Enhancing Backdoor Persistence Under Uncontrolled Federated Clients: A Bidirectional Adversarial and Redundant Embedding Framework
摘要
Federated learning (FL) enables collaborative model training without sharing raw data, yet its distributed and dynamic nature exposes it to persistent security threats such as backdoor attacks. Most existing attacks rely on static triggers or assume full attacker control over all malicious clients, which rarely holds in real-world federated environments. Consequently, their effectiveness rapidly deteriorates as the global model evolves or some clients become uncontrollable. To address these challenges, we present BAT-RDBA, a framework designed to sustain backdoor functionality under dynamic aggregation and partial client loss. Our approach integrates bidirectional adversarial training, where the trigger co-evolves with a simulated defender model to enhance robustness against model updates, and redundant trigger embedding, which distributes overlapping trigger fragments across clients to preserve recoverability when some nodes fail. Extensive experiments on CIFAR-10 and FMNIST demonstrate that BAT-RDBA achieves markedly longer backdoor lifespans and higher attack success rates under various defense mechanisms compared with state-of-the-art methods. This work highlights the overlooked problem of backdoor persistence under uncontrolled clients and provides a new perspective for evaluating the long-term security of federated learning systems.