BadSampler: Harnessing the Power of Catastrophic Forgetting to Poison Byzantine-robust Federated Learning
Yi Liu, Cong Wang, Xingliang Yuan
Abstract
Federated Learning (FL) is susceptible to poisoning attacks, wherein compromised clients manipulate the global model by modifying local datasets or sending manipulated model updates. Experienced defenders can readily detect and mitigate the poisoning effects of malicious behaviors using Byzantine-robust aggregation rules. However, the exploration of poisoning attacks in scenarios where such behaviors are absent remains largely unexplored for Byzantinerobust FL. This paper addresses the challenging problem of poisoning Byzantine-robust FL by introducing catastrophic forgetting. To fill this gap, we first formally define generalization error and establish its connection to catastrophic forgetting, paving the way for the development of a clean-label data poisoning attack named BadSampler. This attack leverages only clean-label data (i.e., without poisoned data) to poison Byzantine-robust FL and requires the adversary to selectively sample training data with high loss to feed model training and maximize the model's generalization error. We formulate the attack as an optimization problem and present two elegant adversarial sampling strategies, Top-𝜅 sampling, and metasampling, to approximately solve it. Additionally, our formal error upper bound and time complexity analysis demonstrate that our design can preserve attack utility with high efficiency. Extensive evaluations on two real-world datasets illustrate the effectiveness and performance of our proposed attacks. CCS CONCEPTS • Security and privacy → Distributed systems security; • Computing methodologies → Machine learning.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 52abb59c-123e-4f61-b4aa-ae411680e818Builds on22
- Federated Learning on Non-IID Data Silos: An Experimental StudyQinbin Li, Yiqun Diao, Quan Chen, Bingsheng HeICDE 2022 · 1,110 citations
- Manipulating Machine Learning: Poisoning Attacks and Countermeasures for Regression LearningMatthew Jagielski, Alina Oprea, Battista Biggio, Chang Liu et al.S&P 2018 · 867 citations
- FLDetector: Defending Federated Learning Against Model Poisoning Attacks via Detecting Malicious ClientsZaixi Zhang, Xiaoyu Cao, Jinyuan Jia, Neil Zhenqiang GongKDD 2022 · 293 citations
- On the Origin of Implicit Regularization in Stochastic Gradient DescentSamuel L. Smith, Benoit Dherin, David G. T. Barrett, Soham DeICLR 2021 · 235 citations
- Rethinking Bias-Variance Trade-off for Generalization of Neural NetworksZitong Yang, Yaodong Yu, Chong You, Jacob Steinhardt et al.ICML 2020 · 219 citations
Related papers
- Oblivion: Poisoning Federated Learning by Inducing Catastrophic ForgettingChen Zhang, Boyang Zhou, Zhiqiang He, Zeyuan Liu et al.INFOCOM 2023 · 4 citations
- Local Model Poisoning Attacks to Byzantine-Robust Federated LearningMinghong Fang, Xiaoyu Cao, Jinyuan Jia, Neil Zhenqiang GongUSENIX Security 2020
- VaniKG: Vanishing Key Gradient Attack and Defense for Robust Federated AggregationHongjia Li, Leshui Lv, Ding Tang, Yan Zhang et al.INFOCOM 2025 · 2 citations
- Do We Really Need to Design New Byzantine-robust Aggregation Rules?Minghong Fang, Seyedsina Nabavirazavi, Zhuqing Liu, Wei Sun et al.NDSS 2025
- AgrEvader: Poisoning Membership Inference against Byzantine-robust Federated LearningYanjun Zhang, Guangdong Bai, Mahawaga Arachchige Pathum Chamikara, Mengyao Ma et al.WWW 2023 · 34 citations
