Vertical Federated Learning (VFL) allows multiple parties holding the same samples but different attributes to collaboratively train models without directly sharing raw data. However, a passive party lacking label information can still launch backdoor attacks, posing significant, yet underexplored, security threats. This paper proposes an Adaptive Federated Backdoor Framework (AFBF) for VFL, integrating dynamic trigger generation and efficient gradient alignment. We introduce an Adaptive Trigger Generation Network (ATGN), a GAN-based module trained jointly with VFL to dynamically produce triggers, enhancing stealthiness and flexibility, especially for multi-class tasks. Building on label-replacement methods, we further propose Gradient-Feature Correlation Attack (GFCA) to align poisoned features and target gradients, achieving high attack success rates without altering labels. Extensive experiments on multiple datasets show that AFBF, combining ATGN and GFCA, achieves nearly 100% success even with very few target samples, outperforming existing mainstream methods. Our findings highlight backdoor risks in VFL and underscore the urgency for robust defenses in sensitive domains like finance and healthcare.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

GAN-Based Adaptive Trigger Generation and Target Gradient Alignment in Vertical Federated Learning Backdoor Attacks

  • Kun Li,
  • Hongyang Yan,
  • Jiatong Lin,
  • Fan Chen,
  • Yu Cheng,
  • Dongyang Liang

摘要

Vertical Federated Learning (VFL) allows multiple parties holding the same samples but different attributes to collaboratively train models without directly sharing raw data. However, a passive party lacking label information can still launch backdoor attacks, posing significant, yet underexplored, security threats. This paper proposes an Adaptive Federated Backdoor Framework (AFBF) for VFL, integrating dynamic trigger generation and efficient gradient alignment. We introduce an Adaptive Trigger Generation Network (ATGN), a GAN-based module trained jointly with VFL to dynamically produce triggers, enhancing stealthiness and flexibility, especially for multi-class tasks. Building on label-replacement methods, we further propose Gradient-Feature Correlation Attack (GFCA) to align poisoned features and target gradients, achieving high attack success rates without altering labels. Extensive experiments on multiple datasets show that AFBF, combining ATGN and GFCA, achieves nearly 100% success even with very few target samples, outperforming existing mainstream methods. Our findings highlight backdoor risks in VFL and underscore the urgency for robust defenses in sensitive domains like finance and healthcare.