提出新型后门攻击,可精准植入隐蔽后门并绕过现有防御。
Exploiting Layer-Specific Vulnerabilities to Backdoor Attack in Federated Learning
- 通过分析识别关键层,针对性操控神经网络特定层注入后门。
- 在多种模型和数据集上实现最高97%的攻击成功率,主任务准确率仍高。
- 揭示当前联邦学习安全框架的深层缺陷,适合安全研究者参考。
联邦学习(FL)使边缘设备在保持数据本地化的同时进行分布式模型训练,成为处理敏感用户数据协同学习的可行方案,有效缓解了集中式系统长期存在的隐私问题。然而,其去中心化特性也带来了新的安全风险,尤其是威胁模型完整性的后门攻击。本文提出一种名为层平滑攻击(LSA)的新后门攻击方法,利用神经网络中层级特异性漏洞。首先,采用层替换分析法系统识别对后门成功贡献最大的关键层(BC层)。随后,LSA针对这些关键层进行策略性操纵,以植入持久性后门,同时规避现有先进防御机制。大量实验在多种模型架构和数据集上表明,LSA在保持主任务高精度的同时,实现了高达97%的后门攻击成功率,持续绕过现代联邦学习防御体系。该研究揭示了当前联邦学习安全框架的根本性漏洞,表明未来防御需引入层级感知的检测与缓解策略。
原文摘要 · Abstract (English)
Federated learning (FL) enables distributed model training across edge devices while preserving data locality. This decentralized approach has emerged as a promising solution for collaborative learning on sensitive user data, effectively addressing the longstanding privacy concerns inherent in centralized systems. However, the decentralized nature of FL exposes new security vulnerabilities, especially backdoor attacks that threaten model integrity. To investigate this critical concern, this paper presents the Layer Smoothing Attack (LSA), a novel backdoor attack that exploits layer-specific vulnerabilities in neural networks. First, a Layer Substitution Analysis methodology systematically identifies backdoor-critical (BC) layers that contribute most significantly to backdoor success. Subsequently, LSA strategically manipulates these BC layers to inject persistent backdoors while remaining undetected by state-of-the-art defense mechanisms. Extensive experiments across diverse model architectures and datasets demonstrate that LSA achieves a remarkably backdoor success rate of up to 97% while maintaining high model accuracy on the primary task, consistently bypassing modern FL defenses. These findings uncover fundamental vulnerabilities in current FL security frameworks, demonstrating that future defenses must incorporate layer-aware detection and mitigation strategies.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。