Federal learning back door defense method based on inter-wheel track credibility

By employing a cross-wheel trajectory credibility mechanism and dynamic weight adjustment, the problem of malicious attacks being difficult to identify in the RSSI indoor positioning federated learning system is solved, thereby improving the system's security and stability and ensuring positioning accuracy and privacy protection.

CN121815272APending Publication Date: 2026-04-07LANZHOU JIAOTONG UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-01-29
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

Existing defense methods struggle to accurately distinguish between model update shifts caused by environmental noise and disturbances caused by malicious attacks in RSSI indoor positioning federated learning systems, leading to a decline in global model security and stability. In particular, under conditions of high noise and non-independent identical distribution, attacks from malicious clients are difficult to identify.

Method used

By constructing a cross-cycle trajectory credibility mechanism, combining historical credibility and penalty correction, the server monitors the client's multi-round training behavior, uses multi-dimensional behavior index vectors and credibility evaluation functions to dynamically adjust the client's contribution weight, suppress the cumulative impact of malicious attacks, and adopts a robust aggregation algorithm to switch defense modes when the attack risk is high.

Benefits of technology

It achieves accurate identification and cumulative suppression of malicious attacks, improves the security and stability of indoor positioning federated learning systems in non-independent and identically distributed environments, reduces false detection rate, ensures the convergence and positioning accuracy of the global model, and avoids the risk of privacy leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121815272A_ABST
    Figure CN121815272A_ABST
Patent Text Reader

Abstract

The invention discloses a federated learning backdoor defense method based on inter-wheel track credibility, relates to the technical field of federated learning and network security, and aims to map short-term update fluctuation of a client into inter-wheel accumulatable credit attenuation by introducing a penalty correction mechanism taking historical credibility as an independent variable. And the effective contribution amplitude of the model update vector in the aggregation stage is dynamically constrained, so that the cumulative injection influence of the malicious client in multiple rounds of training is inhibited. And the server further adaptively allocates aggregation weights based on the comprehensive credibility, and switches to a robust aggregation mode to update the global model when detecting that trajectory distribution is abnormal. According to the method, extra clean data of the server side is not needed, stable suppression of the backdoor attack is realized in RSSI noise and non-IID scenes, and the security and stability of an indoor positioning federated learning system are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the fields of federated learning and cybersecurity technology, specifically a federated learning backdoor defense method based on cross-wheel trajectory credibility. Background Technology

[0002] With the continuous development of wireless communication and smart terminal technologies, indoor positioning technology based on Wi-Fi Received Signal Strength Indicator (RSSI) has been widely used in smart buildings, commercial navigation, public safety, and asset management due to its advantages such as low deployment cost, wide coverage, and low requirements for terminal devices. To further improve indoor positioning accuracy, machine learning models have been gradually introduced in recent years to model and infer RSSI fingerprint data. In practical applications, indoor positioning systems typically involve multiple terminal devices, and the collected data has strong privacy sensitivity. Federated learning, as a distributed machine learning framework, can achieve collaborative model training among multiple clients without centralizing the original data, thus balancing model performance and data privacy protection to a certain extent. Therefore, federated learning is gradually being applied to the training process of RSSI-based indoor positioning models.

[0003] However, compared to common data modalities such as images and speech, RSSI data is characterized by high noise, strong sparsity, and high sensitivity to environmental changes. Multipath effects, occlusion variations, and pedestrian movement in indoor environments can all cause significant fluctuations in RSSI measurements across different times and spatial locations. In federated learning scenarios, because clients are typically distributed across different floors, areas, or building structures, their local data distribution often exhibits a clear non-independent and identically distributed characteristic. This results in significant differences in the magnitude and direction of model updates uploaded by normal clients, leading to highly volatile and unstable model updates received by the server.

[0004] During federated learning training, malicious clients may inject specific perturbations into the model through backdoor attacks, inducing the model to output attack targets under specific triggering conditions. To address this security issue, existing defense methods typically detect abnormal updates based on information such as distance between model updates, statistical distribution characteristics, or directional consistency, and remove or downweight suspicious updates during the aggregation phase. However, in RSSI indoor positioning tasks, normal client updates already exhibit significant natural fluctuations. Defense strategies based on single-round model update similarity or fixed discrimination thresholds struggle to accurately distinguish update offsets caused by environmental noise from structured perturbations resulting from malicious attacks.

