Pith. sign in

REVIEW 1 cited by

FLIP: A Provable Defense Framework for Backdoor Mitigation in Federated Learning

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2210.12873 v2 pith:G5QGGLRA submitted 2022-10-23 cs.CR cs.AIcs.LG

classification cs.CRcs.AIcs.LG
keywords attackbackdoordefenselearningaccuracyattacksbenignclients
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Federated Learning (FL) is a distributed learning paradigm that enables different parties to train a model together for high quality and strong privacy protection. In this scenario, individual participants may get compromised and perform backdoor attacks by poisoning the data (or gradients). Existing work on robust aggregation and certified FL robustness does not study how hardening benign clients can affect the global model (and the malicious clients). In this work, we theoretically analyze the connection among cross-entropy loss, attack success rate, and clean accuracy in this setting. Moreover, we propose a trigger reverse engineering based defense and show that our method can achieve robustness improvement with guarantee (i.e., reducing the attack success rate) without affecting benign accuracy. We conduct comprehensive experiments across different datasets and attack settings. Our results on eight competing SOTA defense methods show the empirical superiority of our method on both single-shot and continuous FL backdoor attacks. Code is available at https://github.com/KaiyuanZh/FLIP.

Discussion (0). Sign in to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. FedBAP: Backdoor Defense via Benign Adversarial Perturbation in Federated Learning

    cs.CR 2025-07 conditional novelty 4.0 of 10

    FedBAP defends federated learning against backdoor attacks by reverse-engineering trigger-like patterns and training clients to ignore them, reporting attack success rates below 3% in experiments.

Pith tools