2026· IEEE Transactions on Information Forensics and Security· Vol 21, pp. 7063-7078· 0 citations· 51 references
Computer Science
Abstract
Federated Learning (FL) has emerged as a leading paradigm for privacy-preserving machine learning, yet the distributed nature of FL introduces unique security challenges, notably the threat of backdoor attacks. However, existing attack strategies face a critical limitation: reliance on end-to-end supervision creates a task-divergence that produces detectable model updates, while the use of fixed triggers is poorly aligned with FL’s evolving global model, leading to limited persistence. To address this limitation, we propose Spa, a novel framework for stealthy and persistent backdoors. Instead of creating a conflicting secondary task, Spa leverages feature-space alignment to seamlessly integrate backdoor features into the primary collaborative objective, thus ensuring stealth. Furthermore, to overcome the fixed-trigger challenge, Spa introduces an adversarial dynamic trigger optimization that mines the current global model for intrinsic vulnerabilities. This creates an adaptive trigger that co-evolves with the learning process, ensuring both efficacy and persistence. Extensive experiments demonstrate that Spa achieves high attack success rates (nearly 100%) with minimal impact on model utility, maintains robustness under data heterogeneity, and exhibits persistence (remains effective around 900 FL rounds after stop attacking), outperforming conventional techniques. Our results highlight the importance of further investigation into this new class of emerging threats and emphasize the need for advanced, feature-level defense techniques.
Federated Learning (FL) inherently preserves privacy but remains highly vulnerable to backdoor attacks due to its open participation architecture. Existing defenses face two fundamental limitations: first, screening-based aggregation strategies prove ineffective against advanced cross-round attacks where adversaries progressively poison model parameters through multi-round collaboration; second, mitigation techniques often cause significant accuracy degradation due to the deep entanglement between backdoor and primary task parameters. To address these challenges, we propose Fed-CBE, a novel client-side defense algorithm that eliminates backdoors through three synergistic mechanisms: 1) periodic alternating layer resetting disrupts deep parameters to dismantle cross-round backdoor accumulation; 2) indiscriminate forgetting employs entropy maximization on non-ground-truth classes to decouple backdoor associations without prior trigger knowledge; and 3) knowledge distillation with historical local models restores primary task performance. Extensive evaluations on three benchmark datasets and model architectures demonstrate that Fed-CBE achieves highly competitive robustness, limiting attack success rates to near-zero levels in most settings and keeping them exceptionally low even under high malicious-client ratios without compromising primary task performance, significantly outperforming existing defenses.
Chun-Hai Li, Yun-Hui Shen, Ming Xie et al.· IEEE Transactions on Informa...· 0 citations
Existing Federated Learning (FL) backdoor attacks commonly employ round-wise proximity strategies, dynamically adapting malicious updates to mimic benign ones in order to evade detection. However, such adaptive mechanisms often introduce instability, increase computational overhead, and create temporal patterns that make attacks more detectable. This work presents a theoretical analysis of how attack configurations affect the disparity between benign and malicious model updates. We derive a two-sided bound on the parameter divergence between benign and backdoored local models, characterizing both an upper bound that governs detectability under defense, and a matching lower bound that exposes an irreducible label-flip signal no trigger optimization can eliminate. Guided by these insights, we propose PREFed, a static-anchor backdoor attack framework that leverages the clean data distribution to optimize trigger patterns under standard training configurations. PREFed eliminates the need for round-wise adaptation by pre-optimizing triggers before training, effectively reducing local training overhead and enhancing attack stability and stealth. Comprehensive evaluations on image classification benchmarks demonstrate that PREFed consistently outperforms three state-of-the-art attacks across six advanced defense mechanisms; cross-domain experiments on SST-2 further confirm the generality of the framework. It achieves over 80% backdoor accuracy within five communication rounds while reducing main task accuracy by less than 2%, compared to more than 15% degradation in prior methods. These results validate PREFed as an efficient and stealthy backdoor attack paradigm for practical federated learning environments.
Xi Chen, Rui Zeng, Chun-Yi Zhou et al.· IEEE Transactions on Informa...· 0 citations
FedPurify is a framework that performs post-training data-free purification to remove malicious backdoors while preserving task-relevant knowledge in FL, and combines contrastive feature alignment with knowledge-preserving self-distillation to remove backdoor effects while preserving benign task performance.
Baolu Xue, Hanyuan Zheng, Tianxing Man et al.· Proceedings of the 32nd ACM...· 0 citations
A novel backdoor attack method, termed Federated Generative Adversarial Trigger (FedGAT), which adopts a Generative Adversarial Network (GAN) framework, and can automatically produce optimized triggers that are highly correlated with the global model’s feature space, effectively reducing the “loss” in backdoor transfer and improving attack performance.
Tao Liu, Ji-Guang Lv, D. Man et al.· Cybersecurity· 0 citations
FedRGD is a federated risk-guided dynamic defense framework that enables efficient fine-grained protection against backdoor attacks in non-IID environments, and combines feature inconsistency detection with lightweight masking and robust aggregation to achieve both accuracy and efficiency.
Rui-Ying Wang· Poster Volume 0008 The 2026...· 0 citations
BackDFL is presented, a unified benchmark for systematically evaluating DFL under realistic and adaptive backdoor attacks, and demonstrates that both state-of-the-art Byzantine-robust DFL methods and adapted FL backdoor defenses fail under modest malicious participation rates, especially in heterogeneous settings.
M. Bouchiha, Gregory Blanc, Yu-Fei Han· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.