[0005] Furthermore, some backdoor attacks can be implemented through gradual injection over multiple rounds or concentrated triggering in specific rounds, making it difficult for defense methods relying solely on single-round training behavior to identify malicious clients in a timely and stable manner. In application scenarios with high RSSI noise, abnormal updates from malicious clients are more easily masked by fluctuations in normal clients, further reducing the effectiveness of existing defense methods. Therefore, there is still a need for a backdoor attack defense method that can combine RSSI data characteristics to comprehensively characterize client multi-round training behavior and dynamically adjust client contributions during federated learning aggregation, in order to improve the security and stability of indoor positioning federated learning systems in non-independent and identically distributed environments. Summary of the Invention

[0006] To address the problem that existing indoor positioning federated learning systems based on Wi-Fi Received Signal Strength Indication (RSSI) suffer from difficulties in reliably distinguishing between normal and malicious model updates due to factors such as non-independent and identically distributed data distribution (non-IID), significant environmental noise, and backdoor attacks by malicious clients, which affect the security and stability of the global model, this invention proposes a federated learning backdoor attack defense method.

[0007] The inventors further discovered that under RSSI high noise and non-IID conditions, the single-round model update of a normal client naturally exhibits significant fluctuations in amplitude and direction. Backdoor perturbations from malicious clients can be masked by these natural fluctuations, making it difficult for defense strategies based solely on single-round update similarity, distance thresholds, or fixed statistical discrimination to achieve stable and repeatable discrimination results. Therefore, this invention transforms the defense objective from "single-round anomaly detection" to "cross-round training behavior trajectory credibility modeling and contribution constraints." By using historical credibility and penalty correction mechanisms, the operational space of suspicious clients in multi-round federated interactions is gradually compressed, thereby suppressing the cumulative injection of backdoors. Unlike existing defense methods based on single-round gradient similarity, reference gradients, or instantaneous statistical features, this invention constructs a client behavior trajectory constraint mechanism for RSSI high noise environments. This mechanism, through the coupling of historical credibility and penalty correction, explicitly introduces the behavioral stability of the client across multiple communication rounds into the evolution process of the aggregation weights, ensuring that even if backdoor attacks employ progressive injection or cross-round camouflage strategies, their cumulative impact will be continuously suppressed by the historical trajectory model. This cross-wheel trajectory constraint characteristic is the core technical feature that distinguishes this invention from existing federated learning defense frameworks.

[0008] To achieve the above objectives, the present invention adopts the following technical solution. On the one hand, this invention provides a federated learning backdoor defense method based on cross-wheel trajectory credibility, including: S1. The server distributes the global model to multiple clients. The clients train the model based on their local data and upload the updated vectors to their local models. and end-to-end training time To the server, wherein the local data is an indoor WiFi RSSI signal with high noise, sparse access point distribution and floor offset characteristics; S2. The server constructs a multi-dimensional behavior index vector to characterize the client's cross-round training behavior trajectory based on the model update vector and training time information uploaded by the client. The multidimensional behavior index vector includes at least: an update magnitude for characterizing the intensity of the update perturbation, a directional consistency for characterizing the shift in the update direction, and a training time mapping value for characterizing the abnormal computation cost. S3. The server inputs the multi-dimensional behavioral indicator vector into a preset credibility evaluation function. The credibility of the client in the current training round is obtained, and the credibility evaluation function is used to obtain the credibility of the client in the current training round. A gradient perturbation mode design is proposed for RSSI noise and non-IID conditions. By weighted fusion and normalization of update amplitude, direction consistency and training time mapping values, the natural update fluctuations caused by RSSI noise and the structured perturbations generated by malicious clients are distinguished. S4. The server maintains historical statistical information for the client, which includes at least the training rounds participated in by the client. Number of times selected and historical reliability updated based on exponential moving average method And calculate the client's historical credibility based on the historical statistical information. This is used to characterize the stability and behavioral consistency of the client during multiple rounds of interaction; S5. The server applies a penalty adjustment to the current round's credibility based on historical credibility: This yields the client's overall trustworthiness, including punitive corrections. Adopting historical credibility A monotonically increasing penalty function is used as the independent variable to perform multiplicative suppression on clients with low historical stability or abnormal participation frequency. This constrains the operational space of suspicious clients in multi-round communication and reduces their impact in subsequent rounds. The penalty correction is not used for anomaly removal in a single round update, but rather to map short-term update fluctuations of clients in the context of RSSI noise into a credit decay that can accumulate across rounds. This is achieved by scaling the effective contribution of the client model update vector during the aggregation phase, ensuring that even if a historically unstable client is statistically similar to a normal client within a single round, the cumulative impact of its corresponding parameter perturbations in multi-round global model updates is continuously suppressed.

