arXiv:2510.22149cs.LGcs.AI2025-10

提出可完全抹除其他客户端贡献的恶意客户端,揭示联邦学习安全漏洞

Power to the Clients: Federated Learning in a Dictatorship Setting

  • 设计'独裁客户端',能彻底消除其他客户端影响
  • 理论证明多独裁客户端协作或背叛均会破坏模型收敛
  • 在视觉与语言任务上验证攻击有效性,揭示系统性风险

联邦学习(FL)作为一种去中心化模型训练范式,允许多个客户端在不交换本地数据的情况下协同学习共享模型。然而,其去中心化特性也带来安全隐患,恶意客户端可能破坏或操纵训练过程。本文提出一种新型、明确定义且可分析的恶意参与者——独裁客户端,这类客户端能够完全抹除所有其他客户端对服务器模型的贡献,同时保留自身影响。我们提出了具体的攻击策略,并系统分析了其对学习过程的影响。进一步探讨了多个独裁客户端共存的复杂场景,包括协作、独立行动或结盟后互相背叛等情况。针对每种情形,我们提供了对全局模型收敛性影响的理论分析。所提出的理论算法及关于多独裁客户端复杂场景的发现,得到了计算机视觉和自然语言处理基准上的实证评估支持。

原文摘要 · Abstract (English)

Federated learning (FL) has emerged as a promising paradigm for decentralized model training, enabling multiple clients to collaboratively learn a shared model without exchanging their local data. However, the decentralized nature of FL also introduces vulnerabilities, as malicious clients can compromise or manipulate the training process. In this work, we introduce dictator clients, a novel, well-defined, and analytically tractable class of malicious participants capable of entirely erasing the contributions of all other clients from the server model, while preserving their own. We propose concrete attack strategies that empower such clients and systematically analyze their effects on the learning process. Furthermore, we explore complex scenarios involving multiple dictator clients, including cases where they collaborate, act independently, or form an alliance in order to ultimately betray one another. For each of these settings, we provide a theoretical analysis of their impact on the global model's convergence. Our theoretical algorithms and findings about the complex scenarios including multiple dictator clients are further supported by empirical evaluations on both computer vision and natural language processing benchmarks.

联邦学习安全攻击模型鲁棒性去中心化

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。