Federal learning model backdoor attack method based on parameter analysis
Through parameter importance analysis and activation difference calculation, combined with parameter manipulation of scaling module, the persistence and vulnerability of backdoor attacks in the federated learning model is solved, and backdoor attacks with high success rate and robustness are achieved, adapted to complex data environments, and supported collaborative attacks of multiple malicious clients.
Patent Information
- Application Number
- CN202510718244.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-30
- Publication Date
- 2025-09-02
AI Technical Summary
The existing federated learning model backdoor attack methods lack persistence in the global model and face vulnerability in defense mechanisms, making it difficult to effectively implant and maintain backdoor characteristics, affecting model performance and privacy security.
The parameter importance analysis module identifies the candidate parameters with the least impact, combines activation of the difference calculation and parameter manipulation of the scaling module, and performs parameter flip or scaling operations to ensure the concealment and durability of the backdoor behavior.
A backdoor attack with high success rate has been achieved, with an increase of 15%-30%. It maintains robustness and strong concealment under various defense mechanisms, adapts to complex data environments, and supports collaborative attacks of multiple malicious clients.
Smart Images

Figure CN120579602A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of federated learning security technology, and in particular to a federated learning model backdoor attack method based on parameter analysis. Background Art
[0002] The rapid development of deep neural network (DNN) technology has achieved tremendous success in fields such as computer vision, speech recognition, and natural language processing. While this technology has promoted the widespread adoption of artificial intelligence (AI), it has also exposed potential privacy risks. Traditional centralized learning requires users to upload all their local data to a central server for unified model training, a process that can lead to the leakage of sensitive user information. In 2016, Google proposed the federated learning (FL) training paradigm, which safeguards user privacy through distributed training. In this approach, clients train models locally and send the trained model parameters to a central server. The central server aggregates the model parameters from some or all clients and sends the aggregated model parameters back to the client to initiate a new round of training. However, due to the distributed nature of FL and the non-independent and identically distributed (Non-IID) nature of data between different clients, it is difficult for the central server to verify the validity of the uploaded models, making FL vulnerable to backdoor attacks. Therefore, studying backdoor attacks in FL is of great significance for developing effective backdoor defense technologies, protecting user privacy, and ensuring the security of information systems.
[0003] After actual investigation, we found that existing federated learning backdoor attacks can be divided into two categories: data backdoor attacks and model backdoor attacks. In data backdoor attacks, attackers implant backdoored data samples into local training data. In this case, the malicious model trained using a standard gradient descent algorithm is unlikely to maintain long-term attack effectiveness after global aggregation. In model backdoor attacks, attackers manipulate the update parameters transmitted from the client to the server, influencing the direction of model parameters throughout the learning process and, in turn, the performance of the federated learning model. However, existing model backdoor attacks often rely on indiscriminate amplification of malicious updates, which can cause model updates to deviate significantly from the normal range and impair the model's performance on the primary task. Summary of the Invention
[0004] In order to solve the technical problems existing in the above-mentioned prior art, the present invention proposes a backdoor attack method for federated learning models based on parameter analysis and activation differences, aiming to solve the problems of lack of backdoor persistence in the global model and vulnerability to defense mechanisms in existing methods.
[0005] To achieve the above object, the present invention provides the following technical solutions:
[0006] A backdoor attack method for federated learning models based on parameter analysis, the steps are as follows:
[0007] S1, identify a set of candidate parameters with the least impact on task performance from the model parameters through the parameter importance analysis module;
[0008] S2. Calculate the activation features of the backdoor image and the clean image during model training using the activation difference calculation module, and then obtain the activation difference matrix introduced by the backdoor trigger.
[0009] S3. The parameter manipulation and scaling module flips or scales the corresponding parameters according to the mapping relationship between the activation difference and the candidate parameters to ensure that the expected backdoor behavior can be effectively triggered.
