Abstract
Federated learning (FL) is a distributed machine learning approach that allows multiple clients to collaboratively train a global model without sharing their local raw data. Despite this advantage, FL remains vulnerable to membership inference attacks (MIAs), which can compromise the membership privacy of federated clients. Nevertheless, existing MIAs exhibit significant performance degradation when the malicious clients lack knowledge of the target model and the training data of benign clients. In this paper, we propose a novel scheme, Temporal Evolution of the Poisoning Effects (TEPE), to conduct MIAs against black-box FL models without any prior knowledge of the target models or benign clients' training data. Specifically, we design a two-stage inference method: the poisoning process and the scoring process. For the poisoning process, we propose three poisoning strategies for three different auditing requirements. For the scoring process, we design a novel quantification method and an unsupervised inference model to extract membership features within the effects of poisoning attacks. The proposed attack leverages the intuition that if a sample is used by FL benign clients, its prediction may not be readily altered by poisoning attacks. Finally, we propose a modified random response algorithm (RR-Group) to detect our attacks, which can guarantee the performance of FL models and effectively reduce the attack performance of TEPE. Extensive experiments demonstrate that TEPE achieves competitive inference accuracy and F1-score compared to the most MIAs, while evading two representative defenses, except for our proposed detection method RR-Group.
| Original language | English |
|---|---|
| Journal | IEEE Transactions on Dependable and Secure Computing |
| DOIs | |
| State | Accepted/In press - 2026 |
| Externally published | Yes |
Keywords
- Federated learning
- membership inference attack
- membership inference defense
- poisoning attack
- temporal evolution
Fingerprint
Dive into the research topics of 'Poisoning-Assisted Membership Inference in Federated Learning'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver