跳到主要导航 跳到搜索 跳到主要内容

Silent Poisoning: A Stealthy and Unified Dual-Space Framework for VFL Backdoor Attacks

  • Qiao Li
  • , Xiaoya Ma
  • , Zijun Zhang*
  • , Jing Chen
  • , Kun He
  • , Ruiying Du
  • , Zijian Zhang
  • , Cong Wu
  • , Yang Liu
  • *此作品的通讯作者
  • Wuhan University
  • Beijing Institute of Technology
  • Nanyang Technological University

科研成果: 期刊稿件文章同行评审

摘要

Vertical federated learning (VFL) allows multiple parties to collaboratively train models while keeping their local features private, but its robustness against backdoor attacks remains poorly understood. Existing backdoor techniques developed for horizontal federated learning are largely inapplicable to VFL, as adversaries in VFL cannot access labels and are strictly limited to manipulating local feature representations under server-side supervision. This raises a fundamental question: can effective and stealthy backdoor attacks be mounted in VFL under such constraints? In this paper, we provide a systematic investigation of backdoor attacks in VFL by exploring attack surfaces in both the input space and the latent space. We first propose an input-space attack that exploits gradient information exchanged during training to subtly perturb local inputs and reshape input–label correlations, thereby bypassing label inaccessibility without relying on surrogate models. We then design a latent-space attack that adversarially steers local embeddings toward target-class representations. To ensure practical undetectability, we incorporate a unified stealthiness regularization strategy into the framework. To quantify this property, we introduce a VFL-specific metric that measures statistical consistency, guiding the trade-off between attack effectiveness and detectability. Extensive experiments show that our attacks achieve high success rates while remaining difficult to detect, exposing previously overlooked security vulnerabilities in VFL systems.

源语言英语
期刊IEEE Transactions on Dependable and Secure Computing
DOI
出版状态已接受/待刊 - 2026
已对外发布

学术指纹

探究 'Silent Poisoning: A Stealthy and Unified Dual-Space Framework for VFL Backdoor Attacks' 的科研主题。它们共同构成独一无二的学术指纹。

引用此