A Meta-Reinforcement Learning-Based Poisoning Attack Framework Against Federated Learning

10Citations
Citations of this article
9Readers
Mendeley users who have this article in their library.

This article is free to access.

Abstract

As a distributed machine learning paradigm, federated learning enables clients to collaboratively train a global model without sharing their raw data, thus preserving data privacy while still utilizing the data. However, the distributed nature of federated learning makes it vulnerable to poisoning attacks, which undermine the integrity and availability of the model by injecting carefully crafted perturbations into the data or model. Most existing poisoning attacks rely on heuristic approaches, which are significantly mitigated by robust aggregation strategies during long-term federated learning training. To overcome this limitation, this work proposes a novel poisoning attack framework based on meta-reinforcement learning. The global data distribution of the clients is first inferred from the global gradient using a conditional generative adversarial network. The inferred distribution is then used to simulate the federated learning environment locally for reinforcement learning training. A novel scaling and noise injection attack is introduced by designing unique scaling coefficients and noise values for the gradient of each layer's parameters using reinforcement learning. Furthermore, meta-reinforcement learning is leveraged to enhance the generalization capability of the attack, ensuring effectiveness across various robust aggregation strategies. Experimental results demonstrate that our approach significantly reduces model accuracy to around 10% across three datasets under various aggregation strategies, outperforming existing methods and exhibiting superior generalization ability and attack performance.

Cite

CITATION STYLE

APA

Zhou, W., Zhang, D., Wang, H., Li, J., & Jiang, M. (2025). A Meta-Reinforcement Learning-Based Poisoning Attack Framework Against Federated Learning. IEEE Access, 13, 28628–28644. https://doi.org/10.1109/ACCESS.2025.3538891

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free