Delving into the Adversarial Robustness of Federated Learning
Jie Zhang, Bo Li, Chen Chen, Lingjuan Lyu, Shuang Wu, Shouhong Ding, Chao Wu
Abstract
In Federated Learning (FL), models are as fragile as centrally trained models against adversarial examples. However, the adversarial robustness of federated learning remains largely unexplored. This paper casts light on the challenge of adversarial robustness of federated learning. To facilitate a better understanding of the adversarial vulnerability of the existing FL methods, we conduct comprehensive robustness evaluations on various attacks and adversarial training methods. Moreover, we reveal the negative impacts induced by directly adopting adversarial training in FL, which seriously hurts the test accuracy, especially in non-IID settings. In this work, we propose a novel algorithm called Decision Boundary based Federated Adversarial Training (DBFAT), which consists of two components (local re-weighting and global regularization) to improve both accuracy and robustness of FL systems. Extensive experiments on multiple datasets demonstrate that DBFAT consistently outperforms other baselines under both IID and non-IID settings.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers11
- Byzantine-Robust Learning on Heterogeneous Data via Gradient SplittingYuchen Liu, Chen Chen, Lingjuan Lyu, Fangzhao Wu et al.ICML 2023 · 27 citations
- Attack Can Benefit: An Adversarial Approach to Recognizing Facial Expressions under Noisy AnnotationsJiawen Zheng, Bo Li, Shengchuan Zhang, Shuang Wu et al.AAAI 2023 · 20 citations
- TranSpeech: Speech-to-Speech Translation With Bilateral PerturbationRongjie Huang, Jinglin Liu, Huadai Liu, Yi Ren et al.ICLR 2023 · 17 citations
- How Does the Smoothness Approximation Method Facilitate Generalization for Federated Adversarial Learning?Wenjun Ding, Ying An, Lixing Chen, Shichao Kan et al.AAAI 2025 · 1 citation
- Certifiably Robust Model Evaluation in Federated Learning under Meta-Distributional ShiftsAmir Najafi, Samin Mahdizadeh Sani, Farzan FarniaICML 2025
Builds on15
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- SCAFFOLD: Stochastic Controlled Averaging for Federated LearningSai Praneeth Karimireddy, Satyen Kale, Mehryar Mohri, Sashank J. Reddi et al.ICML 2020 · 3,875 citations
- On the Convergence of FedAvg on Non-IID DataXiang Li, Kaixuan Huang, Wenhao Yang, Shusen Wang et al.ICLR 2020 · 2,930 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Tackling the Objective Inconsistency Problem in Heterogeneous Federated OptimizationJianyu Wang, Qinghua Liu, Hao Liang, Gauri Joshi et al.NeurIPS 2020 · 2,231 citations
Related papers
- Combating Exacerbated Heterogeneity for Robust Models in Federated LearningJianing Zhu, Jiangchao Yao, Tongliang Liu, Quanming Yao et al.ICLR 2023 · 2 citations
- CalFAT: Calibrated Federated Adversarial Training with Label SkewnessChen Chen, Yuchen Liu, Xingjun Ma, Lingjuan LyuNeurIPS 2022 · 53 citations
- Federated Adversarial Learning: A Framework with Convergence AnalysisXiaoxiao Li, Zhao Song, Jiaming YangICML 2023 · 36 citations
- ShapleyFL: Robust Federated Learning Based on Shapley ValueQiheng Sun, Xiang Li, Jiayao Zhang, Li Xiong et al.KDD 2023 · 57 citations
- Federated Robustness Propagation: Sharing Adversarial Robustness in Heterogeneous Federated LearningJunyuan Hong, Haotao Wang, Zhangyang Wang, Jiayu ZhouAAAI 2023 · 29 citations
