paper

STAIN-FL: Stealthy Targeted Attack Injection with Contextual Triggers in Federated Learning

arXiv:2608.23952

Abstract

Federated video anomaly detection trains model collaboratively without sharing raw surveillance footage, but limited server-side visibility lets compromised clients to inject backdoor via malicious updates. This paper introduces STAIN-FL, a stealthy targeted backdoor attack injection framework that uses naturally occurring surveillance conditions, including low-light scenes, indoor settings, and crowd density, as contextual triggers. STAIN-FL combines anomaly-to-benign label \textit{manipulation} with gradient masking over least-updated coordinates to preserve clean accuracy while inducing trigger-conditioned misclassification. We evaluate STAIN-FL on \texttt{UCF-Crime} using 1024-dimensional I3D features in a non-IID four-client multi-agency setting, comparing FedAvg and FedProx under sparse and continuous attacks. Results show that sparse attacks have low-detectability, operationally significant attacks rather than high-intensity attacks: they keep the mean clean-accuracy drop below , yet still misclassify more than half of triggered anomalies at peak backdoor accuracy under FedAvg () and FedProx (). Under FedAvg, the sparse backdoor remains above the backdoor-accuracy threshold for an average of post-attack rounds, highlighting the persistence risk of contextually triggered attacks in surveillance systems.

STAIN-FL: Stealthy Targeted Attack Injection with Contextual Triggers in Federated Learning · wovepaper