NTH
AI research

Your Neighbors Know: Leveraging Local Neighborhoods for Backdoor Detection in Decentralized Learning

AuthorsSayan Biswas, Antoine Boutet, Davide Frey, Romaric Gaudel, Rachid Guerraoui, Maxime Jacovella, Anne-Marie Kermarrec, Dimitri Lerévérend, François Taïani, Martijn de Vos

May 21, 2026 3 min read
Watch on YouTube
The one-line take

Argus helps decentralized learners spot poisoned model updates by comparing suspicious triggers across neighbors, cutting backdoor attacks without needing a central server.

Key results

below 7%
CIFAR-10 ASR reduction

ARGUS cuts attack success rate on CIFAR-10 from over 70% to below 7% while keeping clean accuracy close to oracle.

near 0%
FEMNIST ASR reduction

On FEMNIST, ARGUS reduces attack success rate to near zero in the main experiments.

within 5 percentage points
Clean accuracy gap to oracle

Across the evaluated datasets, ARGUS preserves test accuracy on non-backdoored samples within 5 percentage points of an omniscient oracle.

What the paper found

This paper addresses backdoor attacks in decentralized learning, where there is no server to inspect or filter poisoned updates. The proposed defense, ARGUS, makes each honest node reverse-engineer candidate triggers from neighbor updates using a DETRIGGER-style gradient optimization on a tiny local validation set, then cross-validates those recovered triggers with second-hop neighbors using a top-k energy map and structural similarity index measure, or SSIM. The key novelty is that false-positive triggers caused by non-IID data are structurally inconsistent across nodes, while genuine backdoor triggers remain similar, so collaborative verification can reject malicious updates without knowing the trigger in advance. ARGUS also adds a trust state machine that moves neighbors from TRUSTED to SUSPECTED after 2 consecutive rejections and to EJECTED after 1 more rejection within the next 3 rounds. The paper is the first to give convergence guarantees for decentralized backdoor detection under asymmetric link failures, with a rate comparable to standard D-PSGD and explicit dependence on the honest false-positive probability pfp. On CIFAR-10 with ResNet-8, FEMNIST with a 2-layer CNN, and TinyImageNet with ResNet-18, ARGUS cuts attack success rate from over 70% to below 7% on CIFAR-10 and to near 0% on FEMNIST and TinyImageNet, while keeping clean accuracy within 5 percentage points of an omniscient oracle. Compared with Multi-Krum, BADFL, and P2PCD, its advantage grows as data heterogeneity increases.

Original abstract

Decentralized learning (DL) is an emerging machine learning paradigm where nodes collaboratively train models without a central server. However, the collaborative nature of DL makes it vulnerable to backdoor attacks, where a model is taught to behave normally on standard inputs while executing hidden, malicious actions when encountering data with specific triggers. Backdoor attacks in DL remain understudied and existing defenses often overlook DL constraints. We introduce Argus, a novel backdoor detection framework native to DL that requires neither a central coordinator nor prior knowledge of the trigger. In Argus, honest nodes locally analyze received model updates to identify potential backdoor triggers. Nodes then collectively share their triggers with their neighbors and use a structural similarity metric to separate true backdoors from false alarms induced by data heterogeneity. A key insight is that false positive triggers exhibit inconsistencies across participants while true positive ones show consistent patterns. Model updates that fail this collaborative test are rejected, and persistently malicious senders are eventually evicted. We provide the first theoretical convergence guarantees for a DL-specific backdoor detection mechanism, showing that filtering out suspicious model updates with high probability preserves a convergence rate comparable to standard DL. We implement and evaluate Argus on three standard datasets and against three state-of-the-art baselines. Across settings, Argus reduces attack success rates by up to 90 points compared to no defense, while preserving model utility within 5 percentage points of an omniscient oracle. Furthermore, the effectiveness of Argus compared to baselines improves as data heterogeneity increases.

Read the original paper