Lune

INFOCOM2026顶会

Datura: Durable and Stable Backdoor Attack against Federated Learning

Xiaoxue Song, Hui Xia, Shuo Xu, Yuyao Zhu, Le Li

2026年份

摘要

Due to the distributed training framework, FL is vulnerable to backdoor attacks from malicious clients. However existing backdoor attack methods have insufficient attack success rates at low attack frequencies, and the attack effects are difficult to sustain. Therefore, we propose a novel backdoor attack method in FL, named Datura. Datura firstly utilizes adversarial samples to obtain the global prediction model. It then leverages the softmax probability vector to design a trigger generation loss to optimize pattern and mask, creating a highly adaptable trigger. This stage makes it possible to achieve a high attack success rate with minimal attack frequencies. Secondly, in order to obtain the durable high attack success rate, Datura leverages the decentralization of model updates and introduces a layered poisoning strategy based on the redundancy of the model parameters, applying ‘heavy poisoning’ to parameters with high redundancy and ‘light poisoning’ to the rest. We compare Datura with five representative backdoor attack methods on six datasets. Detailed experimental results demonstrate that Datura achieves an attack success rate exceeding 95% with just 1 - 2 attack frequencies, defeating the six defense methods. The 90%-Lifespan of backdoors implanted by Datura reaches an average of 845 rounds after the attack stops.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