Backdoor Vulnerabilities in VFL: Bridging Research and Practice.

Ziqi Zhao, Jialin Lu, Junjie Shan, Junyuan Zhang, Shuya Yang, Ka-Ho Chow· August 14, 2026 View original

Key takeaways

  • Existing VFL backdoor research often overlooks practical constraints and unrealistic assumptions.
  • Backdoor attacks in VFL are more complex and less effective in real-world scenarios than previously thought.
  • A new benchmark, BVBench, is introduced for realistic evaluation of VFL backdoor risks.
  • Organizations must adopt practice-oriented security studies for VFL deployments.

Who benefits

BFSIHealthcareGovernmentTelecommunicationsCloud Services

Summary

This paper reveals a significant gap between academic research and practical realities regarding backdoor vulnerabilities in Vertical Federated Learning (VFL). It redefines threat models, proposes practical attack workflows, and introduces BVBench, a benchmark for realistic evaluation of VFL backdoor risks and defenses.

Vertical Federated Learning (VFL) allows multiple organizations to collaboratively train AI models using complementary data features without exposing their raw datasets, which is crucial for privacy. However, this asymmetric information structure also creates vulnerabilities, particularly to backdoor attacks. Malicious participants can inject poisoned data during training and activate these backdoors during inference to manipulate predictions. Despite numerous academic studies reporting high attack success rates and effective defenses, this research argues that most findings do not hold under realistic conditions, highlighting a fundamental disconnect between research and practical application. The paper systematically investigates VFL backdoor vulnerabilities, pointing out flaws in methodological design and evaluation practices in existing literature. It shows that current approaches often overlook practical constraints and rely on unrealistic prior knowledge. To bridge this gap, the authors redefine threat models, propose practical backdoor workflows, and introduce BVBench, a new benchmark designed for fair, practical, and comprehensive evaluation of VFL backdoor risks and defenses, revealing the fragility of current understanding.

Why it matters

For organizations adopting or developing VFL solutions, understanding realistic backdoor vulnerabilities is paramount for ensuring data integrity, model trustworthiness, and regulatory compliance.

How to implement this in your domain

  1. 1Re-evaluate existing VFL security protocols against more realistic threat models, considering practical constraints.
  2. 2Utilize benchmarks like BVBench to rigorously test the robustness of VFL systems against backdoor attacks.
  3. 3Collaborate with security experts to design and implement practical backdoor detection and mitigation strategies.
  4. 4Educate teams on the nuances of VFL security, emphasizing the gap between theoretical and practical vulnerabilities.

Original post by Ziqi Zhao, Jialin Lu, Junjie Shan, Junyuan Zhang, Shuya Yang, Ka-Ho Chow

"arXiv:2608.12962v1 Announce Type: new Abstract: Vertical Federated Learning (VFL) enables organizations holding complementary features of shared entities to collaborate and train models. In this setting, the initiator can withhold information about the learning task, while other…"

View on X

Originally posted by Ziqi Zhao, Jialin Lu, Junjie Shan, Junyuan Zhang, Shuya Yang, Ka-Ho Chow on X · view source

Want to go deeper?

Turn these trends into skills with Learnijoy's hands-on AI & tech courses.

Explore courses

More in AI Engineering & DevTools