Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

Hide and Find: A Distributed Adversarial Attack on Federated Graph Learning

About

Federated Graph Learning (FedGL) is vulnerable to malicious attacks, yet developing a truly effective and stealthy attack method remains a significant challenge. Existing attack methods suffer from low attack success rates, high computational costs, and are easily identified and smoothed by defense algorithms. To address these challenges, we propose \textbf{FedShift}, a novel two-stage "Hide and Find" distributed adversarial attack. In the first stage, before FedGL begins, we inject a learnable and hidden "shifter" into part of the training data, which subtly pushes poisoned graph representations toward a target class's decision boundary without crossing it, ensuring attack stealthiness during training. In the second stage, after FedGL is complete, we leverage the global model information and use the hidden shifter as an optimization starting point to efficiently find the adversarial perturbations. During the final attack, we aggregate these perturbations from multiple malicious clients to form the final effective adversarial sample and trigger the attack. Extensive experiments on six large-scale datasets demonstrate that our method achieves the highest attack effectiveness compared to existing advanced attack methods. In particular, our attack can effectively evade 3 mainstream robust federated learning defense algorithms and converges with a time cost reduction of over 90\%, highlighting its exceptional stealthiness, robustness, and efficiency.

Jinshan Liu, Ken Li, Jiazhe Wei, Bin Shi, Bo Dong• 2026

Related benchmarks

TaskDatasetResultRank
Graph Backdoor AttackGossipcop
ASR100
25
Graph Backdoor AttackEth-Phish&Hack
ASR99
20
Backdoor AttackNCI109
Attack Success Rate (ASR)59
15
Backdoor AttackMutagenicity
ASR58
15
Backdoor AttackDD
ASR62
15
Backdoor AttackFRANKENSTEIN
Attack Success Rate (ASR)61
15
Adversarial AttackDD
AAS58
5
Adversarial AttackNCI109
Average Attack Success (AAS)65
5
Adversarial AttackMutagenicity
AAS74
5
Adversarial AttackEth-Phish&Hack
AAS93
5
Showing 10 of 21 rows

Other info

Follow for update