Less is More: Persistent Low-Frequency Backdoor Injection in Federated Learning
Pei Ye, Yuqing Li, Kun He, Haoran Wang, Ruiying Du, Wei Wang
摘要
Federated learning (FL) enables multiple clients to collaboratively train a machine learning model without sharing their local data. However, the distributed nature of FL makes it vulnerable to backdoor attacks from malicious clients. Most existing attack methods often assume that attackers can inject backdoors in every training round - a scenario that is both unrealistic and inefficient in real-world FL deployment. In this paper, we investigate why backdoor attacks become less effective under low-frequency injection and propose a novel attack paradigm for FL, called REinforced Memorization-based INterval backDoor attack (REMIND). REMIND optimizes the backdoor trigger via task alignment and feature alignment. Task alignment aligns backdoor and main task objectives to resist benign update suppression during non-attack rounds, while feature alignment guides poisoned samples to match the activation trajectory of target-class samples. This dual alignment enhances the backdoor's persistence and narrows the divergence between malicious and benign updates. With strong attack success rates established, we further analyze the advantages of low-frequency backdoor attacks, particularly their ability to improve robustness against defense mechanisms. Extensive evaluations on four benchmark datasets show that REMIND consistently outperforms eight state-of-the-art attack baselines under nine defense strategies.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper16
- Ensemble Distillation for Robust Model Fusion in Federated LearningTao Lin, Lingjing Kong, Sebastian U. Stich, Martin JaggiNeurIPS 2020 · 被引用 1,615 次
- DBA: Distributed Backdoor Attacks against Federated LearningChulin Xie, Keli Huang, Pin-Yu Chen, Bo LiICLR 2020 · 被引用 901 次
- FLDetector: Defending Federated Learning Against Model Poisoning Attacks via Detecting Malicious ClientsZaixi Zhang, Xiaoyu Cao, Jinyuan Jia, Neil Zhenqiang GongKDD 2022 · 被引用 293 次
- Neurotoxin: Durable Backdoors in Federated LearningZhengming Zhang, Ashwinee Panda, Linyue Song, Yaoqing Yang 等ICML 2022 · 被引用 209 次
- Poisoning with Cerberus: Stealthy and Colluded Backdoor Attack against Federated LearningXiaoting Lyu, Yufei Han, Wei Wang, Jingkai Liu 等AAAI 2023 · 被引用 111 次
相关 Paper
- A3FL: Adversarially Adaptive Backdoor Attacks to Federated LearningHangfan Zhang, Jinyuan Jia, Jinghui Chen, Lu Lin 等NeurIPS 2023 · 被引用 102 次
- On the Vulnerability of Backdoor Defenses for Federated LearningPei Fang, Jinghui ChenAAAI 2023 · 被引用 66 次
- Label-Free Backdoor Attacks in Vertical Federated LearningWei Shen, Wenke Huang, Guancheng Wan, Mang YeAAAI 2025 · 被引用 15 次
- Batman: Benign Knowledge Alignment Through Malicious Null Space in Federated Backdoor AttackWenwen He, Wenke Huang, Yiyang Fang, Wenjie Qu 等CVPR 2026
- IBA: Towards Irreversible Backdoor Attacks in Federated LearningThuy Dung Nguyen, Tuan Nguyen, Anh Tran, Khoa D. Doan 等NeurIPS 2023 · 被引用 94 次
