Lockdown: Backdoor Defense for Federated Learning with Isolated Subspace Training

Neural Information Processing Systems 

Federated learning (FL) is vulnerable to backdoor attacks due to its distributed computing nature.