Skip to content
Preprint

TOFD: Target-Oriented Feature Decoupling against Poisoning Attacks in Split Federated Learning

Aug 2026 · 0 citations · 33 references
Computer Science

TL;DR

Target-Oriented Feature Decoupling (TOFD), a unified framework that jointly enables proactive detection and robust optimization against a wide range of poisoning attacks, is proposed and theoretical guarantees for the convergence of TOFD are provided.

Abstract

Split Federated Learning (SFL) facilitates privacy-preserving collaborative training with reduced client-side overhead. However, its split architecture introduces unique attack surfaces, rendering it vulnerable to diverse poisoning attacks. Most existing defenses fail to exploit the split paradigm, limiting their ability to detect and contain malicious behaviors at an early stage. To bridge this gap, we propose Target-Oriented Feature Decoupling (TOFD), a unified framework that jointly enables proactive detection and robust optimization against a wide range of poisoning attacks. TOFD operates in three stages: (1) Target Inference, which identifies potential attack targets by refining class-wise safe zones via class-specific Margin Perturbation (MP); (2) Sample Purification, which adaptively filters poisoned smashed data using thresholds calibrated through cross-class min-max normalization of MP; and (3) Decoupling Optimization, which leverages an adversarial guidance model to capture attack-induced patterns and decouple their influence during optimization, thereby suppressing residual adversarial effects. We provide theoretical guarantees for the convergence of TOFD. Extensive experiments on five datasets demonstrate that TOFD consistently outperforms state-of-the-art defenses under diverse attack scenarios, achieving superior robustness with low computational overhead suitable for practical deployment.

View source

Similar papers

#machine learning Preprint Sep 2026

Fine-grained Distributed Backdoor Attacks in Federated Learning

Federated learning, as a privacy-preserving distributed machine learning paradigm, faces significant threats from backdoor attacks. Compared to centralized attacks, distributed backdoor attacks are more harmful but require more poisoned samples to compensate for the loss of trigger strength due to decomposition. Fixed...

Jian Wang, Hong Shen, Wei Ke et al. · 0 citations
Conference 2026

FedRGD: Risk-Guided Dynamic Defense against Federated Backdoors

FedRGD is a federated risk-guided dynamic defense framework that enables efficient fine-grained protection against backdoor attacks in non-IID environments, and combines feature inconsistency detection with lightweight masking and robust aggregation to achieve both accuracy and efficiency.

Rui-Ying Wang · 0 citations
Open access 2026

Fed-CBE: Client-Side Backdoor Elimination in Federated Learning via Persistent Parameter Disruption

Fed-CBE is proposed, a novel client-side defense algorithm that eliminates backdoors through three synergistic mechanisms: periodic alternating layer resetting disrupts deep parameters to dismantle cross-round backdoor accumulation, and indiscriminate forgetting employs entropy maximization on non-ground-truth classes...

Chun-Hai Li, Yun-Hui Shen, Ming Xie et al. · 0 citations
#federated learning Open access Sep 2026

Friend-Safe Adversarial Attack for selective evasion in personalized federated learning

Federated Learning (FL) enables collaborative model training across distributed clients while preserving data privacy; however, the personalization of client models in non-independent and identically distributed (non-IID) settings creates an unexplored attack surface where adversarial examples can selectively fool spec...

Hyun Kwon, Dae-Jin Kim · 0 citations
Book Open access Aug 2026

FedPurify: Knowledge-Preserving Backdoor Defense with Data-Free Purification in Federated Learning

FedPurify is a framework that performs post-training data-free purification to remove malicious backdoors while preserving task-relevant knowledge in FL, and combines contrastive feature alignment with knowledge-preserving self-distillation to remove backdoor effects while preserving benign task performance.

Baolu Xue, Hanyuan Zheng, Tian-Xing Man et al. · 0 citations
#artificial intelligence Preprint Sep 2026

When Clients Are Orchestrated: Strategic Gradient Manipulation to Defeat Federated Learning Servers with Efficient Defense

Federated Learning enables decentralized model training by exchanging model updates--rather than raw data--with a central parameter server (PS). While most of the existing defenses primarily assume static or independently acting adversaries, we reveal a new class of dynamically adaptive attacks that systematically bypa...

M. Shaaban, A. Abdel-Naby, Mohamed Elmahallawy · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.