Curse or Redemption? How Data Heterogeneity Affects the Robustness of Federated Learning
Syed Zawad, Ahsan Ali, Pin-Yu Chen, Ali Anwar, Yi Zhou, Nathalie Baracaldo, Yuan Tian, Feng Yan
摘要
Data heterogeneity has been identified as one of the key features in federated learning but often overlooked in the lens of robustness to adversarial attacks. This paper focuses on characterizing and understanding its impact on backdooring attacks in federated learning through comprehensive experiments using synthetic and the LEAF benchmarks. The initial impression driven by our experimental results suggests that data heterogeneity is the dominant factor in the effectiveness of attacks and it may be a redemption for defending against backdooring as it makes the attack less efficient, more challenging to design effective attack strategies, and the attack result also becomes less predictable. However, with further investigations, we found data heterogeneity is more of a curse than a redemption as the attack effectiveness can be significantly boosted by simply adjusting the client-side backdooring timing. More importantly, data heterogeneity may result in overfitting at the local training of benign clients, which can be utilized by attackers to disguise themselves and fool skewed-feature based defenses. In addition, effective attack strategies can be made by adjusting attack data distribution. Finally, we discuss the potential directions of defending the curses brought by data heterogeneity. The results and lessons learned from our extensive experiments and analysis offer new insights for designing robust federated learning methods and systems.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- To Store or Not? Online Data Selection for Federated Learning with Limited StorageChen Gong, Zhenzhe Zheng, Fan Wu, Yunfeng Shao 等WWW 2023 · 被引用 28 次
- Distributed Distributionally Robust Optimization with Non-Convex ObjectivesYang Jiao, Kai Yang, Dongjin SongNeurIPS 2022 · 被引用 21 次
- Resisting Backdoor Attacks in Federated Learning via Bidirectional Elections and Individual PerspectiveZhen Qin, Feiyi Chen, Chen Zhi, Xueqiang Yan 等AAAI 2024 · 被引用 20 次
- Certifiably Robust Model Evaluation in Federated Learning under Meta-Distributional ShiftsAmir Najafi, Samin Mahdizadeh Sani, Farzan FarniaICML 2025
- MingledPie: A Cluster Mingling Approach for Mitigating Preference Profiling in CFLCheng Zhang, Yang Xu, Jianghao Tan, Jiajie An 等NDSS 2025
它引用的顶会 Paper6
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan 等CCS 2016 · 被引用 7,620 次
- Practical Secure Aggregation for Privacy-Preserving Machine LearningKallista A. Bonawitz, Vladimir Ivanov, Ben Kreuter, Antonio Marcedone 等CCS 2017 · 被引用 3,936 次
- On the Convergence of FedAvg on Non-IID DataXiang Li, Kaixuan Huang, Wenhao Yang, Shusen Wang 等ICLR 2020 · 被引用 2,930 次
- Neural Cleanse: Identifying and Mitigating Backdoor Attacks in Neural NetworksBolun Wang, Yuanshun Yao, Shawn Shan, Huiying Li 等S&P 2019 · 被引用 1,801 次
- DBA: Distributed Backdoor Attacks against Federated LearningChulin Xie, Keli Huang, Pin-Yu Chen, Bo LiICLR 2020 · 被引用 901 次
相关 Paper
- Bad-PFL: Exploiting Backdoor Attacks against Personalized Federated LearningMingyuan Fan, Zhanyi Hu, Fuyi Wang, Cen ChenICLR 2025
- Exploit Gradient Skewness to Circumvent Byzantine Defenses for Federated LearningYuchen Liu, Chen Chen, Lingjuan Lyu, Yaochu Jin 等AAAI 2025 · 被引用 3 次
- Parameter Disparities Dissection for Backdoor Defense in Heterogeneous Federated LearningWenke Huang, Mang Ye, Zekun Shi, Guancheng Wan 等NeurIPS 2024 · 被引用 12 次
- Mind the Cost of Scaffold! Benign Clients May Even Become Accomplices of Backdoor AttackXingshuo Han, Xuanye Zhang, Xiang Lan, Haozhao Wang 等ICCV 2025 · 被引用 1 次
- FilterFL: Knowledge Filtering-based Data-Free Backdoor Defense for Federated LearningYanxin Yang, Ming Hu, Xiaofei Xie, Yue Cao 等CCS 2025
