cs.LGAug 6, 2025

FLAT: Revealing Hidden Latent-Conditioned Backdoor Failures in Federated Learning

Authors: Tuan NguyenSze Jue YangKhoa D. DoanChee Seng ChanKok-Seng Wong

Organizations: College of Engineering and Computer Science, VinUniversity, Hanoi, Vietnam · VinUni-Illinois Smart Health Center, VinUniversity, Hanoi, Vietnam · Siebel School of Computing and Data Science, University of Illinois Urbana-Champaign, Urbana, IL, USA · Faculty of Computer Science and Information Technology, Universiti Malaya, Kuala Lumpur, Malaysia

Abstract

Horizontal federated learning (HFL) backdoor audits often summarize model behavior through clean accuracy (CA), mean attack success rate (ASR), or a single known-trigger test. Such summaries can hide a different failure mode, in which one target label is activated by many trigger realizations. We study this failure mode with FLAT, a latent-conditioned reliability stress test for HFL backdoors. In FLAT, compromised clients still submit ordinary classifier updates to the server, while an attacker-side generator G(x,t,z)G(x,t,z) separates target intent tt from trigger realization zz. This separation shifts the audit question from whether one known trigger succeeds to how the hidden behavior varies across targets, latent samples, defenses, and post-stop rounds. On CIFAR-10, CIFAR-100, and Tiny-ImageNet, FLAT preserves clean utility while reaching 99.49%, 99.66%, and 94.10% single-target FedAvg ASR. The evaluation also reveals non-uniform defense responses, where a server rule can suppress one target mode while leaving another active. These observations motivate HFL backdoor audits that report target-wise ASR, worst-target ASR, target coverage, latent-sampled behavior, post-stop persistence, and defense response.

Explore similar work

CardsList