Pith. sign in

REVIEW 2 cited by

DarkFed: A Data-Free Backdoor Attack in Federated Learning

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2405.03299 v1 pith:5YYDRIIT submitted 2024-05-06 cs.CR cs.DC

classification cs.CRcs.DC
keywords backdoorattackdatasetclientsdarkfeddataevenshadow
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Federated learning (FL) has been demonstrated to be susceptible to backdoor attacks. However, existing academic studies on FL backdoor attacks rely on a high proportion of real clients with main task-related data, which is impractical. In the context of real-world industrial scenarios, even the simplest defense suffices to defend against the state-of-the-art attack, 3DFed. A practical FL backdoor attack remains in a nascent stage of development. To bridge this gap, we present DarkFed. Initially, we emulate a series of fake clients, thereby achieving the attacker proportion typical of academic research scenarios. Given that these emulated fake clients lack genuine training data, we further propose a data-free approach to backdoor FL. Specifically, we delve into the feasibility of injecting a backdoor using a shadow dataset. Our exploration reveals that impressive attack performance can be achieved, even when there is a substantial gap between the shadow dataset and the main task dataset. This holds true even when employing synthetic data devoid of any semantic information as the shadow dataset. Subsequently, we strategically construct a series of covert backdoor updates in an optimized manner, mimicking the properties of benign updates, to evade detection by defenses. A substantial body of empirical evidence validates the tangible effectiveness of DarkFed.

Discussion (0). Sign in to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. SPA: Towards More Stealth and Persistent Backdoor Attacks in Federated Learning

    cs.CR 2025-06 conditional novelty 6.0 of 10

    SPA is a federated learning backdoor attack that aligns trigger features with target class features in the model's latent space, achieving high, persistent attack success rates while evading detection-based defenses.

  2. FedBAP: Backdoor Defense via Benign Adversarial Perturbation in Federated Learning

    cs.CR 2025-07 conditional novelty 4.0 of 10

    FedBAP defends federated learning against backdoor attacks by reverse-engineering trigger-like patterns and training clients to ignore them, reporting attack success rates below 3% in experiments.

Pith tools