TIMBRE: Backdoor Defense in Federated Learning via Layer-wise Spectral Energy Distributions
Abstract
Federated learning is vulnerable to backdoor attacks, and strong data heterogeneity lets malicious updates hide among benign updates that already differ. Advanced backdoors mimic benign updates in norm, distance, or overall direction, weakening defenses built on these statistics. We observe that backdoored updates can differ in how their energy is allocated within a layer even at comparable magnitudes. We therefore propose TIMBRE, a server-side defense that uses only individual client updates, without labels or trusted reference data. TIMBRE computes each update's normalized spectral energy distribution layer by layer, which is invariant to overall scale. TIMBRE compares an update's distribution with those of the other clients in the same round, and the further it departs beyond their typical spread, the stronger the backdoor evidence. Rather than filtering or removing clients, TIMBRE grades its restrictions by the strength and persistence of the evidence: it suppresses modifications lacking support from other clients, keeps useful contributions, and lifts restrictions as evidence fades. In experiments on multiple datasets and models under five representative attacks, TIMBRE keeps every attack success rate in the main setting below 1.4% with a clean-accuracy cost of at most 1.5 percentage points; it outperforms the eight evaluated defenses overall and keeps the attack success rate low as data heterogeneity and the malicious participation ratio vary.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.