[0010] Furthermore, the specific steps of step S1 are as follows:
[0011] S11. Assumptions represents the weight of the i-th layer network after the t-th round of training, and It represents the weight of the same network layer in the previous round, so the change in weight is defined as for:
[0012]
[0013] This change measures the extent to which the weight changes with the training rounds, and the weight with a smaller change is Manipulate it to minimize its impact on the classification accuracy of the main task;
[0014] S12. Changes in each weight Sort and select the v% weights with the smallest change as candidate parameters, that is, the threshold T of the candidate parameters img for:
[0015]
[0016] Where n is the total number of weights in this layer, Indicates floor operation;
[0017] S13, create a parameter importance mask M with the same shape as the weight change and initialized to 0, and select the weight importance mask M based on whether the weight change is less than or equal to the threshold T img To update the mask value, we aim to identify parameters that have less impact on the model's main task performance:
[0018]
[0019] S14. The binary mask M will guide the parameter update in the subsequent training process, and only the weight of the position M=1 will be adjusted according to the implanted backdoor target.
[0020] Furthermore, the specific steps of step S2 are as follows:
[0021] S21. Assume that the input x is in a convolutional layer w of the network i The resulting activation value is σ(w i (x)), and the activation value after adding the trigger mode p is σ(w i (x′)), the activation difference δ between the two can be expressed as:
[0022] δ=σ(w i (x))-σ(w i (x′)) (4)
[0023] where σ(·) represents the activation function of the network, Indicates a backdoor sample with added triggers;
[0024] S22, process the activation difference matrix δ by downsampling to match w i size;
[0025] S23. Define an importance threshold T act , based on the mean of the absolute values of the activation differences, we determine which regions have the most significant changes in activation values:
[0026] T act =mean(|δ|) (5)
[0027] S24, introduces the activation difference mask K, which is obtained by comparing the activation difference with T act Compare the binary masks obtained; if the activation difference at a certain position exceeds T act , then the mask K of the position is marked as 1, otherwise it is marked as 0, which is expressed as:
[0028]
[0029] Furthermore, the parameter importance mask M and the activation difference mask K are obtained through steps S1 and S2 respectively. In step S3, the parameter manipulation scaling module uses the binary mask K obtained by activation difference analysis and the binary mask M obtained by parameter importance analysis to jointly guide the network layer parameter w i The adjustment of parameters follows the following rules:
[0030] w i ′=w i ⊙(1-M)+η·|w i |⊙M⊙K (7)
[0031] where w i′ represents the adjusted network layer parameters, η is a predefined scaling factor used to adjust the size of the weight, and ⊙ represents element-by-element multiplication.
[0032] Beneficial effects of the present invention:
[0033] Compared with the existing technology, the parameter analysis-based federated learning model backdoor attack method described in this invention has the following technical features and beneficial effects:
[0034] (1) High attack success rate and strong persistence: Through the synergy of three modules, parameter importance analysis, activation difference calculation, and parameter manipulation and scaling, a covert backdoor is implanted into the federated learning model. On the CIFAR10, CelebA, and Tiny-ImageNet datasets and multiple models (CNN, VGG16, ResNet18), the attack success rate (ASR) exceeds 98.5%, an improvement of 15%-30% over the baseline method, and the backdoor characteristics can be retained for a long time in the global model aggregation.
[0035] (2) Highly concealed: By manipulating parameters that have the least impact on the performance of the primary task, the weight difference between the backdoor model and the clean model is minimal. Experiments show that the cosine similarity of the activation values of the last convolutional layer between the two is close to 1 (0.99 for CIFAR10 and Tiny-ImageNet), and the Euclidean distance is low (e.g., 113.71 for CIFAR10), indicating that the attack is difficult to detect by conventional detection methods.
