FLARE: Federated Learning Attack via Robust Expectation-Based Backdooring Using GAN

Hichem Faraoun, Reda Bellafqira, Gouenou Coatrieux, Kassem Kallas · 2025

In Federated Learning (FL), multiple clients trains models locally, and their updates are aggregated on the server to form a global model, while preserving data privacy by shifting training to client side. However, the decentralized nature of FL is susceptible to several adversarial attacks, particularly backdoor attacks, where an adversary embeds a malicious task into the global model to misclassify trigger-injected samples while maintaining normal performance on normal samples raising a critical security concern. One of the main challenges in such attacks is their persistence, as the malicious behavior suffers to benign updates overwriting. Prior work have proposed to approximate benign updates for strategical backdoor injection, but their reliance on local data limits the effectiveness especially in non-IID settings. In this paper, we propose a two-stage attack strategy to address such limitations. First, we train a Generative Adversarial Network (GAN) based inference model exploiting the global model's feedback to infer other participant's data, reducing the gap between local and global distributions, rather than being restricted to local data only. Second, we optimize the attack by approximating benign updates and anticipating future global model updates, effectively improving backdoor persistency. Our results demonstrate that our strategy significantly enhances attack durability.

Read the paper · More papers on PaperTik