Manipulating the Byzantine: Optimizing Model Poisoning Attacks and Defenses for Federated Learning
Virat Shejwalkar, Amir Houmansadr
摘要
—Federated learning (FL) enables many data owners (e.g., mobile devices) to train a joint ML model (e.g., a next-word prediction classifier) without the need of sharing their private training data. However, FL is known to be susceptible to poisoning attacks by malicious participants (e.g., adversary-owned mobile devices) who aim at hampering the accuracy of the jointly trained model through sending malicious inputs during the federated training process. In this paper, we present a generic framework for model poisoning attacks on FL. We show that our framework leads to poisoning attacks that substantially outperform state-of-the-art model poisoning attacks by large margins. For instance, our attacks result in 1 . 5 × to 60 × higher reductions in the accuracy of FL models compared to previously discovered poisoning attacks. Our work demonstrates that existing Byzantine-robust FL algorithms are significantly more susceptible to model poisoning than previously thought. Motivated by this, we design a defense against FL poisoning, called divide-and-conquer (DnC). We demonstrate that DnC outperforms all existing Byzantine-robust FL algorithms in defeating model poisoning attacks, specifically, it is 2 . 5 × to 12 × more resilient in our experiments with different datasets and models.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper88
- Back to the Drawing Board: A Critical Evaluation of Poisoning Attacks on Production Federated LearningVirat Shejwalkar, Amir Houmansadr, Peter Kairouz, Daniel RamageS&P 2022 · 被引用 302 次
- FLDetector: Defending Federated Learning Against Model Poisoning Attacks via Detecting Malicious ClientsZaixi Zhang, Xiaoyu Cao, Jinyuan Jia, Neil Zhenqiang GongKDD 2022 · 被引用 293 次
- Poisoning with Cerberus: Stealthy and Colluded Backdoor Attack against Federated LearningXiaoting Lyu, Yufei Han, Wei Wang, Jingkai Liu 等AAAI 2023 · 被引用 111 次
- FedInv: Byzantine-Robust Federated Learning by Inversing Local Model UpdatesBo Zhao, Peng Sun, Tao Wang, Keyu JiangAAAI 2022 · 被引用 82 次
- EIFFeL: Ensuring Integrity for Federated LearningAmrita Roy Chowdhury, Chuan Guo, Somesh Jha, Laurens van der MaatenCCS 2022 · 被引用 70 次
它引用的顶会 Paper1
相关 Paper
- FL-WBC: Enhancing Robustness against Model Poisoning Attacks in Federated Learning from a Client PerspectiveJingwei Sun, Ang Li, Louis DiValentin, Amin Hassanzadeh 等NeurIPS 2021 · 被引用 131 次
- Do We Really Need to Design New Byzantine-robust Aggregation Rules?Minghong Fang, Seyedsina Nabavirazavi, Zhuqing Liu, Wei Sun 等NDSS 2025
- DeFL: Defending against Model Poisoning Attacks in Federated Learning via Critical Learning Periods AwarenessGang Yan, Hao Wang, Xu Yuan, Jian LiAAAI 2023 · 被引用 38 次
- Byzantine-Robust Decentralized Federated LearningMinghong Fang, Zifan Zhang, Hairi, Prashant Khanduri 等CCS 2024 · 被引用 38 次
- Model Poisoning Attacks to Federated Learning via Multi-Round ConsistencyYueqi Xie, Minghong Fang, Neil Zhenqiang GongCVPR 2025
