OTPA: Federated Model Poisoning via Optimal Transport Alignment
Abstract
Federated defenses often assess client behavior through update geometry, but parameter proximity need not imply benign functional influence. Motivated by neural permutation symmetry, Optimal Transport Poisoning Attack (OTPA) transports a stored poisoned source toward a clean, round-specific anchor before interpolation. Its entropic maps combine approximate feature alignment with mixing, without honest-client updates or explicit amplification. We specify transport propagation for convolutional, residual, vision-transformer, and BERT-style architectures. The primary vision benchmark compares nine baselines while distinguishing attacker-local from oracle information. OTPA reduces accuracy from 66.0% to 14.9% on Tiny-ImageNet and from 66.7% to 39.4% on CIFAR-10 while its updates remain close to the centre of the submitted population. On all three datasets it is Pareto-optimal among the evaluated attacker-local attacks, reducing the median update distance by 70% to 90% relative to matched unaligned interpolation at no more than accuracy points of difference. Further evaluations cover architecture transfer, language, heterogeneous data, and partial participation. OTPA yields the lowest defended accuracy under six robust aggregators, while history-based filtering exposes highly consistent malicious directions. These results establish transport-based source construction as a poisoning mechanism: proximity and directional consistency reveal different aspects of an update, so neither coordinate alignment nor low Euclidean distance establishes benign behavior.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.