acceptodds
Under review as a conference paper at ICLR 2027

Characterizing the Topological Distribution of Compromised Clients in Decentralized Federated Learning via Model Deviation

Abstract

Decentralized federated learning enables interconnected clients to collaboratively train the machine learning model over a communication graph. Since clients distributed across different positions in the graph propagate information along different trajectories, the attack performance of compromised clients depends on both the attack strategy and the topological distribution of compromised clients (TDCC). However, most existing studies evaluate attacks by selecting compromised clients at random, thereby overlooking the heterogeneous ability of different clients to propagate malicious information. In this paper, we investigate how TDCC affects attack performance in a DFL system and propose Maximum Client-Level Accumulated Model Deviation (Max-CL-AMD), a compromised client selection method based on the system's mixing matrices. Specifically, we model the system-level accumulated model deviation (AMD), which captures the overall deviation induced by compromised clients, and decompose it into client-level AMD, each quantifying the deviation attributable to an individual compromised client. Extensive experiments across diverse settings show that Max-CL-AMD can achieve varying degrees of improvement in attack performance over random selection and other baseline selection methods.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.