Lune

INFOCOM2026Top-tier venue

Malicious Forgetting: Backdoor Injection in Active Federated Unlearning and Countermeasure Design

Wenwei Zhao, Yuanzhe Peng, Xiaowen Li, Jie Xu, Yao Liu, Zhuo Lu

2026Year

Abstract

Federated learning (FL) enables collaborative model training without sharing raw data, but also raises increasing demands for the right to be forgotten. To support data erasure, active federated unlearning (FU) allows clients to actively remove their data’s influence from the model. We reveal a critical and overlooked threat: malicious clients can pose as privacy-concerned users requesting to unlearn some of their data, while secretly preparing backdoor attacks during training. We propose FUsion backdoor, a subnetwork-based attack that stealthily constructs a compact backdoor subnetwork from trigger-sensitive units within backdoor-critical layers during training, and rapidly fuses it during the limited rounds of unlearning. FUsion backdoor achieves up to 99% backdoor success rate across diverse datasets and FU methods. We also develop a detection method that captures directional subspace deviations introduced by coordinated backdoor updates, achieving high attack detection accuracy.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

lune papers get 890d7215-0cd9-4f7b-9eb5-9fe5f19d23f3

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines