Defending Against Backdoor Attacks via Alignment Checking in Model-Contrastive Federated Learning
Hongliang Zhang, Zhongyuan Yu, Guijuan Wang, Tianqing He, Wenshuo Ma, Xiaosong Zhang, Jiguo Yu
cs.CR, cs.AI, cs.LG
Submitted: 2026-07-29
License: http://creativecommons.org/licenses/by/4.0/
The gist: Federated Learning (FL) is vulnerable to backdoor attacks because of its distributed nature in edge computing scenarios.
Terminology
Abstract
Federated Learning (FL) is vulnerable to backdoor attacks because of its distributed nature in edge computing scenarios. Existing defense methods show limited efficacy as they overlook the deviations among benign local updates caused by statistical heterogeneity and the stealthiness of backdoor attacks. To tackle these issues, we propose FedDAB, a two-phase method that combines local contrastive regularization with alignment checking, to defend against backdoor attacks. In the first phase, FedDAB introduces a novel model-contrastive term into the local objective to enhance direction and magnitude consistency among benign updates. In the second phase, FedDAB employs an alignment checking strategy to evaluate each local update in terms of overall-direction alignment and parameter-level alignment with historical information, excluding updates that exhibit abnormal alignment patterns from global aggregation. We theoretically prove FedDAB's robustness with a convergence rate of O(1/T). Extensive experiments show that FedDAB outperforms existing defense methods against backdoor attacks.
Sources
- Compare Where It Matters: Using Layer-Wise Regularization To Improve Federated Learning on Heterogeneous Data
- BadNets: Identifying Vulnerabilities in the Machine Learning Model Supply Chain
- Fashion-MNIST: a Novel Image Dataset for Benchmarking Machine Learning Algorithms
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs