Chameleon: Adapting to Peer Images for Planting Durable Backdoors in Federated Learning
Yanbo Dai, Songze Li
Abstract
In a federated learning (FL) system, distributed clients upload their local models to a central server to aggregate into a global model. Malicious clients may plant backdoors into the global model through uploading poisoned local models, causing images with specific patterns to be misclassified into some target labels. Backdoors planted by current attacks are not durable, and vanish quickly once the attackers stop model poisoning. In this paper, we investigate the connection between the durability of FL backdoors and the relationships between benign images and poisoned images (i.e., the images whose labels are flipped to the target label during local training). Specifically, benign images with the original and the target labels of the poisoned images are found to have key effects on backdoor durability. Consequently, we propose a novel attack, Chameleon, which utilizes contrastive learning to further amplify such effects towards a more durable backdoor. Extensive experiments demonstrate that Chameleon significantly extends the backdoor lifespan over baselines by , for a wide range of image datasets, backdoor types, and model architectures.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4c6d817c-4296-42e5-b9e0-8d5a6de2679aCited by top-tier papers11
- FedGame: A Game-Theoretic Defense against Backdoor Attacks in Federated LearningJinyuan Jia, Zhuowen Yuan, Dinuka Sahabandu, Luyao Niu et al.NeurIPS 2023 · 32 citations
- BackdoorIndicator: Leveraging OOD Data for Proactive Backdoor Detection in Federated LearningSongze Li, Yanbo DaiUSENIX Security 2024 · 31 citations
- MARS: A Malignity-Aware Backdoor Defense in Federated LearningWei Wan, Yuxuan Ning, Zhicong Huang, Cheng Hong et al.NeurIPS 2025 · 16 citations
- FedAA: A Reinforcement Learning Perspective on Adaptive Aggregation for Fair and Robust Federated LearningJialuo He, Wei Chen, Xiaojin ZhangAAAI 2025 · 12 citations
- DataStealing: Steal Data from Diffusion Models in Federated Learning with Multiple TrojansYuan Gan, Jiaxu Miao, Yi YangNeurIPS 2024 · 5 citations
Builds on15
- A Simple Framework for Contrastive Learning of Visual RepresentationsTing Chen, Simon Kornblith, Mohammad Norouzi, Geoffrey E. HintonICML 2020 · 24,064 citations
- Supervised Contrastive LearningPrannay Khosla, Piotr Teterwak, Chen Wang, Aaron Sarna et al.NeurIPS 2020 · 7,049 citations
- Inverting Gradients - How easy is it to break privacy in federated learning?Jonas Geiping, Hartmut Bauermeister, Hannah Dröge, Michael MoellerNeurIPS 2020 · 1,822 citations
- Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated LearningMilad Nasr, Reza Shokri, Amir HoumansadrS&P 2019 · 1,778 citations
- Trojaning Attack on Neural NetworksYingqi Liu, Shiqing Ma, Yousra Aafer, Wen-Chuan Lee et al.NDSS 2018 · 1,377 citations
Related papers
- Neurotoxin: Durable Backdoors in Federated LearningZhengming Zhang, Ashwinee Panda, Linyue Song, Yaoqing Yang et al.ICML 2022 · 209 citations
- IBA: Towards Irreversible Backdoor Attacks in Federated LearningThuy Dung Nguyen, Tuan Nguyen, Anh Tran, Khoa D. Doan et al.NeurIPS 2023 · 94 citations
- 3DFed: Adaptive and Extensible Framework for Covert Backdoor Attack in Federated LearningHaoyang Li, Qingqing Ye, Haibo Hu, Jin Li et al.S&P 2023
- A3FL: Adversarially Adaptive Backdoor Attacks to Federated LearningHangfan Zhang, Jinyuan Jia, Jinghui Chen, Lu Lin et al.NeurIPS 2023 · 102 citations
- Mind the Cost of Scaffold! Benign Clients May Even Become Accomplices of Backdoor AttackXingshuo Han, Xuanye Zhang, Xiang Lan, Haozhao Wang et al.ICCV 2025 · 1 citation
