arrow
Return

Model Hijacking Attack in Federated Learning

delete2026-02-19
delete0
PRE
AI
Z
Zheng Li
S
Siyuan Wu
R
Ruichuan Chen
P
Paarijaat Aditya
İ
İstemi Ekin Akkuş
M
Manohar Vanga
M
Min Zhang
H
Hao Li
Y
Yang Zhang
DOI:10.1109/TIFS.2026.3666296delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Machine learning (ML), driven by prominent paradigms such as centralized and federated learning, has made significant progress in various critical applications. However, its remarkable success has been accompanied by various attacks. Recently, the model hijacking attack has shown that ML models can be hijacked to execute tasks different from their original tasks, which increases both accountability and parasitic computational risks. Nevertheless, thus far, this attack has only focused on centralized learning. In this work, we broaden the scope of this attack to the federated learning domain, where multiple clients collaboratively train a global model without sharing their data. Specifically, we present the first-of-its-kind hijacking attack against the global model in federated learning, namely HijackFL. The adversary aims to force the global model to perform a different task (called hijacking task) from its original task without the server or benign client noticing. To accomplish this, unlike existing methods that use data poisoning to modify the target model’s parameters, HijackFL searches for pixel-level perturbations based on their local model (without modifications) to align hijacking samples with the original ones in the feature space. When performing the hijacking task, the adversary applies these perturbations to the hijacking samples, compelling the global model to identify them as original ones and predict them accordingly. Extensive experiments demonstrate HijackFL significantly outperforms baselines, e.g., 92.75% vs. 10%. We further investigate the factors that affect its performance and discuss possible defenses to mitigate its impact. Code is available at https://github.com/zhenglisec/HijackFL
Keywords:
Machine learning
federated learning
security
model hijacking
dataset manipulation

Journal

IEEE Transactions on Information Forensics and Security cover
IEEE Transactions on Information Forensics and Security
IF:
8
Papers:
5.2K
Citations:
2.3W

Organization

N
nokia bell labs
Scholars:
19
Papers: 13
Citations: 0
H
Helmholtz Center for Information Security
Scholars:
2
Papers: 2
Citations: 80
S
shandong university
Scholars:
9.4W
Papers: 6.4W
Citations: 94
C
chinese academy of sciences
Scholars:
56.5W
Papers: 44.9W
Citations: 704
researcher View more organizations