arXiv:2609.02450cs.LGcs.DC2026-09

通过掩码引导的语义触发,在去中心化联邦学习中实现隐蔽且稳定的后门攻击。

CACTUS: Mask-Guided Semantic Clean-Label Backdoors in Decentralized Federated Learning

论文配图:CACTUS: Mask-Guided Semantic Clean-Label Backdoors in Decentralized Federated Learning
图 1 · 摘自论文原文
  • 利用掩码引导的模态特异性操作,将语义对转化为定向表示偏移。
  • 在30%恶意节点下,语音任务平均攻击成功率51.2%,多模态表现最优。
  • 适用于研究去中心化联邦学习安全性的研究人员,尤其关注隐蔽后门。

联邦学习中的语义触发比合成补丁更隐蔽,但样本依赖的放置方式会削弱跨聚合轮次的后门植入效果。这一问题在去中心化联邦学习(DFL)中尤为严重,因拓扑依赖的同伴聚合会反复混合本地模型。CACTUS将标签一致的语义对转化为目标导向的表示偏移。掩码引导、模态特定的操作器可隔离触发影响,跨样本耦合,并在同伴聚合前对清洁非目标嵌入进行反事实偏移。实验涵盖语音、文本、表格和图像任务,覆盖九种聚合规则。在30%恶意节点条件下,CACTUS在Speech Commands数据集上达到51.2%的平均攻击成功率(ASR),并在四种模态中的三种上实现最高平均ASR。敏感性分析表明,攻击成功率随网络拓扑变化,且随恶意节点比例上升而增加。结果表明,CACTUS可在重复的去中心化聚合中传播后门。

原文摘要 · Abstract (English)

Semantic triggers in federated learning (FL) can be less conspicuous than synthetic patches, but sample-dependent placement may weaken backdoor implantation across aggregation rounds. This challenge is compounded in decentralized FL (DFL), where topology-dependent peer aggregation repeatedly mixes local models. CACTUS converts label-consistent semantic pairs into target-directed representation shifts. Mask-guided, modality-specific operators isolate trigger effects, couple them across samples, and apply the shifts counterfactually to clean non-target embeddings before peer aggregation. Experiments cover speech, text, tabular, and image tasks under nine aggregation rules. With 30\% malicious nodes, CACTUS reaches a nine-rule mean attack success rate (ASR) of 51.2\% on Speech Commands and the highest nine-rule mean ASR among evaluated attacks on three of four modalities. Sensitivity analyses show that ASR varies with network topology and increases with the malicious-node ratio. These results indicate that CACTUS can propagate backdoors through repeated DFL aggregation.

联邦学习后门攻击去中心化语义触发

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。