[0009] S6. The server determines the overall trustworthiness based on the client. Determine the contribution weight of each client in the model aggregation process, and perform weighted aggregation of the model update vectors uploaded by the clients based on the contribution weights to update the global model. The contribution weight It is obtained by normalizing the overall credibility to ensure the dominant role of trusted clients in global model updates; S7. The server monitors the distribution stability of the overall trustworthiness of participating clients in real time. When preset aggregation stability conditions or attack risk triggering conditions are met, the server uses a robust central value estimation algorithm to replace the weighted aggregation method for aggregating model updates, thereby improving the stability of model updates under conditions of high proportion of malicious clients participating. The distribution stability anomaly is used to indicate the existence of structured update offsets inconsistent with the RSSI noise model, serving as a criterion for backdoor attack risk.

[0010] Preferably, the specific calculation method for the multi-dimensional behavioral indicator vector in step S2 is as follows: update amplitude This is used to characterize the overall perturbation intensity of model updates in the parameter space, preferably the L2 norm of the update vector or its normalized form; directional consistency. This is used to measure the consistency between the client's update direction and the average update direction of the clients participating in this round, preferably cosine similarity or its monotonic mapping value; training time mapping value. To identify abnormal computational trajectories caused by abnormal optimization processes or attack intensity searches, it is preferable to use statistics obtained by mapping end-to-end training time to a preset interval through a monotonic normalization function.

[0011] Preferably, the calculation process of the current round credibility in step S3 includes: inputting the multi-dimensional behavior index vector into a preset nonlinear evaluation function, and through exponential normalization processing, mapping the behavioral features of different dimensions to the interval [0,1] to obtain an initial score describing the compliance of the client's single-round training behavior.

[0012] Preferably, the historical credibility modeling process in step S4 includes: using the exponential moving average algorithm, combined with the client's initial score in the current round, the historical credibility of previous rounds, and the client's cumulative selection frequency in the total training rounds, to calculate a long-term credit value that characterizes the stability of the client's cross-round training trajectory.

[0013] Preferably, the specific method of the punitive correction in step S5 is as follows: construct a monotonically increasing penalty function with the historical credibility as the independent variable; use the penalty function to perform multiplicative weighting on the credibility of the current round, and reduce the overall credibility output of clients whose historical behavior consistency is lower than a preset deviation threshold.

[0014] Preferably, the dynamic weight adjustment in step S6 specifically includes: normalizing the overall credibility of all participating clients to obtain the aggregate weight coefficients for each client, so that the contribution of malicious disturbance components during the global model update process decays in real time as their credibility decreases.

[0015] Preferably, step S6 further includes defense mode switching judgment: real-time monitoring of the distribution variance of the overall credibility of all participating clients; when the distribution variance is greater than a preset attack risk threshold, the server stops executing weighted aggregation and automatically switches to the robust central value estimation algorithm for global model update.

[0016] Preferably, the robust central value estimation algorithm includes: the median aggregation algorithm or the trimmed-mean algorithm.

[0017] Preferably, the model in the indoor positioning federated learning system is: reshaping a one-dimensional Wi-Fi RSSI signal sequence into a two-dimensional pseudo-image format, and using a convolutional neural network for spatial location mapping training.

