arXiv:2603.03865cs.LGcs.AI2026-03

发现模型结构影响后门攻击效果,提出可预测攻击成功率的新方法

Structure-Aware Distributed Backdoor Attacks in Federated Learning

  • 基于模型结构特性设计分形扰动注入框架
  • 多路径融合网络能增强扰动传播,低兼容性结构则抑制攻击
  • 提出两个量化指标,可用于防御策略设计

联邦学习虽保护数据隐私,却使模型更新易受长期隐蔽扰动攻击。现有研究多关注触发设计或投毒策略,通常假设相同扰动在不同模型中表现一致,忽略了模型结构对扰动效果的影响。本文从结构感知视角分析模型架构与后门扰动间的耦合关系,引入结构响应度(SRS)和结构兼容性系数(SCC)两个指标,分别衡量模型对扰动的敏感性和对分形扰动的偏好。基于此,提出结构感知分形扰动注入框架(TFI),研究架构属性在后门注入过程中的作用。实验表明,具备多路径特征融合的网络可显著放大并保留分形扰动,即使在低投毒比例下;而结构兼容性低的模型会限制扰动有效性。进一步分析显示,SCC与攻击成功率强相关,可预测扰动存活能力。结果表明,后门行为不仅取决于扰动设计或投毒强度,更依赖于模型结构与聚合机制的交互,为结构感知防御设计提供新思路。

原文摘要 · Abstract (English)

While federated learning protects data privacy, it also makes the model update process vulnerable to long-term stealthy perturbations. Existing studies on backdoor attacks in federated learning mainly focus on trigger design or poisoning strategies, typically assuming that identical perturbations behave similarly across different model architectures. This assumption overlooks the impact of model structure on perturbation effectiveness. From a structure-aware perspective, this paper analyzes the coupling relationship between model architectures and backdoor perturbations. We introduce two metrics, Structural Responsiveness Score (SRS) and Structural Compatibility Coefficient (SCC), to measure a model's sensitivity to perturbations and its preference for fractal perturbations. Based on these metrics, we develop a structure-aware fractal perturbation injection framework (TFI) to study the role of architectural properties in the backdoor injection process. Experimental results show that model architecture significantly influences the propagation and aggregation of perturbations. Networks with multi-path feature fusion can amplify and retain fractal perturbations even under low poisoning ratios, while models with low structural compatibility constrain their effectiveness. Further analysis reveals a strong correlation between SCC and attack success rate, suggesting that SCC can predict perturbation survivability. These findings highlight that backdoor behaviors in federated learning depend not only on perturbation design or poisoning intensity but also on the interaction between model architecture and aggregation mechanisms, offering new insights for structure-aware defense design.

联邦学习后门攻击模型结构安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。