Malicious Forgetting: Backdoor Injection in Active Federated Unlearning and Countermeasure Design
Wenwei Zhao, Yuanzhe Peng, Xiaowen Li, Jie Xu, Yao Liu, Zhuo Lu
摘要
Federated learning (FL) enables collaborative model training without sharing raw data, but also raises increasing demands for the right to be forgotten. To support data erasure, active federated unlearning (FU) allows clients to actively remove their data’s influence from the model. We reveal a critical and overlooked threat: malicious clients can pose as privacy-concerned users requesting to unlearn some of their data, while secretly preparing backdoor attacks during training. We propose FUsion backdoor, a subnetwork-based attack that stealthily constructs a compact backdoor subnetwork from trigger-sensitive units within backdoor-critical layers during training, and rapidly fuses it during the limited rounds of unlearning. FUsion backdoor achieves up to 99% backdoor success rate across diverse datasets and FU methods. We also develop a detection method that captures directional subspace deviations introduced by coordinated backdoor updates, achieving high attack detection accuracy.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- REMISVFU: Vertical Federated Unlearning via Representation Misdirection for Intermediate Output FeatureWenhan Wu, Zhili He, Huanghuang Liang, Yili Gong 等AAAI 2026
- Unlearning through Knowledge Overwriting: Reversible Federated Unlearning via Selective Sparse AdapterZhengyi Zhong, Weidong Bao, Ji Wang, Shuai Zhang 等CVPR 2025
- Retaliatory Attacks Against Federated Unlearning via Data LeakageXinyi Sheng, Wei Bao, Hequn Wang, Yuqin Liu 等AAAI 2026
- IBA: Towards Irreversible Backdoor Attacks in Federated LearningThuy Dung Nguyen, Tuan Nguyen, Anh Tran, Khoa D. Doan 等NeurIPS 2023 · 被引用 94 次
- Backdoor Attacks via Machine UnlearningZihao Liu, Tianhao Wang, Mengdi Huai, Chenglin MiaoAAAI 2024 · 被引用 46 次
