Label-Free Backdoor Attacks in Vertical Federated Learning
Wei Shen, Wenke Huang, Guancheng Wan, Mang Ye
Abstract
Vertical Federated Learning (VFL) involves multiple clients collaborating to train a global model, with distributed features of shared samples. While it becomes a critical privacy-preserving learning paradigm, its security can be significantly compromised by backdoor attacks, where a malicious client injects a target backdoor by manipulating local data. Existing attack methods in VFL rely on the assumption that the malicious client can obtain additional knowledge about task labels, which is not applicable in VFL. In this work, we investigate a new backdoor attack paradigm in VFL, Label-Free Backdoor Attacks (LFBA), which does not require any additional task label information and is feasible in VFL settings. Specifically, while existing methods assume access to task labels or target-class samples, we demonstrate that the gradients of local embeddings reflect the semantic information of labels. It can be utilized to construct the target poison sample set. Besides, we uncover that backdoor triggers tend to be ignored and under-fitted due to the learning of original features, which hinders backdoor task optimization. To address this, we propose selectively switching poison samples to disrupt feature learning, promoting backdoor task learning while maintaining accuracy on clean data. Extensive experiments demonstrate the effectiveness of our method in various settings.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext b1d2976b-b132-4d39-88db-011e311bf2bbCited by top-tier papers4
- Backdoor Cleaning without External Guidance in MLLM Fine-tuningXuankun Rong, Wenke Huang, Jian Liang, Jinhe Bi et al.NeurIPS 2025 · 39 citations
- Unbiased Prototype Consistency Learning for Multi-Modal and Multi-Task Object Re-IdentificationZhongao Zhou, Bin Yang, Wenke Huang, Jun Chen et al.NeurIPS 2025 · 2 citations
- DoBlock: Blocking Malicious Association Propagation for Backdoor-Robust Federated Learning Under Domain SkewZhou Tan, De Li, Yirui Huang, Duanshu Fang et al.AAAI 2026
- Eliminate Distance Differences Induced by Backdoor Attacks: Layer-Selective Training and Clipping to Mask Backdoor ModelsXuzeng Li, Tao Zhang, Xiangyun Tang, JIACHENG WANG et al.CVPR 2026
Builds on26
- Attack of the Tails: Yes, You Really Can Backdoor Federated LearningHongyi Wang, Kartik Sreenivasan, Shashank Rajput, Harit Vishwakarma et al.NeurIPS 2020 · 862 citations
- Poisoning with Cerberus: Stealthy and Colluded Backdoor Attack against Federated LearningXiaoting Lyu, Yufei Han, Wei Wang, Jingkai Liu et al.AAAI 2023 · 111 citations
- IBA: Towards Irreversible Backdoor Attacks in Federated LearningThuy Dung Nguyen, Tuan Nguyen, Anh Tran, Khoa D. Doan et al.NeurIPS 2023 · 94 citations
- Secure Bilevel Asynchronous Vertical Federated Learning with Backward UpdatingQingsong Zhang, Bin Gu, Cheng Deng, Heng HuangAAAI 2021 · 81 citations
- FedCDA: Federated Learning with Cross-rounds Divergence-aware AggregationHaozhao Wang, Haoran Xu, Yichen Li, Yuan Xu et al.ICLR 2024 · 62 citations
Related papers
- BadVFL: Backdoor Attacks in Vertical Federated LearningMohammad Naseri, Yufei Han, Emiliano De CristofaroS&P 2024 · 29 citations
- VILLAIN: Backdoor Attacks Against Vertical Split LearningYijie Bai, Yanjiao Chen, Hanlei Zhang, Wenyuan Xu et al.USENIX Security 2023
- Less is More: Persistent Low-Frequency Backdoor Injection in Federated LearningPei Ye, Yuqing Li, Kun He, Haoran Wang et al.INFOCOM 2026
- FILTER: A Framework for Defending Against Backdoor Attacks in Vertical Federated LearningZhanyi Hu, Cen Chen, Yanhao WangAAAI 2026
- DBA: Distributed Backdoor Attacks against Federated LearningChulin Xie, Keli Huang, Pin-Yu Chen, Bo LiICLR 2020 · 901 citations
