Federated Learning Evasion Attacks

Arxiv pdf 2026-08-01T00:00:00
arXiv Paper — PDF not available. Only the Executive Summary is available here. To read or download the full paper, visit the arXiv abstract page.

Abstract

The development of federated learning (FL) techniques has helped improve the privacy preservation of users data and extended the applications of machine learning models. However, the involvement of a large number of users in FL also creates open opportunities for different adversaries, such as poisoning attacks, byzantine attacks, and adversarial examples attacks. Yet, recent research has disclosed that existing poisoning attacks and byzantine attacks can not achieve satisfactory penetration in realistic FL scenarios caused by strong assumptions, e.g., client selection rate, and the ratio of malicious attackers. In this paper, the transferability of adversarial examples among different client models is analyzed to understand the relation between adversarial examples and clients data distribution. Moreover, to mitigate the attacks of transferable adversarial examples, we design a defense mechanism stemming from the transferability of model robustness by adversarial training. As a result, through theoretical analysis of transferability, we gain insights into adversarial examples and the vulnerability of federated learning systems. Our proposed adversarial attack and defense methods are evaluated via real-life datasets in various settings to show their performance over the existing state-of-the-art methods.

Loading executive summary...

LINK COPIED TO CLIPBOARD