Skip to main navigation Skip to search Skip to main content

Hijack Vertical Federated Learning Models as One Party

  • Pengyu Qiu
  • , Xuhong Zhang
  • , Shouling Ji
  • , Changjiang Li
  • , Yuwen Pu
  • , Xing Yang
  • , Ting Wang
  • Zhejiang University
  • Pennsylvania State University
  • National University of Defense Technology

Research output: Contribution to journalArticlepeer-review

9 Scopus citations

Abstract

Vertical Federated Learning (VFL) is an emerging paradigm that enables collaborators to build machine learning models together in a distributed fashion. However, the security of the VFL model remains underexplored, particularly regarding the Byzantine Generals Problem (BGP), which is a well-known issue in distributed systems. This paper focuses on revealing the threat of BGP in VFL systems. Specifically, we propose two attacks, the replay attack and the generation attack, to evaluate the vulnerability of VFL when there is only one malicious party. The goal of the adversary is to hijack the VFL model to give desired predictions. Moreover, considering the uneven distribution of importance among parties, we combine data poisoning with the aforementioned attacks to explore whether they can bypass the situation where the adversary has few features. The evaluation results demonstrate the effectiveness of our attacks. For instance, the adversary holding only 10% of the features can achieve an attack success rate close to 90% on a binary classifier. Additionally, we evaluate potential countermeasures, and the experimental results show that their defense capability is limited and usually at the cost of performance loss of the VFL task. Our work highlights the need for advanced defenses to protect the prediction results of a VFL model and calls for more exploration of VFL’s security issues.

Original languageEnglish
Pages (from-to)4373-4390
Number of pages18
JournalIEEE Transactions on Dependable and Secure Computing
Volume23
Issue number3
DOIs
StatePublished - May 1 2026

Keywords

  • Byzantine generals problem (BGP)
  • Vertical federated learning (VFL)
  • adversarial attack
  • poisoning attack

Fingerprint

Dive into the research topics of 'Hijack Vertical Federated Learning Models as One Party'. Together they form a unique fingerprint.

Cite this