FedHRA: Client-Side Purification and Hierarchical Robust Aggregation for Federated Backdoor Defense in Time-Series Classification
Abstract
Federated learning enables industrial sites to train time-series classification models without sharing raw process data, but it exposes training to backdoor poisoning from compromised clients. Existing robust aggregation defenses, designed for generic cross-device settings, become unreliable under the strong non-IID distributions of industrial cross-silo FL, where benign updates naturally deviate from the global average. We propose Federated Backdoor Defense with Client-Side Purification and Hierarchical Robust Aggregation (FedHRA). On the client side, a conditional variational autoencoder learns the class-conditional normal manifold of local time-series signals; prediction flipping, confidence drop, and reconstruction error are fused into a suspiciousness score that purifies risky samples and provides client-level risk evidence. On the server side, FedHRA separates the backbone from the classification head and, using client-reported risk signals and temporal memory, applies stronger sanctions to the decision-sensitive head while softly downweighting the backbone. Experiments on the Tennessee Eastman Process and Spoken Arabic Digits datasets show that FedHRA suppresses terminal attack success rates to near zero under single-shot, continuous, periodic, and late-stage attacks while maintaining usable main-task accuracy.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.