NeFut Logo NeFut
中 Admin Login

[CS.AI] When Clients Are Orchestrated: Strategic Gradient Manipulation to Defeat Federated Learning Servers with Efficient Defense

Published at: 2026-09-25 22:00 Last updated: 2026-09-28 00:49
#AI #Machine Learning #optimization

Federated learning enables decentralized model training by having clients upload model gradients instead of raw data. Existing defenses mostly assume static or independent attackers, yet we uncover a dynamically adaptive attack that can systematically bypass these protections. We introduce the Fed-ADR framework, where a malicious orchestrator server (OS) coordinates a heterogeneous set of adversarial clients—including targeted and untargeted attackers—in real time. The OS directs malicious clients to modify their gradient updates so they evade the parameter server's (PS) defenses while severely degrading global model performance or steering training toward attacker‑defined objectives.

To counter this threat, we propose a detection mechanism that estimates each client’s true gradient from its historical updates and identifies coordinated anomalous behavior on the fly, without extra communication overhead. We also add an in‑situ recovery module that restores global model performance without restarting training, preserving convergence and minimizing recovery time.

Experiments on MNIST, Fashion‑MNIST, and CIFAR‑10 show that Fed‑ADR can drop global accuracy from over 90% to below 10%, successfully bypassing several state‑of‑the‑art defenses. When our detection and recovery components are activated, the system identifies malicious clients within a few rounds and restores accuracy above 90%, achieving at least a 20× reduction in computational cost compared to retraining from scratch.

Review This work highlights the danger of coordinated attacks in federated learning and offers a lightweight detection‑and‑recovery solution that can be integrated into real‑world deployments for robust security.

Original Source: https://arxiv.org/abs/2609.27124

[h] Back to Home