[0018] On the other hand, the present invention provides a federated learning backdoor defense system based on cross-wheel trajectory credibility that can implement the above method, comprising: The data acquisition module is used to obtain the client model update vector and normalized training time; The feature construction module is used to generate multi-dimensional behavioral indicators that cover amplitude, direction, and computational cost. The credibility assessment module is used to calculate the overall credibility by combining single-wheel behavior characteristics with cross-wheel historical trajectories. The adaptive aggregation module is used to perform dynamic weight allocation or defense mode switching based on the comprehensive credibility to update the global model.

[0019] Compared with the prior art, the present invention has the following beneficial effects: (1) In view of the high fluctuation and non-independent identical distribution (non-IID) characteristics of RSSI signals in complex indoor environments, a three-dimensional behavioral feature vector covering amplitude, direction and time is constructed to effectively decouple the gradient natural offset caused by environmental noise and the structured disturbance caused by backdoor attack, thus solving the technical problem of high false detection rate of traditional single index defense in indoor positioning tasks.

[0020] (2) By utilizing the behavior stability assessment mechanism based on historical credibility modeling, a tracking system for long-term training trajectories of clients was established, which enabled accurate identification and cumulative suppression of intermittent attacks and small-dose injection attacks, and enhanced the robustness of the defense mechanism in identifying covert attacks.

[0021] (3) By leveraging the adaptive weight allocation and dynamic switching logic of aggregation mode driven by comprehensive credibility, the aggregation intensity is automatically adjusted without knowing the prior proportion of malicious clients, thus ensuring the global convergence and positioning accuracy stability of the indoor positioning federated learning model under unknown attack scale.

[0022] (4) The defense scheme of this invention is based entirely on observable statistics on the server side, eliminating the dependence on auxiliary verification datasets or external reference data. While reducing system storage and communication overhead, it avoids the risk of privacy leakage caused by secondary data interaction. Attached Figure Description

[0023] Figure 1 This is a flowchart illustrating the overall process of the federated learning defense method based on multidimensional behavioral indicators and historical credibility modeling in this invention. Figure 2 A schematic diagram of the overall structure of the federated learning backdoor attack defense system provided by the present invention. Detailed Implementation

[0024] The present invention will be further described below with reference to the accompanying drawings and embodiments. It should be understood that the embodiments of the present invention are only for explaining the present invention and are not intended to limit the scope of protection of the present invention; the technical features of the various embodiments can be combined with each other without conflict.

[0025] In this specification, the terms "including," "comprising," "having," etc., all mean "including but not limited to"; the term "and / or" means any combination of related objects; "first," "second," etc., are used only for distinction and do not indicate order or importance.

[0026] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0027] Example 1 A Federated Learning Backdoor Attack Defense Method Based on Multidimensional Behavioral Indicators and Historical Credibility Modeling like Figure 1 As shown, the federated learning backdoor attack defense method provided in this embodiment includes the following steps: S1. The server-side constructs the federated learning framework and initializes global model parameters. The server configures hyperparameters such as the number of clients participating in federated learning, communication rounds, and learning rate. The server determines whether to use a non-independent, identically distributed data partitioning method based on task requirements.

[0028] S2. In the t-th round of federated learning, the server sends the current global model to the selected clients. The client performs several rounds of training based on local data to obtain local model parameters. And calculate the model update vector for this round: Meanwhile, the client records the end-to-end training time from receiving the global model to completing local training and uploading the updated model. and will and Uploaded to the server.

[0029] S3. After receiving the update information uploaded by each client, the server constructs a multi-dimensional behavioral indicator vector for the client. This includes at least the following three types of indicators: 1. Update magnitude metric, used to characterize the size of model updates, is defined as follows: .

[0030] 2. Directional Consistency Metric: This metric characterizes the degree of consistency between local update direction and the overall update trend. The server calculates the average vector of all client updates in this round: And the direction consistency index is obtained by using cosine similarity: .

[0031] 3. Training time metrics, used to reflect the adequacy of the local training process and the computational resource investment. The server uses a monotonic mapping function. End-to-end time Mapped to a preset range You can choose a normalization function, a reciprocal function, or other monotonic functions, for example: .

[0032] In other embodiments, multidimensional behavioral indicators may also include model gradient sparsity, update stability, parameter statistics, etc., and the present invention does not limit these.

