Exploit Gradient Skewness to Circumvent Byzantine Defenses for Federated Learning
Yuchen Liu, Chen Chen, Lingjuan Lyu, Yaochu Jin, Gang Chen
Abstract
Federated Learning (FL) is notorious for its vulnerability to Byzantine attacks. Most current Byzantine defenses share a common inductive bias: among all the gradients, the densely distributed ones are more likely to be honest. However, such a bias is a poison to Byzantine robustness due to a newly discovered phenomenon in this paper -gradient skew. We discover that a group of densely distributed honest gradients skew away from the optimal gradient (the average of honest gradients) due to heterogeneous data. This gradient skew phenomenon allows Byzantine gradients to hide within the densely distributed skewed gradients. As a result, Byzantine defenses are confused into believing that Byzantine gradients are honest. Motivated by this observation, we propose a novel skew-aware attack called STRIKE: first, we search for the skewed gradients; then, we construct Byzantine gradients within the skewed gradients. Experiments on three benchmark datasets validate the effectiveness of our attack. Code - https://github.com/YuchenLiu-a/byzantine skew Federated Learning (FL) (McMahan et al. 2017; Li et al. 2020) emerged as a privacy-aware learning paradigm, in which data owners, i.e., clients, repeatedly use their private data to compute local gradients and upload them to a central server. The central server collects the uploaded gradients from clients and aggregates these gradients to update the global model. In this way, clients can collaborate to train a model without exposing their private data. Unfortunately, FL is susceptible to Byzantine attacks due to its distributed nature (Blanchard et al. 2017; Guerraoui, Rouault et al. 2018). A malicious party can control a small subset of clients, i.e., Byzantine clients, to degrade the utility of the global model. During the training phase, Byzantine clients can send arbitrary messages to the central server to bias the global model. A wealth of defenses (Blanchard et al.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext be4b34d9-6e8b-461e-99f6-b2bf11973e92Builds on13
- On the Convergence of FedAvg on Non-IID DataXiang Li, Kaixuan Huang, Wenhao Yang, Shusen Wang et al.ICLR 2020 · 2,930 citations
- Federated Learning on Non-IID Data Silos: An Experimental StudyQinbin Li, Yiqun Diao, Quan Chen, Bingsheng HeICDE 2022 · 1,110 citations
- No Fear of Heterogeneity: Classifier Calibration for Federated Learning with Non-IID DataMi Luo, Fei Chen, Dapeng Hu, Yifan Zhang et al.NeurIPS 2021 · 510 citations
- Learning from History for Byzantine Robust OptimizationSai Praneeth Karimireddy, Lie He, Martin JaggiICML 2021 · 247 citations
- Minibatch vs Local SGD for Heterogeneous Distributed LearningBlake E. Woodworth, Kumar Kshitij Patel, Nati SrebroNeurIPS 2020 · 231 citations
Related papers
- Byzantine-Robust Learning on Heterogeneous Data via Gradient SplittingYuchen Liu, Chen Chen, Lingjuan Lyu, Fangzhao Wu et al.ICML 2023 · 27 citations
- Self-Driven Entropy Aggregation for Byzantine-Robust Heterogeneous Federated LearningWenke Huang, Zekun Shi, Mang Ye, He Li et al.ICML 2024 · 16 citations
- FedInv: Byzantine-Robust Federated Learning by Inversing Local Model UpdatesBo Zhao, Peng Sun, Tao Wang, Keyu JiangAAAI 2022 · 82 citations
- zPROBE: Zero Peek Robustness Checks for Federated LearningZahra Ghodsi, Mojan Javaheripi, Nojan Sheybani, Xinqiao Zhang et al.ICCV 2023 · 27 citations
- Rethinking Byzantine Robustness in Federated Recommendation from Sparse Aggregation PerspectiveZhongjian Zhang, Mengmei Zhang, Xiao Wang, Lingjuan Lyu et al.AAAI 2025 · 5 citations
