Xiaolin Li, Ning Wang, Ninghui Li, Wenhai Sun
Reveals that differential privacy (DP) can be counterproductive in defending against backdoor attacks in federated learning (FL), and proposes a new backdoor attack technique RING that exploits DP.
Prior research claimed that DP naturally improves FL's defense against backdoor attacks, but overlooked the possibility that DP could modify attacker updates to evade detection. There is a need to verify the effectiveness of existing defenses under DP.
First, empirically analyze two baseline attack strategies to confirm the 'masking effect' where DP helps evade detection. Based on this, design the RING attack: malicious clients collaboratively craft adversarial perturbations to restore a strong backdoor signal during aggregation while avoiding anomaly detection. RING is a plug-in that can be combined with existing backdoor techniques, providing generality.
Experiments on four image/text datasets under non-iid settings show that RING achieves an average attack success rate of 90.3% against six state-of-the-art defenses under a moderate privacy budget, an improvement of up to 26.08x over baseline strategies. It also demonstrates that existing defenses struggle to effectively counter this attack without significant utility loss, exposing a fundamental security vulnerability in DP-FL.