New Attack Bypasses Krum Aggregation in Federated Learning.

Srinivasan Subramanian, Md. Abdullah Al Hafiz Khan, Kazi Aminul Islam· August 10, 2026 View original

Key takeaways

  • Krum-Proxy is a new backdoor attack that bypasses Krum-like robust aggregation in federated learning.
  • The attack optimizes malicious updates to mimic benign updates, infiltrating the core distribution.
  • It achieves high attack success while maintaining the model's clean accuracy.
  • This highlights a significant vulnerability in current distance-based federated learning defenses.

Who benefits

CybersecurityFinanceHealthcareTelecommunicationsAutomotive

Summary

Researchers introduce Krum-Proxy, a selection-aware backdoor attack that consistently bypasses robust aggregation methods like Krum in federated learning. It optimizes malicious updates to infiltrate the benign distribution's dense core, achieving high attack success while preserving clean accuracy.

Robust aggregation methods, such as Krum and Multi-Krum, are widely used in federated learning to protect against adversarial client behavior. These methods select client updates that are geometrically closest to the majority, assuming benign updates form a compact cluster. However, this reliance on geometric properties can be exploited by sophisticated adversaries. This research introduces the Krum-Proxy attack, a novel backdoor injection strategy designed to consistently bypass Byzantine-robust aggregation. Unlike simpler scaling or constraining methods, Krum-Proxy actively optimizes malicious updates to blend into the dense core of the benign update distribution. It achieves this through a two-stage optimization process that separates task-specific attack objectives from geometry-aware refinement, utilizing a nearest-neighbor proxy, stochastic reference modeling, and anchor-guided alignment. To maintain stealth, the attack incorporates a projection mechanism that constrains adversarial updates within realistic norm and variance bounds. Experiments on standard federated learning benchmarks demonstrate that Krum-Proxy achieves higher attack success rates while preserving the clean accuracy of the model, thereby highlighting a significant vulnerability in distance-based aggregation rules against selection-aware adversaries.

Why it matters

This research exposes a critical vulnerability in widely used robust aggregation techniques in federated learning, necessitating a re-evaluation of security measures for distributed AI systems, especially in sensitive applications.

How to implement this in your domain

  1. 1Re-evaluate the security posture of federated learning systems that rely on distance-based aggregation methods like Krum.
  2. 2Investigate and implement alternative or enhanced robust aggregation techniques that are resilient to selection-aware attacks.
  3. 3Develop advanced monitoring and anomaly detection systems to identify subtle, optimized malicious updates in federated learning.
  4. 4Educate development and security teams on the evolving threat landscape in federated learning.

Original post by Srinivasan Subramanian, Md. Abdullah Al Hafiz Khan, Kazi Aminul Islam

"arXiv:2608.06637v1 Announce Type: new Abstract: Robust aggregation methods are widely used in federated learning to mitigate the impact of adversarial client behavior. Distance-based aggregation rules, such as Krum and Multi-Krum, select updates that are closest to the majority u…"

View on X

Originally posted by Srinivasan Subramanian, Md. Abdullah Al Hafiz Khan, Kazi Aminul Islam on X · view source

Want to go deeper?

Turn these trends into skills with Learnijoy's hands-on AI & tech courses.

Explore courses