[0036] (3) The robustness of the defense mechanism is outstanding: Model refinement defense (such as FedDF, FedRAD): the attack success rate converges to more than 99.5%, and the normal classification performance (BA) does not decrease significantly; Robust aggregation defense (such as DeepSight, RobustLR): ASR remains above 99%, and BA fluctuations are controllable; Authentication robustness defense (such as CRFL): ASR remains above 95%, and BA drops significantly.
[0037] (4) Adaptability to complex data environments: Under Non-IID data distribution (simulating client data heterogeneity), even if the parameter α in the dataset is low (data differences are large), the attack success rate can still be maintained high; it supports coordinated attacks by multiple malicious clients. For example, in the CelebA dataset, when the number of malicious clients increases from 1 to 4, the ASR jumps from 0.29% to 99.37%, significantly improving the attack effectiveness.
[0038] (5) Promote technological research and social security: A backdoor attack method based on fine parameter manipulation is proposed, which provides new ideas for the research of backdoor defense technology and promotes the iterative optimization of defense algorithms; it reveals the potential security vulnerabilities of the federated learning system, helps to enhance privacy protection awareness and reduce the risk of user privacy leakage caused by backdoor attacks. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the present invention will be described in detail below in combination with the accompanying drawings and detailed embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0040] in:
[0041] Figure 1 It is the overall framework diagram of the present invention;
[0042] Figure 2 This is a specific framework diagram of the "selection and manipulation" process in the present invention;
[0043] Figure 3 This is a comparison chart of the robustness of the present invention when facing model refinement defense;
[0044] Figure 4 This is a comparison chart of the robustness of the present invention against robust aggregate defense;
[0045] Figure 5 This is a comparison chart of the robustness of the present invention against CRFL defense;
[0046] Figure 6 This is a comparison chart of the impact of data heterogeneity on the present invention. DETAILED DESCRIPTION
[0047] In order to make the purpose, technical solutions and advantages of the present invention more clear, the present invention is further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention. Figure 1-6 The backdoor attack method of the federated learning model based on parameter analysis is further explained.
[0048] Example 1
[0049] The present invention designs three modules: parameter importance analysis, activation difference calculation, and parameter manipulation scaling, which achieve fine manipulation of model parameters through coordination and cooperation. First, the parameter importance analysis module aims to identify a set of candidate parameters from the model parameters that have the least impact on task performance. These parameters are ideal manipulation targets because their changes have the least impact on the normal operation of the model, thereby significantly reducing the risk of being detected by the defense mechanism. Subsequently, the activation difference calculation module calculates the activation features of the backdoor image and the clean image respectively during model training, and then obtains the activation difference matrix introduced by the backdoor trigger. Finally, the parameter manipulation scaling module flips or scales the corresponding parameters according to the mapping relationship between the activation difference and the candidate parameters to ensure that the expected backdoor behavior can be effectively triggered.
[0050] This method, through three parameter analysis and processing modules, achieves a stealthy and efficient backdoor attack on federated learning models, demonstrating exceptional robustness against backdoor defense mechanisms. Specifically, on three datasets, CIFAR10, CelebA, and Tiny-ImageNet, and five federated aggregation methods, this method achieves a 15%-30% improvement in attack success rate over baseline methods. Technically, this technology implements a backdoor attack method for federated learning models that finely manipulates model parameters. By integrating three modules—parameter importance analysis, activation difference calculation, and parameter manipulation scaling—it provides an innovative solution for backdoor attack research and promotes the development of backdoor defense technology. Socially, it discovers a new federated learning security vulnerability, thereby reducing the potential risk of privacy leaks.
[0051] Example 2
[0052] As a new embodiment or a supplement to embodiment 1.
[0053] In order to solve the problems of the lack of backdoor persistence in the global model and the vulnerability to defense mechanisms in existing methods, this paper proposes a federated learning model backdoor attack method based on parameter analysis and activation differences, which fully considers the diversity of client data in federated learning and the complexity of model updates. Figure 1 shown.
