Grupo Alarcos · Conference paper · 2025

Early detection of backdoor attacks in federated learning via ecosystemic symmetry breaking

Carlos Mario Braga Ortuño, Manuel Ángel Serrano Martín, Eduardo Fernández-Medina Patón

BDCAT · 2025

Evasive poisoning attacks such as semantic backdoors pose a growing threat to federated learning because they mimic benign client updates and evade detectors under secure aggregation. We introduce an unsupervised, per-client structural check that runs after each local round, before aggregation, requiring only compact statistical summaries derived from each client update after a geometric transformation that removes dependence on the global model. Client-update statistics are compared against a calibrated benign reference, and deviations are detected through statistical distances. Energy and Wasserstein-1 jointly define an operational pattern where threshold exceedances across projections reveal structural deviations even in apparently benign updates. Evaluated on canonical backdoor scenarios from Bagdasaryan et al., the method detects both strong and stealthy attacks in the first local round through consistent multi-projection threshold excesses, while benign updates show only isolated ones. The procedure is lightweight, unsupervised, compatible with secure aggregation, and does not require trigger datasets. By providing early per-client warnings before aggregation, it complements classical defenses such as norm clipping, differential privacy, and robust aggregation, enabling proactive mitigation of poisoning in federated learning.

View on the group website DOI: 10.1145/3773276.3775243