What bounds how far one enrolled federated client can move the global model?
answer
- Averaging is a vote weighted by size
- Three factors multiplied together
- Enrolment, not compromise, is the multiplier
- One goal is diluted, the other barely
basics
~20 sOne client's reach is the contribution size the server accepts, diluted across the cohort averaged that round. A norm ceiling caps it; without one, a single update's magnitude is unbounded, so the budget is identities times rounds.
solid answer
~50 sCombining updates is a weighted vote, and magnitude is the weight. If the server bounds the norm of an accepted contribution, each enrolled identity is worth a known, bounded amount, and one client's displacement of the global model is roughly that bound spread across the cohort sampled in the round. If the server does not bound it, the first factor is unbounded and one contribution can dominate the average outright. So the adversary's budget is a product: accepted norm, times identities enrolled, times rounds available before the next evaluation or release. The goal changes what that product buys. Broad degradation has to out-pull the entire honest cohort every round and is expensive; a conditional behaviour on inputs the adversary chooses barely competes with the honest signal, because honest clients contribute almost nothing about that region — so it survives on a far smaller share.
go deeper
Know that a client's influence comes from the size of what it submits and that many enrolled identities multiply it. You are not expected to quantify the round-by-round arithmetic.
Explain why averaging weights contributions by magnitude, what a server-side norm ceiling changes, and why a broad degradation goal is diluted while a conditional one largely is not.
Be ready to turn a vague claim into a threat model with all three factors named, and to say what evaluation cadence does to the third one.
Be able to argue where the cheapest factor to move actually is for your deployment, and to insist that any reported federated-poisoning result carries its norm, identity count and round count.
## The quantity being asked about In a round of federated training, a cohort of clients is sampled from the enrolled population, each returns an update — its local parameter change — and the server combines those updates into the next global model. The question is what one participant in that cohort is worth. ## Magnitude is the weight Combining contributions by averaging means the result moves in the direction of whatever was submitted, in proportion to how large it was. That single sentence carries most of the answer. It means: - **Where the server bounds the norm of an accepted contribution**, every identity is worth at most that bound. One client's displacement of the global model in a round is on the order of that bound divided by the cohort size, because the honest contributions in the same cohort pull against it. - **Where the server does not bound it**, the first factor has no ceiling. A contribution far larger than the honest ones dominates the average, and cohort size stops being a meaningful dilution. This is why a norm bound is the difference between a bounded and an unbounded write, not a tuning detail. Be precise about which operation this is: a **server-side ceiling on the size of an accepted contribution**, applied to what strangers submit. It is a limit on reach, and reporting it is reporting a threat model. ## The three factors An enrolled adversary's total reach is a product: 1. **Accepted norm per contribution** — bounded or not, as above. 2. **Identities enrolled.** This is the factor most often missed. Enrolling is not a compromise; nothing is broken into. Whatever a single identity is worth, an adversary who can register many multiplies it linearly, subject only to how many of their identities land in a sampled cohort. 3. **Rounds before the next gate.** Influence accumulates across rounds, so the interval between real evaluations of the global model — not the interval between rounds — is the window. Any statement about federated poisoning that omits one of these is not a threat model. "An attacker can shift the model" is not a finding; "an attacker holding this many identities, under this accepted norm, over this many rounds, can shift it this far" is. ## Where it stops paying Two effects push back, and a good answer names them. **Dilution.** In a large cohort, one bounded contribution among thousands moves the average very little. A **degradation** goal — making the model measurably worse for everyone — has to overcome the honest signal on the same task in every round, and the honest population is enormous. That is an expensive goal in this setting, and it is also the loudest, because it shows up in exactly the metric everyone watches. **Decay.** Influence introduced in one round is not permanent. Subsequent rounds of honest updates pull the parameters back toward whatever the honest data supports, so an effect that is not reinforced fades. An adversary therefore pays rent, not a one-time price. But both pushbacks are much weaker against a **targeted** goal: a behaviour conditional on inputs the adversary picks. Honest clients have essentially no data about a region nobody else visits, so there is little honest signal pulling that region back, and dilution over the cohort matters far less. The general rule is the one worth carrying: **degradation scales with your share of the population; a conditional behaviour behaves much more like an absolute amount of influence.** ## Claims that point the wrong way - *Aggregate accuracy did not move, so no contribution had much reach.* It shows a degradation attack did not succeed, or was never attempted. A targeted goal preserves aggregate accuracy deliberately. - *Cohort size dilutes anything.* Only when contributions are bounded. Unbounded magnitude defeats dilution. - *One identity, one vote.* Only under a bound. Otherwise it is one identity, as many votes as you care to weigh. - *A bound removes the attack.* It prices it. The attacker's response is more identities, or more rounds, and neither is detection.
- How is this different from poisoning a fraction of a centralized corpus?In a corpus the attacker's budget is rows, the artefact can be sampled and re-labelled, and a degradation attack is diluted by corpus size. In a federation the budget is identities and rounds, the dilution is explicit and mechanical over the sampled cohort, and there is nothing to sample — so the defensive move is bounding contribution value rather than reviewing content.
- If the server caps every accepted update at the same norm, is the attack over?No. It converts an unbounded write into a bounded one worth a known amount, which turns the problem into an identity-count and round-count problem. It prices write access; it does not detect it, and it does not distinguish a capped malicious contribution from a capped honest one.
- Why does an attacker's influence fade if they stop participating?Later rounds keep pulling parameters toward whatever the honest population's data supports, so any effect the honest data does not reinforce decays. That is why influence in a federation is rent rather than a purchase — and why a behaviour conditioned on inputs no honest client ever produces decays much more slowly.
saying these in an interview costs you the question
- Quotes a poisoned-client fraction with no norm bound stated
- Assumes cohort size dilutes an unbounded contribution
- Treats identity count as fixed rather than as the attacker's budget
- Says influence persists forever once injected
- Uses one number for degradation and targeted goals alike