{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/multi-metrics-adaptively-identifies-backdoors","title":"Multi-metrics adaptively identifies backdoors in Federated learning","arxiv_id":"2303.06601","date":"2023-03-12","proceeding":"ICCV 2023 1","authors":["Siquan Huang","Yijiang Li","Chong Chen","Leyu Shi","Ying Gao"],"abstract":"The decentralized and privacy-preserving nature of federated learning (FL) makes it vulnerable to backdoor attacks aiming to manipulate the behavior of the resulting model on specific adversary-chosen inputs. However, most existing defenses based on statistical differences take effect only against specific attacks, especially when the malicious gradients are similar to benign ones or the data are highly non-independent and identically distributed (non-IID). In this paper, we revisit the distance-based defense methods and discover that i) Euclidean distance becomes meaningless in high dimensions and ii) malicious gradients with diverse characteristics cannot be identified by a single metric. To this end, we present a simple yet effective defense strategy with multi-metrics and dynamic weighting to identify backdoors adaptively. Furthermore, our novel defense has no reliance on predefined assumptions over attack settings or data distributions and little impact on benign performance. To evaluate the effectiveness of our approach, we conduct comprehensive experiments on different datasets under various attack settings, where our method achieves the best defensive performance. For instance, we achieve the lowest backdoor accuracy of 3.06% under the difficult Edge-case PGD, showing significant superiority over previous defenses. The results also demonstrate that our method can be well-adapted to a wide range of non-IID degrees without sacrificing the benign performance.","url_abs":"https://arxiv.org/abs/2303.06601v2","url_pdf":"https://arxiv.org/pdf/2303.06601v2.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"multi-metrics-adaptively-identifies-backdoors","repo_url":"https://github.com/siquanhuang/Multi-metrics_against_backdoors_in_FL","is_official":1,"mentioned_in_paper":0,"mentioned_in_github":0,"framework":"pytorch","reach":null}],"tasks":[{"task_slug":"federated-learning","task_name":"Federated Learning"},{"task_slug":"privacy-preserving","task_name":"Privacy Preserving"}],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"syntology_url":null,"atlas_url":"https://app.syntology.ai/?focus=2303.06601","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2303.06601"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/siquanhuang/Multi-metrics_against_backdoors_in_FL","reach":null}],"summary":{"ran":1,"ran_honours":1,"unverified":2},"by_repo_kind":{"official":{"samples":4,"ran":2,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":4,"samples":[{"code_sha256_prefix":"67a105ecc99a548c","entry":"Defense","repo":"siquanhuang/Multi-metrics_against_backdoors_in_FL","repo_kind":"official","path":"defense.py","file_url":"https://github.com/siquanhuang/Multi-metrics_against_backdoors_in_FL/blob/HEAD/defense.py","link_basis":"first_harvest_node","language":"python","status":"ran","verification_level":1,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"67a105ecc99a548c"}},{"code_sha256_prefix":"c28d77e6d4923eba","entry":"vectorize_net","repo":"siquanhuang/Multi-metrics_against_backdoors_in_FL","repo_kind":"official","path":"defense.py","file_url":"https://github.com/siquanhuang/Multi-metrics_against_backdoors_in_FL/blob/HEAD/defense.py","link_basis":"first_harvest_node","language":"python","status":"ran_honours","verification_level":1,"contract_check":"HONOURS","metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"c28d77e6d4923eba"}},{"code_sha256_prefix":"f7ba490c746dd30f","entry":"Multi_metrics","repo":"siquanhuang/Multi-metrics_against_backdoors_in_FL","repo_kind":"official","path":"defense.py","file_url":"https://github.com/siquanhuang/Multi-metrics_against_backdoors_in_FL/blob/HEAD/defense.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"f7ba490c746dd30f"}},{"code_sha256_prefix":"cfa8b01c938d8cd8","entry":"load_model_weight","repo":"siquanhuang/Multi-metrics_against_backdoors_in_FL","repo_kind":"official","path":"defense.py","file_url":"https://github.com/siquanhuang/Multi-metrics_against_backdoors_in_FL/blob/HEAD/defense.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"cfa8b01c938d8cd8"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}