USENIX Security2023Top-tier venue
Every Vote Counts: Ranking-Based Training of Federated Learning to Resist Poisoning Attacks
Hamid Mozaffari, Virat Shejwalkar, Amir Houmansadr
Abstract
Federated learning (FL) allows untrusted clients to collaboratively train a common machine learning model, called global model, without sharing their private/proprietary training data. However, FL is susceptible to poisoning by malicious clients who aim to hamper the accuracy of the global model by contributing malicious updates during FL's training process.
We argue that the key factor to the success of poisoning attacks against existing FL systems is the large space of model updates available to the clients to choose from. To address this, we propose Federated Rank Learning (FRL). FRL reduces the space of client updates from model parameter updates (a continuous space of float numbers) in standard FL to the space of parameter rankings (a discrete space of integer values). To be able to train the global model using parameter ranks (instead of parameter weights), FRL leverage ideas from recent supermasks training mechanisms. Specifically, FRL clients rank the parameters of a randomly initialized neural network (provided by the server) based on their local training data, and the FRL server uses a voting mechanism to aggregate the parameter rankings submitted by the clients.
Intuitively, our voting-based aggregation mechanism prevents poisoning clients from making significant adversarial modifications to the global model, as each client will have a single vote! We demonstrate the robustness of FRL to poisoning through analytical proofs and experimentation, and we show its high communication efficiency. 1 .
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers8
- Byzantine-Robust Decentralized Federated LearningMinghong Fang, Zifan Zhang, Hairi, Prashant Khanduri et al.CCS 2024 · 38 citations
- Provably Robust Federated Reinforcement LearningMinghong Fang, Xilong Wang, Neil Zhenqiang GongWWW 2025 · 14 citations
- ACE: A Model Poisoning Attack on Contribution Evaluation Methods in Federated LearningZhangchen Xu, Fengqing Jiang, Luyao Niu, Jinyuan Jia et al.USENIX Security 2024 · 11 citations
- Poisoning Attack on Federated Knowledge Graph EmbeddingEnyuan Zhou, Song Guo, Zhixiu Ma, Zicong Hong et al.WWW 2024 · 6 citations
- Beyond Denial-of-Service: The Puppeteer's Attack for Fine-Grained Control in Ranking-Based Federated LearningZhihao Chen, Zirui Gong, Jianting Ning, Yanjun Zhang et al.WWW 2026 · 1 citation
Builds on7
- Adaptive Federated OptimizationSashank J. Reddi, Zachary Charles, Manzil Zaheer, Zachary Garrett et al.ICLR 2021 · 1,917 citations
- Attack of the Tails: Yes, You Really Can Backdoor Federated LearningHongyi Wang, Kartik Sreenivasan, Shashank Rajput, Harit Vishwakarma et al.NeurIPS 2020 · 862 citations
- Supermasks in SuperpositionMitchell Wortsman, Vivek Ramanujan, Rosanne Liu, Aniruddha Kembhavi et al.NeurIPS 2020 · 364 citations
- Pruning Randomly Initialized Neural Networks with Iterative RandomizationDaiki Chijiwa, Shin'ya Yamaguchi, Yasutoshi Ida, Kenji Umakoshi et al.NeurIPS 2021 · 31 citations
- What's Hidden in a Randomly Weighted Neural Network?Vivek Ramanujan, Mitchell Wortsman, Aniruddha Kembhavi, Ali Farhadi et al.CVPR 2020
Related papers
- Not All Edges are Equally Robust: Evaluating the Robustness of Ranking-Based Federated LearningZirui Gong, Yanjun Zhang, Leo Yu Zhang, Zhaoxi Zhang et al.S&P 2025
- Manipulating the Byzantine: Optimizing Model Poisoning Attacks and Defenses for Federated LearningVirat Shejwalkar, Amir HoumansadrNDSS 2021
- Do We Really Need to Design New Byzantine-robust Aggregation Rules?Minghong Fang, Seyedsina Nabavirazavi, Zhuqing Liu, Wei Sun et al.NDSS 2025
- FL-WBC: Enhancing Robustness against Model Poisoning Attacks in Federated Learning from a Client PerspectiveJingwei Sun, Ang Li, Louis DiValentin, Amin Hassanzadeh et al.NeurIPS 2021 · 131 citations
- FreqFed: A Frequency Analysis-Based Approach for Mitigating Poisoning Attacks in Federated LearningHossein Fereidooni, Alessandro Pegoraro, Phillip Rieger, Alexandra Dmitrienko et al.NDSS 2024
