FedMVC: defense against backdoor attacks in federated learning using multi-feature variational autoencoders and clustering
摘要
Federated learning (FL) enables distributed collaborative model training without centralizing client data, but its decentralized architecture introduces significant vulnerabilities to backdoor attacks. Malicious clients can embed triggers that compromise the global model’s behavior on specific inputs while maintaining normal performance on clean data. However, existing Byzantine-tolerant defense mechanisms struggle to effectively distinguish malicious updates from benign ones in realistic non-IID environments. This paper presents FedMVC, a two-stage backdoor defense framework for Federated Learning that combines Multi-feature Variational Autoencoders with Clustering to proactively detect and remove malicious client updates before aggregation. The server-side VAE learns compact latent representations of client updates, while clustering applied to the multi-dimensional feature space allows robust discrimination between benign and malicious clusters. We evaluate FedMVC on MNIST, CIFAR-10, and IMDb under both standard backdoor attacks (2