论文精选73°

CACTUS:去中心联邦学习中的掩码引导语义后门

CACTUS: Mask-Guided Semantic Clean-Label Backdoors in Decentralized Federated Learning

精选理由

CACTUS在去中心联邦学习中实现了高效后门传播,攻击成功率随恶意节点比例增加而提高。

AI 摘要

CACTUS是一种新型后门攻击方法,在去中心联邦学习(DFL)环境中实现了51.2%的平均攻击成功率。该方法通过掩码引导的模态特定操作器,将语义对转换为有目标表示偏移。研究者在语音、文本、表格和图像四种模态的九种聚合规则下测试了CACTUS。当恶意节点比例为30%时,该方法在语音命令数据集上表现最佳,并在四种模态中的三种中实现了最高的平均攻击成功率。

原文 · arXiv cs.LG

CACTUS: Mask-Guided Semantic Clean-Label Backdoors in Decentralized Federated Learning

Semantic triggers in federated learning (FL) can be less conspicuous than synthetic patches, but sample-dependent placement may weaken backdoor implantation across aggregation rounds. This challenge is compounded in decentralized FL (DFL), where topology-dependent peer aggregation repeatedly mixes local models. CACTUS converts label-consistent semantic pairs into target-directed representation shifts. Mask-guided, modality-specific operators isolate trigger effects, couple them across samples, and apply the shifts counterfactually to clean non-target embeddings before peer aggregation. Experiments cover speech, text, tabular, and image tasks under nine aggregation rules. With 30\% malicious nodes, CACTUS reaches a nine-rule mean attack success rate (ASR) of 51.2\% on Speech Commands and the highest nine-rule mean ASR among evaluated attacks on three of four modalities. Sensitivity analyses show that ASR varies with network topology and increases with the malicious-node ratio. These results indicate that CACTUS can propagate backdoors through repeated DFL aggregation.