Towards Robust Personalized Federated Learning: Vulnerability Assessment and Defense Co-Design
Abstract
For modern machine learning, where vast amounts of sensitive data are distributed across different devices, federated learning (FL) has emerged as a key approach for training models while preserving privacy. While FL's core mechanism of sharing model parameters rather than raw data mitigates significant privacy concerns, a critical aspect remains unexplored: the robustness of FL models to transfer-based adversarial attacks. To address this gap, we examine the most commonly used personalized federated learning (PFL) methods, which allow clients to maintain private, personalized models to address data heterogeneity across clients. Through systematic analysis, we reveal that PFL methods exhibit heightened vulnerability to transfer-based adversarial attacks compared to centralized learning paradigms. Wherein, malicious clients can exploit local model knowledge to craft adversarial examples that can compromise peer clients' personalized models. We establish this vulnerability through both theoretical analysis and empirical evaluation across multiple benchmark datasets, demonstrating significant accuracy drops across various PFL methods. To address this challenge, we propose a defense framework combining stochastic input noise, input-scaled trace regularization, and parameter sensitivity maximization to improve FL's robustness. Our findings establish the first systematic study of adversarial threats in PFL systems, providing both diagnostic tools and practical countermeasures.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.