When Backdoors Disagree: Source-Level Federated Unlearning with Asymmetric Consensus
Abstract
Federated unlearning removes the influence of departing clients from a trained model without retraining it, and it is usually evaluated with a single deletion source. A real request may cover several groups of clients, each of which planted a different backdoor. Their deletion objectives can conflict: when the sources pull in opposing directions, one shared update may leave a source without progress, and serving all of them takes longer steps the more they cancel. We call this tension the coverage bind. A surviving source is also easy to miss, since the mean attack success over sources can be low while one backdoor persists, so we test every source separately. We propose Federated Asymmetric Consensus (FAC), whose two design choices respond to the bind: each client keeps its own objective, and the disagreement between clients and the shared model is carried across rounds rather than lost at every aggregation, and the server penalizes changes to the parameters that retained behavior relies on. The server coordinates unlearning using the forget/retain partition, without trigger specifications or source labels. In a source-scaling study with up to seven sources, FAC is the only one of sixteen approximate unlearning methods that leaves no source measurably above retraining at every source count tested. Once there are several sources, it also retains the most accuracy among the methods that do so. With three sources, FAC leaves no survivor in eight of nine residual-network runs across three datasets; on a vision transformer, neither FAC nor SalUn removes more sources on every dataset, and FAC retains more accuracy. Across 144 endpoint runs with three to seven sources, 58% show a gap of at least 20 points between worst-source and mean attack success, so averaged scores routinely hide surviving backdoors.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.