A Needle in a Haystack: Defending Federated Learning Backdoor Attacks via Orthogonal Subnetwork Pruning
Zihan Ma, Guangchi Liu, Xiangyu Xu, Shaofeng Li, Zhen Ling, Junzhou Luo
摘要
Federated Learning (FL) enables collaborative model training without exposing private data, but remains vulnerable to backdoor attacks, where malicious clients inject backdoor updates into the global model. Detecting such attacks is challenging due to the noisy and heterogeneous nature of benign updates obscuring backdoor patterns. To this end, we propose Peeler, a lightweight backdoor defense framework that accurately identifies backdoor by dynamically isolating normal model weights orthogonal to malicious ones within client-submitted updates. Peeler employs circuit discovery to prune subnetworks associated with the main task, and utilizes gradient-based layer selection to eliminate layers that are non-critical for backdoor objective adaptation. The remaining parameters are then flattened into feature vectors, enabling distance-based anomaly detection across client-submitted model updates. To validate Peeler, we perform a Neural Tangent Kernel (NTK)-based analysis, showing that Peeler effectively retains backdoor-relevant weights while filtering out benign ones. Experiments across diverse scenarios and recent defense benchmarks demonstrate the superiority of Peeler. Peeler reduces the Attack Success Rate (ASR) to 2.79% on average, significantly outperforming the prior state-of-the-art defense (11.48% for FLAME). Even under highly heterogeneous data distributions (with Dirichlet parameter α = 0.3), Peeler achieves an ASR of 10.4%, compared to the prior state-of-the-art defense (27.3% for FLTracer).
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- FLAME: Taming Backdoors in Federated LearningThien Duc Nguyen, Phillip Rieger, Huili Chen, Hossein Yalame 等USENIX Security 2022
- On the Vulnerability of Backdoor Defenses for Federated LearningPei Fang, Jinghui ChenAAAI 2023 · 被引用 66 次
- Defending against Backdoors in Federated Learning with Robust Learning RateMustafa Safa Özdayi, Murat Kantarcioglu, Yulia R. GelAAAI 2021 · 被引用 250 次
- SABRE-FL: Selective and Accurate Backdoor Rejection for Federated Prompt LearningMomin Ahmad Khan, Yasra Chandio, Fatima M. AnwarICLR 2026 · 被引用 2 次
- 3DFed: Adaptive and Extensible Framework for Covert Backdoor Attack in Federated LearningHaoyang Li, Qingqing Ye, Haibo Hu, Jin Li 等S&P 2023
