English

On Hyperparameters and Backdoor-Resistance in Horizontal Federated Learning

Cryptography and Security 2025-09-09 v2

Abstract

Horizontal Federated Learning (HFL) is particularly vulnerable to backdoor attacks as adversaries can easily manipulate both the training data and processes to execute sophisticated attacks. In this work, we study the impact of training hyperparameters on the effectiveness of backdoor attacks and defenses in HFL. More specifically, we show both analytically and by means of measurements that the choice of hyperparameters by benign clients does not only influence model accuracy but also significantly impacts backdoor attack success. This stands in sharp contrast with the multitude of contributions in the area of HFL security, which often rely on custom ad-hoc hyperparameter choices for benign clients\unicodex2013\unicode{x2013}leading to more pronounced backdoor attack strength and diminished impact of defenses. Our results indicate that properly tuning benign clients' hyperparameters\unicodex2013\unicode{x2013}such as learning rate, batch size, and number of local epochs\unicodex2013\unicode{x2013}can significantly curb the effectiveness of backdoor attacks, regardless of the malicious clients' settings. We support this claim with an extensive robustness evaluation of state-of-the-art attack-defense combinations, showing that carefully chosen hyperparameters yield across-the-board improvements in robustness without sacrificing main task accuracy. For example, we show that the 50%-lifespan of the strong A3FL attack can be reduced by 98.6%, respectively\unicodex2013\unicode{x2013}all without using any defense and while incurring only a 2.9 percentage points drop in clean task accuracy.

Keywords

Cite

@article{arxiv.2509.05192,
  title  = {On Hyperparameters and Backdoor-Resistance in Horizontal Federated Learning},
  author = {Simon Lachnit and Ghassan Karame},
  journal= {arXiv preprint arXiv:2509.05192},
  year   = {2025}
}

Comments

To appear in the Proceedings of the ACM Conference on Computer and Communications Security (CCS) 2025

R2 v1 2026-07-01T05:23:19.013Z