跳到主要导航 跳到搜索 跳到主要内容

GUARD: Mitigating Backdoors in Federated Learning Via Influence-Guided Unlearning

  • Beijing Institute of Technology
  • BYD Company Ltd.
  • Tsinghua University

科研成果: 期刊稿件文章同行评审

摘要

Federated learning (FL) is increasingly vulnerable to backdoor attacks, where malicious participants inject poisoned updates to implant hidden behaviors within the global model. Existing defenses often rely on ad-hoc aggregation rules, heuristic parameter modifications, or external trusted datasets, severely limiting their robustness, interpretability, and transferability across diverse architectures and attack modalities. To address these fundamental limitations, we propose a Guided Unlearning for Adversarial Robustness and Defense (i.e., GUARD). It is a unified, data-centric framework, which leverages the principles of machine unlearning to systematically secure FL systems. Specifically, GUARD establishes a rigorous theoretical link between data influence estimation and backdoor mitigation. It utilizes fast influence-function approximation to efficiently isolate poisoned training contributions without requiring auxiliary clean data. Building on this precise detection, the framework executes a sequential, closed-loop defense pipeline: an influence-guided unlearning stage that explicitly neutralizes malicious parameter biases through reverse optimization, followed by a stability-preserving lightweight fine-tuning stage on internally verified clean data to seamlessly restore standard predictive performance. Comprehensive experiments across diverse datasets, advanced backdoor attacks, and model architectures demonstrate that GUARD achieves superior threat eradication and clean accuracy preservation compared to state-of-the-art baselines. By transforming backdoor removal into a causally interpretable unlearning process, this work offers a highly robust and principled pathway toward trustworthy FL.

源语言英语
期刊IEEE Transactions on Dependable and Secure Computing
DOI
出版状态已接受/待刊 - 2026
已对外发布

学术指纹

探究 'GUARD: Mitigating Backdoors in Federated Learning Via Influence-Guided Unlearning' 的科研主题。它们共同构成独一无二的学术指纹。

引用此