: Mitigating Backdoor Attacks in Split Learning

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Dou, Zhihao, Cui, Dongfei, Wang, Weida, Gao, Anjun, Quan, Yueyang, Ma, Mengyao, Vo, Viet, Bai, Guangdong, Liu, Zhuqing, Fang, Minghong
Natura: Preprint
Pubblicazione: 2026
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866908784919576576
author Dou, Zhihao
Cui, Dongfei
Wang, Weida
Gao, Anjun
Quan, Yueyang
Ma, Mengyao
Vo, Viet
Bai, Guangdong
Liu, Zhuqing
Fang, Minghong
author_facet Dou, Zhihao
Cui, Dongfei
Wang, Weida
Gao, Anjun
Quan, Yueyang
Ma, Mengyao
Vo, Viet
Bai, Guangdong
Liu, Zhuqing
Fang, Minghong
contents Split Learning (SL) offers a framework for collaborative model training that respects data privacy by allowing participants to share the same dataset while maintaining distinct feature sets. However, SL is susceptible to backdoor attacks, in which malicious clients subtly alter their embeddings to insert hidden triggers that compromise the final trained model. To address this vulnerability, we introduce SecureSplit, a defense mechanism tailored to SL. SecureSplit applies a dimensionality transformation strategy to accentuate subtle differences between benign and poisoned embeddings, facilitating their separation. With this enhanced distinction, we develop an adaptive filtering approach that uses a majority-based voting scheme to remove contaminated embeddings while preserving clean ones. Rigorous experiments across four datasets (CIFAR-10, MNIST, CINIC-10, and ImageNette), five backdoor attack scenarios, and seven alternative defenses confirm the effectiveness of SecureSplit under various challenging conditions.
format Preprint
id arxiv_https___arxiv_org_abs_2601_14054
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle SecureSplit: Mitigating Backdoor Attacks in Split Learning
Dou, Zhihao
Cui, Dongfei
Wang, Weida
Gao, Anjun
Quan, Yueyang
Ma, Mengyao
Vo, Viet
Bai, Guangdong
Liu, Zhuqing
Fang, Minghong
Cryptography and Security
Distributed, Parallel, and Cluster Computing
Machine Learning
Split Learning (SL) offers a framework for collaborative model training that respects data privacy by allowing participants to share the same dataset while maintaining distinct feature sets. However, SL is susceptible to backdoor attacks, in which malicious clients subtly alter their embeddings to insert hidden triggers that compromise the final trained model. To address this vulnerability, we introduce SecureSplit, a defense mechanism tailored to SL. SecureSplit applies a dimensionality transformation strategy to accentuate subtle differences between benign and poisoned embeddings, facilitating their separation. With this enhanced distinction, we develop an adaptive filtering approach that uses a majority-based voting scheme to remove contaminated embeddings while preserving clean ones. Rigorous experiments across four datasets (CIFAR-10, MNIST, CINIC-10, and ImageNette), five backdoor attack scenarios, and seven alternative defenses confirm the effectiveness of SecureSplit under various challenging conditions.
title SecureSplit: Mitigating Backdoor Attacks in Split Learning
topic Cryptography and Security
Distributed, Parallel, and Cluster Computing
Machine Learning
url https://arxiv.org/abs/2601.14054