XFED: Non-Collusive Poisoning Attack Breaks Byzantine-Robust Federated Learning Without Coordination
arXiv·medium signal
Mouri, Ridowan, and Adnan present XFED, a model poisoning attack on federated learning that requires no collusion between adversarial clients — each attacker operates independently without exchanging models or synchronizing updates. This breaks the assumption underlying most Byzantine-robust FL defenses, which presume coordinated botnet-like attacks that are costly to maintain. Practical implication: current FL defense strategies may be fundamentally miscalibrated against realistic threat models.