[0054] The present invention mainly includes three parts: "client trigger injection", "selection and manipulation", and "server backdoor injection". Among them, "client trigger injection" is used to embed the backdoor into the local model by data poisoning. Modify its model parameters through the "Selection and Manipulation" section to obtain a toxic local model Finally, in the “Server Backdoor Injection” section, the poisonous local model and the benign local models provided by other participants are aggregated by the server model to obtain the poisonous global model.
[0055] Among the three parts mentioned above, the “selection and manipulation” part is the core of this method. Through a carefully designed parameter selection and manipulation strategy, the model is secretly poisoned, so that the backdoor characteristics can be effectively preserved during the model update process. The specific framework of the “selection and manipulation” process is as follows: Figure 2 shown.
[0056] The entire framework can be divided into the following three modules: (1) Parameter importance analysis module, which aims to identify a set of candidate parameters from the model parameters that have the least impact on task performance. These parameters are ideal manipulation targets because their changes have the least impact on the normal operation of the model, significantly reducing the risk of being detected by defense mechanisms; (2) Activation difference calculation module, which calculates the activation features of the backdoor image and the clean image respectively during model training, and then obtains the activation difference matrix introduced by the backdoor trigger; (3) Parameter manipulation scaling module, which flips or scales the corresponding parameters according to the mapping relationship between the activation difference and the candidate parameters to ensure that the expected backdoor behavior can be effectively triggered.
[0057] Parameter importance analysis module:
[0058] Existing research shows that the L2 norm of benign gradients involved in aggregation is concentrated on a small number of coordinates. Therefore, if an attacker can precisely manipulate these "inactive" parameters, they can implant powerful model backdoors without affecting the performance of the main task. Therefore, selecting appropriate model parameters for manipulation is key to optimizing backdoor attack strategies.
[0059] At the same time, research in the field of model compression has shown that by identifying and processing parameters that contribute less to model performance, the size and computational complexity of the model can be effectively reduced. For example, pruning operations typically remove low-importance connections in weights, while quantization operations reduce the size of the model by reducing the number of bits in the weights.
[0060] Therefore, we draw on the idea of model compression and believe that parameters with small weight changes have limited contribution to model performance and can be regarded as ideal manipulation targets. Specifically, assuming represents the weight of the i-th layer network after the t-th round of training, and It represents the weight of the same network layer in the previous round, so the change in weight is defined as for:
[0061]
[0062] This variation measures the magnitude of the weight change over the training rounds. This invention only considers the weights with smaller magnitude of change. Manipulate it to minimize its impact on the classification accuracy of the main task.
[0063] Next, the change in each weight Sort and select the v% weights with the smallest change as candidate parameters, that is, the threshold T of the candidate parameters img for:
[0064]
[0065] Where n is the total number of weights in this layer, Indicates floor operation.
[0066] Then, a parameter importance mask M is created with the same shape as the weight change and initialized to 0, and the weight change is calculated based on whether the weight change is less than or equal to the threshold T. img To update the mask value, we aim to identify parameters that have less impact on the model's main task performance.
[0067]
[0068] Finally, the binary mask M will guide the parameter update in the subsequent training process, and only the weights of those M=1 positions will be adjusted according to the implanted backdoor target.
[0069] The core of this module is that it draws on the concept of weight importance evaluation in the field of model compression and applies it to the exploration of backdoor attack strategies, which not only improves the concealment of the attack but also maintains the normal function of the model.
[0070] Activate the difference calculation module:
[0071] Figure 2 The activation difference calculation module in
[15] is designed to fine-tune parameters in convolutional networks. By calculating the difference in activation values between clean samples and backdoored samples containing the trigger pattern, it identifies key parameters in the model that are affected by the trigger pattern. This module reveals the model's sensitivity to specific patterns and provides a quantitative basis for subsequent parameter adjustments.
