揭露垂直联邦学习后门攻击研究与实际应用间的巨大差距
Understanding Backdoor Vulnerabilities in Vertical Federated Learning: The Gap Between Research and Practice

- 重构真实场景下的攻击模型,揭示现有方法依赖不现实假设
- 提出新评估基准BVBench,发现多数攻击在实际中难以成功
- 适合关注联邦学习安全落地的研究者和系统设计者
垂直联邦学习(VFL)使拥有共享实体互补特征的组织可在不暴露本地数据的前提下协作建模。然而,这种信息不对称也带来了安全隐患。后门攻击尤为严重:恶意参与方可在训练中污染模型,并在推理时激活以操纵预测。尽管已有研究声称攻击成功率接近100%并提出有效防御,我们发现这些结论大多无法在真实条件下复现,暴露出研究与实践之间的根本性鸿沟。本文开展系统性、面向实践的研究,揭示现有方法忽略关键现实约束,且评估方式存在缺陷。为此,我们重新定义威胁模型,提出实用的后门攻击流程,并构建了专为后门攻击设计的基准BVBench,内置当前最优基线。BVBench表明,当前对VFL后门风险的理解极为脆弱,为推动研究聚焦真实漏洞、发展有效防御提供了基础。
原文摘要 · Abstract (English)
Vertical Federated Learning (VFL) enables organizations holding complementary features of shared entities to collaborate and train models. In this setting, the initiator can withhold information about the learning task, while other contributors participate without exposing their local datasets, creating an asymmetric information structure aligned with growing privacy demands. However, this asymmetry is a double-edged sword. Among various threats, backdoor attacks are particularly concerning because VFL not only enables malicious contributors to poison the model during training, but also allows them to activate the backdoor at inference time to manipulate predictions. Although prior work has reported near-perfect attack success rates and proposed effective defenses, we find that most findings fail to hold under realistic conditions, exposing a fundamental gap between research and practice. In this paper, we present a systematic, practice-oriented study of backdoor vulnerabilities in VFL, revealing this gap in both methodological design and evaluation practices. We show that existing approaches overlook key practical constraints and therefore rely on unrealistic prior knowledge. Furthermore, these limitations have remained hidden due to poorly designed evaluation practices in the literature. To bridge this gap, we redefine threat models under realistic constraints, propose practical backdoor workflows, and introduce BVBench, a backdoor-centric benchmark that enables fair, practical, and comprehensive evaluation, preloaded with state-of-the-art baselines. BVBench provides strong evidence of the fragility of the current understanding of VFL backdoor risks and establishes a foundation for steering research toward uncovering practical vulnerabilities and developing more meaningful defenses.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。