Exploiting Feature Non-IIDness for Untargeted Data Poisoning Attacks in Byzantine-Robust Federated Learning
This paper identifies and exploits feature non-IIDness, demonstrating that by manipulating only the features of local data on compromised clients, adversaries can generate malicious updates to bypass RA rules and significantly degrade the global model’s performance.
Junzhe Huang, Chong-Qi Guan, Guo-Hong Cao
· 0 citations