Abstract
Vertical federated learning (VFL) allows multiple parties to collaboratively train models while keeping their local features private, but its robustness against backdoor attacks remains poorly understood. Existing backdoor techniques developed for horizontal federated learning are largely inapplicable to VFL, as adversaries in VFL cannot access labels and are strictly limited to manipulating local feature representations under server-side supervision. This raises a fundamental question: can effective and stealthy backdoor attacks be mounted in VFL under such constraints? In this paper, we provide a systematic investigation of backdoor attacks in VFL by exploring attack surfaces in both the input space and the latent space. We first propose an input-space attack that exploits gradient information exchanged during training to subtly perturb local inputs and reshape input–label correlations, thereby bypassing label inaccessibility without relying on surrogate models. We then design a latent-space attack that adversarially steers local embeddings toward target-class representations. To ensure practical undetectability, we incorporate a unified stealthiness regularization strategy into the framework. To quantify this property, we introduce a VFL-specific metric that measures statistical consistency, guiding the trade-off between attack effectiveness and detectability. Extensive experiments show that our attacks achieve high success rates while remaining difficult to detect, exposing previously overlooked security vulnerabilities in VFL systems.
| Original language | English |
|---|---|
| Journal | IEEE Transactions on Dependable and Secure Computing |
| DOIs | |
| Publication status | Accepted/In press - 2026 |
| Externally published | Yes |
Keywords
- Backdoor Attack
- Input-space
- Latent-space
- Stealthiness
- Vertical Federated Learning
Fingerprint
Dive into the research topics of 'Silent Poisoning: A Stealthy and Unified Dual-Space Framework for VFL Backdoor Attacks'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver