Pith. sign in

REVIEW 1 cited by

Chameleon: Adapting to Peer Images for Planting Durable Backdoors in Federated Learning

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2304.12961 v2 pith:7EA6HWLA submitted 2023-04-25 cs.LG cs.CRcs.CV

classification cs.LGcs.CRcs.CV
keywords imagesbackdoorbackdoorsmodelchameleondurablelabelslearning
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
abstract

In a federated learning (FL) system, distributed clients upload their local models to a central server to aggregate into a global model. Malicious clients may plant backdoors into the global model through uploading poisoned local models, causing images with specific patterns to be misclassified into some target labels. Backdoors planted by current attacks are not durable, and vanish quickly once the attackers stop model poisoning. In this paper, we investigate the connection between the durability of FL backdoors and the relationships between benign images and poisoned images (i.e., the images whose labels are flipped to the target label during local training). Specifically, benign images with the original and the target labels of the poisoned images are found to have key effects on backdoor durability. Consequently, we propose a novel attack, Chameleon, which utilizes contrastive learning to further amplify such effects towards a more durable backdoor. Extensive experiments demonstrate that Chameleon significantly extends the backdoor lifespan over baselines by $1.2\times \sim 4\times$, for a wide range of image datasets, backdoor types, and model architectures.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. DROP: Poison Dilution via Knowledge Distillation for Federated Learning

    cs.LG 2025-02 conditional novelty 6.0 of 10

    DROP combines clustering, client reputation tracking, and GAN-guided knowledge distillation to suppress targeted backdoor attacks in federated learning, reporting under 2% attack success in most tested IID settings.

Pith tools