<p>Federated learning (FL) enables distributed collaborative model training without centralizing client data, but its decentralized architecture introduces significant vulnerabilities to backdoor attacks. Malicious clients can embed triggers that compromise the global model’s behavior on specific inputs while maintaining normal performance on clean data. However, existing Byzantine-tolerant defense mechanisms struggle to effectively distinguish malicious updates from benign ones in realistic non-IID environments. This paper presents <b>FedMVC</b>, a two-stage backdoor defense framework for <b>Fed</b>erated Learning that combines <b>M</b>ulti-feature <b>V</b>ariational Autoencoders with <b>C</b>lustering to proactively detect and remove malicious client updates before aggregation. The server-side VAE learns compact latent representations of client updates, while clustering applied to the multi-dimensional feature space allows robust discrimination between benign and malicious clusters. We evaluate FedMVC on MNIST, CIFAR-10, and IMDb under both standard backdoor attacks (2<InlineEquation ID="IEq1"> <EquationSource Format="TEX">\(\times \)</EquationSource> <EquationSource Format="MATHML"><math> <mo>×</mo> </math></EquationSource> </InlineEquation>2 pixel-block, 10% random-noise) and stronger attacks. Across all settings, FedMVC outperforms existing defenses, substantially reducing the attack success rate while maintaining clean accuracy.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

FedMVC: defense against backdoor attacks in federated learning using multi-feature variational autoencoders and clustering

  • Peter Shaojui Wang,
  • Kanokporn Techapatiphandee,
  • Desalegn Aweke Wako

摘要

Federated learning (FL) enables distributed collaborative model training without centralizing client data, but its decentralized architecture introduces significant vulnerabilities to backdoor attacks. Malicious clients can embed triggers that compromise the global model’s behavior on specific inputs while maintaining normal performance on clean data. However, existing Byzantine-tolerant defense mechanisms struggle to effectively distinguish malicious updates from benign ones in realistic non-IID environments. This paper presents FedMVC, a two-stage backdoor defense framework for Federated Learning that combines Multi-feature Variational Autoencoders with Clustering to proactively detect and remove malicious client updates before aggregation. The server-side VAE learns compact latent representations of client updates, while clustering applied to the multi-dimensional feature space allows robust discrimination between benign and malicious clusters. We evaluate FedMVC on MNIST, CIFAR-10, and IMDb under both standard backdoor attacks (2 \(\times \) × 2 pixel-block, 10% random-noise) and stronger attacks. Across all settings, FedMVC outperforms existing defenses, substantially reducing the attack success rate while maintaining clean accuracy.