Krum-Proxy Attack: New Backdoor Method Bypasses Byzantine-Robust Aggregation in Federated Learning
A recent study published on arXiv (ID: 2608.06637) presents the Krum-Proxy attack, a backdoor injection technique that is aware of selection and effectively circumvents Byzantine-robust aggregation strategies in federated learning. This attack takes advantage of the geometric characteristics of distance-based aggregation rules such as Krum and Multi-Krum, which presuppose that benign updates cluster closely together. Rather than simply scaling or constraining updates, this approach strategically optimizes harmful updates to penetrate the core of the benign distribution. The adversarial updates are designed to closely resemble benign ones and are fine-tuned to align with regions preferred during aggregation, employing a two-stage optimization process. This research reveals weaknesses in robust aggregation techniques and emphasizes the necessity for more adaptive protective measures.
Key facts
- Paper ID: arXiv:2608.06637
- Announce Type: cross
- Introduces Krum-Proxy attack
- Bypasses Byzantine-robust aggregation
- Targets distance-based rules like Krum and Multi-Krum
- Uses two-stage optimization procedure
- Exploits geometric properties of benign update clusters
- Published on arXiv
Entities
Institutions
- arXiv