Abstract
Federated Distillation (FD) has been widely adopted as a prominent framework for enabling collaborative learning among clients with heterogeneous model architectures. By aggregating and distilling architecture-agnostic output logits, FD allows effective knowledge sharing without requiring model homogeneity. However, this paradigm introduces a previously overlooked security risk: an adversary can manipulate logits to implant a backdoor into the global model. To expose this new attack vulnerability, we propose FD-DBA, the first backdoor attack specifically targeting FD. FD-DBA adopts a local distillation-based backdoor injection module that effectively mimics the backdoor knowledge transfer process. After backdoor injection, FD-DBA enables the adversary to utilize distributed optimized triggers to compromise the global model. Extensive experiments demonstrate that FD-DBA is powerful, achieving high attack success rates under IID and non-IID data distributions and across homogeneous and heterogeneous settings, while preserving clean sample accuracy. Moreover, FD-DBA maintains attack robustness even under robust aggregation defenses.
| Original language | English |
|---|---|
| Pages (from-to) | 2400-2404 |
| Number of pages | 5 |
| Journal | IEEE Signal Processing Letters |
| Volume | 33 |
| DOIs | |
| State | Published - 2026 |
| Externally published | Yes |
Keywords
- Federated distillation
- backdoor attack
- heterogeneous federated learning
- targeted attack
Fingerprint
Dive into the research topics of 'Distributed Backdoor Attack Against Knowledge Distillation-Based Federated Learning'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver