Pith. sign in

REVIEW 13 cited by

Threats to Federated Learning: A Survey

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2003.02133 v1 pith:4724ALWD submitted 2020-03-04 cs.CR cs.LGstat.ML

classification cs.CRcs.LGstat.ML
keywords attacksprivacydatadesignfederatedfutureimportantlearning
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

With the emergence of data silos and popular privacy awareness, the traditional centralized approach of training artificial intelligence (AI) models is facing strong challenges. Federated learning (FL) has recently emerged as a promising solution under this new reality. Existing FL protocol design has been shown to exhibit vulnerabilities which can be exploited by adversaries both within and without the system to compromise data privacy. It is thus of paramount importance to make FL system designers to be aware of the implications of future FL algorithm design on privacy-preservation. Currently, there is no survey on this topic. In this paper, we bridge this important gap in FL literature. By providing a concise introduction to the concept of FL, and a unique taxonomy covering threat models and two major attacks on FL: 1) poisoning attacks and 2) inference attacks, this paper provides an accessible review of this important topic. We highlight the intuitions, key techniques as well as fundamental assumptions adopted by various attacks, and discuss promising future research directions towards more robust privacy preservation in FL.

Discussion (0). Sign in to comment.

Forward citations

Cited by 13 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score.

  1. On the Fragility of Data Attribution When Learning Is Distributed

    cs.LG 2026-05 unverdicted novelty 6.0 of 10

    A single adversary in distributed training inflates its attribution value via latent optimization on synthetic batches without degrading accuracy or triggering basic defenses.

  2. FLARE: Adaptive Multi-Dimensional Reputation for Robust Client Reliability in Federated Learning

    cs.LG 2025-11 conditional novelty 6.0 of 10

    FLARE uses adaptive multi-dimensional reputation scores and soft exclusion to improve Byzantine robustness in federated learning by up to 16% over prior methods while handling a new Statistical Mimicry attack.

  3. FedThief: Harming Others to Benefit Oneself in Self-Centered Federated Learning

    cs.LG 2025-08 conditional novelty 6.0 of 10

    FedThief lets malicious federated learning clients poison the global model while training a private ensemble model that outperforms it.

  4. AnalogFed: Privacy-Preserving Discovery of Analog Circuits at Scale with Federated Generative AI

    cs.LG 2025-07 reject novelty 6.0 of 10

    AnalogFed combines federated learning with a generative analog-topology model, adding dummy-token input perturbation and partial homomorphic encryption to resist membership inference and model inversion attacks.

  5. Poisoning with A Pill: Circumventing Detection in Federated Learning

    cs.LG 2024-07 unverdicted novelty 6.0 of 10

    A three-stage pill-based augmentation makes existing FL poisoning attacks evade popular defenses while raising error rates up to 7x on both IID and non-IID data.

  6. Integrity of peer-to-peer distributed LLM inference under malicious nodes

    cs.CR 2026-07 conditional novelty 5.0 of 10

    Under a simulated isotropic noise model, a canary-trap activation-drift detector achieves perfect AUROC separation of one malicious shard in multi-hop LLM inference.

  7. SoK: Federated Learning for Intrusion Detection in Vehicular Networks

    cs.CR 2026-07 conditional novelty 5.0 of 10

    Auditing over 60 vehicular FL-IDS papers reveals pervasive evaluation pitfalls (IID splits, trivial datasets, missing Byzantine and real-time checks) and proposes minimum benchmarking requirements plus a research agenda.

  8. Distributed Deep Variational Approach for Privacy-preserving Data Release

    cs.CR 2026-05 unverdicted novelty 5.0 of 10

    GPP trains local variational encoders in federated settings to release representations that keep utility within 1% of an autoencoder baseline while driving adversary AUC on sensitive attributes to near-random levels o...

  9. Are Targeted Data Poisoning Attacks as Effective as We Think?

    cs.LG 2025-09 unverdicted novelty 5.0 of 10

    The paper introduces clean-model-based metrics that stratify test samples by vulnerability to targeted poisoning, enabling worst-case attack evaluation and vulnerability-aware defenses.

  10. FLAegis: A Two-Layer Defense Framework for Federated Learning Against Poisoning Attacks

    cs.LG 2025-08 conditional novelty 5.0 of 10

    FLAegis defends federated learning by SAX-transforming client updates, spectral-clustering them to filter malicious clients, and applying FFT-based robust aggregation, outperforming several baselines on FEMNIST.

  11. A Bayesian Incentive Mechanism for Poison-Resilient Federated Learning

    cs.LG 2025-07 reject novelty 4.0 of 10

    A validation-loss threshold with per-round payments keeps MNIST accuracy at 96.7% under 50% label-flipping adversaries, but the incentive-compatibility claim is a restatement of the payment rule.

  12. PPFL-RDSN: Privacy-Preserving Federated Learning-based Residual Dense Spatial Networks for Encrypted Lossy Image Reconstruction

    cs.LG 2025-06 reject novelty 4.0 of 10

    A federated, privacy-preserving RDSN framework for encrypted image reconstruction whose local differential privacy mechanism is not actually differentially private because it releases low-frequency DCT coefficients wi...

  13. A Survey on Foundation Models for Personalized Federated Intelligence

    cs.AI 2025-05 unverdicted novelty 3.0 of 10

    The survey introduces personalized federated intelligence (PFI) as a framework integrating federated learning and foundation models to support privacy-aware personalization of AI models.

Pith tools