Pith. sign in

REVIEW 2 cited by

Local Model Poisoning Attacks to Byzantine-Robust Federated Learning

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1911.11815 v4 pith:3KX2HDMC submitted 2019-11-26 cs.CR cs.DCcs.LG

classification cs.CRcs.DCcs.LG
keywords learningattacksmodellocalclientfederateddevicespoisoning
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

In federated learning, multiple client devices jointly learn a machine learning model: each client device maintains a local model for its local training dataset, while a master device maintains a global model via aggregating the local models from the client devices. The machine learning community recently proposed several federated learning methods that were claimed to be robust against Byzantine failures (e.g., system failures, adversarial manipulations) of certain client devices. In this work, we perform the first systematic study on local model poisoning attacks to federated learning. We assume an attacker has compromised some client devices, and the attacker manipulates the local model parameters on the compromised client devices during the learning process such that the global model has a large testing error rate. We formulate our attacks as optimization problems and apply our attacks to four recent Byzantine-robust federated learning methods. Our empirical results on four real-world datasets show that our attacks can substantially increase the error rates of the models learnt by the federated learning methods that were claimed to be robust against Byzantine failures of some client devices. We generalize two defenses for data poisoning attacks to defend against our local model poisoning attacks. Our evaluation results show that one defense can effectively defend against our attacks in some cases, but the defenses are not effective enough in other cases, highlighting the need for new defenses against our local model poisoning attacks to federated learning.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Sensitivity Curve Maximization: Attacking Robust Aggregators in Distributed Learning

    cs.LG 2024-12 conditional novelty 6.0 of 10

    A sensitivity-curve maximization attack, when aligned across training rounds, degrades robust aggregators like IOS and Huber M-estimation and can force accuracy down to chance level.

  2. Adversary-resilient Distributed and Decentralized Statistical Inference and Machine Learning: An Overview of Recent Advances Under the Byzantine Threat Model

    stat.ML 2019-08 conditional novelty 3.0 of 10

    A structured review of Byzantine-robust distributed and decentralized inference and learning, with tables of guarantees and experimental comparisons of screening-based aggregation methods.

Pith tools