{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/neurotoxin-durable-backdoors-in-federated","title":"Neurotoxin: Durable Backdoors in Federated Learning","arxiv_id":"2206.10341","date":"2022-06-12","proceeding":null,"authors":["Zhengming Zhang","Ashwinee Panda","Linyue Song","Yaoqing Yang","Michael W. Mahoney","Joseph E. Gonzalez","Kannan Ramchandran","Prateek Mittal"],"abstract":"Due to their decentralized nature, federated learning (FL) systems have an inherent vulnerability during their training to adversarial backdoor attacks. In this type of attack, the goal of the attacker is to use poisoned updates to implant so-called backdoors into the learned model such that, at test time, the model's outputs can be fixed to a given target for certain inputs. (As a simple toy example, if a user types \"people from New York\" into a mobile keyboard app that uses a backdoored next word prediction model, then the model could autocomplete the sentence to \"people from New York are rude\"). Prior work has shown that backdoors can be inserted into FL models, but these backdoors are often not durable, i.e., they do not remain in the model after the attacker stops uploading poisoned updates. Thus, since training typically continues progressively in production FL systems, an inserted backdoor may not survive until deployment. Here, we propose Neurotoxin, a simple one-line modification to existing backdoor attacks that acts by attacking parameters that are changed less in magnitude during training. We conduct an exhaustive evaluation across ten natural language processing and computer vision tasks, and we find that we can double the durability of state of the art backdoors.","url_abs":"https://arxiv.org/abs/2206.10341v1","url_pdf":"https://arxiv.org/pdf/2206.10341v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"neurotoxin-durable-backdoors-in-federated","repo_url":"https://github.com/jhcknzzm/federated-learning-backdoor","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":1,"framework":"pytorch","reach":null},{"paper_slug":"neurotoxin-durable-backdoors-in-federated","repo_url":"https://github.com/xqx12/daily-info","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"ok"}}],"tasks":[{"task_slug":"backdoor-attack","task_name":"Backdoor Attack"},{"task_slug":"federated-learning","task_name":"Federated Learning"},{"task_slug":"sentence","task_name":"Sentence"}],"methods":[{"method_slug":"test","method_name":"Test"}],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=2206.10341","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"2206.10341"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/jhcknzzm/federated-learning-backdoor","reach":null},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/xqx12/daily-info","reach":{"status":"ok"}}],"summary":{"unverified":1},"by_repo_kind":{"official":{"samples":1,"ran":0,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":1,"samples":[{"code_sha256_prefix":"8f0767ca61874299","entry":"apply_grad_mask","repo":"jhcknzzm/federated-learning-backdoor","repo_kind":"official","path":"FL_Backdoor_CV/train_funcs.py","file_url":"https://github.com/jhcknzzm/federated-learning-backdoor/blob/HEAD/FL_Backdoor_CV/train_funcs.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"8f0767ca61874299"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}