Backdoors Leave Structural Traces: FedMAST for Backdoor Detection and Containment in Federated Learning

📅 2026-09-04
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the challenge that stealthy backdoor attacks in federated learning evade detection by single-signal defenses. To this end, we propose FedMAST, a defense framework integrating multi-axis structural tracing, squeeze-pair coherence scoring, and signed spectral drift tracking. By synergistically capturing coupled feature distortions and persistent directional shifts across structural, spectral, and historical dimensions, FedMAST suppresses malicious updates through a hierarchical filtering mechanism. Experimental results demonstrate that FedMAST reduces the average attack success rate to 1.51% while maintaining a main-task accuracy of 94.84%, significantly outperforming existing baseline methods.
📝 Abstract
Federated learning enables distributed training without requiring clients to share their raw data. However, its reliance on the integrity of the client-submitted updates exposes the global model to stealthy backdoor poisoning. Existing defenses often rely on individual evidence sources, but stealth-constrained attacks can adapt to these signals. Such attacks can suppress anomaly signals they are optimized to evade, yet their poisoned updates still leave residual structural traces. We propose FedMAST, a Federated Multi-Axis Structural Tracing defense for backdoor detection in federated learning. FedMAST scores client updates using complementary structural, spectral, and historical evidence and then applies tiered filtering and round-level containment to limit adversarial influence. To capture traces that isolated signals may miss, FedMAST uses squeeze-pair coherence scoring to expose coupled feature distortions and signed spectral-drift tracking to reveal persistent directional changes over time. Across six backdoor attacks, FedMAST achieves lower attack success rate (ASR) than baseline defenses in all nine evaluated comparisons, averaging 1.51% ASR and 94.84% main-task accuracy (MTA) across the complete 200-round runs. Over the full 200-round method-aware CovertLayers run, FedMAST achieves 1.53% ASR and 92.26% MTA, compared with ASRs of 100.00%, 99.67%, 99.53%, and 32.84% for FedAvg, MultiKrum, AlignIns, and FLAME, respectively.
Problem

Research questions and friction points this paper is trying to address.

Federated Learning
Backdoor Attack
Poisoning Defense
Stealthy Attack
Anomaly Detection
Innovation

Methods, ideas, or system contributions that make the work stand out.

Federated Learning
Backdoor Detection
Multi-Axis Structural Tracing
Spectral Drift Tracking
Squeeze-Pair Coherence
🔎 Similar Papers
No similar papers found.
S
Srinivasan Subramanian
Department of Computer Science, Kennesaw State University, Marietta, USA
M
Md. Abdullah Al Hafiz Khan
Department of Computer Science, Kennesaw State University, Marietta, USA
Kazi Aminul Islam
Kazi Aminul Islam
Assistant Professor of CS, Kennesaw State University
Machine LearningTrustworthy AIImage Processing