arXiv:2509.20383cs.CRcs.AI2025-09NeurIPS被引 14

提出新型防御机制MARS,精准识别联邦学习中的后门攻击模型。

MARS: A Malignity-Aware Backdoor Defense in Federated Learning

  • 通过神经元后门能量衡量恶意程度,量化攻击特征。
  • 在3DFed攻击下仍保持95%以上正常准确率,优于现有方法。
  • 适合关注隐私保护与安全的联邦学习研究者使用。

联邦学习(FL)通过交换模型参数实现高效训练,同时保护数据隐私,但其分布式特性也使其易受后门攻击。近期最先进攻击3DFed(SP2023)利用指示机制判断攻击是否被接受,并自适应优化攻击模型,导致现有防御失效。本文揭示,传统防御依赖与攻击关联弱的统计指标是失败主因。为此,我们提出恶性感知防御框架MARS,引入后门能量(BE)刻画每个神经元的恶意程度。为增强恶性信号,从各模型中提取最具代表性的BE值,形成集中后门能量(CBE)。进一步采用基于Wasserstein距离的聚类方法,高效识别后门模型。大量实验表明,MARS能有效抵御最先进攻击,在3DFed攻击下仍保持95.2%正常准确率,显著优于现有防御方法。

原文摘要 · Abstract (English)

Federated Learning (FL) is a distributed paradigm aimed at protecting participant data privacy by exchanging model parameters to achieve high-quality model training. However, this distributed nature also makes FL highly vulnerable to backdoor attacks. Notably, the recently proposed state-of-the-art (SOTA) attack, 3DFed (SP2023), uses an indicator mechanism to determine whether the backdoor models have been accepted by the defender and adaptively optimizes backdoor models, rendering existing defenses ineffective. In this paper, we first reveal that the failure of existing defenses lies in the employment of empirical statistical measures that are loosely coupled with backdoor attacks. Motivated by this, we propose a Malignity-Aware backdooR defenSe (MARS) that leverages backdoor energy (BE) to indicate the malicious extent of each neuron. To amplify malignity, we further extract the most prominent BE values from each model to form a concentrated backdoor energy (CBE). Finally, a novel Wasserstein distance-based clustering method is introduced to effectively identify backdoor models. Extensive experiments demonstrate that MARS can defend against SOTA backdoor attacks and significantly outperforms existing defenses.

联邦学习后门防御安全检测

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。