Bad-PFL: Exploring Backdoor Attacks against Personalized Federated Learning

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Fan, Mingyuan, Hu, Zhanyi, Wang, Fuyi, Chen, Cen
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866909463824302080
author Fan, Mingyuan
Hu, Zhanyi
Wang, Fuyi
Chen, Cen
author_facet Fan, Mingyuan
Hu, Zhanyi
Wang, Fuyi
Chen, Cen
contents Data heterogeneity and backdoor attacks rank among the most significant challenges facing federated learning (FL). For data heterogeneity, personalized federated learning (PFL) enables each client to maintain a private personalized model to cater to client-specific knowledge. Meanwhile, vanilla FL has proven vulnerable to backdoor attacks. However, recent advancements in PFL community have demonstrated a potential immunity against such attacks. This paper explores this intersection further, revealing that existing federated backdoor attacks fail in PFL because backdoors about manually designed triggers struggle to survive in personalized models. To tackle this, we design Bad-PFL, which employs features from natural data as our trigger. As long as the model is trained on natural data, it inevitably embeds the backdoor associated with our trigger, ensuring its longevity in personalized models. Moreover, our trigger undergoes mutual reinforcement training with the model, further solidifying the backdoor's durability and enhancing attack effectiveness. The large-scale experiments across three benchmark datasets demonstrate the superior performance of our attack against various PFL methods, even when equipped with state-of-the-art defense mechanisms.
format Preprint
id arxiv_https___arxiv_org_abs_2501_12736
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Bad-PFL: Exploring Backdoor Attacks against Personalized Federated Learning
Fan, Mingyuan
Hu, Zhanyi
Wang, Fuyi
Chen, Cen
Machine Learning
Cryptography and Security
Computer Vision and Pattern Recognition
Data heterogeneity and backdoor attacks rank among the most significant challenges facing federated learning (FL). For data heterogeneity, personalized federated learning (PFL) enables each client to maintain a private personalized model to cater to client-specific knowledge. Meanwhile, vanilla FL has proven vulnerable to backdoor attacks. However, recent advancements in PFL community have demonstrated a potential immunity against such attacks. This paper explores this intersection further, revealing that existing federated backdoor attacks fail in PFL because backdoors about manually designed triggers struggle to survive in personalized models. To tackle this, we design Bad-PFL, which employs features from natural data as our trigger. As long as the model is trained on natural data, it inevitably embeds the backdoor associated with our trigger, ensuring its longevity in personalized models. Moreover, our trigger undergoes mutual reinforcement training with the model, further solidifying the backdoor's durability and enhancing attack effectiveness. The large-scale experiments across three benchmark datasets demonstrate the superior performance of our attack against various PFL methods, even when equipped with state-of-the-art defense mechanisms.
title Bad-PFL: Exploring Backdoor Attacks against Personalized Federated Learning
topic Machine Learning
Cryptography and Security
Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2501.12736