[0033] S4. The server will transmit behavioral indicator vectors. Input mapping function To obtain the client's current credibility in round t: .in, The function is a monotonic mapping function, which can be a simple mean, weighted average, or other linear / nonlinear combination. In some preferred embodiments, it is obtained by weighted summation of the normalized amplitude, direction consistency, and time-consuming mapping values. , in These are normalized behavioral indicators. .

[0034] S5. To characterize the client's long-term performance across multiple training rounds, the server maintains the following historical statistics for each client: (1) Participation rounds: The number of rounds the client participates in federated training; (2) Number of times selected: The number of times a client is selected into a trusted set or participates in an aggregation; (3) Reliability of exponential moving average: It is used to smooth out the performance of the most recent rounds.

[0035] After the t-th round of training, if the client participated in that round of training, then: If the client is selected as a trusted client, then: Otherwise, it can be ordered Alternatively, the current credibility level can be taken as the standardized value. The server uses a preset smoothing coefficient. Updated Exponential Moving Average: .

[0036] Based on the above statistics, the server calculates historical reliability: The selection ratio and EMA value can be combined for weighting to balance long-term selection frequency and recent performance.

[0037] S6. To mitigate the impact of long-term unstable or suspicious clients, the server applies a penalty adjustment to the current round's trustworthiness, resulting in a comprehensive trustworthiness score: ,in It is a monotonically increasing mapping function that satisfies In some examples, the following can be selected: Alternatively, a linear piecewise function, an exponential function, or a sigmoid function can be used, and the specific choice can be adjusted according to the task scenario.

[0038] S7. The server determines the overall trustworthiness based on the client. Determine the contribution weight of each client in the model aggregation process, and perform weighted aggregation of the model update vectors uploaded by the clients based on the contribution weights to update the global model. The contribution weight It is obtained by normalizing the overall credibility to ensure the dominant role of the trusted client in global model updates.

[0039] S9. When an anomaly in the overall trustworthiness distribution is detected, the number of trusted clients is insufficient, or the preset anomaly triggering conditions are met, the server enables a robust aggregation algorithm to replace the above weighted aggregation, such as Multi-Krum, Trimmed-Mean, Median aggregation, or geometric median aggregation, so as to maintain the stability and security of the global model in scenarios with high attack intensity or high anomaly ratio.

[0040] Example 2 This embodiment illustrates the specific application of the present invention in a typical indoor positioning task, demonstrating its deployability in a real federated learning training process. This embodiment uses the UJIIndoorLoc public indoor positioning dataset and a non-IID federated learning system consisting of 10 clients. It utilizes the server to enable the backdoor attack defense method provided by this invention, which uses multi-dimensional behavioral indicators and historical credibility modeling.

[0041] The UJIIndoorLoc dataset consists of Wi-Fi RSSI fingerprints from multiple buildings and floors, with each sample containing 520 RSSI measurements. To accommodate the input structure of a convolutional network, this embodiment reshapes the RSSI features into a 1×23×23 pseudo-image format. The server distributes the dataset to 10 clients based on attributes such as building, floor, and spatial region, ensuring each client holds data with a different distribution, thus creating a highly non-IID real-world application scenario. Each client contains only data from a specific building or floor, achieving the data heterogeneity common in weakly connected scenarios.

[0042] S1. Model Update Data Acquisition and Time Preprocessing In the t-th round of training, the server sends global model parameters to all clients. The client performs the following steps: 1. Receive the current model parameters from the server; 2. Perform two rounds of local training based on local non-IID data; 3. Obtain locally updated model parameters ; 4. Calculate the amount of model updates ; 5. Record the end-to-end time from receiving the model to completing training. ; 6. and Uploaded to the server.

[0043] The local training process in this embodiment does not require uploading gradients, intermediate activations, or raw data, which complies with the privacy constraints of federated learning.

[0044] S2, Construction of Multidimensional Behavioral Indicator Vectors After receiving update information from 10 clients, the server calculates 3 behavioral indicators: (1) Update magnitude indicator (L2 norm) (2) The server calculates the average update vector. and calculate (3) Training time indicators ,in Used as the base time.

