Curse or Redemption? How Data Heterogeneity Affects the Robustness of Federated Learning
Syed Zawad, Ahsan Ali, Pin-Yu Chen, Ali Anwar, Yi Zhou, Nathalie Baracaldo, Yuan Tian, Feng Yan
Abstract
Data heterogeneity has been identified as one of the key features in federated learning but often overlooked in the lens of robustness to adversarial attacks. This paper focuses on characterizing and understanding its impact on backdooring attacks in federated learning through comprehensive experiments using synthetic and the LEAF benchmarks. The initial impression driven by our experimental results suggests that data heterogeneity is the dominant factor in the effectiveness of attacks and it may be a redemption for defending against backdooring as it makes the attack less efficient, more challenging to design effective attack strategies, and the attack result also becomes less predictable. However, with further investigations, we found data heterogeneity is more of a curse than a redemption as the attack effectiveness can be significantly boosted by simply adjusting the client-side backdooring timing. More importantly, data heterogeneity may result in overfitting at the local training of benign clients, which can be utilized by attackers to disguise themselves and fool skewed-feature based defenses. In addition, effective attack strategies can be made by adjusting attack data distribution. Finally, we discuss the potential directions of defending the curses brought by data heterogeneity. The results and lessons learned from our extensive experiments and analysis offer new insights for designing robust federated learning methods and systems.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers6
- To Store or Not? Online Data Selection for Federated Learning with Limited StorageChen Gong, Zhenzhe Zheng, Fan Wu, Yunfeng Shao et al.WWW 2023 · 28 citations
- Distributed Distributionally Robust Optimization with Non-Convex ObjectivesYang Jiao, Kai Yang, Dongjin SongNeurIPS 2022 · 21 citations
- Resisting Backdoor Attacks in Federated Learning via Bidirectional Elections and Individual PerspectiveZhen Qin, Feiyi Chen, Chen Zhi, Xueqiang Yan et al.AAAI 2024 · 20 citations
- Certifiably Robust Model Evaluation in Federated Learning under Meta-Distributional ShiftsAmir Najafi, Samin Mahdizadeh Sani, Farzan FarniaICML 2025
- MingledPie: A Cluster Mingling Approach for Mitigating Preference Profiling in CFLCheng Zhang, Yang Xu, Jianghao Tan, Jiajie An et al.NDSS 2025
Builds on6
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Practical Secure Aggregation for Privacy-Preserving Machine LearningKallista A. Bonawitz, Vladimir Ivanov, Ben Kreuter, Antonio Marcedone et al.CCS 2017 · 3,936 citations
- On the Convergence of FedAvg on Non-IID DataXiang Li, Kaixuan Huang, Wenhao Yang, Shusen Wang et al.ICLR 2020 · 2,930 citations
- Neural Cleanse: Identifying and Mitigating Backdoor Attacks in Neural NetworksBolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li et al.S&P 2019 · 1,801 citations
- DBA: Distributed Backdoor Attacks against Federated LearningChulin Xie, Keli Huang, Pin-Yu Chen, Bo LiICLR 2020 · 901 citations
Related papers
- Bad-PFL: Exploiting Backdoor Attacks against Personalized Federated LearningMingyuan Fan, Zhanyi Hu, Fuyi Wang, Cen ChenICLR 2025
- Exploit Gradient Skewness to Circumvent Byzantine Defenses for Federated LearningYuchen Liu, Chen Chen, Lingjuan Lyu, Yaochu Jin et al.AAAI 2025 · 3 citations
- Parameter Disparities Dissection for Backdoor Defense in Heterogeneous Federated LearningWenke Huang, Mang Ye, Zekun Shi, Guancheng Wan et al.NeurIPS 2024 · 12 citations
- Mind the Cost of Scaffold! Benign Clients May Even Become Accomplices of Backdoor AttackXingshuo Han, Xuanye Zhang, Xiang Lan, Haozhao Wang et al.ICCV 2025 · 1 citation
- FilterFL: Knowledge Filtering-based Data-Free Backdoor Defense for Federated LearningYanxin Yang, Ming Hu, Xiaofei Xie, Yue Cao et al.CCS 2025
