Malicious Forgetting: Backdoor Injection in Active Federated Unlearning and Countermeasure Design
Wenwei Zhao, Yuanzhe Peng, Xiaowen Li, Jie Xu, Yao Liu, Zhuo Lu
Abstract
Federated learning (FL) enables collaborative model training without sharing raw data, but also raises increasing demands for the right to be forgotten. To support data erasure, active federated unlearning (FU) allows clients to actively remove their data’s influence from the model. We reveal a critical and overlooked threat: malicious clients can pose as privacy-concerned users requesting to unlearn some of their data, while secretly preparing backdoor attacks during training. We propose FUsion backdoor, a subnetwork-based attack that stealthily constructs a compact backdoor subnetwork from trigger-sensitive units within backdoor-critical layers during training, and rapidly fuses it during the limited rounds of unlearning. FUsion backdoor achieves up to 99% backdoor success rate across diverse datasets and FU methods. We also develop a detection method that captures directional subspace deviations introduced by coordinated backdoor updates, achieving high attack detection accuracy.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 890d7215-0cd9-4f7b-9eb5-9fe5f19d23f3Related papers
- REMISVFU: Vertical Federated Unlearning via Representation Misdirection for Intermediate Output FeatureWenhan Wu, Zhili He, Huanghuang Liang, Yili Gong et al.AAAI 2026
- Unlearning through Knowledge Overwriting: Reversible Federated Unlearning via Selective Sparse AdapterZhengyi Zhong, Weidong Bao, Ji Wang, Shuai Zhang et al.CVPR 2025
- Retaliatory Attacks Against Federated Unlearning via Data LeakageXinyi Sheng, Wei Bao, Hequn Wang, Yuqin Liu et al.AAAI 2026
- IBA: Towards Irreversible Backdoor Attacks in Federated LearningThuy Dung Nguyen, Tuan Nguyen, Anh Tran, Khoa D. Doan et al.NeurIPS 2023 · 94 citations
- Backdoor Attacks via Machine UnlearningZihao Liu, Tianhao Wang, Mengdi Huai, Chenglin MiaoAAAI 2024 · 46 citations
