{"id":"W4417064347","doi":"10.48550/arxiv.2509.08089","title":"Hammer and Anvil: Toward a Theory of Backdoors in Federated Learning","year":2025,"lang":"en","type":"preprint","venue":"ArXiv.org","topic":"Adversarial Robustness in Machine Learning","field":"Computer Science","cited_by":1,"is_retracted":false,"has_abstract":true,"ca_institutions":"","funders":"Natural Sciences and Engineering Research Council of Canada; Government of Ontario; Royal Bank of Canada","keywords":"Backdoor; Adversary; Set (abstract data type); Inference; Federated learning; Adversarial system","routes":{"ca_aff":false,"ca_fund":true,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":true},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.02113479,0.002031631,0.002530017,0.003133157,0.00254233,0.006156171,0.005649157,0.005423426,0.002424353],"category_scores_gemma":[0.05512627,0.001697759,0.002951218,0.002721073,0.01235202,0.01344489,0.0129022,0.01266255,0.0006695885],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.004738966,"about_ca_system_score_gemma":0.005527663,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.003344126,"about_ca_topic_score_gemma":0.002451135,"domain_scores_codex":[0.9807841,0.00853767,0.000997363,0.003585771,0.004632659,0.001462485],"domain_scores_gemma":[0.9508151,0.02835922,0.003055898,0.01442906,0.002360665,0.0009800742],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"theoretical_or_conceptual","study_design_gemma":"theoretical_or_conceptual","study_design_scores_codex":[0.0002831963,0.000147018,0.002826083,0.0002399316,0.000222642,0.0001682532,0.0005313015,0.3502824,0.001366618,0.569964,0.005319722,0.06864881],"study_design_scores_gemma":[0.00003087312,0.00007244851,0.0001448981,0.00005392385,0.00002472204,0.00007678039,0.00003994159,0.6606581,0.001051108,0.3358034,0.002012961,0.00003095892],"study_design_candidate":"theoretical_or_conceptual","study_design_consensus":"theoretical_or_conceptual","genre_codex":"methods","genre_gemma":"methods","genre_scores_codex":[0.00610684,0.0004434575,0.9898915,0.001421725,0.00005459603,0.00006633538,0.00007115166,0.0006771837,0.001267164],"genre_scores_gemma":[0.6616931,0.001186256,0.3293118,0.002367945,0.0003630371,0.000681272,0.0003649318,0.0004161757,0.003615528],"genre_candidate":"methods","genre_consensus":"methods","teacher_disagreement_score":0.02113479,"threshold_uncertainty_score":0.1117728,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.03834422189501694,"score_gpt":0.2868456534938301,"score_spread":0.2485014315988132,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}