acceptodds
Under review as a conference paper at ICLR 2027

BadAvg: Aggregation-aware backdoor attack against Federated Contrastive Learning

Abstract

Federated Learning (FL) enables collaborative model training without explicit data sharing, ensuring the participants' privacy. Unfortunately, the distributed nature of FL exposes trained models to backdoor attacks. Federated Contrastive Learning (FCL), which learns representations from unlabeled data, is often assumed to be more robust than its supervised counterpart, yet recent attacks on centralized Contrastive Learning have raised concerns about FCL's security. In this paper, we propose BadAvg, a novel backdoor attack on FCL that crafts malicious updates by modeling their propagation through federated aggregation. A malicious client running BadAvg replicates the server's aggregation of benign models via simulation, and crafts the backdoor by optimizing an adversarial loss on this differentiable simulation. We evaluate BadAvg on three downstream tasks under IID and Dirichlet-partitioned data, where a single malicious client contributes to only 0.25% of the local updates, measuring both peak effectiveness and attack persistence. BadAvg outperforms the competitors without defenses, and remains the strongest attack in the majority of the defended settings.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.