ResSub: Dual-Level Backdoor Defense via Residual Alignment and Subspace Perturbation in Vertical Federated Learning
Abstract
Vertical Federated Learning (VFL) enables collaborative learning over vertically partitioned data without sharing raw features, but remains vulnerable to backdoor attacks launched by malicious passive parties. Existing defenses primarily rely on attack detection or indiscriminate perturbation, while overlooking that backdoor behaviors fundamentally arise from the supervision and gradient feedback exposed during collaborative optimization. In this paper, we propose ResSub, a dual-level backdoor defense framework that simultaneously restructures supervision and gradient feedback in VFL. Specifically, Residual-Transformed Alignment reformulates the optimization objective of passive parties using residual-transformed targets, encouraging them to learn only the information missing from the active party's local prediction rather than complete label semantics. Meanwhile, Subspace-Structured Gradient Perturbation injects structure-aware perturbations into gradient subspaces, suppressing exploitable class-discriminative optimization signals while preserving model utility. Extensive experiments across multiple datasets and attack settings demonstrate that ResSub reduces the average attack success rates from 89.7% to 8.3%, while maintaining competitive clean-task performance.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.