{"url":"/task/model-poisoning","name":"Model Poisoning","slug":"model-poisoning","description_markdown":null,"categories":[],"source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","slug_source":"archive_url"},"counts":{"papers_tagged":108,"papers_with_code":28,"benchmarks":0,"benchmark_tables_in_archive":0,"benchmark_tables_shown":0,"benchmark_tables_withheld_as_spam":0,"benchmark_definition":"a leaderboard table with at least one row; benchmark_tables_shown also counts the zero-row tables; benchmark_tables_in_archive adds the tables withheld as spam","datasets":3,"subtasks":0,"parent_tasks":0},"benchmarks":[],"datasets":[{"url":"/dataset/cifar-10","name":"CIFAR-10","full_name":"CIFAR-10","num_papers_in_archive":16145},{"url":"/dataset/mnist","name":"MNIST","full_name":"","num_papers_in_archive":7651},{"url":"/dataset/fashion-mnist","name":"Fashion-MNIST","full_name":"","num_papers_in_archive":3202}],"subtasks":[],"parent_tasks":[],"papers":{"order":"repositories listed in the archive (desc), then date (desc); the archive holds no stars","population":"papers tagged with this task that list at least one repository in the archive","shown":28,"of":28,"tagged_in_all":108,"items":[{"url":"/paper/federated-multi-task-learning-for-competing","title":"Ditto: Fair and Robust Federated Learning Through Personalization","date":"2020-12-08","arxiv_id":"2012.04221","repositories_listed":4,"syntology":{"n":18,"n_ran":15,"n_unverified":3,"n_pointer_only":1}},{"url":"/paper/signguard-byzantine-robust-federated-learning","title":"Byzantine-robust Federated Learning through Collaborative Malicious Gradient Filtering","date":"2021-09-13","arxiv_id":"2109.05872","repositories_listed":3,"syntology":null},{"url":"/paper/how-to-backdoor-federated-learning","title":"How To Backdoor Federated Learning","date":"2018-07-02","arxiv_id":"1807.00459","repositories_listed":3,"syntology":{"n":1,"n_ran":1,"n_unverified":0,"n_pointer_only":0}},{"url":"/paper/analyzing-federated-learning-through-an","title":"Analyzing Federated Learning through an Adversarial Lens","date":"2018-11-29","arxiv_id":"1811.12470","repositories_listed":2,"syntology":null},{"url":"/paper/mitigating-sybils-in-federated-learning","title":"Mitigating Sybils in Federated Learning Poisoning","date":"2018-08-14","arxiv_id":"1808.04866","repositories_listed":2,"syntology":{"n":2,"n_ran":2,"n_unverified":0,"n_pointer_only":0}},{"url":"/paper/dual-defense-enhancing-privacy-and-mitigating","title":"Dual Defense: Enhancing Privacy and Mitigating Poisoning Attacks in Federated Learning","date":"2025-02-08","arxiv_id":"2502.05547","repositories_listed":1,"syntology":{"n":9,"n_ran":0,"n_unverified":9,"n_pointer_only":0}},{"url":"/paper/sok-benchmarking-poisoning-attacks-and","title":"SoK: Benchmarking Poisoning Attacks and Defenses in Federated Learning","date":"2025-02-06","arxiv_id":"2502.03801","repositories_listed":1,"syntology":null},{"url":"/paper/fedrise-rating-induced-sign-election-of","title":"FedSECA: Sign Election and Coordinate-wise Aggregation of Gradients for Byzantine Tolerant Federated Learning","date":"2024-11-06","arxiv_id":"2411.03861","repositories_listed":1,"syntology":null},{"url":"/paper/eab-fl-exacerbating-algorithmic-bias-through","title":"EAB-FL: Exacerbating Algorithmic Bias through Model Poisoning Attacks in Federated Learning","date":"2024-10-02","arxiv_id":"2410.02042","repositories_listed":1,"syntology":null},{"url":"/paper/defending-against-sophisticated-poisoning","title":"Defending Against Sophisticated Poisoning Attacks with RL-based Aggregation in Federated Learning","date":"2024-06-20","arxiv_id":"2406.14217","repositories_listed":1,"syntology":null},{"url":"/paper/a-novel-defense-against-poisoning-attacks-on","title":"A Novel Defense Against Poisoning Attacks on Federated Learning: LayerCAM Augmented with Autoencoder","date":"2024-06-02","arxiv_id":"2406.02605","repositories_listed":1,"syntology":null},{"url":"/paper/leverage-variational-graph-representation-for","title":"Leverage Variational Graph Representation For Model Poisoning on Federated Learning","date":"2024-04-23","arxiv_id":"2404.15042","repositories_listed":1,"syntology":null},{"url":"/paper/feddefender-client-side-attack-tolerant","title":"FedDefender: Client-Side Attack-Tolerant Federated Learning","date":"2023-07-18","arxiv_id":"2307.09048","repositories_listed":1,"syntology":null},{"url":"/paper/chameleon-adapting-to-peer-images-for","title":"Chameleon: Adapting to Peer Images for Planting Durable Backdoors in Federated Learning","date":"2023-04-25","arxiv_id":"2304.12961","repositories_listed":1,"syntology":{"n":11,"n_ran":5,"n_unverified":6,"n_pointer_only":0}},{"url":"/paper/exploring-the-limits-of-indiscriminate-data","title":"Exploring the Limits of Model-Targeted Indiscriminate Data Poisoning Attacks","date":"2023-03-07","arxiv_id":"2303.03592","repositories_listed":1,"syntology":{"n":3,"n_ran":3,"n_unverified":0,"n_pointer_only":3}},{"url":"/paper/thinking-two-moves-ahead-anticipating-other","title":"Thinking Two Moves Ahead: Anticipating Other Users Improves Backdoor Attacks in Federated Learning","date":"2022-10-17","arxiv_id":"2210.09305","repositories_listed":1,"syntology":null},{"url":"/paper/fldetector-detecting-malicious-clients-in","title":"FLDetector: Defending Federated Learning Against Model Poisoning Attacks via Detecting Malicious Clients","date":"2022-07-19","arxiv_id":"2207.09209","repositories_listed":1,"syntology":null},{"url":"/paper/fedrecattack-model-poisoning-attack-to","title":"FedRecAttack: Model Poisoning Attack to Federated Recommendation","date":"2022-04-01","arxiv_id":"2204.01499","repositories_listed":1,"syntology":null},{"url":"/paper/semi-targeted-model-poisoning-attack-on","title":"Semi-Targeted Model Poisoning Attack on Federated Learning via Backward Error Analysis","date":"2022-03-22","arxiv_id":"2203.11633","repositories_listed":1,"syntology":null},{"url":"/paper/mpaf-model-poisoning-attacks-to-federated","title":"MPAF: Model Poisoning Attacks to Federated Learning based on Fake Clients","date":"2022-03-16","arxiv_id":"2203.08669","repositories_listed":1,"syntology":{"n":8,"n_ran":0,"n_unverified":8,"n_pointer_only":0}},{"url":"/paper/beas-blockchain-enabled-asynchronous-secure","title":"BEAS: Blockchain Enabled Asynchronous & Secure Federated Machine Learning","date":"2022-02-06","arxiv_id":"2202.02817","repositories_listed":1,"syntology":null},{"url":"/paper/towards-understanding-quality-challenges-of","title":"Towards Understanding Quality Challenges of the Federated Learning for Neural Networks: A First Look from the Lens of Robustness","date":"2022-01-05","arxiv_id":"2201.01409","repositories_listed":1,"syntology":null},{"url":"/paper/sparsefed-mitigating-model-poisoning-attacks","title":"SparseFed: Mitigating Model Poisoning Attacks in Federated Learning with Sparsification","date":"2021-12-12","arxiv_id":"2112.06274","repositories_listed":1,"syntology":{"n":4,"n_ran":4,"n_unverified":0,"n_pointer_only":4}},{"url":"/paper/barfed-byzantine-attack-resistant-federated","title":"ARFED: Attack-Resistant Federated averaging based on outlier elimination","date":"2021-11-08","arxiv_id":"2111.04550","repositories_listed":1,"syntology":null},{"url":"/paper/fl-wbc-enhancing-robustness-against-model","title":"FL-WBC: Enhancing Robustness against Model Poisoning Attacks in Federated Learning from a Client Perspective","date":"2021-10-26","arxiv_id":"2110.13864","repositories_listed":1,"syntology":{"n":4,"n_ran":4,"n_unverified":0,"n_pointer_only":4}},{"url":"/paper/on-the-security-risks-of-automl","title":"On the Security Risks of AutoML","date":"2021-10-12","arxiv_id":"2110.06018","repositories_listed":1,"syntology":null},{"url":"/paper/back-to-the-drawing-board-a-critical","title":"Back to the Drawing Board: A Critical Evaluation of Poisoning Attacks on Production Federated Learning","date":"2021-08-23","arxiv_id":"2108.10241","repositories_listed":1,"syntology":null},{"url":"/paper/robust-federated-learning-with-attack","title":"Robust Federated Learning with Attack-Adaptive Aggregation","date":"2021-02-10","arxiv_id":"2102.05257","repositories_listed":1,"syntology":null}],"syntology_records":9,"syntology_note":"a paper without a record is not a recorded non-run: it may lack an arXiv id or simply be absent from the graph layer"},"description_links":{"kept":0,"unwrapped_to_text":0,"bare_urls_linked":0,"relative_images_dropped":0,"rule":"internal links are kept only when the target slug exists in the catalog"},"syntology":{"read_at":"2026-09-24T18:15:14+00:00","claim":"Per-sample execution status on synthesized fixtures ('ran N of M samples'); not a correctness claim and not a ranking signal.","status_vocabulary":{"ran_honours":"ran, honoured the contract we drafted","ran_violates":"ran, violated the contract we drafted","ran_draft_wrong":"ran; our contract draft was wrong, not the code","ran_fixture":"ran; our fixture could not drive it","ran":"ran on a synthesized input","unverified":"unverified (harvested, no recorded run)"}},"not_shown":{"libraries":"the archive has no per-task library table","trend_sparklines":"the Trend column of the benchmarks table was a rendered image; it is not in the archive","social_and_latest_sorts":"stars and social signals are not in the archive"}}