AD-FL : adversarial defense in federated learning via attention denoising
Lucheng Chen, Bing Chen, Chenglin Zhu, Weiwei Zhai, Jifu Cui, E Yu · Connection Science · 2025
Federated learning (FL) is a typical distributed machine learning framework that can effectively protect users’ private information by only uploading model parameters to the server for training. However, FL is vulnerable to adversarial attacks, where the attacker adds imperceptible perturbations to the samples so that the adversarial examples are misclassified as other classes. Existing defense methods encounter difficulties in detecting and eliminating subtle adversarial perturbations embedded in the inputs, which makes them ineffective against adversarial examples and consequently undermines the overall performance of the model. To address such issues, this study proposes AD-FL, an effective adversarial defense method against different adversarial attacks in FL. AD-FL can mitigate the effects of adversarial attacks via leveraging the attention denoising at the local client level. To further improve the performance of the model, this paper utilizes an adaptive decision boundary strategy to control the decision boundary of federated learning training based on eliminating the effects of adversarial attacks. Extensive experiments on MNIST, Fashion-MNIST, CIFAR-10, and CIFAR-100 under various adversarial attacks, including FGSM, MI-FGSM, PGD, and AutoAttack, demonstrate that AD-FL consistently achieves higher adversarial accuracy compared with state-of-the-art defense methods, while maintaining competitive computational efficiency. Ablation studies further validate the effectiveness of each component.