1 paper indexed here

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

HBA: Hijacking-Based Backdoor Attack for Vertical Federated Learning

Vertical federated learning (VFL) is a distributed machine learning paradigm designed for scenarios with vertically partitioned data features, making it highly compatible with Internet of Things (IoT) ecosystems. While promoting collaborative modeling among IoT devices, VFL also introduces new security risks, particularly backdoor attacks. Existing VFL backdoor attacks typically establish associations between triggers and target labels during the training phase by manipulating intermediate model outputs, making them easily detectable by advanced defense mechanisms. This article proposes a hijacking-based backdoor attack (HBA), which, for the first time, innovatively achieves a backdoor attack by exchanging the forward embeddings during the VFL prediction phase, without embedding traditional triggers. HBA leverages intrinsic semantic relationships in the embedding space to hijack the decision-making process of the top model during inference. HBA’s effectiveness depends on the discriminative nature of the features extracted by the bottom model, and since it does not alter the training process, it can evade most defense mechanisms based on training behavior monitoring. Experiments demonstrate that HBA achieves an attack success rate of 99.9% in classification tasks without compromising the original task’s accuracy. Furthermore, existing defense mechanisms struggle to effectively counter HBA without degrading the model’s original task performance.

Ping-Le Zhang, Kai Fan, Xiang Li et al. · 0 citations