Skip to content
Open access

Fed-CBE: Client-Side Backdoor Elimination in Federated Learning via Persistent Parameter Disruption

2026 · IEEE Transactions on Information Forensics and Security · Vol 21, pp. 7874-7889 · 0 citations · 61 references

TL;DR

Fed-CBE is proposed, a novel client-side defense algorithm that eliminates backdoors through three synergistic mechanisms: periodic alternating layer resetting disrupts deep parameters to dismantle cross-round backdoor accumulation, and indiscriminate forgetting employs entropy maximization on non-ground-truth classes to decouple backdoor associations without prior trigger knowledge.

Abstract

Federated Learning (FL) inherently preserves privacy but remains highly vulnerable to backdoor attacks due to its open participation architecture. Existing defenses face two fundamental limitations: first, screening-based aggregation strategies prove ineffective against advanced cross-round attacks where adversaries progressively poison model parameters through multi-round collaboration; second, mitigation techniques often cause significant accuracy degradation due to the deep entanglement between backdoor and primary task parameters. To address these challenges, we propose Fed-CBE, a novel client-side defense algorithm that eliminates backdoors through three synergistic mechanisms: 1) periodic alternating layer resetting disrupts deep parameters to dismantle cross-round backdoor accumulation; 2) indiscriminate forgetting employs entropy maximization on non-ground-truth classes to decouple backdoor associations without prior trigger knowledge; and 3) knowledge distillation with historical local models restores primary task performance. Extensive evaluations on three benchmark datasets and model architectures demonstrate that Fed-CBE achieves highly competitive robustness, limiting attack success rates to near-zero levels in most settings and keeping them exceptionally low even under high malicious-client ratios without compromising primary task performance, significantly outperforming existing defenses.

Read PDF

Similar papers

Book Open access Aug 2026

FedPurify: Knowledge-Preserving Backdoor Defense with Data-Free Purification in Federated Learning

FedPurify is a framework that performs post-training data-free purification to remove malicious backdoors while preserving task-relevant knowledge in FL, and combines contrastive feature alignment with knowledge-preserving self-distillation to remove backdoor effects while preserving benign task performance.

Baolu Xue, Hanyuan Zheng, Tianxing Man et al. · 0 citations
Conference 2026

FedRGD: Risk-Guided Dynamic Defense against Federated Backdoors

FedRGD is a federated risk-guided dynamic defense framework that enables efficient fine-grained protection against backdoor attacks in non-IID environments, and combines feature inconsistency detection with lightweight masking and robust aggregation to achieve both accuracy and efficiency.

Rui-Ying Wang · 0 citations
Preprint Aug 2026

BackDFL: A Unified Benchmark For Backdoor Attacks and Defenses In Decentralized Federated Learning

BackDFL is presented, a unified benchmark for systematically evaluating DFL under realistic and adaptive backdoor attacks, and demonstrates that both state-of-the-art Byzantine-robust DFL methods and adapted FL backdoor defenses fail under modest malicious participation rates, especially in heterogeneous settings.

M. Bouchiha, Gregory Blanc, Yu-Fei Han · 0 citations
Jul 2026

TriShield: Zero-Utility-Loss Defense Against Privacy Backdoors in Federated Language Model Fine-Tuning via Orthogonal Gradient Projection and Optimizer State Entanglement

TriShield is presented, a three-layer deterministic defense that completely prevents NeuroImprint-style reconstruction with zero model utility loss and no additional communication rounds, and it is proved theoretically that after Layers 2 and 3, the mutual information between the uploaded gradient and any individual training sample is zero.

Chenghui Wei · 0 citations
2026

PREFed: An Effective and Stealthy Static-Anchor Backdoor Attack via Trigger Pre-Optimization in Federated Learning

Existing Federated Learning (FL) backdoor attacks commonly employ round-wise proximity strategies, dynamically adapting malicious updates to mimic benign ones in order to evade detection. However, such adaptive mechanisms often introduce instability, increase computational overhead, and create temporal patterns that make attacks more detectable. This work presents a theoretical analysis of how attack configurations affect the disparity between benign and malicious model updates. We derive a two-sided bound on the parameter divergence between benign and backdoored local models, characterizing both an upper bound that governs detectability under defense, and a matching lower bound that exposes an irreducible label-flip signal no trigger optimization can eliminate. Guided by these insights, we propose PREFed, a static-anchor backdoor attack framework that leverages the clean data distribution to optimize trigger patterns under standard training configurations. PREFed eliminates the need for round-wise adaptation by pre-optimizing triggers before training, effectively reducing local training overhead and enhancing attack stability and stealth. Comprehensive evaluations on image classification benchmarks demonstrate that PREFed consistently outperforms three state-of-the-art attacks across six advanced defense mechanisms; cross-domain experiments on SST-2 further confirm the generality of the framework. It achieves over 80% backdoor accuracy within five communication rounds while reducing main task accuracy by less than 2%, compared to more than 15% degradation in prior methods. These results validate PREFed as an efficient and stealthy backdoor attack paradigm for practical federated learning environments.

Xi Chen, Rui Zeng, Chun-Yi Zhou et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.