Search papers, labs, and topics across Lattice.
This paper systematically investigates the vulnerabilities of Vertical Federated Learning (VFL) to backdoor attacks, highlighting a significant disconnect between theoretical research and practical application. The authors reveal that existing defenses often rely on unrealistic assumptions and fail to account for practical constraints, leading to an overestimation of their effectiveness. By redefining threat models and introducing BVBench, a comprehensive benchmark for evaluating backdoor risks, the study underscores the urgent need for more realistic approaches to safeguard VFL systems.
Existing defenses against backdoor attacks in Vertical Federated Learning are fundamentally flawed, often relying on unrealistic assumptions that mask their true vulnerabilities.
Vertical Federated Learning (VFL) enables organizations holding complementary features of shared entities to collaborate and train models. In this setting, the initiator can withhold information about the learning task, while other contributors participate without exposing their local datasets, creating an asymmetric information structure aligned with growing privacy demands. However, this asymmetry is a double-edged sword. Among various threats, backdoor attacks are particularly concerning because VFL not only enables malicious contributors to poison the model during training, but also allows them to activate the backdoor at inference time to manipulate predictions. Although prior work has reported near-perfect attack success rates and proposed effective defenses, we find that most findings fail to hold under realistic conditions, exposing a fundamental gap between research and practice. In this paper, we present a systematic, practice-oriented study of backdoor vulnerabilities in VFL, revealing this gap in both methodological design and evaluation practices. We show that existing approaches overlook key practical constraints and therefore rely on unrealistic prior knowledge. Furthermore, these limitations have remained hidden due to poorly designed evaluation practices in the literature. To bridge this gap, we redefine threat models under realistic constraints, propose practical backdoor workflows, and introduce BVBench, a backdoor-centric benchmark that enables fair, practical, and comprehensive evaluation, preloaded with state-of-the-art baselines. BVBench provides strong evidence of the fragility of the current understanding of VFL backdoor risks and establishes a foundation for steering research toward uncovering practical vulnerabilities and developing more meaningful defenses.