通过动态触发生成与特征优化,用更少恶意样本实现隐蔽的联邦学习后门攻击。
Fine-grained Distributed Backdoor Attacks in Federated Learning

- 基于图像边缘和拉普拉斯噪声生成动态触发器,降低被检测风险。
- 采用对比学习使恶意样本靠近目标类别中心,提升攻击成功率。
- 在非独立同分布场景下仍保持高攻击性能,可绕过主流防御机制。
联邦学习作为一种隐私保护的分布式机器学习范式,面临严重的后门攻击威胁。与集中式攻击相比,分布式攻击更具危害性,但需更多污染样本以弥补触发强度衰减。固定触发模式易被鲁棒聚合算法检测,增加暴露风险。为此,我们提出细粒度分布式后门攻击框架(FDBA)。该框架采用动态触发生成与嵌入向量对比学习策略,在减少污染样本的同时提升攻击效果。首先,基于图像边缘结构,利用Canny算法提取边缘特征,并注入拉普拉斯噪声;通过RGB通道分解实现分布式触发的隐秘适配,降低被发现概率。其次,引入嵌入向量对比学习机制,迫使污染样本在特征空间中趋近目标类中心,增强攻击有效性。在CIFAR-10上,针对目标攻击成功率(ASR)70%~90%的分段线性估计显示,相较DBA,FDBA将所需污染比例降低37.4%~48.4%。在极端异构的非独立同分布(Non-IID)场景下,FDBA仍保持84.7%的原始性能,而DBA下降至73.5%,且成功绕过主流防御机制。本研究为联邦学习安全提供了新视角,凸显细粒度分布式攻击的潜在威胁与防御挑战。
原文摘要 · Abstract (English)
Federated learning, as a privacy-preserving distributed machine learning paradigm, faces significant threats from backdoor attacks. Compared to centralized attacks, distributed backdoor attacks are more harmful but require more poisoned samples to compensate for the loss of trigger strength due to decomposition. Fixed trigger patterns are also easily detected by robust aggregation algorithms, increasing the risk of attack exposure. To address these challenges, we propose a fine-grained distributed backdoor attack framework (FDBA). This framework uses dynamic trigger generation and embedding vector optimization to perform attacks with fewer poisoned samples. First, we design a dynamic trigger generation method based on image edge structures using the Canny algorithm to extract edge features, which are then injected with Laplacian noise. RGB channel decomposition is applied for covert adaptation of the distributed trigger, reducing detection chances. Second, we introduce an embedding vector contrastive learning strategy that forces poisoned samples to approach the target class center in the feature space, enhancing attack effectiveness. On CIFAR-10, piecewise-linear estimates for target ASRs between 70\% and 90\% show that FDBA reduces the required poisoning ratio by 37.4\%--48.4\% compared with DBA. In non-independent and identically distributed (Non-IID) scenarios, FDBA retains 84.7\% of its IID attack performance under extreme heterogeneity, whereas DBA drops to 73.5\%, and the framework successfully bypasses mainstream defense mechanisms. This study offers new insights into federated learning security and emphasizes the potential threats and defense challenges posed by fine-grained distributed attacks.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。