arXiv:2607.26933cs.CRcs.AI2026-07

通过对比一致性和对齐检测,提升联邦学习抗后门攻击能力。

Defending Against Backdoor Attacks via Alignment Checking in Model-Contrastive Federated Learning

  • 在本地优化中引入模型对比正则,增强正常更新的方向与幅度一致性。
  • 分两阶段防御:先强化正常更新,再通过历史对齐度筛选异常更新。
  • 适合关注边缘计算中安全联邦学习的研究者和工程师。

联邦学习在边缘计算场景下因分布式特性易受后门攻击。现有防御方法效果有限,因其忽视了由统计异质性引起的良性本地更新偏差以及后门攻击的隐蔽性。为此,我们提出FedDAB,一种两阶段方法,结合局部对比正则化与对齐检查,以抵御后门攻击。第一阶段,在本地目标函数中引入新型模型对比项,提升良性更新在方向与幅度上的一致性;第二阶段,采用对齐检查策略,从整体方向和参数层面评估每轮本地更新与历史信息的对齐程度,剔除存在异常对齐模式的更新,避免其参与全局聚合。理论证明了FedDAB的鲁棒性,收敛速率为$/mathcal{O}(1/T)$。大量实验表明,该方法在多种后门攻击场景下均优于现有防御方法。

原文摘要 · Abstract (English)

Federated Learning (FL) is vulnerable to backdoor attacks because of its distributed nature in edge computing scenarios. Existing defense methods show limited efficacy as they overlook the deviations among benign local updates caused by statistical heterogeneity and the stealthiness of backdoor attacks. To tackle these issues, we propose FedDAB, a two-phase method that combines local contrastive regularization with alignment checking, to defend against backdoor attacks. In the first phase, FedDAB introduces a novel model-contrastive term into the local objective to enhance direction and magnitude consistency among benign updates. In the second phase, FedDAB employs an alignment checking strategy to evaluate each local update in terms of overall-direction alignment and parameter-level alignment with historical information, excluding updates that exhibit abnormal alignment patterns from global aggregation. We theoretically prove FedDAB's robustness with a convergence rate of $\mathcal{O}(1/T)$. Extensive experiments show that FedDAB outperforms existing defense methods against backdoor attacks.

联邦学习后门攻击对抗防御

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。