{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T16:13:43Z","timestamp":1783613623806,"version":"3.55.0"},"reference-count":56,"publisher":"Association for Computing Machinery (ACM)","issue":"2","funder":[{"name":"Science and Technology Tackling Program of Anhui Province","award":["202423k09020016"],"award-info":[{"award-number":["202423k09020016"]}]},{"DOI":"10.13039\/501100001809","name":"China National Natural Science Foundation","doi-asserted-by":"crossref","award":["62441228"],"award-info":[{"award-number":["62441228"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/\"http:\/\/dx.doi.org\/10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["2021YFB2900103"],"award-info":[{"award-number":["2021YFB2900103"]}],"id":[{"id":"10.13039\/\"http:\/\/dx.doi.org\/10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Sen. Netw."],"published-print":{"date-parts":[[2026,3,31]]},"abstract":"<jats:p>Vertical federated learning (VFL) enables multiple parties with disjoint features to collaboratively train models without sharing raw data. While privacy vulnerabilities of VFL are extensively-studied, its security threats\u2014particularly targeted label attacks\u2014remain underexplored. In such attacks, a passive party perturbs inputs at inference to force misclassification into adversary-chosen labels. Existing methods rely on unrealistic assumptions (e.g., accessing VFL-model\u2019s outputs) and ignore anomaly detectors deployed in real-world systems. To bridge this gap, we introduce VTarbel, a two-stage, minimal-knowledge attack framework explicitly designed to evade detector-enhanced VFL inference. During the preparation stage, the attacker selects a minimal set of high-expressiveness samples (via maximum mean discrepancy), submits them through VFL protocol to collect predicted labels, and uses these pseudo-labels to train estimated detector and surrogate model on local features. In attack stage, these models guide gradient-based perturbations of remaining samples, crafting adversarial instances that induce targeted misclassifications and evade detection. We implement VTarbel and evaluate it against four model architectures, seven multimodal datasets, and two anomaly detectors. Across all settings, VTarbel outperforms four state-of-the-art baselines, evades detection, and retains effective against three representative privacy-preserving defenses. These results reveal critical security blind spots in current VFL deployments and underscore urgent need for robust, attack-aware defenses.<\/jats:p>","DOI":"10.1145\/3790100","type":"journal-article","created":{"date-parts":[[2026,1,23]],"date-time":"2026-01-23T21:10:59Z","timestamp":1769202659000},"page":"1-33","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["VTarbel: Targeted Label Attack with Minimal Knowledge on Detector-Enhanced Vertical Federated Learning"],"prefix":"10.1145","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0009-0002-4325-9023","authenticated-orcid":false,"given":"Juntao","family":"Tan","sequence":"first","affiliation":[{"name":"School of Computer Science and Technology, University of Science and Technology of China","place":["Hefei, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3592-4153","authenticated-orcid":false,"given":"Anran","family":"Li","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, University of Science and Technology of China","place":["Hefei, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-1820-2052","authenticated-orcid":false,"given":"Quanchao","family":"Liu","sequence":"additional","affiliation":[{"name":"Department of Security Technology Research, China Mobile Research Institute","place":["Beijing, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-7334-8605","authenticated-orcid":false,"given":"Peng","family":"Ran","sequence":"additional","affiliation":[{"name":"Department of Security Technology Research, China Mobile Research Institute","place":["Beijing, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1004-8588","authenticated-orcid":false,"given":"Lan","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, University of Science and Technology of China","place":["Hefei, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,2,20]]},"reference":[{"key":"e_1_3_3_2_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2021.115782"},{"key":"e_1_3_3_3_2","first-page":"2743","volume-title":"Proceedings of the 32nd USENIX Security Symposium (USENIX Security 23)","author":"Bai Yijie","year":"2023","unstructured":"Yijie Bai, Yanjiao Chen, Hanlei Zhang, Wenyuan Xu, Haiqin Weng, and Dou Goodman. 