Journal of Computer Applications ›› 2026, Vol. 46 ›› Issue (7): 2184-2195.DOI: 10.11772/j.issn.1001-9081.2025070873
• Cyber security • Previous Articles
Qi ZHONG1,2,3, Shufen ZHANG1,2,3,4(
), Zhenbo ZHANG1,2,3, Tao LI1,2,3
Received:2025-08-04
Revised:2025-09-08
Accepted:2025-09-11
Online:2025-11-05
Published:2026-07-10
Contact:
Shufen ZHANG
About author:ZHONG Qi, born in 1999, M. S. candidate. Her research interests include data security, privacy protection.Supported by:
钟琪1,2,3, 张淑芬1,2,3,4(
), 张镇博1,2,3, 李涛1,2,3
通讯作者:
张淑芬
作者简介:钟琪(1999—),女,河北张家口人,硕士研究生,主要研究方向:数据安全、隐私保护基金资助:CLC Number:
Qi ZHONG, Shufen ZHANG, Zhenbo ZHANG, Tao LI. Federated learning backdoor defense algorithm based on gradient features[J]. Journal of Computer Applications, 2026, 46(7): 2184-2195.
钟琪, 张淑芬, 张镇博, 李涛. 基于梯度特征的联邦学习后门防御算法[J]. 《计算机应用》唯一官方网站, 2026, 46(7): 2184-2195.
Add to citation manager EndNote|Ris|BibTeX
URL: https://www.joca.cn/EN/10.11772/j.issn.1001-9081.2025070873
| 参数 | 含义 |
|---|---|
| 客户端梯度 | |
| 客户端梯度的维度数量 | |
| 客户端 | |
| 客户端 | |
| 平均模型 | |
| 平均模型梯度 | |
| 本地模型与平均模型的对齐度 | |
| 主导梯度 | |
| 裁剪后的 | |
| 裁剪后的 | |
| 第 | |
| 攻击者的数量 |
Tab. 1 Main symbol description
| 参数 | 含义 |
|---|---|
| 客户端梯度 | |
| 客户端梯度的维度数量 | |
| 客户端 | |
| 客户端 | |
| 平均模型 | |
| 平均模型梯度 | |
| 本地模型与平均模型的对齐度 | |
| 主导梯度 | |
| 裁剪后的 | |
| 裁剪后的 | |
| 第 | |
| 攻击者的数量 |
| 算法 | 后门攻击 | 边缘后门攻击 | ||||||
|---|---|---|---|---|---|---|---|---|
| freq = 1 | freq = 10 | freq = 20 | freq = 100 | freq = 1 | freq = 10 | freq = 20 | freq = 100 | |
| FedAvg | 99.74 | 86.09 | 49.21 | 1.86 | 100 | 88.03 | 79.11 | 20.74 |
| Foolsgold | 50.79 | 47.96 | 38.58 | 0.89 | 77.98 | 77.27 | 52.57 | 4.95 |
| Flame | 52.09 | 26.19 | 20.15 | 56.79 | 32.91 | 22.52 | 5.97 | |
| Multi-Metrics | 15.39 | 19.22 | 10.93 | 0.78 | 26.65 | 22.91 | 16.47 | 3.33 |
| Datadefense | 6.39 | 0.74 | 14.77 | 2.65 | ||||
| Scope | 16.12 | 9.83 | 3.21 | 0.77 | 27.14 | 15.22 | ||
| GradGuard | 9.11 | 7.33 | 0.25 | 12.24 | 9.54 | 5.26 | 1.86 | |
Tab. 2 Comparison of BA of various algorithms in backdoor attacks and edge backdoor attacks with different values of freq
| 算法 | 后门攻击 | 边缘后门攻击 | ||||||
|---|---|---|---|---|---|---|---|---|
| freq = 1 | freq = 10 | freq = 20 | freq = 100 | freq = 1 | freq = 10 | freq = 20 | freq = 100 | |
| FedAvg | 99.74 | 86.09 | 49.21 | 1.86 | 100 | 88.03 | 79.11 | 20.74 |
| Foolsgold | 50.79 | 47.96 | 38.58 | 0.89 | 77.98 | 77.27 | 52.57 | 4.95 |
| Flame | 52.09 | 26.19 | 20.15 | 56.79 | 32.91 | 22.52 | 5.97 | |
| Multi-Metrics | 15.39 | 19.22 | 10.93 | 0.78 | 26.65 | 22.91 | 16.47 | 3.33 |
| Datadefense | 6.39 | 0.74 | 14.77 | 2.65 | ||||
| Scope | 16.12 | 9.83 | 3.21 | 0.77 | 27.14 | 15.22 | ||
| GradGuard | 9.11 | 7.33 | 0.25 | 12.24 | 9.54 | 5.26 | 1.86 | |
| 防御算法 | 参与比例为0.2 | 参与比例为0.4 | 参与比例为0.6 | 参与比例为0.8 | ||||
|---|---|---|---|---|---|---|---|---|
| MA | BA | MA | BA | MA | BA | MA | BA | |
| FedAvg | 83.70 | 92.76 | 83.71 | 87.73 | 83.77 | 90.84 | 84.00 | 87.57 |
| Foolsgold | 69.42 | 78.95 | 75.93 | 78.95 | 82.06 | 80.00 | 83.86 | 78.59 |
| Flame | 83.50 | 55.00 | 84.14 | 28.44 | 83.34 | 15.47 | ||
| Multi-Metrics | 82.86 | 34.44 | 27.05 | 18.26 | 84.21 | 14.36 | ||
| Datadefense | 81.02 | 32.51 | 83.77 | 25.56 | 83.52 | 17.39 | 83.52 | 12.65 |
| Scope | 84.33 | 80.93 | 15.55 | 82.76 | ||||
| GradGuard | 84.45 | 15.94 | 84.70 | 12.22 | 84.61 | 10.59 | 84.56 | 8.08 |
