Digitala Vetenskapliga Arkivet

Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Adaptive Adversary against Robust Federated Learning: A GAN-Based Attack Framework
Uppsala University, Disciplinary Domain of Science and Technology, Mathematics and Computer Science, Department of Information Technology. (Division of Scientific Computing)
2026 (English)Independent thesis Advanced level (degree of Master (Two Years)), 20 credits / 30 HE creditsStudent thesis
Abstract [en]

Federated learning (FL) is a distributed learning training paradigm in which a global model iscollaboratively trained by a network of clients without sharing their raw data, which providessubstantial privacy benefits but also exposes the system to malicious participants who cansubmit poisoned updates. To address this, a body of defenses has emerged, the majority ofwhich inspect the submitted model parameters and judge updates by parameter similaritymetrics. The c-GAN authentication defense of Zafar et al. is a recent and qualitatively differentaddition: instead of inspecting parameters, it judges and selects client updates by its empiricalperformance on a synthetic validation set the server itself generates, a criterion that most of theexisting parameter-based attack literature is not specifically calibrated for.This thesis develops and evaluates an untargeted poisoning attack designed to bypass thisdefense. The attack is two-phase: an initial perturbation of the global model is followed by aconstrained correction step on an attacker-side surrogate of the defender's syntheticdistribution, which restores the update's performance on the filter while preserving thedegrading effect on the real task. Knowledge distillation and minibatch discrimination areadditionally explored as stealth enhancement techniques.The attack is evaluated across three image-classification benchmarks, under varying corruptionrates and defender generator architectures. On CIFAR-10, the attack reliably degrades theglobal model while remaining essentially undetected by the filter, whereas the sameperturbation without the correction phase is detected at a much higher rate and overall lesseffective; on the simpler MNIST and FMNIST benchmarks the picture is more heterogeneous,with the control surpassing our GAN-attack in some instances. These results suggest that in thefuture, existing parameter-based poisoning attacks could be combined with performance-awaretechniques such as the surrogate-based correction developed here, producing attacks thatevade detection from both parameter and performance-based defenses like the c-GAN.

Place, publisher, year, edition, pages
2026. , p. 32
Series
IT ; mTBV 26 012
National Category
Engineering and Technology
Identifiers
URN: urn:nbn:se:uu:diva-592769OAI: oai:DiVA.org:uu-592769DiVA, id: diva2:2080636
Presentation
2026-06-17, Online, 15:15 (English)
Supervisors
Examiners
Available from: 2026-06-29 Created: 2026-06-26 Last updated: 2026-06-29Bibliographically approved

Open Access in DiVA

fulltext(3825 kB)76 downloads
File information
File name FULLTEXT01.pdfFile size 3825 kBChecksum SHA-512
0004b7d8f724ee21881bbda6c5dd53e2b3ff7407e9cc795f6ff8c3730995b77d55fa233493595436c5f69082138421c46723866292dc4f8dfb82163156118faa
Type fulltextMimetype application/pdf

Search in DiVA

By author/editor
Gallardo García, Fernando
By organisation
Department of Information Technology
Engineering and Technology

Search outside of DiVA

GoogleGoogle Scholar
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 596 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf