摘要
Vertical federated learning (VFL) allows multiple parties to collaboratively train models while keeping their local features private, but its robustness against backdoor attacks remains poorly understood. Existing backdoor techniques developed for horizontal federated learning are largely inapplicable to VFL, as adversaries in VFL cannot access labels and are strictly limited to manipulating local feature representations under server-side supervision. This raises a fundamental question: can effective and stealthy backdoor attacks be mounted in VFL under such constraints? In this paper, we provide a systematic investigation of backdoor attacks in VFL by exploring attack surfaces in both the input space and the latent space. We first propose an input-space attack that exploits gradient information exchanged during training to subtly perturb local inputs and reshape input–label correlations, thereby bypassing label inaccessibility without relying on surrogate models. We then design a latent-space attack that adversarially steers local embeddings toward target-class representations. To ensure practical undetectability, we incorporate a unified stealthiness regularization strategy into the framework. To quantify this property, we introduce a VFL-specific metric that measures statistical consistency, guiding the trade-off between attack effectiveness and detectability. Extensive experiments show that our attacks achieve high success rates while remaining difficult to detect, exposing previously overlooked security vulnerabilities in VFL systems.
| 源语言 | 英语 |
|---|---|
| 期刊 | IEEE Transactions on Dependable and Secure Computing |
| DOI | |
| 出版状态 | 已接受/待刊 - 2026 |
| 已对外发布 | 是 |
学术指纹
探究 'Silent Poisoning: A Stealthy and Unified Dual-Space Framework for VFL Backdoor Attacks' 的科研主题。它们共同构成独一无二的学术指纹。引用此
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver