This invention relates to a method and
system for defending against
backdoor attacks in
federated learning, belonging to the field of
information security. The method first performs data preprocessing operations on the terminal before executing local training, converting the data from the
time domain to the
frequency domain and designing a low-pass filter to filter high-frequency signals introduced by
backdoor samples. Second, malicious uploads and updates are detected on the
server side, the
cosine similarity between the pre-
global model and the local model is calculated, and an appropriate threshold is set to filter maliciously uploaded local model updates. Finally, a global aggregation operation is performed on the remaining non-malicious uploads and updates to obtain an updated
global model, and
differential privacy technology is used to perturb the obtained
global model. This invention fully considers the
scenario where
backdoor attacks occur in different locations, mitigating backdoor attacks in
federated learning without affecting the model's performance on benign data, thus solving the problem of backdoor
attack defense in
federated learning.