acceptodds
Under review as a conference paper at ICLR 2027

FedHarden: Proactive Defense Against Persistent Backdoor Attacks in Federated Learning

Abstract

Federated learning (FL) enables decentralized clients to jointly train a global model by uploading locally trained updates to a central server. However, compromised clients may inject backdoors that cause trigger-specific misclassification while preserving main-task performance. Existing defenses mainly act on client updates after local training, but may leave residual backdoor influence under sustained poisoning. This influence can accumulate across rounds when benign training does not sufficiently erase it. Motivated by the low-activity parameter subspace exploited by persistent attacks, we propose FedHarden, a detection-free FL defense that proactively robustifies the global model before each communication round. FedHarden uses OOD-derived auxiliary data to introduce competing gradients and limits server-side training to selected convolutional kernels and associated batch-normalization parameters to suppress backdoor accumulation. Experiments across diverse attacks, datasets, and model architectures show that FedHarden suppresses backdoors under sustained poisoning while maintaining comparable main-task accuracy. Specifically, in a CIFAR10 experiment with 600 poisoning rounds, it reduces backdoor accuracy to near the random-guess level (10.00%), compared with 42.44% for the strongest baseline, a reduction.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.