A Comparative Analysis of Label Flipping and Backdoor Data Poisoning Attacks in Federated Learning
N. D. Bisna, D Navaneeth, Ajay James · 2025
With growing concerns around data privacy and communication efficiency, Federated Learning (FL) has emerged as a key area of focus in the artificial intelligence domain. FL enables a global model to be collaboratively trained across multiple decentralized client devices without requiring direct access to their private data. Instead of sharing raw data, clients transmit model updates, such as gradients or weight changes, which are then aggregated by a central server. This iterative process enhances the global model’s performance over multiple training rounds.Despite its privacy-preserving nature, Federated Learning introduces new security vulnerabilities. These vulnerabilities are commonly exploited through poisoning attacks, which are broadly categorized into two types: model performance attacks and data privacy attacks. Model performance attacks aim to degrade the effectiveness of the global model and can be further classified as targeted or untargeted. Both targeted and untargeted attacks can be carried out using data poisoning or model poisoning techniques.This study presents a comparative analysis of two widely studied data poisoning methods, label flipping and backdoor insertion, both of which compromise the integrity of local training data. We also examine a range of existing defense strategies designed to mitigate such attacks and maintain the robustness of Federated Learning systems.