Backdoor Risks in Personalized Federated Learning Under Practical Constraints
摘要
Backdoor attacks pose a persistent security risk to Personalized Federated Learning (pFL) systems, which are widely adopted to handle heterogeneous client data. In this work, we study backdoor risks in pFL under practical end–edge settings, focusing on scenarios with low poisoning rates and multiple attackers. We show that clean-label backdoor attacks can remain feasible even when the attacker only has access to training data from the target class. To investigate this risk, we present a backdoor attack that exploits the edge–end federated learning workflow to inject target-class-consistent triggers. Experimental results on CIFAR-10 across representative pFL methods and model architectures demonstrate that such attacks can achieve non-negligible attack success rates without substantially degrading clean accuracy, even under constrained attacker assumptions. Our findings highlight that personalization alone does not eliminate backdoor vulnerabilities in pFL and underscore the importance of evaluating defenses under realistic low-poisoning and limited-information settings. This study provides practical insights into the security implications of backdoor attacks in pFL systems and motivates further research on robust and deployment-oriented defense mechanisms.