REVIEW 13 cited by
Threats to Federated Learning: A Survey
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
With the emergence of data silos and popular privacy awareness, the traditional centralized approach of training artificial intelligence (AI) models is facing strong challenges. Federated learning (FL) has recently emerged as a promising solution under this new reality. Existing FL protocol design has been shown to exhibit vulnerabilities which can be exploited by adversaries both within and without the system to compromise data privacy. It is thus of paramount importance to make FL system designers to be aware of the implications of future FL algorithm design on privacy-preservation. Currently, there is no survey on this topic. In this paper, we bridge this important gap in FL literature. By providing a concise introduction to the concept of FL, and a unique taxonomy covering threat models and two major attacks on FL: 1) poisoning attacks and 2) inference attacks, this paper provides an accessible review of this important topic. We highlight the intuitions, key techniques as well as fundamental assumptions adopted by various attacks, and discuss promising future research directions towards more robust privacy preservation in FL.
Forward citations
Cited by 13 Pith papers
-
On the Fragility of Data Attribution When Learning Is Distributed
A single adversary in distributed training inflates its attribution value via latent optimization on synthetic batches without degrading accuracy or triggering basic defenses.
-
FLARE: Adaptive Multi-Dimensional Reputation for Robust Client Reliability in Federated Learning
FLARE uses adaptive multi-dimensional reputation scores and soft exclusion to improve Byzantine robustness in federated learning by up to 16% over prior methods while handling a new Statistical Mimicry attack.
-
FedThief: Harming Others to Benefit Oneself in Self-Centered Federated Learning
FedThief lets malicious federated learning clients poison the global model while training a private ensemble model that outperforms it.
-
AnalogFed: Privacy-Preserving Discovery of Analog Circuits at Scale with Federated Generative AI
AnalogFed combines federated learning with a generative analog-topology model, adding dummy-token input perturbation and partial homomorphic encryption to resist membership inference and model inversion attacks.
-
Poisoning with A Pill: Circumventing Detection in Federated Learning
A three-stage pill-based augmentation makes existing FL poisoning attacks evade popular defenses while raising error rates up to 7x on both IID and non-IID data.
-
Integrity of peer-to-peer distributed LLM inference under malicious nodes
Under a simulated isotropic noise model, a canary-trap activation-drift detector achieves perfect AUROC separation of one malicious shard in multi-hop LLM inference.
-
SoK: Federated Learning for Intrusion Detection in Vehicular Networks
Auditing over 60 vehicular FL-IDS papers reveals pervasive evaluation pitfalls (IID splits, trivial datasets, missing Byzantine and real-time checks) and proposes minimum benchmarking requirements plus a research agenda.
-
Distributed Deep Variational Approach for Privacy-preserving Data Release
GPP trains local variational encoders in federated settings to release representations that keep utility within 1% of an autoencoder baseline while driving adversary AUC on sensitive attributes to near-random levels o...
-
Are Targeted Data Poisoning Attacks as Effective as We Think?
The paper introduces clean-model-based metrics that stratify test samples by vulnerability to targeted poisoning, enabling worst-case attack evaluation and vulnerability-aware defenses.
-
FLAegis: A Two-Layer Defense Framework for Federated Learning Against Poisoning Attacks
FLAegis defends federated learning by SAX-transforming client updates, spectral-clustering them to filter malicious clients, and applying FFT-based robust aggregation, outperforming several baselines on FEMNIST.
-
A Bayesian Incentive Mechanism for Poison-Resilient Federated Learning
A validation-loss threshold with per-round payments keeps MNIST accuracy at 96.7% under 50% label-flipping adversaries, but the incentive-compatibility claim is a restatement of the payment rule.
-
PPFL-RDSN: Privacy-Preserving Federated Learning-based Residual Dense Spatial Networks for Encrypted Lossy Image Reconstruction
A federated, privacy-preserving RDSN framework for encrypted image reconstruction whose local differential privacy mechanism is not actually differentially private because it releases low-frequency DCT coefficients wi...
-
A Survey on Foundation Models for Personalized Federated Intelligence
The survey introduces personalized federated intelligence (PFI) as a framework integrating federated learning and foundation models to support privacy-aware personalization of AI models.
Discussion (0). Sign in to comment.