后门
计算机科学
计算机安全
撤销
数据库事务
MNIST数据库
钥匙(锁)
GSM演进的增强数据速率
降级
适应性
联合学习
影子(心理学)
正确性
容器(类型理论)
边缘设备
芯(光纤)
计算机网络
联想(心理学)
标识
DOI:10.1109/trustcom66490.2025.00306
摘要
Federated Learning (FL) enables decentralized model training while preserving data privacy, but it remains susceptible to backdoor attacks, especially under dynamic client participation and non-IID data. Existing attacks, such as Distributed Backdoor Attack (DBA) and Shadow Attack, often struggle to balance stealthiness, robustness, and persistence. To address these challenges, we propose the Stealthy Associate Trigger Attack (SATA), which integrates four key techniques: trigger splitting, associative learning, L2-norm control, and progressive backdoor injection. Experimental results on CIFAR-10 using ResNet-18 demonstrate that SATA achieves a 99.26% Attack Success Rate (ASR) with only 10% malicious clients, while maintaining L2-norm deviations within 0.1 to evade detection. Moreover, SATA achieves an ASR-100 of 86.68%, indicating strong persistence. Additional evaluations on MNIST and under defense mechanisms like Multi-Krum and FoolsGold validate the generalizability and adaptability of our method. These findings highlight critical vulnerabilities in privacy-sensitive FL systems and call for the development of more effective defenses. Future work will explore extending SATA to text and audio domains and improving efficiency on edge devices.
科研通智能强力驱动
Strongly Powered by AbleSci AI