构建统一基准,揭示去中心化联邦学习在后门攻击下的脆弱性
BackDFL: A Unified Benchmark For Backdoor Attacks and Defenses In Decentralized Federated Learning

- 设计统一评测框架,模拟真实自适应后门攻击
- 15%恶意节点即导致主流防御失效,异构环境下更严重
- 适合关注联邦学习安全的科研与工程人员
去中心化联邦学习(DFL)通过点对点模型交换替代集中式参数服务器,实现无信任协作学习。然而,这种架构转变重塑了威胁格局:缺乏全局协调聚合,使DFL极易遭受后门攻击——恶意参与者可植入持久隐藏行为,同时保持高清洁任务性能。本文指出,现有研究对DFL鲁棒性的评估严重高估。原因包括简化威胁模型、非自适应攻击者、碎片化评估协议、不一致通信拓扑及随意训练配置。为此,我们提出BackDFL,一个统一基准,系统评估真实且自适应后门攻击下的DFL表现。大量实验揭示了去中心化学习的关键失效模式:即使最先进的拜占庭鲁棒型DFL方法和适配的后门防御,在仅15%恶意参与率下也会失败,尤其在异构设置中,其鲁棒性随通信图拓扑结构差异显著变化。
原文摘要 · Abstract (English)
Decentralized Federated Learning (DFL) promises trust-free collaborative learning by replacing the centralized parameter server with peer-to-peer model exchange. However, this architectural shift fundamentally reshapes the threat landscape. Without globally coordinated aggregation, DFL becomes particularly susceptible to backdoor attacks, in which malicious participants implant persistent hidden behaviors while maintaining high clean-task performance. In this paper, we argue that the robustness of DFL has been significantly overestimated. Existing studies rely on simplified threat models, non-adaptive adversaries, fragmented evaluation protocols, inconsistent communication topologies, and ad hoc training configurations, leading to an incomplete understanding of DFL security. To address these limitations, we present BackDFL, a unified benchmark for systematically evaluating DFL under realistic and adaptive backdoor attacks. Through extensive experiments, BackDFL exposes critical failure modes of decentralized learning. Our results demonstrate that both state-of-the-art Byzantine-robust DFL methods and adapted FL backdoor defenses fail under modest malicious participation rates (as low as 15%), especially in heterogeneous settings, while their robustness varies substantially across communication graph topologies.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。