Poisoning Cross-View Correspondence in Vertical Federated Learning via Consistent Latent-Cluster Reassignment
Abstract
Vertical Federated Learning (VFL) is a privacy-preserving collaborative training paradigm in which participants holding disjoint feature sets over a shared sample space jointly train a global model without exposing raw data. Although VFL security has attracted growing research interest, the literature remains heavily skewed toward targeted threats, particularly backdoor and reconstruction attacks. Byzantine attacks, a family of untargeted poisoning threats that degrade global model accuracy, have been extensively studied in horizontal federated learning but remain largely unexplored in the vertical setting. This gap is especially consequential: the classical two-party design of many VFL systems allows a single compromised passive party to unilaterally destabilize the entire system. In this paper, we introduce a novel Byzantine attack strategy for vertical settings that performs consistent cluster-based swapping, constructing a poisoned cross-view association during training. The global model gets corrupted and catastrophically fails on clean, correctly aligned data at inference time. Since existing VFL defenses fail to detect this attack without incurring substantial performance penalties, we propose a targeted defense that attributes and repairs the corrupted associations. Our findings establish untargeted Byzantine attacks as a real, underappreciated availability threat to VFL and motivate robustness mechanisms tailored to its unique cross-view learning dynamics.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.