acceptodds
Under review as a conference paper at ICLR 2027

Exploiting Global Model Feedback: An Adaptive Model Poisoning Attack against Robust Federated Learning

Abstract

Federated learning (FL) supports collaborative model training, but its repeated exchange of model states also creates a feedback surface for Model Poisoning Attacks (MPAs). Existing MPAs are largely feedback-agnostic: they predefine malicious updates without assessing how previous updates affected the aggregated model. In this paper, we introduce COMPASS, a feedback-guided MPA that exploits early training dynamics and adaptive aggregation feedback. COMPASS analyzes early broadcast models to extract the dominant training direction and identify Top- important weights. It then crafts an orthogonal perturbation that induces lateral displacement in the optimization trajectory while concentrating attack energy specifically on important weights. Crucially, COMPASS incorporates a matched filter feedback mechanism by embedding a lightweight probe into the malicious update, enabling the attack to dynamically adapt its attack strategy based on the observed aggregation feedback. Evaluations on six datasets, covering 15 aggregation rules and nine baseline attacks, show that COMPASS achieves a mean accuracy reduction of 57.91 percentage points, compared with 23.53 for PoisonedFL, the strongest baseline by this metric (2.46). These findings expose a broader threat to distributed learning systems that repeatedly release aggregated model states.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.