arXiv:2508.08031cs.CRcs.CV2025-08被引 2

提出新型隐蔽后门攻击,突破联邦自监督学习安全瓶颈

IPBA: Imperceptible Perturbation Backdoor Attack in Federated Self-Supervised Learning

  • 解耦后门与增强样本特征分布,提升攻击隐蔽性
  • 用Sliced-Wasserstein距离缓解分布偏移,攻击成功率超90%
  • 适合研究联邦学习安全或对抗攻击的开发者参考

联邦自监督学习(FSSL)结合了去中心化建模与无标签表征学习的优势,是极具可扩展性和隐私保护潜力的前沿范式。尽管受到广泛关注,研究发现其仍易受后门攻击。现有方法多依赖视觉明显的触发器,难以满足实际部署中的隐蔽性要求。本文提出一种针对FSSL的不可察觉且高效的后门攻击方法IPBA。实证研究表明,现有不可察觉触发器在FSSL中面临转移性差、特征与增强样本纠缠、分布外等问题,严重削弱攻击效果与隐蔽性。为克服这些挑战,IPBA通过解耦后门与增强样本的特征分布,并引入切片-沃尔瑟斯坦距离以缓解后门样本的分布外特性,优化触发器生成过程。在多个FSSL场景和数据集上的实验表明,IPBA显著优于现有攻击方法,在多种防御机制下仍保持强鲁棒性。

原文摘要 · Abstract (English)

Federated self-supervised learning (FSSL) combines the advantages of decentralized modeling and unlabeled representation learning, serving as a cutting-edge paradigm with strong potential for scalability and privacy preservation. Although FSSL has garnered increasing attention, research indicates that it remains vulnerable to backdoor attacks. Existing methods generally rely on visually obvious triggers, which makes it difficult to meet the requirements for stealth and practicality in real-world deployment. In this paper, we propose an imperceptible and effective backdoor attack method against FSSL, called IPBA. Our empirical study reveals that existing imperceptible triggers face a series of challenges in FSSL, particularly limited transferability, feature entanglement with augmented samples, and out-of-distribution properties. These issues collectively undermine the effectiveness and stealthiness of traditional backdoor attacks in FSSL. To overcome these challenges, IPBA decouples the feature distributions of backdoor and augmented samples, and introduces Sliced-Wasserstein distance to mitigate the out-of-distribution properties of backdoor samples, thereby optimizing the trigger generation process. Our experimental results on several FSSL scenarios and datasets show that IPBA significantly outperforms existing backdoor attack methods in performance and exhibits strong robustness under various defense mechanisms.

联邦学习后门攻击自监督安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。