FeatShield: Isolating Malicious Feature Extractors for Backdoor-Robust Federated Learning
Zhou Tan, De Li, Yirui Huang, Jia-Li Yin, Ximeng Liu
Abstract
Federated learning remains vulnerable to backdoor attacks through malicious parameter updates, with existing defenses limited by homogeneous data assumptions or reliance on gradient anomaly detection. We reveal that FedAvg's critical flaw lies in malicious feature extractor propagation: aggregating poisoned extractors degrades defense accuracy to <70% across five benchmarks, while benign extractors with poisoned headers retain an average of 89.36% defense accuracy. Therefore, we propose FeatShield, a feature-space isolation framework that prevents backdoor propagation via non-aggregated local extractors trained on clean client data. FeatShield introduces 1) variance-aware alignment, adaptively balancing client-specific features and global consistency using local variance metrics, and 2) adversarial feature synthesis, generating non-linear synthetic features via GAN to enhance the global prediction header's generalization on main tasks. Extensive experiments on eight real-world datasets show that FeatShield achieves the best defense performance. For instance, under heterogeneous data (Dirichlet β=0.5) and strong attacks (50% malicious clients), FeatShield achieves 99.26-99.89% defense accuracy and main task accuracy exceeding FedAvg by 1.32-5.70%, demonstrating its superior resistance to backdoor attacks without sacrificing the benign performance.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 3302e798-e611-4050-b96a-2c50e0ebb74dCited by top-tier papers2
- DoBlock: Blocking Malicious Association Propagation for Backdoor-Robust Federated Learning Under Domain SkewZhou Tan, De Li, Yirui Huang, Duanshu Fang et al.AAAI 2026
- Modulation-Based Backdoors: Leveraging Amplitude and Frequency Patterns to Attack Speaker RecognitionHanbo Cai, Pengcheng Zhang, Yan Xiao, De Li et al.AAAI 2026
Related papers
- FedPurify: Knowledge-Preserving Backdoor Defense with Data-Free Purification in Federated LearningBaolu Xue, Hanyuan Zheng, Tianxing Man, Bing ChenKDD 2026
- FLShield: A Validation Based Federated Learning Framework to Defend Against Poisoning AttacksEhsanul Kabir, Zeyu Song, Md. Rafi Ur Rashid, Shagufta MehnazS&P 2024 · 32 citations
- Detecting Backdoor Attacks in Federated Learning via Direction Alignment InspectionJiahao Xu, Zikai Zhang, Rui HuCVPR 2025
- FilterFL: Knowledge Filtering-based Data-Free Backdoor Defense for Federated LearningYanxin Yang, Ming Hu, Xiaofei Xie, Yue Cao et al.CCS 2025
- A Needle in a Haystack: Defending Federated Learning Backdoor Attacks via Orthogonal Subnetwork PruningZihan Ma, Guangchi Liu, Xiangyu Xu, Shaofeng Li et al.INFOCOM 2026
