Journal of Information Security Reserach ›› 2026, Vol. 12 ›› Issue (9): 801-812.DOI: 10.12379/j.issn.2096-1057.2026.09.03

Previous Articles     Next Articles

Federated Learning Backdoor Attack Method Based on Dynamic Trigger Transformation

Wang Yonghao, Wang Chenghao, Li Yikai, Xiao Feng   

  • Online:2026-09-02 Published:2026-09-02

基于触发器动态变换的联邦学习后门攻击方法

汪永好,王铖浩,李沂锴,肖峰   

  • 作者简介:汪永好,王铖浩,李沂锴,肖峰

Abstract: To address the rapid degradation of fixed-trigger backdoor attacks in Federated Learning after attack termination, a backdoor attack method based on dynamic trigger transformation was developed. The method dynamically adjusted the position, size, and pattern of the trigger during federated training, selected trigger states according to historical attack success rates in data preprocessing, and introduced supervised contrastive learning in the adaptation stage to align representations of poisoned samples with the target class and mitigate catastrophic forgetting. Experiments were conducted on MNIST, CIFAR-10, and Tiny-ImageNet under multiple aggregation algorithms and five representative defense mechanisms, evaluating attack effectiveness, stealthiness, and persistence. The attack success rate exceeded 95% across the evaluated defense scenarios. In the CIFAR-10 setting, the attack success rate remained approximately 90% after trigger injection had been stopped for 1,000 rounds. These results indicate that dynamic trigger selection and supervised contrastive learning improve the persistence and adaptability of federated learning backdoor attacks.

Key words: federated learning, backdoor attack, dynamic trigger transformation, contrastive learning, model security

摘要: 针对联邦学习(Federated Learning,FL)后门攻击中固定触发器易被检测、攻击停止后效果快速衰减的问题,本文提出一种基于触发器动态变换的后门攻击方法。该方法在联邦训练过程中动态调整触发器的位置、大小与样式,在数据预处理阶段依据历史攻击成功率选择触发器状态,并在适应阶段引入监督对比学习,增强中毒样本与目标类别表征的一致性,以减缓灾难性遗忘。基于MNIST、CIFAR-10和Tiny-ImageNet数据集开展实验,并在多种聚合算法和五类典型防御机制下评估攻击效果、隐蔽性与持续性。结果表明,该方法在不同防御场景中的攻击成功率均超过95%;在CIFAR-10场景中,停止注入1000轮后攻击成功率仍保持在90%左右。研究表明,动态触发器选择与监督对比学习能够提高联邦学习后门攻击的持久性和适应性。

关键词: 联邦学习, 后门攻击, 触发器动态变换, 对比学习, 模型安全

CLC Number: