PaperScope
LIVE · 2026-09-03 05:40 UTC

CACTUS: Mask-Guided Semantic Clean-Label Backdoors in Decentralized Federated Learning

Chao Feng, Burkhard Stiller

Latestcs.CLcs.LGcs.AIcs.CV
arXiv ID
2609.02450 v1
Category
Submitted
2026-09-02

Abstract

Semantic triggers in federated learning (FL) can be less conspicuous than synthetic patches, but sample-dependent placement may weaken backdoor implantation across aggregation rounds. This challenge is compounded in decentralized FL (DFL), where topology-dependent peer aggregation repeatedly mixes local models. CACTUS converts label-consistent semantic pairs into target-directed representation shifts. Mask-guided, modality-specific operators isolate trigger effects, couple them across samples, and apply the shifts counterfactually to clean non-target embeddings before peer aggregation. Experiments cover speech, text, tabular, and image tasks under nine aggregation rules. With 30\% malicious nodes, CACTUS reaches a nine-rule mean attack success rate (ASR) of 51.2\% on Speech Commands and the highest nine-rule mean ASR among evaluated attacks on three of four modalities. Sensitivity analyses show that ASR varies with network topology and increases with the malicious-node ratio. These results indicate that CACTUS can propagate backdoors through repeated DFL aggregation.

arXiv abs page · PDF · same-day batch