acceptodds
Under review as a conference paper at ICLR 2027

ConCam: Anchor Consensus and Camouflaged Injection for Backdoor Attacks in Vertical Federated Learning

Abstract

Vertical federated learning (VFL) enables parties holding disjoint feature partitions to collaboratively train models without sharing raw data. However, the embedding gradients exchanged during training can be exploited by a malicious passive party to implant backdoors. Recent VFL attacks can infer target-related samples from gradient information, yet single-anchor target-set construction remains sensitive to anchor quality, while explicit triggers and relatively large poisoning budgets may introduce conspicuous attack patterns. In this paper, we propose ConCam, a targeted backdoor attack that combines anchor consensus for reliable target-set construction with camouflaged backdoor injection. Specifically, ConCam aggregates candidate target sets from multiple target-class anchors through consensus voting and employs sample-specific implicit triggers together with dynamic gradient-based sample and carrier selection to enable effective injection at low poisoning rates. Across four datasets, ConCam achieves attack success rates above 97% with at most a 1.05-percentage-point reduction in accuracy, remains effective at a poisoning rate as low as 0.06%, and achieves substantially higher attack success rates than prior attacks under dedicated VFL backdoor defenses.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.