Generic Adversarial Attack Framework Against Graph-based Vertical Federated Learning
Yimin Liu, Peng Jiang, Qi Liu, Liehuang Zhu
摘要
Vertical federated learning (VFL) enables featurelevel collaboration by incorporating scattered attributes from aligned samples, and allows each party to contribute its personalized input to joint training and inference. The injection of adversarial inputs can mislead the joint inference towards the attacker's will, forcing other benign parties to make negligible contributions and losing rewards regarding the importance of their contributions. However, most attacks require server model queries, subsets of complete test samples, or labeled auxiliary images from the training domain. These extra requirements are not practical for real-world VFL applications. In this paper, we propose PGAC, a novel and practical attack framework for crafting adversarial inputs to dominate joint inference, which does not rely on the above requirements. PGAC advances prior attacks by requiring only access to auxiliary images from non-training domains. PGAC learns generalized label-indicative embeddings and estimates class-transferable probabilities across domains to generate a proxy model that closely approximates the server model. PGAC then augments images by emphasizing salient regions with class activation maps, creating a diverse shadow input set that resembles influential test inputs. With proxy fidelity and input diversity, PGAC crafts transferable adversarial inputs. Evaluation on diverse model architectures confirms the effectiveness of PGAC.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper8
- Moment Matching for Multi-Source Domain AdaptationXingchao Peng, Qinxun Bai, Xide Xia, Zijun Huang 等ICCV 2019 · 被引用 2,239 次
- Fast Private Set Intersection from Homomorphic EncryptionHao Chen, Kim Laine, Peter RindalCCS 2017 · 被引用 446 次
- Structure Invariant Transformation for better Adversarial TransferabilityXiaosen Wang, Zeliang Zhang, Jianping ZhangICCV 2023 · 被引用 130 次
- Stochastic Variance Reduced Ensemble Adversarial Attack for Boosting the Adversarial TransferabilityYifeng Xiong, Jiadong Lin, Min Zhang, John E. Hopcroft 等CVPR 2022 · 被引用 124 次
- Boosting Adversarial Transferability via Gradient Relevance AttackHegui Zhu, Yuchen Ren, Xiaoyan Sui, Lianping Yang 等ICCV 2023 · 被引用 80 次
相关 Paper
- Label-Free Backdoor Attacks in Vertical Federated LearningWei Shen, Wenke Huang, Guancheng Wan, Mang YeAAAI 2025 · 被引用 15 次
- ADI: Adversarial Dominating Inputs in Vertical Federated Learning SystemsQi Pang, Yuanyuan Yuan, Shuai Wang, Wenting ZhengS&P 2023
- URVFL: Undetectable Data Reconstruction Attack on Vertical Federated LearningDuanyi Yao, Songze Li, Xueluan Gong, Sizai Hou 等NDSS 2025
- Preference Profiling Attacks Against Vertical Federated Learning Over Graph DataYimin Liu, Peng Jiang, Liehuang ZhuINFOCOM 2025 · 被引用 1 次
- Accelerated Vertical Federated Adversarial Learning through Decoupling Layer-Wise DependenciesTianxing Man, Yu Bai, Ganyu Wang, Jinjie Fang 等NeurIPS 2025
