Sybil-based Virtual Data Poisoning Attacks in Federated Learning

📅 2025-05-15
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
Federated learning is vulnerable to malicious client poisoning attacks, yet existing approaches suffer from high attack costs and poor stealth. This paper proposes a Sybil-enhanced virtual data poisoning framework that amplifies attack efficacy via lightweight pseudo-client generation. Our method addresses three key challenges: (1) a gradient-matching-driven virtual data generation mechanism that drastically reduces computational and communication overhead; (2) the first unified inverse model reconstruction scheme covering online local, online global, and offline settings; and (3) explicit modeling of non-IID data distributions to enhance cross-client generalizability of the attack. Extensive experiments demonstrate that our approach efficiently reconstructs the global target model across diverse non-IID configurations, achieving significantly higher attack success rates while maintaining superior stealth and substantially lower resource consumption compared to state-of-the-art baselines.

Technology Category

Application Category

📝 Abstract
Federated learning is vulnerable to poisoning attacks by malicious adversaries. Existing methods often involve high costs to achieve effective attacks. To address this challenge, we propose a sybil-based virtual data poisoning attack, where a malicious client generates sybil nodes to amplify the poisoning model's impact. To reduce neural network computational complexity, we develop a virtual data generation method based on gradient matching. We also design three schemes for target model acquisition, applicable to online local, online global, and offline scenarios. In simulation, our method outperforms other attack algorithms since our method can obtain a global target model under non-independent uniformly distributed data.
Problem

Research questions and friction points this paper is trying to address.

Sybil-based virtual data poisoning in federated learning
Reducing computational complexity via gradient matching
Target model acquisition for diverse FL scenarios
Innovation

Methods, ideas, or system contributions that make the work stand out.

Sybil-based virtual data poisoning attack
Gradient matching for data generation
Three target model acquisition schemes
🔎 Similar Papers
No similar papers found.
C
Changxun Zhu
Department of Automation, Shanghai Jiao Tong University, Shanghai 200240, P.R. China
Q
Qilong Wu
Department of Automation, Shanghai Jiao Tong University, Shanghai 200240, P.R. China
Lingjuan Lyu
Lingjuan Lyu
Sony
Foundation ModelsFederated LearningResponsible AI
Shibei Xue
Shibei Xue
Associate Professor, School of Automation and Intelligent Sensing, Shanghai Jiao Tong University
Quantum ControlDecis. & Ctrl. of Cmplx. Sys.