SPA: Towards More Stealth and Persistent Backdoor Attacks in Federated Learning

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Zhu, Chengcheng, Li, Ye, Rao, Bosen, Zhang, Jiale, Mao, Yunlong, Zhong, Sheng
Natura: Preprint
Pubblicazione: 2025
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866911023171108864
author Zhu, Chengcheng
Li, Ye
Rao, Bosen
Zhang, Jiale
Mao, Yunlong
Zhong, Sheng
author_facet Zhu, Chengcheng
Li, Ye
Rao, Bosen
Zhang, Jiale
Mao, Yunlong
Zhong, Sheng
contents Federated Learning (FL) has emerged as a leading paradigm for privacy-preserving distributed machine learning, yet the distributed nature of FL introduces unique security challenges, notably the threat of backdoor attacks. Existing backdoor strategies predominantly rely on end-to-end label supervision, which, despite their efficacy, often results in detectable feature disentanglement and limited persistence. In this work, we propose a novel and stealthy backdoor attack framework, named SPA, which fundamentally departs from traditional approaches by leveraging feature-space alignment rather than direct trigger-label association. Specifically, SPA reduces representational distances between backdoor trigger features and target class features, enabling the global model to misclassify trigger-embedded inputs with high stealth and persistence. We further introduce an adaptive, adversarial trigger optimization mechanism, utilizing boundary-search in the feature space to enhance attack longevity and effectiveness, even against defensive FL scenarios and non-IID data distributions. Extensive experiments on various FL benchmarks demonstrate that SPA consistently achieves high attack success rates with minimal impact on model utility, maintains robustness under challenging participation and data heterogeneity conditions, and exhibits persistent backdoor effects far exceeding those of conventional techniques. Our results call urgent attention to the evolving sophistication of backdoor threats in FL and emphasize the pressing need for advanced, feature-level defense techniques.
format Preprint
id arxiv_https___arxiv_org_abs_2506_20931
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle SPA: Towards More Stealth and Persistent Backdoor Attacks in Federated Learning
Zhu, Chengcheng
Li, Ye
Rao, Bosen
Zhang, Jiale
Mao, Yunlong
Zhong, Sheng
Cryptography and Security
Federated Learning (FL) has emerged as a leading paradigm for privacy-preserving distributed machine learning, yet the distributed nature of FL introduces unique security challenges, notably the threat of backdoor attacks. Existing backdoor strategies predominantly rely on end-to-end label supervision, which, despite their efficacy, often results in detectable feature disentanglement and limited persistence. In this work, we propose a novel and stealthy backdoor attack framework, named SPA, which fundamentally departs from traditional approaches by leveraging feature-space alignment rather than direct trigger-label association. Specifically, SPA reduces representational distances between backdoor trigger features and target class features, enabling the global model to misclassify trigger-embedded inputs with high stealth and persistence. We further introduce an adaptive, adversarial trigger optimization mechanism, utilizing boundary-search in the feature space to enhance attack longevity and effectiveness, even against defensive FL scenarios and non-IID data distributions. Extensive experiments on various FL benchmarks demonstrate that SPA consistently achieves high attack success rates with minimal impact on model utility, maintains robustness under challenging participation and data heterogeneity conditions, and exhibits persistent backdoor effects far exceeding those of conventional techniques. Our results call urgent attention to the evolving sophistication of backdoor threats in FL and emphasize the pressing need for advanced, feature-level defense techniques.
title SPA: Towards More Stealth and Persistent Backdoor Attacks in Federated Learning
topic Cryptography and Security
url https://arxiv.org/abs/2506.20931