Lune

INFOCOM2026顶会

A Needle in a Haystack: Defending Federated Learning Backdoor Attacks via Orthogonal Subnetwork Pruning

Zihan Ma, Guangchi Liu, Xiangyu Xu, Shaofeng Li, Zhen Ling, Junzhou Luo

2026年份

摘要

Federated Learning (FL) enables collaborative model training without exposing private data, but remains vulnerable to backdoor attacks, where malicious clients inject backdoor updates into the global model. Detecting such attacks is challenging due to the noisy and heterogeneous nature of benign updates obscuring backdoor patterns. To this end, we propose Peeler, a lightweight backdoor defense framework that accurately identifies backdoor by dynamically isolating normal model weights orthogonal to malicious ones within client-submitted updates. Peeler employs circuit discovery to prune subnetworks associated with the main task, and utilizes gradient-based layer selection to eliminate layers that are non-critical for backdoor objective adaptation. The remaining parameters are then flattened into feature vectors, enabling distance-based anomaly detection across client-submitted model updates. To validate Peeler, we perform a Neural Tangent Kernel (NTK)-based analysis, showing that Peeler effectively retains backdoor-relevant weights while filtering out benign ones. Experiments across diverse scenarios and recent defense benchmarks demonstrate the superiority of Peeler. Peeler reduces the Attack Success Rate (ASR) to 2.79% on average, significantly outperforming the prior state-of-the-art defense (11.48% for FLAME). Even under highly heterogeneous data distributions (with Dirichlet parameter α = 0.3), Peeler achieves an ASR of 10.4%, compared to the prior state-of-the-art defense (27.3% for FLTracer).

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

lune papers get 9d6d77cd-37e3-4928-8462-e039e4d84a38

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