arXiv:2509.12964cs.LG2025-09被引 1

针对原型联邦学习设计新型后门攻击,提升攻击成功率35%-75%。

BAPFL: Exploring Backdoor Attacks Against Prototype-based Federated Learning

  • 通过污染原型并优化触发器,误导客户端原型训练。
  • 在多个数据集上实现35%-75%的攻击成功率提升。
  • 适合关注联邦学习安全性的研究人员和系统设计者。

原型联邦学习(PFL)通过使用均值特征向量作为原型,缓解联邦学习中的数据异构问题,但其对后门攻击的鲁棒性尚未被充分研究。本文发现,由于原型学习机制和本地数据异构性,现有后门攻击对PFL效果有限。为此,提出首个专为PFL设计的后门攻击方法BAPFL,结合原型污染策略与触发器优化机制。原型污染策略改变全局原型轨迹,使良性客户端的干净样本原型远离带触发器样本原型;触发器优化机制为每个目标标签学习独特且隐蔽的触发器,引导带触发器样本原型与目标标签全局原型对齐。在多个数据集和PFL变体上的实验表明,相比传统攻击,BAPFL攻击成功率提升35%-75%,同时保持主任务准确率。结果验证了BAPFL的有效性、隐蔽性和适应性。

原文摘要 · Abstract (English)

Prototype-based federated learning (PFL) has emerged as a promising paradigm to address data heterogeneity problems in federated learning, as it leverages mean feature vectors as prototypes to enhance model generalization. However, its robustness against backdoor attacks remains largely unexplored. In this paper, we identify that PFL is inherently resistant to existing backdoor attacks due to its unique prototype learning mechanism and local data heterogeneity. To further explore the security of PFL, we propose BAPFL, the first backdoor attack method specifically designed for PFL frameworks. BAPFL integrates a prototype poisoning strategy with a trigger optimization mechanism. The prototype poisoning strategy manipulates the trajectories of global prototypes to mislead the prototype training of benign clients, pushing their local prototypes of clean samples away from the prototypes of trigger-embedded samples. Meanwhile, the trigger optimization mechanism learns a unique and stealthy trigger for each potential target label, and guides the prototypes of trigger-embedded samples to align closely with the global prototype of the target label. Experimental results across multiple datasets and PFL variants demonstrate that BAPFL achieves a 35\%-75\% improvement in attack success rate compared to traditional backdoor attacks, while preserving main task accuracy. These results highlight the effectiveness, stealthiness, and adaptability of BAPFL in PFL.

联邦学习后门攻击原型学习

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。