发表机构
School of Computing and Data Science, The University of Hong Kong(香港大学计算机与数据科学学院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文针对垂直联邦学习(VFL)的后门漏洞开展面向实践的系统性研究,发现现有研究与实践存在差距,提出实用后门工作流并引入BVBench基准,为相关研究奠定基础。
AI 中文摘要
垂直联邦学习(Vertical Federated Learning, VFL)使持有共享实体互补特征的组织能够协作训练模型。在该设置中,发起方可隐瞒学习任务的信息,而其他参与方在不暴露本地数据集的情况下参与,形成了符合日益增长的隐私需求的不对称信息结构。然而,这种不对称性是一把双刃剑。在各类威胁中,后门攻击尤其令人担忧,因为VFL不仅使恶意参与方能够在训练期间投毒模型,还允许他们在推理时激活后门以操纵预测。尽管已有研究报告了近乎完美的攻击成功率并提出了有效的防御措施,但我们发现大多数发现在现实条件下无法成立,暴露出研究与实践之间存在的根本差距。本文针对VFL中的后门漏洞开展了面向实践的系统性研究,揭示了该差距在方法设计与评估实践两方面的体现。我们表明现有方法忽略了关键的实际约束,因此依赖不切实际的先验知识;此外,由于文献中评估实践设计不当,这些限制一直未被发现。为弥合该差距,我们在现实约束下重新定义了威胁模型,提出了实用的后门工作流,并引入了BVBench——一个以后门为核心的基准,可实现公平、实用且全面的评估,且预加载了最先进的基线。BVBench提供了有力证据,证明当前对VFL后门风险的理解存在脆弱性,并为引导研究转向发现实际漏洞及开发更有意义的防御措施奠定了基础。
英文摘要
Vertical Federated Learning (VFL) enables organizations holding complementary features of shared entities to collaborate and train models. In this setting, the initiator can withhold information about the learning task, while other contributors participate without exposing their local datasets, creating an asymmetric information structure aligned with growing privacy demands. However, this asymmetry is a double-edged sword. Among various threats, backdoor attacks are particularly concerning because VFL not only enables malicious contributors to poison the model during training, but also allows them to activate the backdoor at inference time to manipulate predictions. Although prior work has reported near-perfect attack success rates and proposed effective defenses, we find that most findings fail to hold under realistic conditions, exposing a fundamental gap between research and practice. In this paper, we present a systematic, practice-oriented study of backdoor vulnerabilities in VFL, revealing this gap in both methodological design and evaluation practices. We show that existing approaches overlook key practical constraints and therefore rely on unrealistic prior knowledge. Furthermore, these limitations have remained hidden due to poorly designed evaluation practices in the literature. To bridge this gap, we redefine threat models under realistic constraints, propose practical backdoor workflows, and introduce BVBench, a backdoor-centric benchmark that enables fair, practical, and comprehensive evaluation, preloaded with state-of-the-art baselines. BVBench provides strong evidence of the fragility of the current understanding of VFL backdoor risks and establishes a foundation for steering research toward uncovering practical vulnerabilities and developing more meaningful defenses.