ConCam: Anchor Consensus and Camouflaged Injection for Backdoor Attacks in Vertical Federated Learning
Abstract
Vertical federated learning (VFL) enables parties holding disjoint feature partitions to collaboratively train models without sharing raw data. However, the embedding gradients exchanged during training can be exploited by a malicious passive party to implant backdoors. Recent VFL attacks can infer target-related samples from gradient information, yet single-anchor target-set construction remains sensitive to anchor quality, while explicit triggers and relatively large poisoning budgets may introduce conspicuous attack patterns. In this paper, we propose ConCam, a targeted backdoor attack that combines anchor consensus for reliable target-set construction with camouflaged backdoor injection. Specifically, ConCam aggregates candidate target sets from multiple target-class anchors through consensus voting and employs sample-specific implicit triggers together with dynamic gradient-based sample and carrier selection to enable effective injection at low poisoning rates. Across four datasets, ConCam achieves attack success rates above 97% with at most a 1.05-percentage-point reduction in accuracy, remains effective at a poisoning rate as low as 0.06%, and achieves substantially higher attack success rates than prior attacks under dedicated VFL backdoor defenses.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.