Coupled Trigger Optimization and Vulnerable Parameter Alignment for Persistent Backdoor Attacks on Federated Learning
zhixuan ma, Haichang Gao, Shangwen Li, Ping Wang, Han Yu
Abstract
Federated learning (FL) is vulnerable to backdoor attacks. Yet sustaining backdoor effectiveness under repeated aggregation remains challenging. Existing methods often rely on heuristic trigger designs or indiscriminant parameter manipulation, leading to rapid decay or detectable anomalies. In this work, we view FL backdoor persistence through the lens of optimization dynamics, and argue that long-lasting attacks require alignment between trigger-induced representations and aggregation-stable parameter directions. Based on this insight, we propose the Coupled Trigger Optimization and Vulnerable Parameter Alignment (CTO-VPA) FL backdoor attack method. By constraining updates to this coupled subspace, backdoor behaviors can be embedded into optimization-stable directions while preserving benign performance. Experiments across multiple datasets and defense settings show that CTO-VPA achieves substantially improved persistence and robustness compared to prior attacks, highlighting the importance of trigger–parameter coupling in FL settings. The code is available at https://github.com/SwLi415/COVERT.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on11
- Attack of the Tails: Yes, You Really Can Backdoor Federated LearningHongyi Wang, Kartik Sreenivasan, Shashank Rajput, Harit Vishwakarma et al.NeurIPS 2020 · 862 citations
- Lockdown: Backdoor Defense for Federated Learning with Isolated Subspace TrainingTiansheng Huang, Sihao Hu, Ka-Ho Chow, Fatih Ilhan et al.NeurIPS 2023 · 46 citations
- Backdoor Federated Learning by Poisoning Backdoor-Critical LayersHaomin Zhuang, Mingxian Yu, Hao Wang, Yang Hua et al.ICLR 2024 · 40 citations
- Cross-Silo Feature Space Alignment for Federated Learning on Clients with Imbalanced DataZhuang Qi, Lei Meng, Zhaochuan Li, Han Hu et al.AAAI 2025 · 39 citations
- Lurking in the shadows: Unveiling Stealthy Backdoor Attacks against Personalized Federated LearningXiaoting Lyu, Yufei Han, Wei Wang, Jingkai Liu et al.USENIX Security 2024 · 20 citations
Related papers
- A3FL: Adversarially Adaptive Backdoor Attacks to Federated LearningHangfan Zhang, Jinyuan Jia, Jinghui Chen, Lu Lin et al.NeurIPS 2023 · 102 citations
- FedBAP: Backdoor Defense via Benign Adversarial Perturbation in Federated LearningXinhai Yan, Libing Wu, Zhuangzhuang Zhang, Bingyi Liu et al.ACM MM 2025 · 2 citations
- Less is More: Persistent Low-Frequency Backdoor Injection in Federated LearningPei Ye, Yuqing Li, Kun He, Haoran Wang et al.INFOCOM 2026
- Batman: Benign Knowledge Alignment Through Malicious Null Space in Federated Backdoor AttackWenwen He, Wenke Huang, Yiyang Fang, Wenjie Qu et al.CVPR 2026
- FLIP: A Provable Defense Framework for Backdoor Mitigation in Federated LearningKaiyuan Zhang, Guanhong Tao, Qiuling Xu, Siyuan Cheng et al.ICLR 2023 · 17 citations
