arXiv:2507.04903cs.CRcs.AI2025-07被引 2

构建标准化基准,真实评估联邦学习后门攻击与防御效果

BackFed: An Efficient & Standardized Benchmark Suite for Backdoor Attacks in Federated Learning

  • 统一评估框架,模拟真实联邦学习场景
  • 多数据集多模型测试发现现有方法效率低、易受时间限制
  • 揭示多个攻击代码存在语义错误,性能被夸大

近年来,联邦学习中的后门攻击研究迅速发展,新攻击与防御方法层出不穷,但评估方式缺乏标准且不可靠。首先,各研究的评估设置差异巨大,许多采用不现实的威胁模型;其次,我们代码审查发现多个攻击方法的官方实现存在语义错误,人为夸大了性能表现。这些问题引发对现有方法是否真正有效的质疑。本文提出BackFed,一个旨在标准化并压力测试联邦学习后门攻击与防御的基准套件,通过在三个代表性数据集和三种不同架构上统一攻击与防御方法的评估框架,揭示现有方法的关键局限:恶意客户端常需过多训练时间和计算资源,易受服务器时间约束影响;部分防御措施导致显著精度下降或聚合开销增加。主流攻击与防御在本基准中表现有限,挑战了其先前的有效性声明。BackFed为联邦学习后门研究提供了严谨公平的评估基础。

原文摘要 · Abstract (English)

Research on backdoor attacks in Federated Learning (FL) has accelerated in recent years, with new attacks and defenses continually proposed in an escalating arms race. However, the evaluation of these methods remains neither standardized nor reliable. First, there are severe inconsistencies in the evaluation settings across studies, and many rely on unrealistic threat models. Second, our code review uncovers semantic bugs in the official codebases of several attacks that artificially inflate their reported performance. These issues raise fundamental questions about whether current methods are truly effective or simply overfitted to narrow experimental setups. We introduce \textbf{BackFed}, a benchmark designed to standardize and stress-test FL backdoor evaluation by unifying attacks and defenses under a common evaluation framework that mirrors realistic FL deployments. Our benchmark on three representative datasets with three distinct architectures reveals critical limitations of existing methods. Malicious clients often require excessive training time and computation, making them vulnerable to server-enforced time constraints. Meanwhile, several defenses incur severe accuracy degradation or aggregation overhead. Popular defenses and attacks achieve limited performance in our benchmark, which challenges their previous efficacy claims. We establish BackFed as a rigorous and fair evaluation framework that enables more reliable progress in FL backdoor research.

联邦学习后门攻击基准测试安全评估

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。