Backdoor attack method based on multi-trigger optimization

By using the Multi-Trigger Cyclic Optimization (MTCO) framework, multiple triggers are initialized in the federated learning system and parameters are optimized cyclically. This solves the problems of persistence and stealth of backdoor attacks under dynamic training and heterogeneous data, and realizes persistent and stealthy backdoor attacks in the federated learning system.

CN121173518APending Publication Date: 2025-12-19DALIAN MARITIME UNIVERSITY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511281586.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-09-09
Publication Date
2025-12-19

AI Technical Summary

Technical Problem

Backdoor attack techniques for existing federated learning systems are difficult to maintain over a long period during dynamic training, and their effectiveness is significantly reduced in heterogeneous data distribution scenarios, limiting their applicability in practical applications.

Method used

The Multi-Trigger Cyclic Optimization (MTCO) framework is adopted. By initializing multiple triggers on the malicious client, defining the trigger activation region using a parameter masking mechanism, cyclically optimizing the trigger parameters, constructing an accumulated target loss function, and combining the projected gradient descent algorithm to optimize the trigger parameters, it adapts to dynamic changes in the model and enhances the persistence and stealth of the attack.

Benefits of technology

In dynamic and heterogeneous data environments, the MTCO method significantly improves the persistence and stealth of backdoor attacks, maintains good attack effectiveness, and does not affect the performance of the main task.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121173518A_ABST
    Figure CN121173518A_ABST
Patent Text Reader

Abstract

The invention provides a backdoor attack method based on multi-trigger optimization, which is applied to a federated learning system, and comprises the following steps: S1, in a federated learning environment, a malicious client initializes a plurality of local triggers, defines trigger activation areas through a parameter mask mechanism to ensure that disturbances are not overlapped, and generates poisoning samples by using the triggers; s2, when the malicious client is in a poisoning round, iteratively optimizing trigger parameters through an offline loop optimization strategy; s3, injecting a backdoor into the local data set by using the optimized trigger, and training a local model by using the poisoning data set to obtain a local model containing the backdoor; and S4, updating and submitting the malicious model containing the backdoor to a server. According to the method, multiple trigger parameters are dynamically optimized through the malicious client, cross-round backdoor feature disturbance complementation is realized, and the durability and the concealment of attacks are improved so as to adapt to dynamic updating of a federal learning model and heterogeneous distribution of client data.
Need to check novelty before this filing date? Find Prior Art