Granularity Blind Spots in Byzantine-Robust Federated Learning: Shapley-Guided Subspace Poisoning of Whole-Update Defenses
Abstract
Federated learning (FL) exposes its optimization process to model poisoning by compromised clients. Byzantine-robust aggregators inspect complete updates using distances, coordinate statistics, or alignment with a reference. Because of the resulting mismatch in granularity, non-IID honest updates may appear anomalous, whereas malicious changes in a compact parameter subspace may evade detection. We demonstrate the systematic exploitability of this mismatch by introducing GRASP, a wrapper that identifies influential parameter blocks for each base attack and concentrates malicious perturbations in the corresponding subspace. GRASP ranks blocks in the target model using a scalable second-order Shapley approximation. This approximation captures individual contributions and cooperative effects within each layer without enumerating coalitions. It then injects the selected residual into the reference update and chooses the largest scale within an adaptive Euclidean radius. Across five poisoning strategies and nine Byzantine-robust defenses on MNIST, Fashion-MNIST, and CIFAR-10, GRASP exceeds the base attack in 85 of 95 settings (89.5%). It raises the average Attack Impact from 22.17 to 33.02 points. Under FLAME at a 40% malicious client fraction, it raises the malicious admission rate from 28.09% to 99.80%. These results expose a systematic blind spot in defenses that assess complete updates and motivate robustness mechanisms that operate at a finer granularity.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.