ישראל מירסקי

אקדמי בכיר

FLux

Covert Channels in FL through Transposed Training

Alexandra Dmitrienko, Torsten Krauß, Yisroel Mirsky

Federated learning (FL) routinely exchanges model-derived signals (e.g., logits or updates) between clients and a server, creating an attractive substrate for covert communication - especially in settings where adversaries cannot rely on direct, out-of-band coordination. Existing FL covert channels often trade off capacity, reliability under aggregation, setup requirements, or operational stealth (e.g., needing extensive pre-shared state, warm-up rounds, or leaving persistent artifacts).We present FLux, a covert channel that uses a transposed (mirrored) version of the model architecture as the decoding mechanism. By embedding either images directly or bit sequences (via dot codes) into the transposed model, FLux requires only small output-vector keys as minimal pre-shared information. The channel is functional from the first FL round, supports bidirectional messaging, and can be cleared after use. To remain robust to aggregation, FLux applies signal-preserving scaling of embedded updates, enabling reliable transmission of multiple bits per aggregation round and optional accumulation across rounds for higher throughput. We evaluate FLux across multiple datasets and model architectures, study factors that influence its capacity and reliability, and extensively compare it to related work.

שפת פרסום אנגלית
דפים 645-660
סטטוס פרסום פורסם - 04.06.2026

Keywords

Covert Channel
Cybersecurity
Deep Learning Security
Federated Learning
Transposed Training

ASJC Scopus subject areas

Computational Theory and Mathematics
Computer Networks and Communications
Computer Science Applications
גישה למסמך
10.1145/3779208.3805980
קבצים וקישורים אחרים
Link to publication in Scopus