Your Privacy My Cloak: Backdoor Attacks on Differentially Private Federated Learning
arXiv·medium signal
Challenges the prevailing assumption that differential privacy (DP) inherently hardens federated learning against backdoor attacks. The authors show DP can instead act as a 'cloak' that conceals malicious updates, demonstrating backdoor attacks that exploit DP noise — a security caution for practitioners deploying privacy-preserving FL.