When Trust Becomes a Liability: Bounding Persistent Influence under Temporally Adaptive Attacks in Federated Learning
Abstract
Reputation-based defenses in federated learning can make historical trust persist in aggregation. As a result, benign behavior in earlier rounds may continue to affect a client's aggregation weight after it turns malicious. We study this vulnerability under temporally adaptive adversaries and argue that aggregation influence should decay unless it is continually re-earned. We introduce DAIRE-FL (Decaying Aggregation Influence with Renewal and Enforcement), which separates behavioral acceptance, current aggregation weight, and future influence renewal to limit persistent historical influence. We derive finite-horizon guarantees that bound both inherited and re-earned influence after a behavioral pivot. Our threat model also considers pseudonymous re-enrollment and data reuse to distinguish persistent influence from increased adversarial participation. Experiments on CIFAR-10, CIFAR-100, FEMNIST, and Shakespeare under abrupt, gradual, threshold-aware, and layer-selective attacks show that DAIRE-FL substantially limits post-pivot adversarial influence while preserving benign-task performance.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.