Anchor in Evidence: Distribution-Preserving Backdoor Attacks in Federated Learning
Abstract
Federated learning (FL) enables collaborative model training without sharing local data, but its decentralized nature also makes it vulnerable to backdoor attacks. Among these attacks, in-distribution (ID) backdoor attacks are particularly attractive because they preserve distribution consistency and are difficult to detect. However, we observe that existing ID backdoor attacks become highly unstable under heterogeneous client distributions, where attack success can abruptly deteriorate during federated training. We identify this previously overlooked phenomenon as *Attack Collapse* and show that it arises from the continuously evolving feature space in FL, which progressively misaligns injected backdoor representations with the target-class distribution. Motivated by this observation, we propose IDEA, a distribution-preserving backdoor attack that maintains stable target alignment throughout federated training. IDEA first leverages evidential deep learning to identify reliable target-class samples and construct robust target regions. It then jointly performs region-aware alignment and evidential geometric refinement to preserve both target affinity and local semantic structure, enabling poisoned samples to remain compatible with the evolving feature space. Extensive experiments on multiple benchmark datasets demonstrate that IDEA consistently mitigates Attack Collapse and significantly improves attack efficiency and stability over state-of-the-art backdoor attacks, while maintaining competitive clean-task performance.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.