Backspin: A backdoor attack framework for split learning based on smashed data.
Where this comes from
- Record sourced from PubMed, PMID 42492103.
- Also identified by DOI 10.1016/j.neunet.2026.109402.
- No licence information is recorded for this record.
- Because redistribution is not established, this page shows the abstract only. Follow the links below for the full text.
Abstract
Split Learning (SL) represents a novel collaborative machine learning paradigm tailored for participants with private data and constrained computational capabilities. As with Federated Learning (FL) and other collaborative learning paradigms, SL is also vulnerable to security threats, including backdoor attacks. Although prior research has claimed that SL is highly resilient to backdoor attacks because attackers lack access to other participants' training data and models, this study reveals vulnerabilities in SL to such threats by analyzing smashed data from multiple clients. Based on our analysis and observations, we propose a novel Backdoor attack framework against split learning, termed Backspin, that leverages the similarity of smashed data from different clients to execute both client-side and server-side attacks. Our evaluations cover both Computer Vision (CV) and Natural Language Processing (NLP) tasks across six widely used datasets and six models in diverse split-learning settings to validate Backspin's effectiveness and robustness against prevalent privacy defenses. Remarkably, our method achieves an average Attack Success Rate (ASR) exceeding 90%, while incurring only a 1.5% reduction in Clean Data Accuracy (CDA) relative to centralized training, demonstrating the balanced nature of our approach for effective attack execution without significantly compromising data integrity.