arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

STAIN-FL:联邦学习中基于上下文触发器的隐蔽定向攻击注入

STAIN-FL: Stealthy Targeted Attack Injection with Contextual Triggers in Federated Learning

Ashlinder Kaur, Purnima Murali Mohan, Zengxiang Li, Tram Truong-Huu

arXiv 2608.23952首次发表:更新:

发表机构

Singapore Institute of Technology (SIT); SingHealth Duke-NUS AI in Medicine Institute; SingHealth AI Office(新加坡理工学院(SIT); 新加坡保健服务集团杜克-新加坡国立大学医学院AI研究所; 新加坡保健服务集团AI办公室)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

本文提出STAIN-FL框架,利用自然监控场景作为上下文触发器,在联邦视频异常检测中实现隐蔽定向后门攻击,稀疏攻击兼具低检测率与高持续性,可在保持低干净准确率下降的同时达成较高后门准确率。

AI 中文摘要

联邦视频异常检测可在不共享原始监控录像的情况下协同训练模型,但服务器端可见性有限,致使被入侵的客户端能通过恶意更新注入后门。本文提出STAIN-FL,这是一种隐蔽的定向后门攻击注入框架,它利用自然出现的监控场景(包括低光照场景、室内环境和人群密度)作为上下文触发器。STAIN-FL将异常到良性标签的操纵与最少更新坐标上的梯度掩码相结合,以在保持干净样本准确率的同时,诱导触发条件下的错误分类。我们在UCF-Crime数据集上使用1024维I3D特征,在非独立同分布的四客户端多机构设置中对STAIN-FL进行评估,对比FedAvg和FedProx在稀疏攻击与连续攻击下的表现。结果显示,稀疏攻击属于低检测率、具有操作意义的攻击,而非高强度攻击:它们使平均干净准确率下降幅度低于2%,但在FedAvg下,触发异常的错误分类率在后门准确率峰值时超过一半(56.7%),在FedProx下则为54.2%。在FedAvg下,稀疏后门在攻击后平均336轮内仍保持在25%的后门准确率阈值以上,凸显了监控系统中基于上下文触发器的攻击的持续性风险。

英文摘要

Federated video anomaly detection trains model collaboratively without sharing raw surveillance footage, but limited server-side visibility lets compromised clients to inject backdoor via malicious updates. This paper introduces STAIN-FL, a stealthy targeted backdoor attack injection framework that uses naturally occurring surveillance conditions, including low-light scenes, indoor settings, and crowd density, as contextual triggers. STAIN-FL combines anomaly-to-benign label \textit{manipulation} with gradient masking over least-updated coordinates to preserve clean accuracy while inducing trigger-conditioned misclassification. We evaluate STAIN-FL on \texttt{UCF-Crime} using 1024-dimensional I3D features in a non-IID four-client multi-agency setting, comparing FedAvg and FedProx under sparse and continuous attacks. Results show that sparse attacks have low-detectability, operationally significant attacks rather than high-intensity attacks: they keep the mean clean-accuracy drop below $2\%$, yet still misclassify more than half of triggered anomalies at peak backdoor accuracy under FedAvg ($56.7\%$) and FedProx ($54.2\%$). Under FedAvg, the sparse backdoor remains above the $25\%$ backdoor-accuracy threshold for an average of $336$ post-attack rounds, highlighting the persistence risk of contextually triggered attacks in surveillance systems.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