arXiv:2608. 07274v1 Announce Type: cross Abstract: Split Federated Learning (SFL) facilitates privacy-preserving collaborative training with reduced client-side overhead.
By Yuhan Xie, Jingrong Huang, Chen Lyu
The paper introduces FedIoC, a federated learning framework that embeds structured threat indicators into gradient updates using a supervised contrastive loss. By aligning gradients from clients that share indicators for the same attack campaign, the server can cluster updates via cosine similarity to recover global campaign patterns without transmitting sensitive indicators. Experiments on two public threat‑detection benchmarks show that the server successfully identifies cross‑organizational campaign cohorts from fragmented local data.
By Manuel R\"oder, Bibin Babu, Frank-Michael Schleif
arXiv:2511. 13749v2 Announce Type: replace Abstract: Deep neural networks are known to be vulnerable to adversarial perturbations, which are small, carefully crafted inputs that lead to incorrect predictions.
By Ci Lin, Tet Yeap, Iluju Kiringa
arXiv:2609.07147v1 Announce Type: new
Abstract: Federated learning, as a privacy-preserving distributed machine learning paradigm, faces significant threats from backdoor attacks. Compared to central...
By Jian Wang, Hong Shen, Wei Ke, Xue Hua Liu
arXiv:2511. 04949v2 Announce Type: replace-cross Abstract: Rapid advances in generative AI have led to increasingly realistic deepfakes, posing growing challenges for law enforcement and public trust.
By Tharindu Fernando, Clinton Fookes, Sridha Sridharan
arXiv:2511. 07210v3 Announce Type: replace-cross Abstract: Clean-image backdoor attacks, which use only label manipulation in training datasets to compromise deep neural networks, pose a significant threat to security-critical applications.
By Binyan Xu, Fan Yang, Di Tang, Xilin Dai, Kehuan Zhang
The paper introduces the Threat Conditional Network (TCN), a model that achieves robust performance across a continuous range of adversarial threat levels. TCN splits representation learning into a threat‑invariant backbone and a lightweight threat‑conditional adaptor, using Fourier‑based embeddings and channel‑wise affine modulation to condition on perturbation budgets. Experiments on CIFAR‑10, CIFAR‑100, and Tiny‑ImageNet demonstrate that TCN matches or exceeds ensembles of budget‑specialized models while adding only 4.6% more parameters, and it generalizes to unseen budgets and mismatched threat conditions.
By Zhichao Hou, Xiaorui Liu
arXiv:2601. 14300v4 Announce Type: replace Abstract: Hard-label black-box attacks, relying solely on top-1 predictions, represent one of the most challenging yet practically threat models.
By Jun Liu, Leo Yu Zhang, Fengpeng Li, Isao Echizen, Jiantao Zhou
The paper introduces STAIN-FL, a stealthy backdoor attack framework for federated video anomaly detection that uses natural surveillance conditions—such as low light, indoor settings, and crowd density—as contextual triggers. STAIN-FL manipulates anomaly labels and masks gradients to keep clean accuracy low while inducing trigger‑conditioned misclassification. Experiments on UCF‑Crime with I3D features show that sparse attacks remain undetectable, drop clean accuracy by less than 2%, yet achieve over 50% backdoor accuracy for hundreds of rounds under FedAvg and FedProx.
By Ashlinder Kaur, Purnima Murali Mohan, Zengxiang Li, Tram Truong-Huu
The paper introduces TRIM, a black‑box defense for backdoor attacks in computer vision models. TRIM identifies and removes malicious trigger regions at inference time using region‑based segmentation, adaptive trigger discovery via inpainting and diffusion, and selective purification, without needing model internals, training data, or clean samples. Experiments on various datasets and trigger types show TRIM reduces attack success rates to as low as 1.16% while maintaining high clean accuracy.
By Ahmed Abdelnaby, Mohamed Elmahallawy
FSPGD introduces a feature-space black-box attack for semantic segmentation that targets intermediate representations rather than just output logits. The method uses a dual loss: an external loss to disrupt cross-model feature alignment and an internal loss to reduce consistency among same-class instances. Experiments on Pascal VOC 2012 and Cityscapes show that FSPGD outperforms existing logit-level and segmentation-specific attacks across CNN and Transformer backbones, and its adversarial examples improve robustness when used for training.
By Eun-Sol Park, MiSo Park, Yong-Goo Shin
arXiv:2607. 07314v1 Announce Type: cross Abstract: Federated learning (FL) avoids explicit data exposure by keeping raw data on local clients, yet privacy risks remain in the training process and the learned model itself.
By Chongkai Li, Bang Zhang, Wenjian Luo