BackDFL: A Unified Benchmark For Backdoor Attacks and Defenses In Decentralized Federated Learning

📅 2026-08-21
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文针对去中心化联邦学习中的后门攻击问题,提出了一种统一的评估基准BackDFL,揭示了现有防御方法在实际攻击下的脆弱性。
📝 Abstract
Decentralized Federated Learning (DFL) promises trust-free collaborative learning by replacing the centralized parameter server with peer-to-peer model exchange. However, this architectural shift fundamentally reshapes the threat landscape. Without globally coordinated aggregation, DFL becomes particularly susceptible to backdoor attacks, in which malicious participants implant persistent hidden behaviors while maintaining high clean-task performance. In this paper, we argue that the robustness of DFL has been significantly overestimated. Existing studies rely on simplified threat models, non-adaptive adversaries, fragmented evaluation protocols, inconsistent communication topologies, and ad hoc training configurations, leading to an incomplete understanding of DFL security. To address these limitations, we present BackDFL, a unified benchmark for systematically evaluating DFL under realistic and adaptive backdoor attacks. Through extensive experiments, BackDFL exposes critical failure modes of decentralized learning. Our results demonstrate that both state-of-the-art Byzantine-robust DFL methods and adapted FL backdoor defenses fail under modest malicious participation rates (as low as 15%), especially in heterogeneous settings, while their robustness varies substantially across communication graph topologies.
Problem

Research questions and friction points this paper is trying to address.

Decentralized Federated Learning
backdoor attacks
threat models
communication topologies
Byzantine-robust
Innovation

Methods, ideas, or system contributions that make the work stand out.

Backdoor Attacks
Decentralized Federated Learning
Adaptive Adversaries
Robustness Evaluation
Communication Topologies