Batman: Benign Knowledge Alignment Through Malicious Null Space in Federated Backdoor Attack
Wenwen He, Wenke Huang, Yiyang Fang, Wenjie Qu, Jiaheng Zhang, Mang Ye
摘要
Federated Learning (FL), a distributed learning paradigm that enables local training on user-held data across decentralized devices, is vulnerable to backdoor attacks due to limited visibility into client updates. Exploiting this opacity, adversaries induce targeted misbehavior on trigger inputs without affecting overall performance, thereby compromising the trust and integrity of collaborative training in federated learning systems. Existing federated backdoor attacks mainly concentrate on benign knowledge alignment on trigger-surface design or representation guidance to evade defense mechanisms. However, trigger-surface attacks suffer from insufficient alignment, leaving malicious knowledge distinguishable from benign updates. In contrast, representation-guided attacks attempt to obscure the boundary between benign and malicious behaviors. Nevertheless, excessive incorporation of benign knowledge within a shared parameter space leads to over-alignment, ultimately degrading attack effectiveness. To overcome shared parameter space dilemma in backdoor attack, we propose Batman, a novel backdoor attack that aligns benign knowledge within the malicious null space, which effectively decouples malicious space from shared parameter space and enables benign alignment in an orthogonal direction of this space that does not interfere with the attack effectiveness. To further enhance stealthiness, we combine both clean and global models to guide the alignment perturbation within this null space to evade detection. Experiments on four benchmark datasets demonstrate that Batman consistently achieves strong backdoor performance while remaining stealthy under various defenses.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper20
- Attack of the Tails: Yes, You Really Can Backdoor Federated LearningHongyi Wang, Kartik Sreenivasan, Shashank Rajput, Harit Vishwakarma 等NeurIPS 2020 · 被引用 862 次
- Rethinking the Backdoor Attacks' Triggers: A Frequency PerspectiveYi Zeng, Won Park, Z. Morley Mao, Ruoxi JiaICCV 2021 · 被引用 274 次
- Neurotoxin: Durable Backdoors in Federated LearningZhengming Zhang, Ashwinee Panda, Linyue Song, Yaoqing Yang 等ICML 2022 · 被引用 209 次
- Sageflow: Robust Federated Learning against Both Stragglers and AdversariesJungwuk Park, Dong-Jun Han, Minseok Choi, Jaekyun MoonNeurIPS 2021 · 被引用 149 次
- Revisiting Weighted Aggregation in Federated Learning with Neural NetworksZexi Li, Tao Lin, Xinyi Shang, Chao WuICML 2023 · 被引用 119 次
相关 Paper
- Less is More: Persistent Low-Frequency Backdoor Injection in Federated LearningPei Ye, Yuqing Li, Kun He, Haoran Wang 等INFOCOM 2026
- 3DFed: Adaptive and Extensible Framework for Covert Backdoor Attack in Federated LearningHaoyang Li, Qingqing Ye, Haibo Hu, Jin Li 等S&P 2023
- A3FL: Adversarially Adaptive Backdoor Attacks to Federated LearningHangfan Zhang, Jinyuan Jia, Jinghui Chen, Lu Lin 等NeurIPS 2023 · 被引用 102 次
- On the Vulnerability of Backdoor Defenses for Federated LearningPei Fang, Jinghui ChenAAAI 2023 · 被引用 66 次
- Coupled Trigger Optimization and Vulnerable Parameter Alignment for Persistent Backdoor Attacks on Federated Learningzhixuan ma, Haichang Gao, Shangwen Li, Ping Wang 等ICML 2026