Tab. 3 Comparison of MA and BA among various algorithms with different client participation ratios
| 防御算法 | 参与比例为0.2 | 参与比例为0.4 | 参与比例为0.6 | 参与比例为0.8 | ||||
|---|---|---|---|---|---|---|---|---|
| MA | BA | MA | BA | MA | BA | MA | BA | |
| FedAvg | 83.70 | 92.76 | 83.71 | 87.73 | 83.77 | 90.84 | 84.00 | 87.57 |
| Foolsgold | 69.42 | 78.95 | 75.93 | 78.95 | 82.06 | 80.00 | 83.86 | 78.59 |
| Flame | 83.50 | 55.00 | 84.14 | 28.44 | 83.34 | 15.47 | ||
| Multi-Metrics | 82.86 | 34.44 | 27.05 | 18.26 | 84.21 | 14.36 | ||
| Datadefense | 81.02 | 32.51 | 83.77 | 25.56 | 83.52 | 17.39 | 83.52 | 12.65 |
| Scope | 84.33 | 80.93 | 15.55 | 82.76 | ||||
| GradGuard | 84.45 | 15.94 | 84.70 | 12.22 | 84.61 | 10.59 | 84.56 | 8.08 |
| 算法 | EMNIST | CIFAR-10 | ||
|---|---|---|---|---|
| 通信轮次 | 训练时间/s | 通信轮次 | 训练时间/s | |
| FedAvg | 940 | 479.40 | 924 | 2 961.60 |
| Foolsgold | 804.78 | 989 | 6 339.88 | |
| Flame | 892 | 336.23 | 995 | 2 531.19 |
| Multi-Metrics | 806 | 299.40 | 920 | 1 357.52 |
| Datadefense | 835 | 497.71 | 864 | 1 958.02 |
| Scope | 791 | |||
| GradGuard | 695 | 127.42 | 688 | 920.92 |
Tab. 4 Communication costs and training time overhead of various algorithms
| 算法 | EMNIST | CIFAR-10 | ||
|---|---|---|---|---|
| 通信轮次 | 训练时间/s | 通信轮次 | 训练时间/s | |
| FedAvg | 940 | 479.40 | 924 | 2 961.60 |
| Foolsgold | 804.78 | 989 | 6 339.88 | |
| Flame | 892 | 336.23 | 995 | 2 531.19 |
| Multi-Metrics | 806 | 299.40 | 920 | 1 357.52 |
| Datadefense | 835 | 497.71 | 864 | 1 958.02 |
| Scope | 791 | |||
| GradGuard | 695 | 127.42 | 688 | 920.92 |
| [1] | Deng S, Zhao H, Fang W, et al. Edge intelligence: the confluence of edge computing and artificial intelligence[J]. IEEE Internet of Things Journal, 2020, 7(8): 7457-7469. |
| [2] | McMahan H B, Moore E, Ramage D, et al. Communication-efficient learning of deep networks from decentralized data [C]// AISTATS 2017. New York: JMLR.org, 2017: 1273-1282. |
| [3] | Beltrán E T M, Pérez M Q, Sánchez P M S, et al. Decentralized federated learning: fundamentals, state of the art, frameworks, trends, and challenges [J]. IEEE Communications Surveys and Tutorials, 2023, 25(4): 2983-3013. |
| [4] | Gong X, Chen Y, Wang Q, et al. Backdoor attacks and defenses in federated learning: state-of-the-art, taxonomy, and future directions [J]. IEEE Wireless Communications, 2023, 30(2): 114-121. |
| [5] | Liu T, Zhang Y, Feng Z, et al. Beyond traditional threats: a persistent backdoor attack on federated learning [C]// AAAI 2024. Palo Alto: AAAI Press, 2024: 21359-21367. |
| [6] | Han X, Zhang X, Lan X, et al. BadSFL: backdoor attack against scaffold federated learning [PP/OL]. V2. arXiv (2024-11-26) [2025-01-23]. . |
| [7] | Li S, Cheng Y, Wang W, et al. Learning to detect malicious clients for robust federated learning [PP/OL]. arXiv (2020-02-01) [2025-02-02]. . |
| [8] | Wang H, Sreenivasan K, Rajput S, et al. Attack of the tails: yes, you really can backdoor federated learning [C]// NeurIPS 2020. Red Hook: Curran Associates Inc., 2020: 16070-16084. |
| [9] | Molina Coronado B. Celtibero: robust layered aggregation for federated learning [PP/OL]. V2. arXiv (2018-09-20) [2025-02-12]. . |
| [10] | Chen H, Chen X, Peng L, et al. FLRAM: robust aggregation technique for defense against Byzantine poisoning attacks in federated learning [J]. Electronics, 2023, 12(21): No.4463. |
