TOFD: New Defense Framework Against Poisoning Attacks in Split Federated Learning
A recent study published on arXiv (2608.07274) presents Target-Oriented Feature Decoupling (TOFD), a comprehensive defense strategy against poisoning attacks in Split Federated Learning (SFL). SFL is a collaborative training approach that prioritizes privacy while minimizing client-side burdens, yet its split architecture makes it susceptible to various poisoning threats. Current defense mechanisms often do not take full advantage of the split structure, hindering the early identification and management of harmful activities. TOFD fills this void with a three-step method: Target Inference identifies potential targets through class-specific Margin Perturbation (MP); Sample Purification filters out contaminated data adaptively using thresholds from cross-class min-max normalization of MP; and Decoupling Optimization uses decoupled features for robust model enhancement. This framework aims to improve the security of SFL systems, crucial for privacy-sensitive applications.
Key facts
- Paper arXiv:2608.07274 introduces TOFD, a unified defense against poisoning attacks in Split Federated Learning.
- TOFD operates in three stages: Target Inference, Sample Purification, and Decoupling Optimization.
- Target Inference uses class-specific Margin Perturbation (MP) to refine class-wise safe zones.
- Sample Purification filters poisoned data using thresholds from cross-class min-max normalization of MP.
- Decoupling Optimization leverages decoupled features for robust model optimization.
- SFL is vulnerable to diverse poisoning attacks due to its split architecture.
- Existing defenses often fail to exploit the split paradigm for early detection.
- TOFD enables proactive detection and robust optimization against a wide range of attacks.
Entities
Institutions
- arXiv