Federated Learning (FL) enables collaborative training among multiple data owners without direct sharing of users’ local data, which not only protects user privacy but also enhances model performance. However, due to the invisibility of local model training processes to the aggregation server, FL is vulnerable to Byzantine attacks and backdoor attacks initiated by adversaries. Backdoor attacks are highly covert and difficult to detect, thus posing significant threats to model security. Current backdoor attack defense mechanisms frequently fail to adequately account for the sophisticated capabilities of adversaries and the heterogeneous nature of data distributions encountered in practical deployment environments. Conventional defense approaches relying on singular evaluation metrics exhibit notable limitations when confronting highly self-adaptive adversarial attacks, with their defensive efficacy being particularly compromised under non-independent and identically distributed (Non-IID) data conditions. To overcome these limitations, we present a novel multi-metric cascading defense framework against backdoor attacks in federated learning systems. The proposed methodology systematically integrates five complementary yet mutually constraining evaluation metrics that collectively capture different aspects of model behavior. Through layer-wise feature extraction from distributed local models and adaptive threshold determination via rigorous statistical hypothesis testing, our framework achieves robust detection of both static and adaptive backdoor attacks. Comprehensive experimental evaluations confirm that the proposed solution maintains detection efficacy against sophisticated adversarial strategies while preserving the baseline accuracy of the global model.
Paper
Full text
A Defense Scheme of Backdoor Attacks for Federated Learning Based on Multi-Index Cascading
OpenAlex · Privacy-Preserving Technologies in Data · 2025
Abstract
Federated Learning (FL) enables collaborative training among multiple data owners without direct sharing of users’ local data, which not only protects user privacy but also enhances model performance. However, due to the invisibility of local model training processes to the aggregation server, FL is vulnerable to Byzantine attacks and backdoor attacks initiated by adversaries. Backdoor attacks are highly covert and difficult to detect, thus posing significant threats to model security. Current backdoor attack defense mechanisms frequently fail to adequately account for the sophisticated capabilities of adversaries and the heterogeneous nature of data distributions encountered in practical deployment environments. Conventional defense approaches relying on singular evaluation metrics exhibit notable limitations when confronting highly self-adaptive adversarial attacks, with their defensive efficacy being particularly compromised under non-independent and identically distributed (Non-IID) data conditions. To overcome these limitations, we present a novel multi-metric cascading defense framework against backdoor attacks in federated learning systems. The proposed methodology systematically integrates five complementary yet mutually constraining evaluation metrics that collectively capture different aspects of model behavior. Through layer-wise feature extraction from distributed local models and adaptive threshold determination via rigorous statistical hypothesis testing, our framework achieves robust detection of both static and adaptive backdoor attacks. Comprehensive experimental evaluations confirm that the proposed solution maintains detection efficacy against sophisticated adversarial strategies while preserving the baseline accuracy of the global model.