Federated Learning (FL) facilitates decentralized collaborative model training among multiple entities while preserving data locality, wherein participants iteratively refine local models and transmit parameter updates to a centralized coordinator for global aggregation. As a typical kind of FL, Vertical FL (VFL) focuses more on vertical federated learning where clients’ data contain homogenous feature space given its significant real-world applicability potential. Despite its growing adoption in domains such as financial fraud detection, there remains a paucity of research examining the security implications inherent to VFL frameworks. This work conducts a systematic investigation of VFL robustness against backdoor attacks – adversarial manipulations during distributed training that induce targeted misclassifications through trigger pattern implantation. We identify two fundamental constraints complicating such attacks in VFL environments: 1) label inaccessibility during distributed training phases, and 2) inability to manipulate decision boundaries through label poisoning given adversaries’ restriction to feature space operations. We propose a first-of-its-kind backdoor attack method in VFL, which is capable of exploiting and contrasting the latent information in input sample features and achieves effective backdoor implantation with strong stealthiness. Experimental results demonstrate the effectiveness of the attack on different datasets, investigate the factors involved in its success.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Stealthy Backdoors in Vertical Federated Learning

  • Xu Yang,
  • Yuchuan Luo,
  • Shaojing Fu,
  • Ming Xu

摘要

Federated Learning (FL) facilitates decentralized collaborative model training among multiple entities while preserving data locality, wherein participants iteratively refine local models and transmit parameter updates to a centralized coordinator for global aggregation. As a typical kind of FL, Vertical FL (VFL) focuses more on vertical federated learning where clients’ data contain homogenous feature space given its significant real-world applicability potential. Despite its growing adoption in domains such as financial fraud detection, there remains a paucity of research examining the security implications inherent to VFL frameworks. This work conducts a systematic investigation of VFL robustness against backdoor attacks – adversarial manipulations during distributed training that induce targeted misclassifications through trigger pattern implantation. We identify two fundamental constraints complicating such attacks in VFL environments: 1) label inaccessibility during distributed training phases, and 2) inability to manipulate decision boundaries through label poisoning given adversaries’ restriction to feature space operations. We propose a first-of-its-kind backdoor attack method in VFL, which is capable of exploiting and contrasting the latent information in input sample features and achieves effective backdoor implantation with strong stealthiness. Experimental results demonstrate the effectiveness of the attack on different datasets, investigate the factors involved in its success.