Provably Robust Federated Reinforcement Learning
Minghong Fang, Xilong Wang, Neil Zhenqiang Gong
Abstract
Federated reinforcement learning (FRL) allows agents to jointly learn a global decision-making policy under the guidance of a central server. While FRL has advantages, its decentralized design makes it prone to poisoning attacks. To mitigate this, Byzantinerobust aggregation techniques tailored for FRL have been introduced. Yet, in our work, we reveal that these current Byzantinerobust techniques are not immune to our newly introduced Normalized attack. Distinct from previous attacks that targeted enlarging the distance of policy updates before and after an attack, our Normalized attack emphasizes on maximizing the angle of deviation between these updates. To counter these threats, we develop an ensemble FRL approach that is provably secure against both known and our newly proposed attacks. Our ensemble method involves training multiple global policies, where each is learnt by a group of agents using any foundational aggregation rule. These well-trained global policies then individually predict the action for a specific test state. The ultimate action is chosen based on a majority vote for discrete action systems or the geometric median for continuous ones. Our experimental results across different settings show that the Normalized attack can greatly disrupt non-ensemble Byzantine-robust methods, and our ensemble approach offers substantial resistance against poisoning attacks. CCS Concepts • Security and privacy → Systems security.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers5
- Tracing Back the Malicious Clients in Poisoning Attacks to Federated LearningYuqi Jia, Minghong Fang, Hongbin Liu, Jinghuai Zhang et al.NeurIPS 2025 · 8 citations
- Find a Scapegoat: Poisoning Membership Inference Attack and Defense to Federated LearningWenjin Mo, Zhiyuan Li, Minghong Fang, Mingwei FangICCV 2025 · 3 citations
- SecureSplit: Mitigating Backdoor Attacks in Split LearningZhihao Dou, Dongfei Cui, Weida Wang, Anjun Gao et al.WWW 2026 · 1 citation
- Competitive Advantage Attacks to Decentralized Federated LearningYuqi Jia, Minghong Fang, Neil GongNeurIPS 2025
- Robust Reinforcement Learning in Finance: Modeling Market Impact with Elliptic Uncertainty SetsShaocong Ma, Heng HuangNeurIPS 2025
Builds on15
- Attack of the Tails: Yes, You Really Can Backdoor Federated LearningHongyi Wang, Kartik Sreenivasan, Shashank Rajput, Harit Vishwakarma et al.NeurIPS 2020 · 862 citations
- FLDetector: Defending Federated Learning Against Model Poisoning Attacks via Detecting Malicious ClientsZaixi Zhang, Xiaoyu Cao, Jinyuan Jia, Neil Zhenqiang GongKDD 2022 · 293 citations
- Provably Secure Federated Learning against Malicious ClientsXiaoyu Cao, Jinyuan Jia, Neil Zhenqiang GongAAAI 2021 · 161 citations
- Adaptive Reward-Poisoning Attacks against Reinforcement LearningXuezhou Zhang, Yuzhe Ma, Adish Singla, Xiaojin ZhuICML 2020 · 154 citations
- Fault-Tolerant Federated Reinforcement Learning with Theoretical GuaranteeFlint Xiaofeng Fan, Yining Ma, Zhongxiang Dai, Wei Jing et al.NeurIPS 2021 · 102 citations
Related papers
- Do We Really Need to Design New Byzantine-robust Aggregation Rules?Minghong Fang, Seyedsina Nabavirazavi, Zhuqing Liu, Wei Sun et al.NDSS 2025
- Learning to Attack Federated Learning: A Model-based Reinforcement Learning Attack FrameworkHenger Li, Xiaolin Sun, Zizhan ZhengNeurIPS 2022 · 55 citations
- Rethinking Byzantine Robustness in Federated Recommendation from Sparse Aggregation PerspectiveZhongjian Zhang, Mengmei Zhang, Xiao Wang, Lingjuan Lyu et al.AAAI 2025 · 5 citations
- Defending Against Sophisticated Poisoning Attacks with RL-based Aggregation in Federated LearningYujing Wang, Hainan Zhang, Sijia Wen, Wangjie Qiu et al.AAAI 2025 · 4 citations
- VaniKG: Vanishing Key Gradient Attack and Defense for Robust Federated AggregationHongjia Li, Leshui Lv, Ding Tang, Yan Zhang et al.INFOCOM 2025 · 2 citations