| [11] | Mai P, Yan R, Pang Y. RFLPA: a robust federated learning framework against poisoning attacks with secure aggregation [C]// NeurIPS 2024. Red Hook: Curran Associates Inc., 2024: 104329-104356. |
| [12] | Zhang Z, Cao X, Jia J, et al. FLDetector: defending federated learning against model poisoning attacks via detecting malicious clients [C]// KDD 2022. New York: ACM, 2022: 2545-2555. |
| [13] | 陈谦,柴政,王子龙,等.基于生成对抗网络的联邦学习中投毒攻击检测方案[J].计算机应用, 2023, 43(12): 3790-3798. |
| Chen Qian, Chai Zheng, Wang Zilong, et al. Poisoning attack detection scheme based on generative adversarial network for federated learning [J]. Journal of Computer Applications, 2023, 43(12): 3790-3798. | |
| [14] | Han S, Wu W, Buyukates B, et al. Kick bad guys out! conditionally activated anomaly detection in federated learning with zero-knowledge proof verification [PP/OL]. V4. arXiv (2024-10-07) [2025-03-10]. . |
| [15] | Ghosh A, Hong J, Yin D, et al. Robust federated learning in a heterogeneous environment [PP/OL]. V2. arXiv (2019-10-09) [2025-03-12]. . |
| [16] | Bagdasaryan E, Veit A, Hua Y, et al. How to backdoor federated learning [C]// AISTATS 2020. New York: JMLR.org, 2020: 2938-2948. |
| [17] | Blanchard P, El Mhamdi E M, Guerraoui R, et al. Machine learning with adversaries: Byzantine tolerant gradient descent [C]// NeurIPS 2017. Red Hook: Curran Associates Inc., 2017: 118-128. |
| [18] | Pillutla K, Kakade S M, Harchaoui Z. Robust aggregation for federated learning [J]. IEEE Transactions on Signal Processing, 2022, 70: 1142-1154. |
| [19] | Hao L, Hao K, Wei B, et al. Multi-target federated backdoor attack based on feature aggregation [J]. Pattern Recognition, 2026, 172(Pt A): No.112333. |
| [20] | Xie C, Chen M, Chen P Y, et al. CRFL: certifiably robust federated learning against backdoor attacks [C]// ICML 2021. New York: JMLR.org, 2021: 11372-11382. |
| [21] | Nguyen T D, Rieger P, Chen H, et al. FLAME: taming backdoors in federated learning [C]// USENIX Security 2022. Berkeley: USENIX Association, 2022: 1415-1432. |
| [22] | Fung C, Yoon C J M, Beschastnikh I. The limitations of federated learning in Sybil settings [C]// RAID 2020. Berkeley: USENIX Association, 2020: 301-316. |
| [23] | Xu J, Zhang Z, Hu R. Detecting backdoor attacks in federated learning via direction alignment inspection [C]// CVPR 2025. Piscataway: IEEE, 2025: 20654-20664. |
| [24] | Huang S, Li Y, Chen C, et al. Multi-metrics adaptively identifies backdoors in federated learning [C]// ICCV 2023. Piscataway: IEEE, 2023: 4629-4639. |
| [25] | Purohit K, Das S, Bhattacharya S, et al. A data-driven defense against edge-case model poisoning attacks on federated learning [PP/OL]. V2. arXiv (2024-08-14) [2025-01-02]. . |
| [26] | Huang S, Li Y, Yan X, et al. Scope: on detecting constrained backdoor attacks in federated learning [J]. IEEE Transactions on Information Forensics and Security, 2025, 20: 3302-3315. |
| [27] | Wang S, Hayase J, Fanti G, et al. Towards a defense against federated backdoor attacks under continuous training [PP/OL]. V4. arXiv (2023-01-31) [2025-03-27]. . |
| [28] | Chen M, Mao B, Ma T. FedSA: a staleness-aware asynchronous federated learning algorithm with non-IID data [J]. Future Generation Computer Systems, 2021, 120: 1-12. |
| [29] | Uddin M P, Xiang Y, Hasan M, et al. A systematic literature review of robust federated learning: issues, solutions, and future research directions [J]. ACM Computing Surveys, 2025, 57(10): No.245. |