[0072] Assume that the input x is in a convolutional layer w of the network i The resulting activation value is σ(w i (x)), and the activation value after adding the trigger mode p is σ(w i (x′)), the activation difference δ between the two can be expressed as:
[0073] δ=σ(w i (x))-σ(w i(x′)) (4)
[0074] δ=σ(w i (x))-σ(w i (x′)) (4)
[0075] Where σ(·) represents the activation function of the network (ReLU function), Indicates a backdoor sample with added triggers.
[0076] In order to further map the activation differences caused by the triggering pattern to the network layer parameters w i In the example, the activation difference matrix δ is processed by downsampling to match w i Then, define an importance threshold T act , based on the mean of the absolute values of the activation differences, we determine which regions have the most significant changes in activation values:
[0077] T act =mean(|δ|) (5)
[0078] T act =mean(|δ|) (5)
[0079] Subsequently, the activation difference mask K is introduced, which is obtained by comparing the activation difference with T act Compare the binary masks obtained. If the activation difference at a certain position exceeds T act , then the mask K of the position is marked as 1, otherwise it is marked as 0, which can be expressed as:
[0080]
[0081] In this way, the mask K can indicate the regions where activation differences are significant due to the firing pattern, providing target regions for weight adjustment in the parameter manipulation scaling module.
[0082] Parameter manipulation scaling module:
[0083] After obtaining the parameter importance mask M and the activation difference mask K, it is necessary to perform an amplification operation on the manipulation parameters obtained based on the two, so as to enhance the impact of the backdoor trigger without compromising the performance of the model's main task. To this end, the present invention proposes a parameter manipulation scaling module. Among them, this method identifies parameters that are less active in the normal behavior of the model. At the same time, the activation difference analysis module further determines which parameters respond significantly to the trigger mode. Based on the results of these two modules, the parameter manipulation scaling module uses the binary mask K obtained by the activation difference analysis and the binary mask M obtained by the parameter importance analysis to jointly guide the network layer parameters w i The adjustment of parameters follows the following rules:
[0084] w i ′=w i ⊙(1-M)+η·|w i |⊙M⊙K (7)
[0085] w i ′=w i ⊙(1-M)+η·|w i |⊙M⊙K (7)
[0086] where w i ′ represents the adjusted network layer parameters, η is a predefined scaling factor used to adjust the size of the weight, and ⊙ represents element-by-element multiplication. This weight adjustment takes into account both the importance of the weight in the normal task and the significance of the activation difference, thereby achieving precise control of the backdoor trigger response.
[0087] Example 3
[0088] This example provides experimental setup and results:
[0089] To evaluate the proposed method, experiments were conducted on multiple visual classification datasets and models, including three datasets: CIFAR10, CelebA, and Tiny-ImageNet, and three models: Convolutional Neural Network (CNN), VGG16, and ResNet18. The CelebA dataset uses the three attributes "Male," "Eyeglasses," and "Smiling" to create an 8-category dataset. Table 1 lists the attack effectiveness of the proposed method under different dataset and model combinations. Benign accuracy and attack success rate are represented by BA and ASR, respectively, which measure the performance of backdoor attacks under normal classification tasks and specific trigger conditions.
[0090] Table 1 BA / ASR (%) of this method
[0091]
[0092] The results in Table 1 demonstrate the effectiveness of the proposed method. ASR scores exceeded 98.5% for all nine dataset and model combinations. This demonstrates the universality and effectiveness of the proposed attack strategy across diverse model structures, and its ability to retain backdoor characteristics during global model aggregation without significantly deviating from the normal model update range.
[0093] (1) Robustness against model refinement defense
[0094] The present invention uses two model refinement defense methods, FedDF and FedRAD, to study the robustness of this method. Figure 3As shown. It can be found that in the FedDF and FedRAD defense scenarios, the present method exhibits significant robustness and a very high attack success rate. Using the FedDF and FedRAD defense strategies on the CIFAR10 dataset, the attack success rate of the present method gradually converges to more than 99.5%. At the same time, the present method maintains normal classification performance without triggering the backdoor. This shows that the method proposed in the present invention can retain the backdoor characteristics in the model parameters by accurately constructing the backdoor on the local client, thereby being able to bypass the defense based on model refinement and ensuring the persistence and stability of the attack effect during the iterative update of the model.
