Pith. sign in

REVIEW 1 cited by

Analyzing Federated Learning through an Adversarial Lens

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 1811.12470 v4 pith:ICL4OUSP submitted 2018-11-29 cs.LG cs.AIcs.CRstat.ML

classification cs.LGcs.AIcs.CRstat.ML
keywords modelfederatedlearningadversarialagentsattackmalicioustraining
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Federated learning distributes model training among a multitude of agents, who, guided by privacy concerns, perform training using their local data but share only model parameter updates, for iterative aggregation at the server. In this work, we explore the threat of model poisoning attacks on federated learning initiated by a single, non-colluding malicious agent where the adversarial objective is to cause the model to misclassify a set of chosen inputs with high confidence. We explore a number of strategies to carry out this attack, starting with simple boosting of the malicious agent's update to overcome the effects of other agents' updates. To increase attack stealth, we propose an alternating minimization strategy, which alternately optimizes for the training loss and the adversarial objective. We follow up by using parameter estimation for the benign agents' updates to improve on attack success. Finally, we use a suite of interpretability techniques to generate visual explanations of model decisions for both benign and malicious models and show that the explanations are nearly visually indistinguishable. Our results indicate that even a highly constrained adversary can carry out model poisoning attacks while simultaneously maintaining stealth, thus highlighting the vulnerability of the federated learning setting and the need to develop effective defense strategies.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 1 Pith paper

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Performance Guaranteed Poisoning Attacks in Federated Learning: A Sliding Mode Approach

    cs.LG 2025-05 conditional novelty 6.0 of 10

    FedSA uses sliding mode control on malicious local updates to drive a federated global model's test accuracy to a preset target while evading Byzantine-robust aggregators.

Pith tools