Skip to main navigation Skip to search Skip to main content

Poisoning-Assisted Membership Inference in Federated Learning

  • Xukun Luan
  • , Yuanguo Bi
  • , Kuan Zhang
  • , Zixuan Huang
  • , Zhou Su
  • , Tom H. Luan
  • , Bing Hu
  • Northeastern University China
  • University of Nebraska-Lincoln
  • Xi'an Jiaotong University
  • Dalhousie University

Research output: Contribution to journalArticlepeer-review

Abstract

Federated learning (FL) is a distributed machine learning approach that allows multiple clients to collaboratively train a global model without sharing their local raw data. Despite this advantage, FL remains vulnerable to membership inference attacks (MIAs), which can compromise the membership privacy of federated clients. Nevertheless, existing MIAs exhibit significant performance degradation when the malicious clients lack knowledge of the target model and the training data of benign clients. In this paper, we propose a novel scheme, Temporal Evolution of the Poisoning Effects (TEPE), to conduct MIAs against black-box FL models without any prior knowledge of the target models or benign clients' training data. Specifically, we design a two-stage inference method: the poisoning process and the scoring process. For the poisoning process, we propose three poisoning strategies for three different auditing requirements. For the scoring process, we design a novel quantification method and an unsupervised inference model to extract membership features within the effects of poisoning attacks. The proposed attack leverages the intuition that if a sample is used by FL benign clients, its prediction may not be readily altered by poisoning attacks. Finally, we propose a modified random response algorithm (RR-Group) to detect our attacks, which can guarantee the performance of FL models and effectively reduce the attack performance of TEPE. Extensive experiments demonstrate that TEPE achieves competitive inference accuracy and F1-score compared to the most MIAs, while evading two representative defenses, except for our proposed detection method RR-Group.

Original languageEnglish
JournalIEEE Transactions on Dependable and Secure Computing
DOIs
StateAccepted/In press - 2026
Externally publishedYes

Keywords

  • Federated learning
  • membership inference attack
  • membership inference defense
  • poisoning attack
  • temporal evolution

Fingerprint

Dive into the research topics of 'Poisoning-Assisted Membership Inference in Federated Learning'. Together they form a unique fingerprint.

Cite this