Exploit Gradient Skewness to Circumvent Byzantine Defenses for Federated Learning

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Liu, Yuchen, Chen, Chen, Lyu, Lingjuan, Jin, Yaochu, Chen, Gang
Format: Preprint
Veröffentlicht: 2025
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866909492971569152
author Liu, Yuchen
Chen, Chen
Lyu, Lingjuan
Jin, Yaochu
Chen, Gang
author_facet Liu, Yuchen
Chen, Chen
Lyu, Lingjuan
Jin, Yaochu
Chen, Gang
contents Federated Learning (FL) is notorious for its vulnerability to Byzantine attacks. Most current Byzantine defenses share a common inductive bias: among all the gradients, the densely distributed ones are more likely to be honest. However, such a bias is a poison to Byzantine robustness due to a newly discovered phenomenon in this paper - gradient skew. We discover that a group of densely distributed honest gradients skew away from the optimal gradient (the average of honest gradients) due to heterogeneous data. This gradient skew phenomenon allows Byzantine gradients to hide within the densely distributed skewed gradients. As a result, Byzantine defenses are confused into believing that Byzantine gradients are honest. Motivated by this observation, we propose a novel skew-aware attack called STRIKE: first, we search for the skewed gradients; then, we construct Byzantine gradients within the skewed gradients. Experiments on three benchmark datasets validate the effectiveness of our attack
format Preprint
id arxiv_https___arxiv_org_abs_2502_04890
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Exploit Gradient Skewness to Circumvent Byzantine Defenses for Federated Learning
Liu, Yuchen
Chen, Chen
Lyu, Lingjuan
Jin, Yaochu
Chen, Gang
Machine Learning
Federated Learning (FL) is notorious for its vulnerability to Byzantine attacks. Most current Byzantine defenses share a common inductive bias: among all the gradients, the densely distributed ones are more likely to be honest. However, such a bias is a poison to Byzantine robustness due to a newly discovered phenomenon in this paper - gradient skew. We discover that a group of densely distributed honest gradients skew away from the optimal gradient (the average of honest gradients) due to heterogeneous data. This gradient skew phenomenon allows Byzantine gradients to hide within the densely distributed skewed gradients. As a result, Byzantine defenses are confused into believing that Byzantine gradients are honest. Motivated by this observation, we propose a novel skew-aware attack called STRIKE: first, we search for the skewed gradients; then, we construct Byzantine gradients within the skewed gradients. Experiments on three benchmark datasets validate the effectiveness of our attack
title Exploit Gradient Skewness to Circumvent Byzantine Defenses for Federated Learning
topic Machine Learning
url https://arxiv.org/abs/2502.04890