Abstract
Federated learning (FL) is increasingly vulnerable to backdoor attacks, where malicious participants inject poisoned updates to implant hidden behaviors within the global model. Existing defenses often rely on ad-hoc aggregation rules, heuristic parameter modifications, or external trusted datasets, severely limiting their robustness, interpretability, and transferability across diverse architectures and attack modalities. To address these fundamental limitations, we propose a Guided Unlearning for Adversarial Robustness and Defense (i.e., GUARD). It is a unified, data-centric framework, which leverages the principles of machine unlearning to systematically secure FL systems. Specifically, GUARD establishes a rigorous theoretical link between data influence estimation and backdoor mitigation. It utilizes fast influence-function approximation to efficiently isolate poisoned training contributions without requiring auxiliary clean data. Building on this precise detection, the framework executes a sequential, closed-loop defense pipeline: an influence-guided unlearning stage that explicitly neutralizes malicious parameter biases through reverse optimization, followed by a stability-preserving lightweight fine-tuning stage on internally verified clean data to seamlessly restore standard predictive performance. Comprehensive experiments across diverse datasets, advanced backdoor attacks, and model architectures demonstrate that GUARD achieves superior threat eradication and clean accuracy preservation compared to state-of-the-art baselines. By transforming backdoor removal into a causally interpretable unlearning process, this work offers a highly robust and principled pathway toward trustworthy FL.
| Original language | English |
|---|---|
| Journal | IEEE Transactions on Dependable and Secure Computing |
| DOIs | |
| Publication status | Accepted/In press - 2026 |
| Externally published | Yes |
Keywords
- Adversarial robustness
- backdoor defense
- federated learning
- influence estimation
- unlearning
Fingerprint
Dive into the research topics of 'GUARD: Mitigating Backdoors in Federated Learning Via Influence-Guided Unlearning'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver