Browse State-of-the-Art › Model Poisoning
Model Poisoning
28 papers with code · 0 benchmarks · 3 datasets archive 2025-07-28
Benchmarks archive 2025-07-28
No benchmark for this task in the archive.
Libraries
Not in the archive: the export carries no per-task library table, so there is nothing to show at snapshot 2025-07-28.
Datasets archive 2025-07-28
3 datasets whose archive record lists this task, ordered by the archive's paper count.
Subtasks archive 2025-07-28
No subtask under this task in the archive's task tree.
Most implemented papers archive 2025-07-28
28 shown of 28 papers with code (108 tagged with this task in all), ordered by repositories listed in the archive, not by stars (the archive holds no stars, so PwC's “Social” and “Latest” sorts cannot be reproduced). Papers without a page here are shown as plain text.
-
8 Dec 2020 4 repositories listed Syntology ran 15 of 18 samples · 3 unverified · 1 pointer-only (licence)Fairness and robustness are two important concerns for federated learning systems.
-
13 Sep 2021 3 repositories listedTo this end, previous work either makes use of auxiliary data at parameter server to verify the received gradients (e.
-
2 Jul 2018 3 repositories listed Syntology ran 1 of 1 samples · 0 unverifiedAn attacker selected in a single round of federated learning can cause the global model to immediately reach 100% accuracy on the backdoor task.
-
29 Nov 2018 2 repositories listedFederated learning distributes model training among a multitude of agents, who, guided by privacy concerns, perform training using their local data but share only model parameter updates, for iterative aggregation at…
-
14 Aug 2018 2 repositories listed Syntology ran 2 of 2 samples · 0 unverifiedUnfortunately, such approaches are susceptible to a variety of attacks, including model poisoning, which is made substantially worse in the presence of sybils.
-
8 Feb 2025 1 repository listed Syntology ran 0 of 9 samples · 9 unverifiedHowever, simultaneously addressing both concerns is challenging; secure aggregation facilitates poisoning attacks as most anomaly detection techniques require access to unencrypted local model updates, which are…
-
6 Feb 2025 1 repository listedThis paper aims to provide a unified benchmark and analysis of defenses against DPAs and MPAs, clarifying the distinction between these two similar but slightly distinct domains.
-
6 Nov 2024 1 repository listedWe compare our proposed FedSECA method against 10 robust aggregators under 7 Byzantine attacks on 3 datasets and architectures.
-
2 Oct 2024 1 repository listedIn this paper, we propose a new type of model poisoning attack, EAB-FL, with a focus on exacerbating group unfairness while maintaining a good level of model utility.
-
20 Jun 2024 1 repository listedThen, we use the maximum mean discrepancy (MMD) to calculate the pairwise similarity of the current local model data distribution, its historical data distribution, and global model data distribution.
-
A Novel Defense Against Poisoning Attacks on Federated Learning: LayerCAM Augmented with Autoencoder2 Jun 2024 1 repository listedThe autoencoder is designed to process the LayerCAM heat maps from the local model updates, improving their distinctiveness and thereby increasing the accuracy in spotting anomalous maps and malicious local models.
-
23 Apr 2024 1 repository listedThis paper puts forth a new training data-untethered model poisoning (MP) attack on federated learning (FL).
-
18 Jul 2023 1 repository listedEvaluations of real-world scenarios across multiple datasets show that the proposed method enhances the robustness of federated learning against model poisoning attacks.
-
25 Apr 2023 1 repository listed Syntology ran 5 of 11 samples · 6 unverifiedIn a federated learning (FL) system, distributed clients upload their local models to a central server to aggregate into a global model.
-
7 Mar 2023 1 repository listed Syntology ran 3 of 3 samples · 0 unverified · 3 pointer-only (licence)Building on existing parameter corruption attacks and refining the Gradient Canceling attack, we perform extensive experiments to confirm our theoretical findings, test the predictability of our transition threshold,…
-
17 Oct 2022 1 repository listedFederated learning is particularly susceptible to model poisoning and backdoor attacks because individual users have direct control over the training data and model updates.
-
19 Jul 2022 1 repository listedFLDetector aims to detect and remove the majority of the malicious clients such that a Byzantine-robust FL method can learn an accurate global model using the remaining clients.
-
1 Apr 2022 1 repository listedExperimental results demonstrate that our proposed FedRecAttack achieves the state-of-the-art effectiveness while its side effects are negligible.
-
22 Mar 2022 1 repository listedTo overcome this challenge, we propose the Attacking Distance-aware Attack (ADA) to enhance a poisoning attack by finding the optimized target class in the feature space.
-
16 Mar 2022 1 repository listed Syntology ran 0 of 8 samples · 8 unverifiedSpecifically, we assume the attacker injects fake clients to a federated learning system and sends carefully crafted fake local model updates to the cloud server during training, such that the learnt global model has…
-
6 Feb 2022 1 repository listedThis makes it prone to gradient tampering and privacy leakage by a malicious aggregator.
-
5 Jan 2022 1 repository listedTherefore, to better understand the current quality status and challenges of these SOTA FL techniques in the presence of attacks and faults, we perform a large-scale empirical study to investigate the SOTA FL's quality…
-
12 Dec 2021 1 repository listed Syntology ran 4 of 4 samples · 0 unverified · 4 pointer-only (licence)Federated learning is inherently vulnerable to model poisoning attacks because its decentralized nature allows attackers to participate with compromised devices.
-
8 Nov 2021 1 repository listedARFED mainly considers the outlier status of participant updates for each layer of the model architecture based on the distance to the global model.
-
26 Oct 2021 1 repository listed Syntology ran 4 of 4 samples · 0 unverified · 4 pointer-only (licence)Furthermore, we derive a certified robustness guarantee against model poisoning attacks and a convergence guarantee to FedAvg after applying our FL-WBC.
-
12 Oct 2021 1 repository listedNeural Architecture Search (NAS) represents an emerging machine learning (ML) paradigm that automatically searches for models tailored to given tasks, which greatly simplifies the development of ML systems and propels…
-
23 Aug 2021 1 repository listedWhile recent works have indicated that federated learning (FL) may be vulnerable to poisoning attacks by compromised clients, their real impact on production FL systems is not fully understood.
-
10 Feb 2021 1 repository listedTo the best of our knowledge, our aggregation strategy is the first one that can be adapted to defend against various attacks in a data-driven fashion.
Syntology lines on 9 of the papers shown; no Syntology record for the others (a paper without an arXiv id cannot be joined to the graph, and absence from the graph layer is not a recorded non-run). “Ran” means the sample executed on a synthesized fixture, not that the paper's result was reproduced. Read from the graph 2026-09-24.
Report a problem or propose a change · a person checks every report against the paper or source before anything changes; decisions are listed on /corrections