arXiv:2511.19248cs.CRcs.CV2025-11

联邦学习测试时个性化遭毒化攻击,模型性能大幅下降。

FedPoisonTTP: A Threat Model and Poisoning Attack for Federated Test-Time Personalization

  • 通过对抗查询构建代理模型,生成可逃过过滤的毒化数据。
  • 在视觉基准上,攻击使整体测试性能显著下降。
  • 适合关注联邦学习安全与防御的研究者阅读。

联邦学习中的测试时个性化允许客户端模型在部署阶段在线适应本地域变化,提升鲁棒性与个性化。然而,现有工作大多忽视了测试时本地适配带来的安全风险。异构域到达、多样的适应算法及有限的跨客户端可见性,使得受损参与者能构造毒化输入并提交对抗性更新,破坏全局与各客户端性能。为此,我们提出 FedPoisonTTP,一个现实的灰盒攻击框架,探索联邦适配场景下的测试时数据中毒。该方法从对抗查询中提取代理模型,利用特征一致性合成分布内毒化样本,并优化攻击目标生成高熵或类别置信毒化样本,以逃避常见适应过滤机制。这些毒化样本在本地适配过程中注入,并通过协作更新传播,导致广泛性能退化。在损坏的视觉基准上的大量实验表明,受损参与者可显著降低整体测试时性能。

原文摘要 · Abstract (English)

Test-time personalization in federated learning enables models at clients to adjust online to local domain shifts, enhancing robustness and personalization in deployment. Yet, existing federated learning work largely overlooks the security risks that arise when local adaptation occurs at test time. Heterogeneous domain arrivals, diverse adaptation algorithms, and limited cross-client visibility create vulnerabilities where compromised participants can craft poisoned inputs and submit adversarial updates that undermine both global and per-client performance. To address this threat, we introduce FedPoisonTTP, a realistic grey-box attack framework that explores test-time data poisoning in the federated adaptation setting. FedPoisonTTP distills a surrogate model from adversarial queries, synthesizes in-distribution poisons using feature-consistency, and optimizes attack objectives to generate high-entropy or class-confident poisons that evade common adaptation filters. These poisons are injected during local adaptation and spread through collaborative updates, leading to broad degradation. Extensive experiments on corrupted vision benchmarks show that compromised participants can substantially diminish overall test-time performance.

联邦学习安全攻防测试时个性化数据毒化

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。