SADBA: Self-Adaptive Distributed Backdoor Attack Against Federated Learning
Jun Feng, Yuzhe Lai, Hong Sun, Bocheng Ren
Abstract
Backdoor attacks in federated learning (FL) face challenges such as lower attack success rates and compromised main task accuracy (MA) compared to local training. Existing methods like distributed backdoor attack (DBA) mitigate these issues by modifying malicious clients' updates and partitioning global triggers to enhance backdoor persistence and stealth. The recent full combination backdoor attack (FCBA) further improves backdoor efficiency with a full combination strategy. However, these methods are mainly applicable in small-scale FL. In large-scale FL, small trigger patterns weaken impact, and scaling them requires controlling exponentially more clients, which poses significant challenges, while simply reverting to DBA may decrease backdoor performance. To overcome these challenges, we propose the self-adaptive distributed backdoor attack (SADBA), which achieves similar performance to FCBA with a lower percentage of malicious clients (PMC). It also adapts more flexibly through an optimized model poisoning strategy and a self-adaptive data poisoning strategy. Experiments demonstrate SADBA outperforms state-of-the-art methods, achieving higher or comparable backdoor performance and MA across various datasets with limited PMC.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4df434e9-0527-4f6c-99cd-022366af6a0fCited by top-tier papers2
- TransFR: Transferable Federated Recommendation with Adapter Tuning on Pre-trained Language ModelsHonglei Zhang, Zhiwei Li, Haoxuan Li, Xin Zhou et al.AAAI 2026 · 1 citation
- Less is More: Persistent Low-Frequency Backdoor Injection in Federated LearningPei Ye, Yuqing Li, Kun He, Haoran Wang et al.INFOCOM 2026
Builds on11
- Neural Cleanse: Identifying and Mitigating Backdoor Attacks in Neural NetworksBolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li et al.S&P 2019 · 1,801 citations
- DBA: Distributed Backdoor Attacks against Federated LearningChulin Xie, Keli Huang, Pin-Yu Chen, Bo LiICLR 2020 · 901 citations
- Adversary Instantiation: Lower Bounds for Differentially Private Machine LearningMilad Nasr, Shuang Song, Abhradeep Thakurta, Nicolas Papernot et al.S&P 2021 · 288 citations
- Learn from Others and Be Yourself in Heterogeneous Federated LearningWenke Huang, Mang Ye, Bo DuCVPR 2022 · 254 citations
- Model-Reuse Attacks on Deep Learning SystemsYujie Ji, Xinyang Zhang, Shouling Ji, Xiapu Luo et al.CCS 2018 · 197 citations
Related papers
- IBA: Towards Irreversible Backdoor Attacks in Federated LearningThuy Dung Nguyen, Tuan Nguyen, Anh Tran, Khoa D. Doan et al.NeurIPS 2023 · 94 citations
- Datura: Durable and Stable Backdoor Attack against Federated LearningXiaoxue Song, Hui Xia, Shuo Xu, Yuyao Zhu et al.INFOCOM 2026
- Lurking in the shadows: Unveiling Stealthy Backdoor Attacks against Personalized Federated LearningXiaoting Lyu, Yufei Han, Wei Wang, Jingkai Liu et al.USENIX Security 2024 · 20 citations
- FFCBA: Feature-based Full-target Clean-label Backdoor AttacksYangxu Yin, Honglong Chen, Yudong Gao, Peng Sun et al.ACM MM 2025 · 1 citation
- Eliminate Distance Differences Induced by Backdoor Attacks: Layer-Selective Training and Clipping to Mask Backdoor ModelsXuzeng Li, Tao Zhang, Xiangyun Tang, JIACHENG WANG et al.CVPR 2026
