An Equivalence Between Data Poisoning and Byzantine Gradient Attacks
Sadegh Farhadkhani, Rachid Guerraoui, Lê Nguyên Hoang, Oscar Villemaud
Abstract
To study the resilience of distributed learning, the “Byzantine” literature considers a strong threat model where workers can report arbitrary gradients to the parameter server. Whereas this model helped obtain several fundamental results, it has sometimes been considered unrealistic, when the workers are mostly trustworthy machines. In this paper, we show a surprising equivalence between this model and data poisoning, a threat considered much more realistic. More specifi-cally, we prove that every gradient attack can be reduced to data poisoning, in any personalized federated learning system with PAC guarantees (which we show are both desirable and realis-tic). This equivalence makes it possible to obtain new impossibility results on the resilience of any “robust” learning algorithm to data poisoning in highly heterogeneous applications, as corollaries of existing impossibility theorems on Byzantine machine learning. Moreover, using our equivalence, we derive a practical attack that we show (theoretically and empirically) can be very effective against classical personalized federated learning models.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ae1428b9-d5a1-4760-bf4b-236611db664dCited by top-tier papers5
- Towards Understanding and Enhancing Robustness of Deep Learning Models against Malicious Unlearning AttacksWei Qian, Chenxu Zhao, Wei Le, Meiyi Ma et al.KDD 2023 · 38 citations
- Algorithmic Collective Action in Machine LearningMoritz Hardt, Eric Mazumdar, Celestine Mendler-Dünner, Tijana ZrnicICML 2023 · 36 citations
- On Optimal Learning Under Targeted Data PoisoningSteve Hanneke, Amin Karbasi, Mohammad Mahmoody, Idan Mehalel et al.NeurIPS 2022 · 15 citations
- Tight Stability Bounds for Robust Distributed Learning: Byzantine Failures Hurt Generalization More than Data PoisoningThomas Boudou, Batiste Le Bars, Nirupam Gupta, Aurélien BelletICML 2026 · 3 citations
- Agnostic Learning under Targeted Poisoning: Optimal Rates and the Role of RandomnessBogdan Chornomaz, Yonatan Koren, Shay Moran, Tom WaknineNeurIPS 2025 · 2 citations
Builds on10
- Language Models are Few-Shot LearnersTom B. Brown, Benjamin Mann, Nick Ryder, Melanie Subbiah et al.NeurIPS 2020 · 64,255 citations
- Learning from History for Byzantine Robust OptimizationSai Praneeth Karimireddy, Lie He, Martin JaggiICML 2021 · 247 citations
- MetaPoison: Practical General-purpose Clean-label Data PoisoningW. Ronny Huang, Jonas Geiping, Liam Fowl, Gavin Taylor et al.NeurIPS 2020 · 242 citations
- Just How Toxic is Data Poisoning? A Unified Benchmark for Backdoor and Data Poisoning AttacksAvi Schwarzschild, Micah Goldblum, Arjun Gupta, John P. Dickerson et al.ICML 2021 · 207 citations
- Explanation-Guided Backdoor Poisoning Attacks Against Malware ClassifiersGiorgio Severi, Jim Meyer, Scott E. Coull, Alina OpreaUSENIX Security 2021 · 186 citations
Related papers
- Local Model Poisoning Attacks to Byzantine-Robust Federated LearningMinghong Fang, Xiaoyu Cao, Jinyuan Jia, Neil Zhenqiang GongUSENIX Security 2020
- Manipulating the Byzantine: Optimizing Model Poisoning Attacks and Defenses for Federated LearningVirat Shejwalkar, Amir HoumansadrNDSS 2021
- Ditto: Fair and Robust Federated Learning Through PersonalizationTian Li, Shengyuan Hu, Ahmad Beirami, Virginia SmithICML 2021 · 1,313 citations
- Back to the Drawing Board: A Critical Evaluation of Poisoning Attacks on Production Federated LearningVirat Shejwalkar, Amir Houmansadr, Peter Kairouz, Daniel RamageS&P 2022 · 302 citations
- FedInv: Byzantine-Robust Federated Learning by Inversing Local Model UpdatesBo Zhao, Peng Sun, Tao Wang, Keyu JiangAAAI 2022 · 82 citations
