arXiv:2511.14406cs.LGcs.CR2025-11中稿 · FPS 2025

研究低秩适配对联邦学习后门攻击持久性的影响,发现越低秩越难清除后门。

Watch Out for the Lifespan: Evaluating Backdoor Attacks Against Federated Model Adaptation

  • 通过实验分析LoRA秩对后门攻击持久性的影响
  • 低秩设置下后门存活时间显著更长
  • 为联邦学习安全评估提供新基准,适合安全研究人员

大型模型通过联邦学习(FL)进行适应性调整,广泛应用于各类场景,其依赖参数高效微调技术如低秩适配(LoRA)。然而,这种分布式学习范式面临多重安全威胁,尤其是完整性威胁,例如攻击者在部分客户端的本地训练阶段注入后门行为。本文首次分析了LoRA对针对联邦模型适配的前沿后门攻击的影响。重点考察后门寿命这一关键特性,其持续时间受攻击场景和攻击者注入能力影响。实验发现,在最优注入条件下,洛拉秩越低,后门在攻击结束后持续时间越长。本工作揭示了联邦学习中后门攻击评估的潜在问题,推动更鲁棒、公平的评估方法发展,提升关键联邦学习系统风险评估的可靠性。代码已公开。

原文摘要 · Abstract (English)

Large models adaptation through Federated Learning (FL) addresses a wide range of use cases and is enabled by Parameter-Efficient Fine-Tuning techniques such as Low-Rank Adaptation (LoRA). However, this distributed learning paradigm faces several security threats, particularly to its integrity, such as backdoor attacks that aim to inject malicious behavior during the local training steps of certain clients. We present the first analysis of the influence of LoRA on state-of-the-art backdoor attacks targeting model adaptation in FL. Specifically, we focus on backdoor lifespan, a critical characteristic in FL, that can vary depending on the attack scenario and the attacker's ability to effectively inject the backdoor. A key finding in our experiments is that for an optimally injected backdoor, the backdoor persistence after the attack is longer when the LoRA's rank is lower. Importantly, our work highlights evaluation issues of backdoor attacks against FL and contributes to the development of more robust and fair evaluations of backdoor attacks, enhancing the reliability of risk assessments for critical FL systems. Our code is publicly available.

联邦学习后门攻击安全评估低秩适配

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。