TY - JOUR
T1 - Poisoning-Assisted Membership Inference in Federated Learning
AU - Luan, Xukun
AU - Bi, Yuanguo
AU - Zhang, Kuan
AU - Huang, Zixuan
AU - Su, Zhou
AU - Luan, Tom H.
AU - Hu, Bing
N1 - Publisher Copyright:
© 2004-2012 IEEE.
PY - 2026
Y1 - 2026
N2 - Federated learning (FL) is a distributed machine learning approach that allows multiple clients to collaboratively train a global model without sharing their local raw data. Despite this advantage, FL remains vulnerable to membership inference attacks (MIAs), which can compromise the membership privacy of federated clients. Nevertheless, existing MIAs exhibit significant performance degradation when the malicious clients lack knowledge of the target model and the training data of benign clients. In this paper, we propose a novel scheme, Temporal Evolution of the Poisoning Effects (TEPE), to conduct MIAs against black-box FL models without any prior knowledge of the target models or benign clients' training data. Specifically, we design a two-stage inference method: the poisoning process and the scoring process. For the poisoning process, we propose three poisoning strategies for three different auditing requirements. For the scoring process, we design a novel quantification method and an unsupervised inference model to extract membership features within the effects of poisoning attacks. The proposed attack leverages the intuition that if a sample is used by FL benign clients, its prediction may not be readily altered by poisoning attacks. Finally, we propose a modified random response algorithm (RR-Group) to detect our attacks, which can guarantee the performance of FL models and effectively reduce the attack performance of TEPE. Extensive experiments demonstrate that TEPE achieves competitive inference accuracy and F1-score compared to the most MIAs, while evading two representative defenses, except for our proposed detection method RR-Group.
AB - Federated learning (FL) is a distributed machine learning approach that allows multiple clients to collaboratively train a global model without sharing their local raw data. Despite this advantage, FL remains vulnerable to membership inference attacks (MIAs), which can compromise the membership privacy of federated clients. Nevertheless, existing MIAs exhibit significant performance degradation when the malicious clients lack knowledge of the target model and the training data of benign clients. In this paper, we propose a novel scheme, Temporal Evolution of the Poisoning Effects (TEPE), to conduct MIAs against black-box FL models without any prior knowledge of the target models or benign clients' training data. Specifically, we design a two-stage inference method: the poisoning process and the scoring process. For the poisoning process, we propose three poisoning strategies for three different auditing requirements. For the scoring process, we design a novel quantification method and an unsupervised inference model to extract membership features within the effects of poisoning attacks. The proposed attack leverages the intuition that if a sample is used by FL benign clients, its prediction may not be readily altered by poisoning attacks. Finally, we propose a modified random response algorithm (RR-Group) to detect our attacks, which can guarantee the performance of FL models and effectively reduce the attack performance of TEPE. Extensive experiments demonstrate that TEPE achieves competitive inference accuracy and F1-score compared to the most MIAs, while evading two representative defenses, except for our proposed detection method RR-Group.
KW - Federated learning
KW - membership inference attack
KW - membership inference defense
KW - poisoning attack
KW - temporal evolution
UR - https://www.scopus.com/pages/publications/105040961354
U2 - 10.1109/TDSC.2026.3699355
DO - 10.1109/TDSC.2026.3699355
M3 - 文章
AN - SCOPUS:105040961354
SN - 1545-5971
JO - IEEE Transactions on Dependable and Secure Computing
JF - IEEE Transactions on Dependable and Secure Computing
ER -