Adaptive Layered-Trust Robust Defense Mechanism for Personalized Federated Learning
He Wang, Zhen Xu, Yan Zhang, Yu Wang
Abstract
Personalized Federated Learning (PFL) is confronted with escalating security threats, yet existing defense strategies primarily concentrate on traditional federated learning, lacking robust defense mechanisms tailored for PFL. To fortify the robustness of PFL against stealthy malicious attacks, we propose an adaptive layered-trust robust defense mechanism, PFL-ALB. Firstly, we employ a layer gradient parameter similarity matrix to detect the malicious parameters of advanced stealthy backdoor attacks, and then conduct layer-wise robust aggregation on the server to enhance the robustness of the global model. Subsequently, we propose a client-adaptive personalized layering method, which adaptively partitions each client’s model into personalized and shared layers. This approach balances accuracy and robustness under heterogeneous data conditions while mitigating the impact of malicious attacks. Experimental results demonstrate that PFL-ALB significantly enhances robustness (with ASR remarkably reduced to within 1%-10%) under three types of advanced stealthy backdoor attacks and exhibits superior performance compared to existing defense schemes.
BibTeX
@inproceedings{icassp2025_adaptivelayeredt,
title = {Adaptive Layered-Trust Robust Defense Mechanism for Personalized Federated Learning},
author = {He Wang and Zhen Xu and Yan Zhang and Yu Wang},
booktitle = {ICASSP 2025},
year = {2025}
}