FedDAB: New Defense Against Backdoor Attacks in Federated Learning
Researchers propose FedDAB, a two-phase defense method against backdoor attacks in Federated Learning (FL). The first phase uses local contrastive regularization to align benign updates. The second phase employs alignment checking to detect and exclude malicious updates from global aggregation. The method addresses statistical heterogeneity and stealthy attacks. Theoretical proof is provided.
Key facts
- FedDAB is a two-phase defense method for Federated Learning.
- First phase uses local contrastive regularization for benign update consistency.
- Second phase uses alignment checking to detect abnormal updates.
- Method addresses statistical heterogeneity and stealthy backdoor attacks.
- Theoretical proof of FedDAB's effectiveness is provided.
- Published on arXiv with ID 2607.26933.
- Announce type is cross.
- Proposed to defend against backdoor attacks in edge computing.
Entities
Institutions
- arXiv