MPAF: Model Poisoning Attacks to Federated Learning based on Fake Clients

Existing model poisoning attacks to federated learning assume that an\nattacker has access to a large fraction of compromised genuine clients.\nHowever, such assumption is not realistic in production federated learning\nsystems that involve millions of clients. In this work, we propose the first\nModel Poisoning Attack based on Fake clients called MPAF. Specifically, we\nassume the attacker injects fake clients to a federated learning system and\nsends carefully crafted fake local model updates to the cloud server during\ntraining, such that the learnt global model has low accuracy for many\nindiscriminate test inputs. Towards this goal, our attack drags the global\nmodel towards an attacker-chosen base model that has low accuracy.\nSpecifically, in each round of federated learning, the fake clients craft fake\nlocal model updates that point to the base model and scale them up to amplify\ntheir impact before sending them to the cloud server. Our experiments show that\nMPAF can significantly decrease the test accuracy of the global model, even if\nclassical defenses and norm clipping are adopted, highlighting the need for\nmore advanced defenses.\n

Paper

References (31)

Scroll for more · 19 remaining

Similar papers

© 2026 NYSGPT2525 LLC