[0095] (2) Robustness against robust aggregate defenses
[0096] In order to evaluate the robustness of this method in the face of robust aggregation defense, this paper selects DeepSight and RobustLR algorithms as defense strategies. The experimental results are as follows: Figure 4 shown.
[0097] Experimental results show that this method exhibits extremely high robustness when facing robust aggregation defense. On all three data sets, the ASR of this method converges to above 99%, and the BA difference is not much different. This shows that the backdoor attack method of the present invention is relatively meticulous in manipulating the model parameters. It not only selects relatively easy-to-ignore parameters through parameter importance analysis, but also performs appropriate operations on them through precise activation differences and parameter manipulation. This makes this method sufficiently stealthy in the parameter space, thus being able to effectively evade detection by DeepSight and RobustLR, two robust aggregation defense strategies.
[0098] (3) Robustness against CRFL defense
[0099] CRFL is a certified robustness defense algorithm that ensures the robustness of the model by assigning a certified radius to samples, and achieves parameter smoothing by trimming model parameters and adding Gaussian noise during training. In the testing phase, Gaussian noise sampling and an integrated voting mechanism are used to improve the model's adversarial capabilities. The experimental results of this method against CRFL defense are as follows: Figure 5 As shown in the figure, the CRFL defense strategy has a certain defensive effect on this method, but its success is based on a decrease in clean accuracy. Specifically, ASR on the CIFAR10 dataset drops from 99.5% to around 95%, but BA drops from 70% to 60%. On the Tiny-ImageNet dataset, ASR drops from 98.5% to 97%, but BA drops from 32% to 22%. Compared to ASR, the decrease in BA is even greater. This shows that the present invention is also robust against the CRFL defense strategy.
[0100] (4) Covert experiment
[0101] To evaluate the stealthiness of the proposed backdoor attack method, the cosine similarity and Euclidean distance of the activation values of the clean model and the backdoor model at the last convolutional layer are used as evaluation indicators. The experimental results are shown in Table 2. Since the parameters precisely manipulated by this method contribute little to the model performance, the difference between the weights of the generated backdoor model and the clean model is very small, which proves the stealthiness of the proposed method.
[0102] Table 2 Concealment experiment of this method
[0103]
[0104] (5) Ablation experiment
[0105] 1) Impact of Non-IID Settings on Backdoor Attacks
[0106] The Non-IID setting simulates the heterogeneity of client data distribution in the federated learning environment. In order to evaluate the impact of the Non-IID setting on this method, the present invention adjusts the parameter α of the Dirichlet distribution to explore the performance of this method under different data heterogeneity levels. The experimental results are shown in Figure 2. Figure 6 As shown in Figure 2, a lower centralization parameter exacerbates the differences between client data, making it difficult for the global model to learn consistent parameter representations from each client, which in turn affects its performance on clean data. Furthermore, as α decreases, the volatility of BA and ASR increases, further indicating that a lower centralization parameter makes it more difficult for the global model to converge. This not only affects the model's performance on clean data, but also provides more opportunities for attackers.
[0107] 2) Impact of the number of malicious clients on backdoor attacks
[0108] In a federated learning environment, the number of malicious clients is a key factor affecting the effectiveness of backdoor attacks. To evaluate the impact of varying numbers of malicious clients on the attack success rate and model convergence speed, experiments were conducted with a single malicious client, two malicious clients, and four malicious clients. The results are shown in Table 3.