[0045] S3. Current round initial credibility assessment and cross-round behavior stability modeling The server uses a non-linear mapping function to calculate the credibility score for the current round. This step compresses the multidimensional behavioral features into the [0,1] interval by performing a normal distribution statistical mapping on the update magnitude index and combining it with a weighted sum of the directional consistency index and the time mapping index. Subsequently, the server maintains the historical credibility of each client and updates the client's historical participation record: participation round. Number of times selected The historical reliability is obtained by iteratively updating the algorithm using the exponential moving average. .in, The momentum factor has a value range of [0,1] and is used to capture the stability of the client's behavior across multiple consecutive training rounds.

[0046] S4, Credibility Penalty Modification To mitigate the impact of long-term unstable clients, the server constructs a monotonically increasing penalty function to calculate the overall reliability. If the client causes an attack in a previous round, The contribution is too low, and its contribution in the current round will be... The function performs multiplicative suppression.

[0047] S5, Adaptive Weight Aggregation and Mode Switching 1. The server calculates the variance of the overall credibility of all participating clients in the current round. ; 2. Model Decision: like ( (Based on a preset risk threshold), perform adaptive weighted aggregation: , .

[0048] like If this is determined to be a strong attack scenario, the server will automatically switch to a robust centroid algorithm (such as Multi-Krum or Trimmed-Mean). Perform aggregation.

[0049] To further illustrate the applicability of the method of this invention in typical indoor positioning tasks, this embodiment constructs a federated learning environment on the UJIIndoorLoc dataset and conducts comparative tests on common defense methods. The experiments include two settings: IID scenarios and non-IID scenarios, using different robust aggregation methods as comparative examples. Table 1 presents the comparison results of classification accuracy (TA) and attack success rate (ASR) of multiple aggregation strategies under the same attack configuration.

[0050] Table 1 Comparison of Methods ; The results above demonstrate the performance differences of different methods under various data distribution conditions. This embodiment shows that, without the need for an additional clean validation set, the method of the present invention can be applied normally in a typical indoor location federated learning environment and supports the entire process of dynamic credibility modeling and robust aggregation in attack scenarios.

[0051] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.

Claims

1. A federated learning backdoor defense method based on cross-wheel trajectory credibility, characterized in that, include: S1. The server distributes the global model to multiple clients. The clients train the model based on their local data and upload the updated vectors to their local models. and end-to-end training time To the server, wherein the local data is an indoor WiFi RSSI signal with high noise, sparse access point distribution and floor offset characteristics; S2. The server constructs a multi-dimensional behavior index vector to characterize the client's cross-round training behavior trajectory based on the model update vector and training time information uploaded by the client. The multidimensional behavior index vector includes at least: an update magnitude for characterizing the intensity of the update perturbation, a directional consistency for characterizing the shift in the update direction, and a training time mapping value for characterizing the abnormal computation cost. S3. The server inputs the multi-dimensional behavioral indicator vector into a preset credibility evaluation function. The credibility of the client in the current training round is obtained, and the credibility evaluation function is used to obtain the credibility of the client in the current training round. A gradient perturbation mode design is proposed for RSSI noise and non-IID conditions. The update amplitude, direction consistency and training time mapping values ​​are weighted, fused and normalized. S4. The server maintains historical statistical information for the client, which includes at least the training rounds participated in by the client. Number of times selected and historical reliability updated based on exponential moving average method And calculate the client's historical credibility based on the historical statistical information. ; S5. The server applies a penalty adjustment to the current round's credibility based on historical credibility: This yields the client's overall trustworthiness, including punitive corrections. Adopting historical credibility The monotonically increasing penalty function is used to perform multiplicative suppression on clients with low historical stability or abnormal participation frequency, thereby constraining the operational space of suspicious clients in multi-round communication and reducing their impact in subsequent rounds. The penalty correction is not used to remove anomalies in a single round of updates, but rather to map the short-term update fluctuations of clients in the context of RSSI noise into a credit decay that can be accumulated across rounds, and is achieved by scaling the effective contribution of the client model update vector in the aggregation stage. S6. The server determines the overall trustworthiness based on the client. Determine the contribution weight of each client in the model aggregation process, and perform weighted aggregation of the model update vectors uploaded by the clients based on the contribution weights to update the global model. The contribution weight Obtained by normalization of overall credibility; S7. The server monitors the distribution stability of the overall trustworthiness of participating clients in real time. When the preset aggregation stability condition or attack risk triggering condition is met, the server uses a robust central value estimation algorithm to replace the weighted aggregation method to aggregate the model update. The distribution stability anomaly is used to indicate the existence of a structured update offset that is inconsistent with the RSSI noise model, as a criterion for backdoor attack risk.

