Skip to content
Conference

Rethinking the Transferable Adversarial Attacks and Robust Defense in Federated Learning

Jul 2026 · International Conference on Computer Communications and Networks · pp. 1-9 · 0 citations · 44 references
Computer Science

TL;DR

To mitigate the attacks of transferable adversarial examples, a defense mechanism stemming from the transferability of model robustness by adversarial training is designed, gaining insights into adversarial examples and the vulnerability of federated learning systems.

Abstract

The development of federated learning (FL) techniques has helped improve the privacy preservation of users’ data and extended the applications of machine learning models. However, the involvement of a large number of users in FL also creates open opportunities for different adversaries, such as poisoning attacks, byzantine attacks, and adversarial examples attacks. Yet, recent research has disclosed that existing poisoning attacks and byzantine attacks can not achieve satisfactory penetration in realistic FL scenarios caused by strong assumptions, e.g., client selection rate, and the ratio of malicious attackers. In this paper, the transferability of adversarial examples among different client models is analyzed to understand the relation between adversarial examples and clients’ data distribution. Moreover, to mitigate the attacks of transferable adversarial examples, we design a defense mechanism stemming from the transferability of model robustness by adversarial training. As a result, through theoretical analysis of transferability, we gain insights into adversarial examples and the vulnerability of federated learning systems. Our proposed adversarial attack and defense methods are evaluated via real-life datasets in various settings to show their performance over the existing state-of-the-art methods.

View source

Similar papers

Review Open access 2026

Adversarial Machine Learning: Security Risks and Defense Strategies in AI-Driven Applications

A detailed overview of the security risks associated with adversarial attacks is offered, including evasion attacks carried out at inference time, data poisoning that corrupts the training process, backdoor insertion that hides dormant triggers inside a model, and model inversion that leaks private information back out of a trained system.

Harsh Verma · 0 citations
Open access Jul 2026

A Comprehensive Defense Framework Against Poisoning Backdoor Attacks in Federated Learning

This work employs the novel dimensionality reduction technique UMAP and a stringent filtering mechanism to effectively identify and exclude potential malicious participants without relying on traditional noise addition methods and demonstrates that the proposed method maintains high main task accuracy while effectively mitigating backdoor attacks across various attack scenarios.

Chun-I Fan, Hsin-Yen Wang, Tomohiro Morikawa · 0 citations
Review Open access 2026

Review of Adversarial Attack Mechanisms, Detection Techniques and Defence Strategies in Critical Network Infrastructures

Many of the critical networks are now vulnerable to complex security threats, especially those launched by adversaries against the machine learning-driven security systems used by these networks. Such attacks take advantage of weaknesses in AI systems by perturbing the model with carefully designed perturbations, which result in misclassification of malicious content as benign, compromising the system's confidentiality, integrity, and availability. The adversarial threat is unlike traditional cyberattacks; it is dynamic, adaptive and can circumvent traditional intrusion detection capabilities. This paper provides an extensive literature review on the adversarial attack methods, detection and defence techniques of critical network infrastructures. This review includes peer-reviewed publications published between 2019 and 2024 from the leading academic databases such as IEEE Xplore, SpringerLink, ScienceDirect and Google Scholar. The total number of studies analyzed were 48, covering contributions in the fields of creating adversarial attack methods, machine learning and deep learning based detection methods, and mitigation techniques. The results indicate that adversarial attacks can be divided into the following categories: evasion attacks, poisoning attacks, and exploratory attacks, where some of the more sophisticated methods, including those based on gradient, optimization, and reinforcement learning, are very effective in evading security systems. Current solutions, however, suffer from limited real-time adaptability, cross-domain generalization ability, explainability and integration across the attack lifecycle. While there are several defence mechanisms proposed, such as adversarial training, anomaly detection, and input transformation, existing defences have difficulties in being adaptable in real time, cross-domain generalizable, explainable and suitable for certain phases of the attack lifecycle. The study highlights a number of critical research challenges such as the lack of a common defence framework, inadequate real-time detection capabilities, absence of a standardized data sets and poor ability to withstand adaptive adversaries. The paper suggests the creation of multi-strategic, adaptive, and real-time adversarial threat management systems that can sustain themselves in a heterogeneous network environment.

F. Okoye, Aghaizu Herman Chijioke, Shamsudeen Mohammed S.B · 0 citations
Open access Aug 2026

Adversarial Training and Differential Privacy-Style Noise Injection for Privacy-Preserving Vertical Federated Learning

An improved defense mechanism that combines adversarial training and differential-privacy-style noise injection to collectively enhance the robustness of the existing KDk defense mechanism with marginal model utility trade-off is introduced.

N. Azeez, Oluwatobi Sunday Malomo, Omotolani Mary Okerinde et al. · 0 citations