| [30] | 陈学斌,屈昌盛.面向联邦学习的后门攻击与防御综述[J].计算机应用, 2024, 44(11): 3459-3469. |
| Chen Xuebin, Qu Changsheng. Overview of backdoor attacks and defenses in federated learning [J]. Journal of Computer Applications, 2024, 44(11): 3459-3469. |
| [1] | Zhijian DONG, Ruichun GU. Federated learning framework integrating dynamic feature alignment and temperature-aware aggregation [J]. Journal of Computer Applications, 2026, 46(6): 1746-1755. |
| [2] | Hao YU, Jing FAN, Enkang XI, Yadong JIN, Hua DONG, Yihang SUN. HEFSL: high-efficient federated split learning framework for edge heterogeneity [J]. Journal of Computer Applications, 2026, 46(5): 1397-1407. |
| [3] | Zhi JIANG, Xuebin CHEN, Changyin LUO, Ziye ZHEN. Hybrid optimization framework for improving Kolmogorov-Arnold network in federated learning [J]. Journal of Computer Applications, 2026, 46(4): 1023-1033. |
| [4] | Kaiguang MA, Xuebin CHEN, Yinlong JIAN, Liu WANG, Yuan GAO. Network intrusion detection based on hybrid sequence model and federated class balance algorithm [J]. Journal of Computer Applications, 2026, 46(3): 857-866. |
| [5] | Enkang XI, Jing FAN, Yadong JIN, Hua DONG, Hao YU, Yihang SUN. Review of threats faced by federated learning in privacy and security field [J]. Journal of Computer Applications, 2026, 46(3): 798-808. |
| [6] | Huan PING, Zhanguo XIA, Sicheng LIU, Qihan LIU, Chunlei LI. Terminal data privacy-preserving scheme based on hierarchical federated learning [J]. Journal of Computer Applications, 2026, 46(3): 830-838. |
| [7] | Lei WANG, Wenxuan ZHOU, Ninghui JIA, Zhihao QU. Federated learning with two-pass communication compression for privacy-sensitive IoT data [J]. Journal of Computer Applications, 2026, 46(3): 887-898. |
| [8] | Qi ZHONG, Shufen ZHANG, Zhenbo ZHANG, Yinlong JIAN, Zhongrui JING. Detection and defense mechanism for poisoning attacks to federated learning [J]. Journal of Computer Applications, 2026, 46(2): 445-457. |
| [9] | Kejia ZHANG, Zhijun FANG, Nanrun ZHOU, Zhicai SHI. Personalized federated learning method based on model pre-assignment and self-distillation [J]. Journal of Computer Applications, 2026, 46(1): 10-20. |
| [10] | Yingchun TANG, Rong HUANG, Shubo ZHOU, Xueqin JIANG. Clean-label multi-backdoor attack method based on feature regulation and color separation [J]. Journal of Computer Applications, 2026, 46(1): 124-134. |
| [11] | Yinlong JIAN, Xuebin CHEN, Zhongrui JING, Qi ZHONG, Zhenbo ZHANG. Data augmentation scheme based on conditional generative adversarial network in federated learning [J]. Journal of Computer Applications, 2026, 46(1): 21-32. |
| [12] | Hao YU, Jing FAN, Yihang SUN, Yadong JIN, Enkang XI, Hua DONG. Federated split learning optimization method under edge heterogeneity [J]. Journal of Computer Applications, 2026, 46(1): 33-42. |
| [13] | Hao YU, Jing FAN, Yihang SUN, Hua DONG, Enkang XI. Survey of statistical heterogeneity in federated learning [J]. Journal of Computer Applications, 2025, 45(9): 2737-2746. |
| [14] | Jintao SU, Lina GE, Liguang XIAO, Jing ZOU, Zhe WANG. Detection and defense scheme for backdoor attacks in federated learning [J]. Journal of Computer Applications, 2025, 45(8): 2399-2408. |
| [15] | Lina GE, Mingyu WANG, Lei TIAN. Review of research on efficiency of federated learning [J]. Journal of Computer Applications, 2025, 45(8): 2387-2398. |
| Viewed | ||||||
|
Full text |
|
|||||
|
Abstract |
|
|||||