错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Parameter Masking Meets Temporal Smoothness in Backdoor Defense for Federated Learning

  • Houxun Jiang,
  • Zikai Zhang,
  • Ziyi Li,
  • Yaoyue Zhang,
  • Yidong Li

摘要

Federated learning (FL), a collaborative training paradigm, exhibits significant vulnerability to backdoor attacks. Current defense mechanisms often struggle to reconcile computational efficiency with robust resilience against varied attack strategies, particularly when dealing with low poisoning rates where malicious behaviors are subtle. To overcome these limitations, we propose PMTS, a novel framework integrating Parameter Masking-enhanced client detection with a Temporal Smoothness strategy. Initially, to address the challenge of distinguishing malicious clients under low poisoning rates, we introduce a random masking enhancement applied to critical parameter subsets. This disrupts the propagation of malicious parameters and effectively reduces the Jaccard similarity between benign and malicious clients. Subsequently, to mitigate temporal inconsistencies in both detection and training, we present a two-pronged temporal smoothness strategy: constructing a historical sliding window based on Pearson correlation for weighted aggregation of detection results, and incorporating an \(\ell 2\) -norm constraint during local training to restrict abrupt parameter shifts. Extensive experiments on multiple datasets demonstrate the superior performance of PMTS over state-of-the-art defenses, achieving up to 2.45% reduction in attack success rates with a 0.56% increase in normal task accuracy.