Skip to content
Open access

CAEBA: A Dynamic Hidden Backdoor Attack Framework in Federated Learning

Jul 2026 · ACM Transactions on Privacy and Security · Vol 29, pp. 1 - 21 · 0 citations · 55 references

Abstract

Federated Learning (FL) is a privacy-preserving distributed learning framework, but its distributed data collection and client-side training pipeline expose the global model to backdoor attacks. Existing FL backdoor attacks often depend on fixed triggers or on update manipulations that are easier to isolate under robust aggregation and model-inspection defenses. We propose CAEBA (Conditional AutoEncoder Backdoor Attack), a dynamic hidden backdoor framework that uses a conditional autoencoder to generate target-aware and visually stealthy triggers while progressively implanting the backdoor through federated optimization. CAEBA separates the clean classifier from the trigger generator, formulates the attack as a dual-constrained objective, and updates the generator at a lower frequency than the classifier to stabilize local optimization. We evaluate CAEBA on MNIST, FashionMNIST, CIFAR-10, CIFAR-100, and Tiny-ImageNet under representative aggregation rules and defenses, including FL-Detector, RFLBAT, DeepSight, FoolsGold, and FLAME. The results show that CAEBA preserves main-task accuracy while maintaining persistent backdoor effectiveness.

Read PDF