IPBA: Imperceptible Perturbation Backdoor Attack in Federated Self-Supervised Learning

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Wang, Jiayao, Song, Yang, Zhao, Zhendong, Zhang, Jiale, Wu, Qilin, Zhu, Junwu, Zhao, Dongfang
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866909732411801600
author Wang, Jiayao
Song, Yang
Zhao, Zhendong
Zhang, Jiale
Wu, Qilin
Zhu, Junwu
Zhao, Dongfang
author_facet Wang, Jiayao
Song, Yang
Zhao, Zhendong
Zhang, Jiale
Wu, Qilin
Zhu, Junwu
Zhao, Dongfang
contents Federated self-supervised learning (FSSL) combines the advantages of decentralized modeling and unlabeled representation learning, serving as a cutting-edge paradigm with strong potential for scalability and privacy preservation. Although FSSL has garnered increasing attention, research indicates that it remains vulnerable to backdoor attacks. Existing methods generally rely on visually obvious triggers, which makes it difficult to meet the requirements for stealth and practicality in real-world deployment. In this paper, we propose an imperceptible and effective backdoor attack method against FSSL, called IPBA. Our empirical study reveals that existing imperceptible triggers face a series of challenges in FSSL, particularly limited transferability, feature entanglement with augmented samples, and out-of-distribution properties. These issues collectively undermine the effectiveness and stealthiness of traditional backdoor attacks in FSSL. To overcome these challenges, IPBA decouples the feature distributions of backdoor and augmented samples, and introduces Sliced-Wasserstein distance to mitigate the out-of-distribution properties of backdoor samples, thereby optimizing the trigger generation process. Our experimental results on several FSSL scenarios and datasets show that IPBA significantly outperforms existing backdoor attack methods in performance and exhibits strong robustness under various defense mechanisms.
format Preprint
id arxiv_https___arxiv_org_abs_2508_08031
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle IPBA: Imperceptible Perturbation Backdoor Attack in Federated Self-Supervised Learning
Wang, Jiayao
Song, Yang
Zhao, Zhendong
Zhang, Jiale
Wu, Qilin
Zhu, Junwu
Zhao, Dongfang
Cryptography and Security
Computer Vision and Pattern Recognition
Federated self-supervised learning (FSSL) combines the advantages of decentralized modeling and unlabeled representation learning, serving as a cutting-edge paradigm with strong potential for scalability and privacy preservation. Although FSSL has garnered increasing attention, research indicates that it remains vulnerable to backdoor attacks. Existing methods generally rely on visually obvious triggers, which makes it difficult to meet the requirements for stealth and practicality in real-world deployment. In this paper, we propose an imperceptible and effective backdoor attack method against FSSL, called IPBA. Our empirical study reveals that existing imperceptible triggers face a series of challenges in FSSL, particularly limited transferability, feature entanglement with augmented samples, and out-of-distribution properties. These issues collectively undermine the effectiveness and stealthiness of traditional backdoor attacks in FSSL. To overcome these challenges, IPBA decouples the feature distributions of backdoor and augmented samples, and introduces Sliced-Wasserstein distance to mitigate the out-of-distribution properties of backdoor samples, thereby optimizing the trigger generation process. Our experimental results on several FSSL scenarios and datasets show that IPBA significantly outperforms existing backdoor attack methods in performance and exhibits strong robustness under various defense mechanisms.
title IPBA: Imperceptible Perturbation Backdoor Attack in Federated Self-Supervised Learning
topic Cryptography and Security
Computer Vision and Pattern Recognition
url https://arxiv.org/abs/2508.08031