Skip to main navigation Skip to search Skip to main content

Distributed Backdoor Attack Against Knowledge Distillation-Based Federated Learning

  • Harbin Institute of Technology
  • Chongqing University
  • Griffith University Queensland

Research output: Contribution to journalArticlepeer-review

Abstract

Federated Distillation (FD) has been widely adopted as a prominent framework for enabling collaborative learning among clients with heterogeneous model architectures. By aggregating and distilling architecture-agnostic output logits, FD allows effective knowledge sharing without requiring model homogeneity. However, this paradigm introduces a previously overlooked security risk: an adversary can manipulate logits to implant a backdoor into the global model. To expose this new attack vulnerability, we propose FD-DBA, the first backdoor attack specifically targeting FD. FD-DBA adopts a local distillation-based backdoor injection module that effectively mimics the backdoor knowledge transfer process. After backdoor injection, FD-DBA enables the adversary to utilize distributed optimized triggers to compromise the global model. Extensive experiments demonstrate that FD-DBA is powerful, achieving high attack success rates under IID and non-IID data distributions and across homogeneous and heterogeneous settings, while preserving clean sample accuracy. Moreover, FD-DBA maintains attack robustness even under robust aggregation defenses.

Original languageEnglish
Pages (from-to)2400-2404
Number of pages5
JournalIEEE Signal Processing Letters
Volume33
DOIs
StatePublished - 2026
Externally publishedYes

Keywords

  • Federated distillation
  • backdoor attack
  • heterogeneous federated learning
  • targeted attack

Fingerprint

Dive into the research topics of 'Distributed Backdoor Attack Against Knowledge Distillation-Based Federated Learning'. Together they form a unique fingerprint.

Cite this