DMPA: Model Poisoning Attacks on Decentralized Federated Learning for Model Differences

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Feng, Chao, Li, Yunlong, Gao, Yuanzhe, Celdrán, Alberto Huertas, von der Assen, Jan, Bovet, Gérôme, Stiller, Burkhard
Format: Preprint
Publié: 2025
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866909482675601408
author Feng, Chao
Li, Yunlong
Gao, Yuanzhe
Celdrán, Alberto Huertas
von der Assen, Jan
Bovet, Gérôme
Stiller, Burkhard
author_facet Feng, Chao
Li, Yunlong
Gao, Yuanzhe
Celdrán, Alberto Huertas
von der Assen, Jan
Bovet, Gérôme
Stiller, Burkhard
contents Federated learning (FL) has garnered significant attention as a prominent privacy-preserving Machine Learning (ML) paradigm. Decentralized FL (DFL) eschews traditional FL's centralized server architecture, enhancing the system's robustness and scalability. However, these advantages of DFL also create new vulnerabilities for malicious participants to execute adversarial attacks, especially model poisoning attacks. In model poisoning attacks, malicious participants aim to diminish the performance of benign models by creating and disseminating the compromised model. Existing research on model poisoning attacks has predominantly concentrated on undermining global models within the Centralized FL (CFL) paradigm, while there needs to be more research in DFL. To fill the research gap, this paper proposes an innovative model poisoning attack called DMPA. This attack calculates the differential characteristics of multiple malicious client models and obtains the most effective poisoning strategy, thereby orchestrating a collusive attack by multiple participants. The effectiveness of this attack is validated across multiple datasets, with results indicating that the DMPA approach consistently surpasses existing state-of-the-art FL model poisoning attack strategies.
format Preprint
id arxiv_https___arxiv_org_abs_2502_04771
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle DMPA: Model Poisoning Attacks on Decentralized Federated Learning for Model Differences
Feng, Chao
Li, Yunlong
Gao, Yuanzhe
Celdrán, Alberto Huertas
von der Assen, Jan
Bovet, Gérôme
Stiller, Burkhard
Machine Learning
Artificial Intelligence
Federated learning (FL) has garnered significant attention as a prominent privacy-preserving Machine Learning (ML) paradigm. Decentralized FL (DFL) eschews traditional FL's centralized server architecture, enhancing the system's robustness and scalability. However, these advantages of DFL also create new vulnerabilities for malicious participants to execute adversarial attacks, especially model poisoning attacks. In model poisoning attacks, malicious participants aim to diminish the performance of benign models by creating and disseminating the compromised model. Existing research on model poisoning attacks has predominantly concentrated on undermining global models within the Centralized FL (CFL) paradigm, while there needs to be more research in DFL. To fill the research gap, this paper proposes an innovative model poisoning attack called DMPA. This attack calculates the differential characteristics of multiple malicious client models and obtains the most effective poisoning strategy, thereby orchestrating a collusive attack by multiple participants. The effectiveness of this attack is validated across multiple datasets, with results indicating that the DMPA approach consistently surpasses existing state-of-the-art FL model poisoning attack strategies.
title DMPA: Model Poisoning Attacks on Decentralized Federated Learning for Model Differences
topic Machine Learning
Artificial Intelligence
url https://arxiv.org/abs/2502.04771