SPMC: Self-Purifying Federated Backdoor Defense via Margin Contribution
Wenwen He, Wenke Huang, Bin Yang, Shukan Liu, Mang Ye
Abstract
Federated Learning (FL) enables collaborative training with privacy preservation but is vulnerable to backdoor attacks, where malicious clients degrade model performance on targeted inputs. These attacks exploit FL decentralized nature, while existing defenses, based on isolated behaviors and fixed rules, can be bypassed by adaptive attackers. To address these limitations, we propose SPMC, a marginal collaboration defense mechanism that leverages intrinsic consistency across clients to estimate inter-client marginal contributions. This allows the system to dynamically reduce the influence of clients whose behavior deviates from the collaborative norm, thus maintaining robustness even as the number of attackers changes. In addition to overcoming proxydependent purification's weaknesses, we introduce a self-purification process that locally adjusts suspicious gradients. By aligning them with margin-based model updates, we mitigate the effect of local poisoning. Together, these two modules significantly improve the adaptability and resilience of FL systems, both at the client and server levels. Experimental results on a variety of classification benchmarks demonstrate that SPMC achieves strong defense performance against sophisticated backdoor attacks without sacrificing accuracy on benign tasks. The code is posted at: https://github.com/WenddHe0119/SPMC .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers3
- Batman: Benign Knowledge Alignment Through Malicious Null Space in Federated Backdoor AttackWenwen He, Wenke Huang, Yiyang Fang, Wenjie Qu et al.CVPR 2026
- Prototype-guided Bilateral Alignment Multimodal Federated LearningTianchi Liao, Lele Fu, Sheng Huang, Qing Hu et al.ICML 2026
- Coupled Trigger Optimization and Vulnerable Parameter Alignment for Persistent Backdoor Attacks on Federated Learningzhixuan ma, Haichang Gao, Shangwen Li, Ping Wang et al.ICML 2026
Builds on25
- Fair Resource Allocation in Federated LearningTian Li, Maziar Sanjabi, Ahmad Beirami, Virginia SmithICLR 2020 · 971 citations
- Prompt-aligned Gradient for Prompt TuningBeier Zhu, Yulei Niu, Yucheng Han, Yue Wu et al.ICCV 2023 · 475 citations
- Gradient Matching for Domain GeneralizationYuge Shi, Jeffrey Seely, Philip H. S. Torr, Siddharth Narayanaswamy et al.ICLR 2022 · 358 citations
- Learn from Others and Be Yourself in Heterogeneous Federated LearningWenke Huang, Mang Ye, Bo DuCVPR 2022 · 254 citations
- Defending against Backdoors in Federated Learning with Robust Learning RateMustafa Safa Özdayi, Murat Kantarcioglu, Yulia R. GelAAAI 2021 · 250 citations
Related papers
- FedDefender: Client-Side Attack-Tolerant Federated LearningSungwon Park, Sungwon Han, Fangzhao Wu, Sundong Kim et al.KDD 2023 · 26 citations
- Sibai: A Few-Shot Meta-Classifier for Poisoning Detection in Federated LearningMelanie Gotz, Torsten Krauß, Alexandra DmitrienkoICCV 2025
- FedPurify: Knowledge-Preserving Backdoor Defense with Data-Free Purification in Federated LearningBaolu Xue, Hanyuan Zheng, Tianxing Man, Bing ChenKDD 2026
- FLAME: Taming Backdoors in Federated LearningThien Duc Nguyen, Phillip Rieger, Huili Chen, Hossein Yalame et al.USENIX Security 2022
- Eliminate Distance Differences Induced by Backdoor Attacks: Layer-Selective Training and Clipping to Mask Backdoor ModelsXuzeng Li, Tao Zhang, Xiangyun Tang, JIACHENG WANG et al.CVPR 2026
