Learning to Attack Federated Learning: A Model-based Reinforcement Learning Attack Framework
Henger Li, Xiaolin Sun, Zizhan Zheng
Abstract
We propose a model-based reinforcement learning framework to derive untargeted poisoning attacks against federated learning (FL) systems. Our framework first approximates the distribution of the clients’ aggregated data using model updates from the server. The learned distribution is then used to build a simulator of the FL environment, which is utilized to learn an adaptive attack policy through reinforcement learning. Our framework is capable of learning strong attacks automatically even when the server adopts a robust aggregation rule. We further derive an upper bound on the attacker’s performance loss due to inaccurate distribution estimation. Experimental results on real-world datasets demonstrate that the proposed attack framework significantly outperforms state-of-the-art poisoning attacks. This indicates the importance of developing adaptive defenses for FL systems.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers5
- Byzantine-Robust Decentralized Federated LearningMinghong Fang, Zifan Zhang, Hairi, Prashant Khanduri et al.CCS 2024 · 38 citations
- Static and Sequential Malicious Attacks in the Context of Selective ForgettingChenxu Zhao, Wei Qian, Rex Ying, Mengdi HuaiNeurIPS 2023 · 30 citations
- FedAA: A Reinforcement Learning Perspective on Adaptive Aggregation for Fair and Robust Federated LearningJialuo He, Wei Chen, Xiaojin ZhangAAAI 2025 · 12 citations
- Defending Against Sophisticated Poisoning Attacks with RL-based Aggregation in Federated LearningYujing Wang, Hainan Zhang, Sijia Wen, Wangjie Qiu et al.AAAI 2025 · 4 citations
- Find a Scapegoat: Poisoning Membership Inference Attack and Defense to Federated LearningWenjin Mo, Zhiyuan Li, Minghong Fang, Mingwei FangICCV 2025 · 3 citations
Builds on18
- On the Convergence of FedAvg on Non-IID DataXiang Li, Kaixuan Huang, Wenhao Yang, Shusen Wang et al.ICLR 2020 · 2,930 citations
- Inverting Gradients - How easy is it to break privacy in federated learning?Jonas Geiping, Hartmut Bauermeister, Hannah Dröge, Michael MoellerNeurIPS 2020 · 1,822 citations
- Exploiting Unintended Feature Leakage in Collaborative LearningLuca Melis, Congzheng Song, Emiliano De Cristofaro, Vitaly ShmatikovS&P 2019 · 1,736 citations
- Deep Models Under the GAN: Information Leakage from Collaborative Deep LearningBriland Hitaj, Giuseppe Ateniese, Fernando Pérez-CruzCCS 2017 · 1,581 citations
- Ditto: Fair and Robust Federated Learning Through PersonalizationTian Li, Shengyuan Hu, Ahmad Beirami, Virginia SmithICML 2021 · 1,313 citations
Related papers
- Back to the Drawing Board: A Critical Evaluation of Poisoning Attacks on Production Federated LearningVirat Shejwalkar, Amir Houmansadr, Peter Kairouz, Daniel RamageS&P 2022 · 302 citations
- Adversarial Attacks on Federated-Learned Adaptive Bitrate AlgorithmsRui-Xiao Zhang, Tianchi HuangAAAI 2024 · 4 citations
- Model Poisoning Attacks to Federated Learning via Multi-Round ConsistencyYueqi Xie, Minghong Fang, Neil Zhenqiang GongCVPR 2025
- FL-WBC: Enhancing Robustness against Model Poisoning Attacks in Federated Learning from a Client PerspectiveJingwei Sun, Ang Li, Louis DiValentin, Amin Hassanzadeh et al.NeurIPS 2021 · 131 citations
- Oblivion: Poisoning Federated Learning by Inducing Catastrophic ForgettingChen Zhang, Boyang Zhou, Zhiqiang He, Zeyuan Liu et al.INFOCOM 2023 · 4 citations