2. The federated learning backdoor defense method based on cross-wheel trajectory credibility according to claim 1, characterized in that, The specific calculation method for the multi-dimensional behavioral indicator vector in step S2 is as follows: update amplitude This is used to characterize the overall perturbation intensity of model updates in the parameter space, preferably the L2 norm of the update vector or its normalized form; directional consistency. This is used to measure the consistency between the client's update direction and the average update direction of the clients participating in this round, preferably cosine similarity or its monotonic mapping value; training time mapping value. It is used to identify abnormal computational trajectories caused by abnormal optimization processes or attack intensity searches. Preferably, it is a statistic obtained by mapping the end-to-end training time to a preset interval through a monotonic normalization function.

3. The federated learning backdoor defense method based on cross-wheel trajectory credibility according to claim 1, characterized in that, The calculation process of the current round credibility in step S3 includes: inputting the multi-dimensional behavior index vector into a preset nonlinear evaluation function, and through exponential normalization processing, mapping the behavioral features of different dimensions to the interval [0,1] to obtain an initial score describing the compliance of the client's single-round training behavior.

4. The federated learning backdoor defense method based on cross-wheel trajectory credibility according to claim 1, characterized in that, The historical credibility modeling process in step S4 includes: using the exponential moving average algorithm, combined with the client's initial score in the current round, the historical credibility of previous rounds, and the client's cumulative selection frequency in the total training rounds, to calculate a long-term credit value that characterizes the stability of the client's cross-round training trajectory.

5. The federated learning backdoor defense method based on cross-wheel trajectory credibility according to claim 1, characterized in that, The specific method of the punitive correction in step S5 is as follows: construct a monotonically increasing penalty function with the historical credibility as the independent variable; use the penalty function to perform multiplicative weighting on the credibility of the current round, and reduce the overall credibility output of clients whose historical behavior consistency is lower than the preset deviation threshold.

6. The federated learning backdoor defense method based on cross-wheel trajectory credibility according to claim 1, characterized in that, The dynamic weight adjustment in step S6 specifically includes: normalizing the overall credibility of all participating clients to obtain the aggregate weight coefficients for each client, so that the contribution of malicious disturbance components during the global model update process decays in real time as their credibility decreases.

7. The federated learning backdoor defense method based on cross-wheel trajectory credibility according to claim 1, characterized in that, Step S6 further includes defense mode switching judgment: real-time monitoring of the distribution variance of the overall credibility of all participating clients; when the distribution variance is greater than the preset attack risk threshold, the server stops executing weighted aggregation and automatically switches to the robust central value estimation algorithm for global model update.

8. The federated learning backdoor defense method based on cross-wheel trajectory credibility according to claim 7, characterized in that, The robust central value estimation algorithm includes: Median aggregation algorithm or Trimmed-Mean algorithm.

9. The federated learning backdoor defense method based on cross-wheel trajectory credibility according to claim 1, characterized in that, The model in the indoor positioning federated learning system is as follows: a one-dimensional Wi-Fi RSSI signal sequence is reshaped into a two-dimensional pseudo-image format, and a convolutional neural network is used for spatial location mapping training.

10. A federated learning backdoor defense system based on cross-wheel trajectory credibility that can implement the method of any one of claims 1-9, characterized in that, include: The data acquisition module is used to obtain the client model update vector and normalized training time; The feature construction module is used to generate multi-dimensional behavioral indicators that cover magnitude, direction, and computational cost. The credibility assessment module is used to calculate the overall credibility by combining single-wheel behavior characteristics with cross-wheel historical trajectories. The adaptive aggregation module is used to perform dynamic weight allocation or defense mode switching based on the comprehensive credibility to update the global model.