Datura: Durable and Stable Backdoor Attack against Federated Learning
Xiaoxue Song, Hui Xia, Shuo Xu, Yuyao Zhu, Le Li
Abstract
Due to the distributed training framework, FL is vulnerable to backdoor attacks from malicious clients. However existing backdoor attack methods have insufficient attack success rates at low attack frequencies, and the attack effects are difficult to sustain. Therefore, we propose a novel backdoor attack method in FL, named Datura. Datura firstly utilizes adversarial samples to obtain the global prediction model. It then leverages the softmax probability vector to design a trigger generation loss to optimize pattern and mask, creating a highly adaptable trigger. This stage makes it possible to achieve a high attack success rate with minimal attack frequencies. Secondly, in order to obtain the durable high attack success rate, Datura leverages the decentralization of model updates and introduces a layered poisoning strategy based on the redundancy of the model parameters, applying ‘heavy poisoning’ to parameters with high redundancy and ‘light poisoning’ to the rest. We compare Datura with five representative backdoor attack methods on six datasets. Detailed experimental results demonstrate that Datura achieves an attack success rate exceeding 95% with just 1 - 2 attack frequencies, defeating the six defense methods. The 90%-Lifespan of backdoors implanted by Datura reaches an average of 845 rounds after the attack stops.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get d7162a22-693b-41aa-b80d-990cc13788abRelated papers
- 3DFed: Adaptive and Extensible Framework for Covert Backdoor Attack in Federated LearningHaoyang Li, Qingqing Ye, Haibo Hu, Jin Li et al.S&P 2023
- SADBA: Self-Adaptive Distributed Backdoor Attack Against Federated LearningJun Feng, Yuzhe Lai, Hong Sun, Bocheng RenAAAI 2025 · 9 citations
- IBA: Towards Irreversible Backdoor Attacks in Federated LearningThuy Dung Nguyen, Tuan Nguyen, Anh Tran, Khoa D. Doan et al.NeurIPS 2023 · 94 citations
- Neurotoxin: Durable Backdoors in Federated LearningZhengming Zhang, Ashwinee Panda, Linyue Song, Yaoqing Yang et al.ICML 2022 · 209 citations
- A3FL: Adversarially Adaptive Backdoor Attacks to Federated LearningHangfan Zhang, Jinyuan Jia, Jinghui Chen, Lu Lin et al.NeurIPS 2023 · 102 citations