2023. VILLAIN: Backdoor attacks against vertical split learning. In Proceedings of the 32nd USENIX Security Symposium (USENIX Security 23). USENIX Association, Anaheim, CA, 2743\u20132760. Retrieved from https:\/\/www.usenix.org\/conference\/usenixsecurity23\/presentation\/bai"},{"key":"e_1_3_3_4_2","volume-title":"Proceedings of the 19th International Conference on Machine Learning (ICML-2002","author":"Basu Sugato","year":"2002","unstructured":"Sugato Basu, Arindam Banerjee, and Raymond Mooney. 2002. Semi-supervised clustering by seeding. In Proceedings of the 19th International Conference on Machine Learning (ICML-2002. Citeseer."},{"key":"e_1_3_3_5_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICC45855.2022.9838942"},{"key":"e_1_3_3_6_2","doi-asserted-by":"publisher","DOI":"10.1145\/3447548.3467210"},{"key":"e_1_3_3_7_2","doi-asserted-by":"publisher","DOI":"10.1145\/2939672.2939785"},{"key":"e_1_3_3_8_2","doi-asserted-by":"publisher","DOI":"10.1080\/24709360.2017.1396742"},{"key":"e_1_3_3_9_2","unstructured":"Luke N Darlow Elliot J Crowley Antreas Antoniou and Amos J Storkey. 2018. Cinic-10 is not imagenet or cifar-10. arXiv:1810.03505. Retrieved from https:\/\/arxiv.org\/abs\/1810.03505"},{"key":"e_1_3_3_10_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSP.2004.830985"},{"key":"e_1_3_3_11_2","volume-title":"Python Socket Library","author":"Foundation Python Software","year":"1991","unstructured":"Python Software Foundation. 1991. Python Socket Library. Python Software Foundation, Beaverton, OR, USA. Retrieved from https:\/\/docs.python.org\/3\/library\/socket.html"},{"key":"e_1_3_3_12_2","first-page":"1397","volume-title":"Proceedings of the 31st USENIX Security Symposium (USENIX Security 22)","author":"Fu Chong","year":"2022","unstructured":"Chong Fu, Xuhong Zhang, Shouling Ji, Jinyin Chen, Jingzheng Wu, Shanqing Guo, Jun Zhou, Alex X Liu, and Ting Wang. 2022. Label inference attacks against vertical federated learning. In Proceedings of the 31st USENIX Security Symposium (USENIX Security 22). 1397\u20131414."},{"key":"e_1_3_3_13_2","volume-title":"NDSS","author":"Fu Jiayun","year":"2023","unstructured":"Jiayun Fu, Xiaojing Ma, Bin B Zhu, Pingyi Hu, Ruixin Zhao, Yaru Jia, Peng Xu, Hai Jin, and Dongmei Zhang. 2023. Focusing on pinocchio\u2019s nose: A gradients scrutinizer to thwart split-learning hijacking attacks using intrinsic attributes.. In NDSS."},{"key":"e_1_3_3_14_2","first-page":"5271","volume-title":"Proceedings of the 32nd USENIX Security Symposium (USENIX Security 23)","author":"Gao Xinben","year":"2023","unstructured":"Xinben Gao and Lan Zhang. 2023. PCAT: Functionality and data stealing from split learning by pseudo-client attack. In Proceedings of the 32nd USENIX Security Symposium (USENIX Security 23). USENIX Association, Anaheim, CA, 5271\u20135288. Retrieved from https:\/\/www.usenix.org\/conference\/usenixsecurity23\/presentation\/gao"},{"key":"e_1_3_3_15_2","doi-asserted-by":"publisher","DOI":"10.5555\/2188385.2188410"},{"key":"e_1_3_3_16_2","unstructured":"Jindong Gu Xiaojun Jia Pau de Jorge Wenqain Yu Xinwei Liu Avery Ma Yuan Xun Anjun Hu Ashkan Khakzar Zhijiang Li et\u00a0al. 2024. A survey on transferability of adversarial examples across deep neural networks. Transactions on Machine Learning Research (TMLR\u201924). https:\/\/openreview.net\/forum?id=AYJ3m7BocI"},{"key":"e_1_3_3_17_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103193"},{"key":"e_1_3_3_18_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_3_19_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3327853"},{"key":"e_1_3_3_20_2","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359824"},{"key":"e_1_3_3_21_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00723"},{"key":"e_1_3_3_22_2","doi-asserted-by":"publisher","DOI":"10.1145\/3687478"},{"key":"e_1_3_3_23_2","first-page":"994","article-title":"Cafe: Catastrophic data leakage in vertical federated learning","volume":"34","author":"Jin Xiao","year":"2021","unstructured":"Xiao Jin, Pin-Yu Chen, Chia-Yi Hsu, Chia-Mu Yu, and Tianyi Chen. 2021. Cafe: Catastrophic data leakage in vertical federated learning. Advances in Neural Information Processing Systems 34 (2021), 994\u20131006.