Skip to content
Book Open access

Rethinking the Stealthiness of Cryptographically Undetectable Backdoors in Practical RFF Learning

Aug 2026 · Proceedings of the 32nd ACM SIGKDD Conference on Knowledge Discovery and Data Mining V.2 · pp. 699-709 · 0 citations · 4 references

Abstract

Random Fourier Features (RFF) learning is a classical technique in scalable data mining. However, at FOCS 2022, Goldwasser et al. proposed a theoretical framework for planting cryptographically undetectable backdoors in RFF learning based on the hardness of the Continuous Learning With Errors (CLWE) problem. Their construction guarantees white-box undetectability in the model parameter space against any polynomial-time distinguisher. In this paper, we revisit the undetectability of CLWE backdoors from a practical RFF learning perspective. We prove that the operational validity of the CLWE backdoor critically hinges on assumptions that are incompatible with the realistic RFF learning deployment. Specifically, standard data preprocessing required for effective RFF learning fundamentally destroys the input-space stealthiness of CLWE backdoors, inevitably resulting in conspicuous input-level artifacts. We further validate our theoretical findings through extensive experiments on both tabular and image datasets, demonstrating that simple sanity checks at the input level suffice to reliably identify backdoored inputs. In addition, under the same threat model, we analyze the adversarial robustness of RFF learning models and provide a concrete certified robustness analysis, enabling a deeper security assessment of its practical deployment. Overall, our work emphasizes the importance of evaluating theoretical backdoor attacks under realistic machine learning pipelines and offers broader insights into the secure deployment of RFF learning systems.

Read PDF

Similar papers

#machine learning Preprint Sep 2026

Implementing a White-Box Undetectable Backdoor for Random Fourier Features

Goldwasser et al. showed that undetectable backdoors can be planted in machine learning models trained with the Random Fourier Features (RFF) algorithm, under a hardness assumption tied to the Continuous Learning With Errors (CLWE) problem. Under standard cryptographic assumptions, even a full white-box audit of a mode...

Michael Collins, J. Cumberland, Brianne Dunn et al. · 0 citations
Aug 2026

Transferability of Evasion and Backdoor Attacks in Encrypted Domain

It is demonstrated that FHE-enabled models remain susceptible to both evasion and backdoor attacks, underscoring the need for stronger defenses in encrypted ML systems.

Reeshav Chowdhury, Ayantika Chatterjee · 0 citations
Preprint Aug 2026

BackDFL: A Unified Benchmark For Backdoor Attacks and Defenses In Decentralized Federated Learning

BackDFL is presented, a unified benchmark for systematically evaluating DFL under realistic and adaptive backdoor attacks, and demonstrates that both state-of-the-art Byzantine-robust DFL methods and adapted FL backdoor defenses fail under modest malicious participation rates, especially in heterogeneous settings.

M. Bouchiha, Gregory Blanc, Yu-Fei Han · 0 citations
Preprint Aug 2026

Z-PEFT: Zero-shot Backdoor Detection in Parameter-Efficient Fine-Tuning via Canonical Spectral Signatures

This work proposes Z-PEFT, a lightweight meta-classifier that relies exclusively on layer-wise spectral measures for classification, and achieves the best performance while maintaining low and scalable computational cost among weight-space detectors.

Nicola Pitzalis, Donald Shenaj, Giacomo Cignoni et al. · 0 citations
Open access 2026

SiftFL: Scheduling-Based Robust Backdoor Detection in Federated Learning

Backdoor attacks pose a serious threat to federated learning, particularly when client data are non-IID and the attacker ratio is high. FilterFL is a recent server-side defense that employs two Conditional Generative Adversarial Networks (CGANs) to generate synthetic samples and identify malicious client models without...

Ekhlas Hashem, Muhamad Felemban, Sajjad Mahmood et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.