Lune

INFOCOM2025顶会

VaniKG: Vanishing Key Gradient Attack and Defense for Robust Federated Aggregation

Hongjia Li, Leshui Lv, Ding Tang, Yan Zhang, Weiping Wang, Xinghua Yang

2025年份
2被引次数

摘要

The AGgregation Algorithms (AGAs) that combine locally trained models into a single global model in Federated Learning (FL) is becoming a new attack vector for adversaries. Model Poisoning Attacks (MPAs) are the most notorious repre-sentative; it aims to hamper the accuracy of the jointly trained model through manipulating byzantine FL clients' model updates to deviate the aggregated model from the global optimum. To defeat MPAs, the robust AGAs become prevailing in academia. In this paper, we present a new type of MPA against robust AGAs, referred to as Vanishing Key Gradient attack (VaniKG). In VaniKG, byzantine FL clients first formulate the perturbation vector by inactivating key neurons of one/multiple layer(s) through vanishing their gradients, and then confuse the vector to a population of most benign clients' updates. Through extensive experiments, we show that VaniKG can disable 6 state-of-the-art robust AGAs and sabotage the accuracy. To defeat VaniKG and stealthy MPAs, we enhance robust AGAs by proposing the Diverse Client Selection (DCS) scheme, where byzantine clients with overly consistent gradients are avoided from being all selected. Finally, we demonstrate that DCS plus classical AGAs can guarantee the accuracy at a normal level when FL suffers with VaniKG and classical MPAs.

问问这篇 Paper

问问你的智能体。

Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。

可以从这些问题问起

智能体调用

Lunesearch_papers

在 Lune 里问

免费开始,无需绑卡

相关 Paper

黄昏的海面,两侧是细线勾勒的悬崖