Almanac
paper

Your Privacy My Cloak: Backdoor Attacks on Differentially Private Federated Learning

paperactiveprovisionalyour-privacy-my-cloak-backdoor-attacks-on-differentially-private-federated-learning-6852a348·1 events·first seen 33h ago

Aliases: Your Privacy My Cloak: Backdoor Attacks on Differentially Private Federated Learning

Co-occurring entities

More like this (12)

Recent events (1)

6arXiv · cs.LG·33h ago·source ↗

RING attack exploits differential privacy to amplify backdoor success in federated learning

A new arXiv paper challenges the assumption that differential privacy (DP) inherently protects federated learning (FL) against backdoor attacks, demonstrating that DP's noise mechanism actually masks the statistical signatures that defenses rely on to detect malicious updates. The authors propose RING, an attack that exploits this masking effect by having compromised clients collaboratively craft adversarial perturbations that reconstruct a strong backdoor signal at aggregation time. Evaluated across four datasets against six state-of-the-art defenses, RING achieves a 90.3% average attack success rate under moderate privacy budgets, up to 26x better than baselines. Proposed countermeasures incur significant utility trade-offs, exposing a fundamental security gap in DP-FL deployments.