发表机构
SAMOVAR, Télécom SudParis, Institut Polytechnique de Paris; PIRAT, INRIA Rennes(萨莫瓦尔实验室、南巴黎电信学院、巴黎综合理工学院; 皮拉特实验室、法国国家信息与自动化研究所雷恩分部)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
BackDFL是评估去中心化联邦学习(DFL)在自适应后门攻击下安全性的统一基准,实验表明现有鲁棒方法在15%恶意参与率下即失效,且性能随通信拓扑变化大。
AI 中文摘要
去中心化联邦学习(Decentralized Federated Learning, DFL)通过用点对点模型交换替代集中式参数服务器,有望实现无信任的协作学习。然而,这种架构转变从根本上重塑了威胁态势:由于缺乏全局协调聚合,DFL极易遭受后门攻击,即恶意参与者在保持干净任务高性能的同时植入持续的隐藏行为。本文指出,DFL的鲁棒性被显著高估:现有研究依赖简化的威胁模型、非自适应攻击者、碎片化评估协议、不一致的通信拓扑及临时训练配置,导致对DFL安全性的理解不完整。为解决这些局限,我们提出BackDFL,一个用于在现实自适应后门攻击下系统评估DFL的统一基准。通过大量实验,BackDFL揭示了去中心化学习的关键失效模式:在较低的恶意参与率(低至15%)下,最先进的拜占庭鲁棒DFL方法及适配的FL后门防御均失效,尤其在异质性设置中,且其鲁棒性随通信图拓扑差异显著变化。
英文摘要
Decentralized Federated Learning (DFL) promises trust-free collaborative learning by replacing the centralized parameter server with peer-to-peer model exchange. However, this architectural shift fundamentally reshapes the threat landscape. Without globally coordinated aggregation, DFL becomes particularly susceptible to backdoor attacks, in which malicious participants implant persistent hidden behaviors while maintaining high clean-task performance. In this paper, we argue that the robustness of DFL has been significantly overestimated. Existing studies rely on simplified threat models, non-adaptive adversaries, fragmented evaluation protocols, inconsistent communication topologies, and ad hoc training configurations, leading to an incomplete understanding of DFL security. To address these limitations, we present BackDFL, a unified benchmark for systematically evaluating DFL under realistic and adaptive backdoor attacks. Through extensive experiments, BackDFL exposes critical failure modes of decentralized learning. Our results demonstrate that both state-of-the-art Byzantine-robust DFL methods and adapted FL backdoor defenses fail under modest malicious participation rates (as low as 15%), especially in heterogeneous settings, while their robustness varies substantially across communication graph topologies.
CommentsAccepted for presentation at the ANUBIS Workshop, co-located with ESORICS'26