Return
Backdoor Attack on Encryption-Protected Vertical Federated Learning
DOI:10.1109/TIFS.2025.3581095.png)
Abstract
En 中文
Vertical Federated Learning (VFL), as one of the key paradigms in federated learning, is commonly employed in scenarios where multiple parties share the same sample set but possess different features for these samples. Previous studies have demonstrated that VFL is vulnerable to backdoor attacks due to its inherent characteristics. However, the issue of backdoor attacks in encryption-protected VFL has been underexplored. In such scenarios, adversaries cannot directly access plaintext sample-level gradients, which seemingly offers enhanced security for VFL. Adversaries are restricted to leveraging their own bottom model and a small subset of auxiliary samples to conduct backdoor attacks, rendering many existing attack strategies ineffective. In this paper, we propose a powerful backdoor attack: BAEVFL (Backdoor Attack on Encryption-protected Vertical Federated Learning), which is executed through three key stages: pseudo-label inference, trigger optimization, and backdoor poisoning. Our attack can be successfully launched without access to plaintext gradient information or auxiliary samples including all classes. Instead, it requires only the adversary’s bottom model and a minimal set of target class samples. We conducted extensive experiments demonstrating that BAEVFL outperforms various state-of-the-art baseline methods, achieving over 98% ASR on four benchmark datasets, while maintaining a utility drop of less than 0.3%. Additionally, we evaluated the effectiveness of current representative defense methods against our BAEVFL. The results indicate that existing defenses fail to strike a balance between defense and utility, and we provide key suggestions for potential improvements to these methods. The BAEVFL, with its stealth and effectiveness, exposes significant security vulnerabilities in encryption-protected VFL, underscoring the urgent need for future research on robust defense mechanisms for this paradigm.
Keywords:
Backdoor attack
vertical federated learning
encryption-protected
Journal
IF:
8
Papers:
5.2K
Citations:
2.3W

