arXiv:2509.18904cs.LG2025-09

通过动态优化触发器,让后门攻击在联邦学习中更隐蔽持久。

Enhancing the Effectiveness and Durability of Backdoor Attacks in Federated Learning through Maximizing Task Distinction

  • 用极小化-最大化框架动态生成触发器,分离主任务与后门任务。
  • 在多个数据集上实现高攻击成功率,且能抵御六种防御机制。
  • 适合研究后门安全或防御机制的学者参考。

联邦学习允许多方在不共享私有数据的情况下协同训练中心模型,但其分布式特性也带来了新的攻击面。后门攻击可使攻击者在保持良性输入高准确率的同时,向全局模型植入恶意行为。现有方法通常依赖固定模式或对抗扰动作为触发器,导致主任务与后门任务紧密耦合,易被正常更新稀释,难以在联邦防御下持续存在。本文提出一种新方法,通过在极小-最大化框架内动态优化后门触发器,解耦主任务与后门任务。内层最大化中毒样本与良性样本间的性能差距,确保良性用户更新对后门影响最小;外层将自适应触发器注入本地模型。我们在计算机视觉与自然语言处理任务上评估该方法,并与六种后门攻击方法在六种防御算法下进行对比。实验表明,该方法在多种场景下均表现优异,且易于集成到现有攻击技术中。

原文摘要 · Abstract (English)

Federated learning allows multiple participants to collaboratively train a central model without sharing their private data. However, this distributed nature also exposes new attack surfaces. In particular, backdoor attacks allow attackers to implant malicious behaviors into the global model while maintaining high accuracy on benign inputs. Existing attacks usually rely on fixed patterns or adversarial perturbations as triggers, which tightly couple the main and backdoor tasks. This coupling makes them vulnerable to dilution by honest updates and limits their persistence under federated defenses. In this work, we propose an approach to decouple the backdoor task from the main task by dynamically optimizing the backdoor trigger within a min-max framework. The inner layer maximizes the performance gap between poisoned and benign samples, ensuring that the contributions of benign users have minimal impact on the backdoor. The outer process injects the adaptive triggers into the local model. We evaluate our method on both computer vision and natural language tasks, and compare it with six backdoor attack methods under six defense algorithms. Experimental results show that our method achieves good attack performance and can be easily integrated into existing backdoor attack techniques.

联邦学习后门攻击模型安全触发器优化

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。