arXiv:2511.09252cs.CRcs.AI2025-11

用分形结构让联邦学习后门攻击更隐蔽,大幅减少污染数据量。

Unveiling Hidden Threats: Using Fractal Triggers to Boost Stealthiness of Distributed Backdoor Attacks in Federated Learning

  • 利用分形自相似性增强子触发器特征,降低攻击所需污染数据量。
  • 仅需传统方法62.4%的污染数据,攻击成功率仍达92.3%。
  • 动态角度扰动提升隐蔽性,适合研究对抗攻击与安全防御的读者。

联邦学习中的传统分布式后门攻击通过将全局触发器分解为子触发器来提升隐蔽性,但需更多污染数据以维持攻击强度,增加暴露风险。本文提出分形触发分布式后门攻击(FTDBA),利用分形自相似性增强子触发器的特征强度,显著降低相同攻击强度下的污染体积。为应对频域和梯度域中分形结构的可检测性,引入动态角度扰动机制,自适应调节训练各阶段的扰动强度,平衡效率与隐蔽性。实验表明,FTDBA在仅使用传统方法62.4%污染数据的情况下,仍实现92.3%的攻击成功率,检测率降低22.8%,KL散度减少41.2%。该研究提出一种低暴露、高效率的联邦后门攻击范式,拓展了分形特征在对抗样本生成中的应用。

原文摘要 · Abstract (English)

Traditional distributed backdoor attacks (DBA) in federated learning improve stealthiness by decomposing global triggers into sub-triggers, which however requires more poisoned data to maintian the attck strength and hence increases the exposure risk. To overcome this defect, This paper proposes a novel method, namely Fractal-Triggerred Distributed Backdoor Attack (FTDBA), which leverages the self-similarity of fractals to enhance the feature strength of sub-triggers and hence significantly reduce the required poisoning volume for the same attack strength. To address the detectability of fractal structures in the frequency and gradient domains, we introduce a dynamic angular perturbation mechanism that adaptively adjusts perturbation intensity across the training phases to balance efficiency and stealthiness. Experiments show that FTDBA achieves a 92.3\% attack success rate with only 62.4\% of the poisoning volume required by traditional DBA methods, while reducing the detection rate by 22.8\% and KL divergence by 41.2\%. This study presents a low-exposure, high-efficiency paradigm for federated backdoor attacks and expands the application of fractal features in adversarial sample generation.

后门攻击联邦学习分形对抗样本

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。