Research
Rethinking the Transferable Adversarial Attacks and Robust Defense in Federated Learning
arXiv:2608.25133v1 Announce Type: new Abstract: The development of federated learning (FL) techniques has helped improve the privacy preservation of users' data and extended the applications of machin
arXiv:2608.25133v1 Announce Type: new Abstract: The development of federated learning (FL) techniques has helped improve the privacy preservation of users' data and extended the applications of machine learning models. However, the involvement of a large number of users in FL also creates open opportunities for different adversaries, such as poisoning attacks, Byzantine attacks, and adversarial example attacks. Yet, recent research has disclosed that existing poisoning attacks and Byzantine attacks can not achieve satisfactory penetration in realistic FL scenarios caused by strong assumptions, extit{e.g.,} client selection rate, and the ratio of malicious attackers. In this paper, the transferability of adversarial examples among different client models is analyzed to understand the relation between adversarial examples and clients' data distribution. Moreover, to mitigate the attacks of transferable adversarial examples, we design a defense mechanism stemming from the transferability of model robustness by adversarial training. As a result, through theoretical analysis of transferability, we gain insights into adversarial examples and the vulnerability of federated learning systems. Our proposed adversarial attack and defense methods are evaluated via real-life datasets in various settings to show their performance over the existing state-of-the-art methods.
Related
- Poisoning with A Pill: Circumventing Detection in Federated Learning
- Your Privacy My Cloak: Backdoor Attacks on Differentially Private Federated Learning
- Adversarial Update-Based Federated Unlearning for Poisoned Model Recovery
Source: arXiv cs.LG | 2026-08-27