Researchers Demonstrate Hardware-Based Backdoor Attack Against Federated Learning Systems
Researchers have developed a novel backdoor attack against federated learning (FL) systems that combines model poisoning with hardware-level bit-flip faults, achieving up to 94% attack success rate on ResNet-18 models. Federated learning allows distributed clients to collaboratively train AI models without sharing raw data, but this decentralization creates vulnerability to malicious participants. The findings expand the known attack surface for FL systems by showing that hardware fault techniques like Rowhammer can be weaponized alongside algorithmic approaches to implant persistent backdoors.
A study accepted at ACNS/AIHWS 2026 introduces a task-agnostic backdoor attack targeting federated learning systems by exploiting hardware-level memory faults, specifically bit-flips induced via Rowhammer-style attacks. Unlike prior FL backdoor attacks that rely purely on algorithmic manipulation of training data, this approach poisons a single local model's parameters during the FL training phase by physically corrupting bits in memory. The backdoor is crafted offline from the pretrained model used to initialize the FL system, making it stealthy and preparation-efficient. Experimental results show that as few as 10 faults per malicious client occurrence, across 19 total occurrences, are sufficient to achieve a 94% attack success rate on a ResNet-18 architecture. The attack was validated across multiple model types and datasets, suggesting broad applicability. The authors also discuss potential defenses and the practical constraints of Rowhammer as an attack vector, acknowledging real-world deployment challenges.
What's missing
The paper acknowledges Rowhammer's practical constraints but does not fully quantify the physical access requirements or the likelihood of successful exploitation in real-world FL deployments (e.g., cloud vs. edge hardware). The study's evaluation of defenses appears preliminary; robustness against state-of-the-art Byzantine-resilient FL aggregation methods is not comprehensively assessed. It is also unclear how the attack scales with larger, more heterogeneous FL systems involving many clients.
What different sources said
- arXiv cs.AICenter
Model Poisoning Against Federated Model Adaptation with Chain of Bit-Flips
Related
Gut Bacteria Enzyme Found to Break Down Heat-Processed Food Compounds, Producing Novel Biogenic Amines
Researchers have discovered that an enzyme in common gut bacteria can degrade N-epsilon-carboxymethyllysine (CML), a compound formed during thermal food processing, producing previously unknown biogenic amines. The enzyme, ornithine decarboxylase SpeC from enterobacteria, acts on CML and related modified lysine derivatives through a low-level 'underground' catalytic activity. This finding suggests a previously unrecognized communication axis between thermally processed dietary compounds and gut microbial physiology, with potential implications for host health.
Full-Length Gene Sequencing Reveals Two Distinct Bacterial Communities in Black-Legged Ticks Expanding Into Canada
Researchers used Oxford Nanopore full-length 16S rRNA gene sequencing to characterize the microbiome of Ixodes scapularis black-legged ticks collected in Nova Scotia, Canada, distinguishing between tick-adapted bacteria and environmentally acquired bacteria. The study comes as I. scapularis — the primary vector of Lyme disease — is rapidly expanding northward into Canada due to climate change. The findings suggest that environmentally derived bacteria in tick microbiomes are not mere contamination, which has implications for how tick microbiome data is collected and interpreted across surveillance studies.
Study Identifies Metabolic Link Between Cell Envelope Stress and Biofilm Formation in Bacteria
Researchers have discovered that the metabolite acetyl-CoA directly inhibits enzymes that degrade the bacterial signaling molecule c-di-GMP, connecting cell envelope biosynthesis stress to biofilm formation in Pseudomonas aeruginosa. The study found that sub-inhibitory concentrations of antibiotics targeting early peptidoglycan biosynthesis — but not other antibiotic classes — elevate c-di-GMP levels by reducing phosphodiesterase activity, with acetyl-CoA competing for the enzyme active site. Because the relevant enzyme domain is broadly conserved across bacterial species, this checkpoint mechanism may be widespread and could have implications for understanding antibiotic-induced biofilm responses.