Backdoor Federated Learning by Poisoning Key Parameters
Xuan Song, Huibin Li, Kailang Hu, Guangjun Zai · Electronics · 2024
Federated learning (FL) utilizes distributed data processing to enable collaborative machine learning model development while safeguarding user privacy. However, the decentralized nature of FL, combined with data heterogeneity, substantially expands the attack surface for backdoor threats. Existing FL attack and defense strategies typically target the entire model, neglecting the critical backdoor parameters—a small subset of parameters that govern model vulnerabilities. Focusing on these parameters can replicate the impact of attacking the entire model while greatly reducing the risk of detection by advanced defenses. To address this challenge, we introduce Key Parameter Backdoor Attack in Federated Learning (KPBAFL), an innovative, adaptive, and scalable framework specifically designed to exploit model vulnerabilities by targeting critical backdoor parameters. KPBAFL integrates three core components: key parameter analysis, a beacon feedback mechanism, and adaptive attack strategies. By embedding beacons within the backdoor model, the framework can gather real-time attack feedback and dynamically adjust its strategy accordingly. When these components operate in concert, KPBAFL exhibits exceptional stealthiness, achieving an attack success rate (ASR) exceeding 96.5% while maintaining a benign task accuracy (BTA) of 97.8% across various datasets and models. Extensive experiments demonstrate its effectiveness, even in the presence of advanced defenses such as FLAME, Fldetector, Rflbat, and Deepsight, underscoring its strong generalizability. Although the modular design ensures adaptability, the framework’s performance may significantly degrade if the components are not properly synchronized. Our research provides a critical foundation for understanding and mitigating backdoor vulnerabilities in federated learning systems.