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_3_24_2","unstructured":"Yan Kang Jiahuan Luo Yuanqin He Xiaojin Zhang Lixin Fan and Qiang Yang. 2022. A framework for evaluating privacy-utility trade-off in vertical federated learning. arXiv:2209.03885. Retrieved from https:\/\/arxiv.org\/abs\/2209.03885"},{"key":"e_1_3_3_25_2","doi-asserted-by":"crossref","unstructured":"Afsana Khan Marijn ten Thij and Anna Wilbik. 2025. Vertical federated learning: A structured literature review. Knowledge and Information Systems 67 4 (2025) 3205\u20133243.","DOI":"10.1007\/s10115-025-02356-y"},{"key":"e_1_3_3_26_2","volume-title":"Combinatorial Optimization","author":"Korte Bernhard H","year":"2011","unstructured":"Bernhard H Korte, Jens Vygen, B Korte, and J Vygen. 2011. Combinatorial Optimization. Vol. 1. Springer."},{"key":"e_1_3_3_27_2","doi-asserted-by":"publisher","DOI":"10.1109\/3477.764879"},{"key":"e_1_3_3_28_2","unstructured":"Alex Krizhevsky. 2009. Learning Multiple Layers of Features from Tiny Images. Technical Report CIFAR-10 dataset. University of Toronto 1\u201360."},{"key":"e_1_3_3_29_2","article-title":"MNIST handwritten digit database","author":"LeCun Yann","year":"2010","unstructured":"Yann LeCun, Corinna Cortes, and CJ Burges. 2010. MNIST handwritten digit database. ATT Labs [Online]. Available: http:\/\/yann.lecun.com\/exdb\/mnist","journal-title":"ATT Labs [Online]"},{"key":"e_1_3_3_30_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Li Oscar","year":"2022","unstructured":"Oscar Li, Jiankai Sun, Xin Yang, Weihao Gao, Hongyi Zhang, Junyuan Xie, Virginia Smith, and Chong Wang. 2022. Label leakage and protection in two-party split learning. In Proceedings of the International Conference on Learning Representations. Retrieved from https:\/\/openreview.net\/forum?id=cOtBRgsf2fO"},{"key":"e_1_3_3_31_2","unstructured":"Qun Li Chandra Thapa Lawrence Ong Yifeng Zheng Hua Ma Seyit A Camtepe Anmin Fu and Yansong Gao. 2023. Vertical federated learning: Taxonomies threats and prospects. arXiv:2302.01550. Retrieved from https:\/\/arxiv.org\/abs\/2302.01550"},{"key":"e_1_3_3_32_2","unstructured":"Wenjie Li Qiaolin Xia Hao Cheng Kouyin Xue and Shu-Tao Xia. 2022. Vertical semi-federated learning for efficient online advertising. arXiv:2209.15635. Retrieved from https:\/\/arxiv.org\/abs\/2209.15635"},{"key":"e_1_3_3_33_2","doi-asserted-by":"publisher","DOI":"10.3115\/1072228.1072378"},{"key":"e_1_3_3_34_2","doi-asserted-by":"publisher","DOI":"10.1145\/3687478"},{"key":"e_1_3_3_35_2","first-page":"26645","article-title":"CoPur: Certifiably robust collaborative inference via feature purification","volume":"35","author":"Liu Jing","year":"2022","unstructured":"Jing Liu, Chulin Xie, Sanmi Koyejo, and Bo Li. 2022. CoPur: Certifiably robust collaborative inference via feature purification. Advances in Neural Information Processing Systems 35 (2022), 26645\u201326657.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_3_36_2","doi-asserted-by":"crossref","unstructured":"Yang Liu Yan Kang Tianyuan Zou Yanhong Pu Yuanqin He Xiaozhou Ye Ye Ouyang Ya-Qin Zhang and Qiang Yang. 2024. Vertical Federated Learning: Concepts Advances and Challenges. IEEE Transactions on Knowledge and Data Engineering 36 7 (2024) 3615\u20133634.","DOI":"10.1109\/TKDE.2024.3352628"},{"key":"e_1_3_3_37_2","unstructured":"Yang Liu Zhihao Yi and Tianjian Chen. 2020. Backdoor attacks and defenses in feature-partitioned collaborative learning. arXiv:2007.03608. Retrieved from https:\/\/arxiv.org\/abs\/2007.03608"},{"key":"e_1_3_3_38_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE51399.2021.00023"},{"key":"e_1_3_3_39_2","doi-asserted-by":"publisher","DOI":"10.5555\/2002472.2002491"},{"key":"e_1_3_3_40_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00008"},{"key":"e_1_3_3_41_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179446"},{"key":"e_1_3_3_42_2","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3485259"},{"key":"e_1_3_3_43_2","first-page":"8024","volume-title":"Proceedings