[0109] Table 3 Impact of the number of malicious clients on ASR (%)
[0110]
[0111] Experimental results show that as the number of malicious clients increases from 1 to 4 on the CIFAR-10 dataset, the ASR increases from 98.39% to 99.92%, and on the Tiny-ImageNet dataset, it significantly increases from 51.12% to 98.08%, a 46.96% increase. For the CelebA dataset, when the number of malicious clients is 1, due to the large number of samples in this dataset, the backdoor injected by a single malicious client is diluted during model training, rendering the attack ineffective. However, when the number of malicious clients increases to 4, the ASR increases to 99.37%, further demonstrating the robustness of our method.
[0112] The above description is only a preferred specific embodiment of the present invention, but the scope of protection of the present invention is not limited thereto. Any technician familiar with the technical field, within the technical scope disclosed by the present invention, who makes equivalent replacements or changes based on the technical solution and inventive concept of the present invention, should be covered by the scope of protection of the present invention.
Claims
1. A backdoor attack method for federated learning models based on parameter analysis, characterized in that: Here are the steps: S1, identify a set of candidate parameters with the least impact on task performance from the model parameters through the parameter importance analysis module; S2. Calculate the activation features of the backdoor image and the clean image during model training using the activation difference calculation module, and then obtain the activation difference matrix introduced by the backdoor trigger. S3. The parameter manipulation and scaling module flips or scales the corresponding parameters according to the mapping relationship between the activation difference and the candidate parameters to ensure that the expected backdoor behavior can be effectively triggered.
2. The method for backdoor attack on a federated learning model based on parameter analysis according to claim 1, characterized in that: The specific steps of step S1 are as follows: S11. Assumptions represents the weight of the i-th layer network after the t-th round of training, and It represents the weight of the same network layer in the previous round, so the change in weight is defined as for: This change measures the extent to which the weight changes with the training rounds, and the weight with a smaller change is Manipulate it to minimize its impact on the classification accuracy of the main task; S12. Changes in each weight Sort and select the v% weights with the smallest change as candidate parameters, that is, the threshold T of the candidate parameters img for: Where n is the total number of weights in this layer, Indicates floor operation; S13, create a parameter importance mask M with the same shape as the weight change and initialized to 0, and select the weight importance mask M based on whether the weight change is less than or equal to the threshold T img To update the mask value, we aim to identify parameters that have less impact on the model's main task performance: S14. The binary mask M will guide the parameter update in the subsequent training process, and only the weight of the position M=1 will be adjusted according to the implanted backdoor target.
3. The method for backdoor attack on a federated learning model based on parameter analysis according to claim 1, characterized in that: The specific steps of step S2 are as follows: S21. Assume that the input x is in a convolutional layer w of the network i The resulting activation value is σ(w i (x)), and the activation value after adding the trigger mode p is σ(w i (x′)), the activation difference δ between the two can be expressed as: δ=σ(w i (x))-σ(w i (x′))(4) where σ(·) represents the activation function of the network, Indicates a backdoor sample with added triggers; S22, process the activation difference matrix δ by downsampling to match w i size; S23. Define an importance threshold T act , based on the mean of the absolute values of the activation differences, we determine which regions have the most significant changes in activation values: T act =mean(|δ|)(5) S24, introduces the activation difference mask K, which is obtained by comparing the activation difference with T act Compare the binary masks obtained; if the activation difference at a certain position exceeds T act , then the mask K of the position is marked as 1, otherwise it is marked as 0, which is expressed as:
4. The method for backdoor attack on a federated learning model based on parameter analysis according to claim 1, characterized in that: The parameter importance mask M and activation difference mask K are obtained through steps S1 and S2 respectively. In step S3, the parameter manipulation scaling module uses the binary mask K obtained by activation difference analysis and the binary mask M obtained by parameter importance analysis to jointly guide the network layer parameter w i The adjustment of parameters follows the following rules: w i ′=w i ⊙(1-M)+η·|w i |⊙M⊙K(7) where w i ′ represents the adjusted network layer parameters, η is a predefined scaling factor used to adjust the size of the weight, and ⊙ represents element-by-element multiplication.