acceptodds
Under review as a conference paper at ICLR 2027

CCCV: Cross-Client Consistency Verification for High-Precision Backdoor Defense in Vertical Federated Learning

Abstract

Vertical federated learning (VFL) enables parties with disjoint feature sets of the same samples to collaboratively train and infer without sharing raw data. However, VFL is vulnerable to clean-label backdoor attacks, where one or more malicious clients manipulate its representation to induce targeted misclassification while preserving benign labels and training behavior. Existing defenses can detect such attacks but often misclassify atypical benign representations, leading to high false-positive rates and utility degradation, while some methods additionally require auxiliary trusted data. Our key insight is to directly estimate the conditional probability of each client representation given the others. Backdoor representations create a mismatch with the cross-client context and thus receive low conditional likelihood. Compared with reconstruction-based methods that approximate conditional consistency through a point estimate and other defenses that rely on auxiliary trusted data or indirect anomaly signals, direct density estimation enables more precise detection with fewer false positives and less performance degradation without requiring additional trusted data. Based on this insight, we propose Cross-Client Consistency Verification (CCCV), an inference-time defense combining lightweight semantic screening with contrastively enhanced conditional normalizing flows. CCCV requires no trusted data and does not modify the optimization of the original VFL model, while supporting backdoor detection, attacker attribution, and prediction recovery.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.