Abstract
Vertical Federated Learning (VFL) is an emerging paradigm that enables collaborators to build machine learning models together in a distributed fashion. However, the security of the VFL model remains underexplored, particularly regarding the Byzantine Generals Problem (BGP), which is a well-known issue in distributed systems. This paper focuses on revealing the threat of BGP in VFL systems. Specifically, we propose two attacks, the replay attack and the generation attack, to evaluate the vulnerability of VFL when there is only one malicious party. The goal of the adversary is to hijack the VFL model to give desired predictions. Moreover, considering the uneven distribution of importance among parties, we combine data poisoning with the aforementioned attacks to explore whether they can bypass the situation where the adversary has few features. The evaluation results demonstrate the effectiveness of our attacks. For instance, the adversary holding only 10% of the features can achieve an attack success rate close to 90% on a binary classifier. Additionally, we evaluate potential countermeasures, and the experimental results show that their defense capability is limited and usually at the cost of performance loss of the VFL task. Our work highlights the need for advanced defenses to protect the prediction results of a VFL model and calls for more exploration of VFL’s security issues.
| Original language | English |
|---|---|
| Pages (from-to) | 4373-4390 |
| Number of pages | 18 |
| Journal | IEEE Transactions on Dependable and Secure Computing |
| Volume | 23 |
| Issue number | 3 |
| DOIs | |
| State | Published - May 1 2026 |
Keywords
- Byzantine generals problem (BGP)
- Vertical federated learning (VFL)
- adversarial attack
- poisoning attack
Fingerprint
Dive into the research topics of 'Hijack Vertical Federated Learning Models as One Party'. Together they form a unique fingerprint.Cite this
- APA
- Author
- BIBTEX
- Harvard
- Standard
- RIS
- Vancouver