Skip to main navigation Skip to search Skip to main content

FALCON: an agentic probe-and-switch attack on Byzantine-robust federated learning

  • Alanoud Al Mazroa
  • , Wajdan Al malwi
  • , Bakri Hossain Awaji
  • , Fatima Asiri
  • , Habib Ullah Manzoor*
  • *Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

Abstract

In federated learning, Byzantine-robust aggregation rules defend against poisoned updates, but existing adaptive attacks require prior knowledge of the defense, typically unavail able in deployment. We identify the diversity-collusion antagonism: geometric defenses (Krum, Bulyan, Median) can only be broken by colluding (identical) poisoned copies, because they score updates by mutual proximity and identical copies dominate that score; the Sybil-aware rule FoolsGold can only be broken by diverse (independently perturbed) copies, because it penalises similar gradient histories and zeroes identical copies within a few rounds. No fixed primitive exceeds +0.096 drop against the opposing family. The antagonism is self-revealing: FoolsGold neutralises colluding copies as its similarity memory accumulates, causing a recovery of global accuracy absent under geometric defenses. We formalise this recovery signature as a convergence and-threshold test, correct across all seven evaluated defenses on both datasets. These two findings underpin FALCON, a probe-and switch adversary that starts colluding and switches to diversity upon detecting the signature, with no prior defense knowledge. On UCI HAR and WISDM (n=20, f=10, 3 seeds, 7 defenses), FALCON achieves worst-case drops of +0.701 (HAR) and +0.271 (WISDM), improving always-colluding by 50× (HAR) and 4.3× (WISDM) and the best fixed strategy by 21× and 4.3×, with correct FoolsGold detection in all six seed–dataset trials.
Original languageEnglish
Article number134923
JournalNeurocomputing
Early online date27 Aug 2026
DOIs
Publication statusE-pub ahead of print - 27 Aug 2026
Externally publishedYes

Keywords

  • federated learning
  • Byzantine robustness
  • poisoning attacks
  • Sybil defense
  • FoolsGold
  • Krum
  • FALCON
  • adaptive adversary
  • black-box attack

Fingerprint

Dive into the research topics of 'FALCON: an agentic probe-and-switch attack on Byzantine-robust federated learning'. Together they form a unique fingerprint.

Cite this