差分隐私保护下,攻击者可利用其掩蔽特性实现高成功率后门攻击。
Your Privacy My Cloak: Backdoor Attacks on Differentially Private Federated Learning

- 设计新型攻击 RING,利用差分隐私掩盖恶意更新特征
- 在四种数据集上平均攻击成功率达90.3%,比基线提升26.08倍
- 适用于多种攻击方式,暴露隐私保护与安全的深层矛盾
现有研究认为差分隐私(DP)能增强联邦学习(FL)对后门攻击的鲁棒性。本文通过实证分析两种基线攻击策略,揭示了 DP-FL 中的根本矛盾:绕过 DP 可使先进防御检测并过滤恶意更新,但遵守 DP 会隐匿其统计特征,导致现有防御失效。基于此掩蔽效应,我们提出 RING 攻击,主动利用 DP 隐蔽恶意贡献的同时最大化攻击影响。通过协作构造对抗扰动,受损客户端在聚合时重建强后门信号而不触发异常检测。RING 作为与底层攻击技术无关的扰动层,具备广泛适用性和可组合性,显著加剧威胁。在四个图像与文本数据集、非独立同分布设置下评估显示,其平均攻击成功率达 90.3%,相较基线提升最高 26.08 倍,且在中等隐私预算下仍有效。最后评估发现,缓解该威胁需付出显著性能代价,暴露了差分私有联邦学习部署中的根本安全缺口。
原文摘要 · Abstract (English)
Prior research suggests that differential privacy (DP) inherently enhances the robustness of federated learning (FL) against backdoor attacks. In this paper, we challenge this assumption. Through an empirical analysis of two baseline attack strategies, we uncover a fundamental tension in DP-FL: while bypassing DP allows state-of-the-art defenses to detect and filter malicious updates, complying with DP inadvertently masks their distinguishing statistical characteristics. Consequently, existing defenses become ineffective as DP reduces the raw backdoor signal. Building on this masking effect, we propose RING, a novel attack that explicitly exploits DP to conceal malicious contributions while maximizing attack impact. By collaboratively crafting adversarial perturbations, compromised clients reconstruct a strong backdoor signal during aggregation without triggering anomaly detection. RING operates as a perturbation layer that is agnostic to the underlying backdoor technique, making it broadly applicable and composable with existing attacks -- a property that significantly amplifies the threat it poses to DP-FL. Extensive evaluations across four image and text datasets under non-iid distributions show that RING achieves an average attack success rate of 90.3% against six state-of-the-art defenses under a moderate privacy budget, an improvement of up to 26.08x over baseline strategies. Finally, we evaluate potential countermeasures and find that mitigating this threat incurs significant utility trade-offs, exposing a fundamental security gap in the deployment of differentially private FL.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。