发表机构
Kennesaw State University(肯尼索州立大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
针对联邦学习中的隐蔽后门攻击,本文提出FedMAST,利用结构、频谱和历史证据的多轴追踪检测后门,在多种攻击下显著降低ASR并保持高主任务准确率。
AI 中文摘要
联邦学习使得共享模型的分布式训练成为可能,而无需客户端共享其原始数据。然而,其对客户端提交更新完整性的依赖使全局模型面临隐蔽的后门投毒风险。尽管现有防御方法常常检查孤立的证据来源,但受隐蔽约束的攻击能够适应这些信号。在本文中,我们表明此类攻击能够抑制孤立的异常信号,但其投毒更新仍会留下残余的结构痕迹。我们提出FedMAST,一种用于联邦学习中后门检测的联邦多轴结构追踪防御方法。FedMAST使用互补的结构、频谱和历史证据对客户端更新进行评分,然后应用分层过滤和轮级遏制来限制对抗性影响。为了捕获孤立信号可能遗漏的痕迹,FedMAST使用挤压对相干性评分来暴露耦合的特征扭曲,并使用带符号的频谱漂移跟踪来揭示随时间推移的持久方向变化。在六种联邦后门攻击(即Constrain-and-Scale、Neurotoxin、BC-Layers、LGA、DBA和3DFed)中,FedMAST在所有九项评估的攻击-防御比较中均实现了比基线防御更低的ASR。在完整的200轮运行中,其平均ASR为1.51%,同时保持了94.84%的平均主任务准确率。在方法感知的CovertLayers攻击下,FedAvg、MultiKrum、AlignIns和FLAME的全程ASR分别为100.00%、99.67%、99.53%和32.84%。FedMAST在所有评估方法中实现了最低的ASR,将其降至1.53%,同时保持了92.26%的主任务准确率。
英文摘要
Federated learning enables distributed training without requiring clients to share their raw data. However, its reliance on the integrity of the client-submitted updates exposes the global model to stealthy backdoor poisoning. Existing defenses often rely on individual evidence sources, but stealth-constrained attacks can adapt to these signals. Such attacks can suppress anomaly signals they are optimized to evade, yet their poisoned updates still leave residual structural traces. We propose FedMAST, a Federated Multi-Axis Structural Tracing defense for backdoor detection in federated learning. FedMAST scores client updates using complementary structural, spectral, and historical evidence and then applies tiered filtering and round-level containment to limit adversarial influence. To capture traces that isolated signals may miss, FedMAST uses squeeze-pair coherence scoring to expose coupled feature distortions and signed spectral-drift tracking to reveal persistent directional changes over time. Across six backdoor attacks, FedMAST achieves lower attack success rate (ASR) than baseline defenses in all nine evaluated comparisons, averaging 1.51% ASR and 94.84% main-task accuracy (MTA) across the complete 200-round runs. Over the full 200-round method-aware CovertLayers run, FedMAST achieves 1.53% ASR and 92.26% MTA, compared with ASRs of 100.00%, 99.67%, 99.53%, and 32.84% for FedAvg, MultiKrum, AlignIns, and FLAME, respectively.
Comments10 pages, 5 figures. Accepted at IEEE ICTAI 2026