Lune

INFOCOM2025Top-tier venue

VaniKG: Vanishing Key Gradient Attack and Defense for Robust Federated Aggregation

Hongjia Li, Leshui Lv, Ding Tang, Yan Zhang, Weiping Wang, Xinghua Yang

2025Year
2Citations

Abstract

The AGgregation Algorithms (AGAs) that combine locally trained models into a single global model in Federated Learning (FL) is becoming a new attack vector for adversaries. Model Poisoning Attacks (MPAs) are the most notorious repre-sentative; it aims to hamper the accuracy of the jointly trained model through manipulating byzantine FL clients' model updates to deviate the aggregated model from the global optimum. To defeat MPAs, the robust AGAs become prevailing in academia. In this paper, we present a new type of MPA against robust AGAs, referred to as Vanishing Key Gradient attack (VaniKG). In VaniKG, byzantine FL clients first formulate the perturbation vector by inactivating key neurons of one/multiple layer(s) through vanishing their gradients, and then confuse the vector to a population of most benign clients' updates. Through extensive experiments, we show that VaniKG can disable 6 state-of-the-art robust AGAs and sabotage the accuracy. To defeat VaniKG and stealthy MPAs, we enhance robust AGAs by proposing the Diverse Client Selection (DCS) scheme, where byzantine clients with overly consistent gradients are avoided from being all selected. Finally, we demonstrate that DCS plus classical AGAs can guarantee the accuracy at a normal level when FL suffers with VaniKG and classical MPAs.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

lune papers get 96b851b3-c285-4fa7-86ee-f2f120d054da

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines