A Needle in a Haystack: Defending Federated Learning Backdoor Attacks via Orthogonal Subnetwork Pruning
Zihan Ma, Guangchi Liu, Xiangyu Xu, Shaofeng Li, Zhen Ling, Junzhou Luo
Abstract
Federated Learning (FL) enables collaborative model training without exposing private data, but remains vulnerable to backdoor attacks, where malicious clients inject backdoor updates into the global model. Detecting such attacks is challenging due to the noisy and heterogeneous nature of benign updates obscuring backdoor patterns. To this end, we propose Peeler, a lightweight backdoor defense framework that accurately identifies backdoor by dynamically isolating normal model weights orthogonal to malicious ones within client-submitted updates. Peeler employs circuit discovery to prune subnetworks associated with the main task, and utilizes gradient-based layer selection to eliminate layers that are non-critical for backdoor objective adaptation. The remaining parameters are then flattened into feature vectors, enabling distance-based anomaly detection across client-submitted model updates. To validate Peeler, we perform a Neural Tangent Kernel (NTK)-based analysis, showing that Peeler effectively retains backdoor-relevant weights while filtering out benign ones. Experiments across diverse scenarios and recent defense benchmarks demonstrate the superiority of Peeler. Peeler reduces the Attack Success Rate (ASR) to 2.79% on average, significantly outperforming the prior state-of-the-art defense (11.48% for FLAME). Even under highly heterogeneous data distributions (with Dirichlet parameter α = 0.3), Peeler achieves an ASR of 10.4%, compared to the prior state-of-the-art defense (27.3% for FLTracer).
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 9d6d77cd-37e3-4928-8462-e039e4d84a38Related papers
- FLAME: Taming Backdoors in Federated LearningThien Duc Nguyen, Phillip Rieger, Huili Chen, Hossein Yalame et al.USENIX Security 2022
- On the Vulnerability of Backdoor Defenses for Federated LearningPei Fang, Jinghui ChenAAAI 2023 · 66 citations
- Defending against Backdoors in Federated Learning with Robust Learning RateMustafa Safa Özdayi, Murat Kantarcioglu, Yulia R. GelAAAI 2021 · 250 citations
- SABRE-FL: Selective and Accurate Backdoor Rejection for Federated Prompt LearningMomin Ahmad Khan, Yasra Chandio, Fatima M. AnwarICLR 2026 · 2 citations
- 3DFed: Adaptive and Extensible Framework for Covert Backdoor Attack in Federated LearningHaoyang Li, Qingqing Ye, Haibo Hu, Jin Li et al.S&P 2023
