Find a Scapegoat: Poisoning Membership Inference Attack and Defense to Federated Learning

Fuente: arXiv
Enregistré dans:
Détails bibliographiques
Auteurs principaux: Mo, Wenjin, Li, Zhiyuan, Fang, Minghong, Fang, Mingwei
Format: Preprint
Publié: 2025
Sujets:
Accès en ligne:
Tags: Ajouter un tag
Pas de tags, Soyez le premier à ajouter un tag!
_version_ 1866918076821274624
author Mo, Wenjin
Li, Zhiyuan
Fang, Minghong
Fang, Mingwei
author_facet Mo, Wenjin
Li, Zhiyuan
Fang, Minghong
Fang, Mingwei
contents Federated learning (FL) allows multiple clients to collaboratively train a global machine learning model with coordination from a central server, without needing to share their raw data. This approach is particularly appealing in the era of privacy regulations like the GDPR, leading many prominent companies to adopt it. However, FL's distributed nature makes it susceptible to poisoning attacks, where malicious clients, controlled by an attacker, send harmful data to compromise the model. Most existing poisoning attacks in FL aim to degrade the model's integrity, such as reducing its accuracy, with limited attention to privacy concerns from these attacks. In this study, we introduce FedPoisonMIA, a novel poisoning membership inference attack targeting FL. FedPoisonMIA involves malicious clients crafting local model updates to infer membership information. Additionally, we propose a robust defense mechanism to mitigate the impact of FedPoisonMIA attacks. Extensive experiments across various datasets demonstrate the attack's effectiveness, while our defense approach reduces its impact to a degree.
format Preprint
id arxiv_https___arxiv_org_abs_2507_00423
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Find a Scapegoat: Poisoning Membership Inference Attack and Defense to Federated Learning
Mo, Wenjin
Li, Zhiyuan
Fang, Minghong
Fang, Mingwei
Cryptography and Security
Distributed, Parallel, and Cluster Computing
Machine Learning
Federated learning (FL) allows multiple clients to collaboratively train a global machine learning model with coordination from a central server, without needing to share their raw data. This approach is particularly appealing in the era of privacy regulations like the GDPR, leading many prominent companies to adopt it. However, FL's distributed nature makes it susceptible to poisoning attacks, where malicious clients, controlled by an attacker, send harmful data to compromise the model. Most existing poisoning attacks in FL aim to degrade the model's integrity, such as reducing its accuracy, with limited attention to privacy concerns from these attacks. In this study, we introduce FedPoisonMIA, a novel poisoning membership inference attack targeting FL. FedPoisonMIA involves malicious clients crafting local model updates to infer membership information. Additionally, we propose a robust defense mechanism to mitigate the impact of FedPoisonMIA attacks. Extensive experiments across various datasets demonstrate the attack's effectiveness, while our defense approach reduces its impact to a degree.
title Find a Scapegoat: Poisoning Membership Inference Attack and Defense to Federated Learning
topic Cryptography and Security
Distributed, Parallel, and Cluster Computing
Machine Learning
url https://arxiv.org/abs/2507.00423