of the Advances in Neural Information Processing Systems 32","author":"Paszke Adam","year":"2019","unstructured":"Adam Paszke, Sam Gross, Francisco Massa, Adam Lerer, James Bradbury, Gregory Chanan, Trevor Killeen, Zeming Lin, Natalia Gimelshein, Luca Antiga, et\u00a0al. 2019. PyTorch: An imperative style, high-performance deep learning library. In Proceedings of the Advances in Neural Information Processing Systems 32. Curran Associates, Inc., 8024\u20138035. Retrieved from http:\/\/papers.neurips.cc\/paper\/9015-pytorch-an-imperative-style-high-performance-deep-learning-library.pdf"},{"key":"e_1_3_3_44_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2024.3358081"},{"key":"e_1_3_3_45_2","unstructured":"Victor Sanh Lysandre Debut Julien Chaumond and Thomas Wolf. 2019. DistilBERT a distilled version of BERT: Smaller faster cheaper and lighter. arXiv:1910.01108. Retrieved from https:\/\/arxiv.org\/abs\/1910.01108"},{"key":"e_1_3_3_46_2","unstructured":"Karen Simonyan and Andrew Zisserman. 2015. Very deep convolutional networks for large-scale image recognition. 3rd International Conference on Learning Representations (ICLR\u201915). Conference Track Proceedings San Diego CA USA."},{"key":"e_1_3_3_47_2","unstructured":"Jiankai Sun Xin Yang Yuanshun Yao and Chong Wang. 2022. Label leakage and protection from forward embedding in vertical federated learning. arXiv:2203.01451. Retrieved from https:\/\/arxiv.org\/abs\/2203.01451"},{"key":"e_1_3_3_48_2","doi-asserted-by":"publisher","DOI":"10.1109\/BigCom57025.2022.00051"},{"key":"e_1_3_3_49_2","unstructured":"Kang Wei Jun Li Chuan Ma Ming Ding Sha Wei Fan Wu Guihai Chen and Thilina Ranbaduge. 2022. Vertical federated learning: Challenges methodologies and experiments. arXiv:2202.04309. Retrieved from https:\/\/arxiv.org\/abs\/2202.04309"},{"key":"e_1_3_3_50_2","unstructured":"Haiqin Weng Juntao Zhang Feng Xue Tao Wei Shouling Ji and Zhiyuan Zong. 2020. Privacy leakage of real-world vertical federated learning. arXiv:2011.09290. Retrieved from https:\/\/arxiv.org\/abs\/2011.09290"},{"key":"e_1_3_3_51_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.emnlp-demos.6"},{"key":"e_1_3_3_52_2","unstructured":"Han Xiao Kashif Rasul and Roland Vollgraf. 2017. Fashion-MNIST: a Novel Image Dataset for Benchmarking Machine Learning Algorithms. arXiv:1708.07747. Retrieved from https:\/\/arxiv.org\/abs\/1708.07747"},{"key":"e_1_3_3_53_2","unstructured":"Liu Yang Di Chai Junxue Zhang Yilun Jin Leye Wang Hao Liu Han Tian Qian Xu and Kai Chen. 2023. A survey on vertical federated learning: From a layered perspective. arXiv:2304.01829. Retrieved from https:\/\/arxiv.org\/abs\/2304.01829"},{"key":"e_1_3_3_54_2","doi-asserted-by":"publisher","DOI":"10.1145\/3298981"},{"key":"e_1_3_3_55_2","doi-asserted-by":"publisher","DOI":"10.1145\/3501809"},{"key":"e_1_3_3_56_2","article-title":"Deep leakage from gradients","volume":"32","author":"Zhu Ligeng","year":"2019","unstructured":"Ligeng Zhu, Zhijian Liu, and Song Han. 2019. Deep leakage from gradients. Advances in Neural Information Processing Systems 32 (2019), 14747\u201314756.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_3_57_2","doi-asserted-by":"publisher","DOI":"10.1109\/TBDATA.2022.3192121"}],"container-title":["ACM Transactions on Sensor Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3790100","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,7]],"date-time":"2026-03-07T16:08:02Z","timestamp":1772899682000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3790100"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,2,20]]},"references-count":56,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2026,3,31]]}},"alternative-id":["10.1145\/3790100"],"URL":"https:\/\/doi.org\/10.1145\/3790100","relation":{},"ISSN":["1550-4859","1550-4867"],"issn-type":[{"value":"1550-4859","type":"print"},{"value":"1550-4867","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,2,20]]},"assertion":[{"value":"2025-04-16","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-01-11","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-02-20","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}