TY - JOUR
T1 - Robust Decentralized Online Learning against Targeted and Untargeted Malicious Data Feature Manipulation
AU - Li, Yupeng
AU - Wen, Dacheng
AU - Xia, Mengjia
AU - Chen, Mingzhe
AU - Fu, Xiaoming
N1 - This work was supported in part by the National Natural Science Foundation of China under Grant 62202402, in part by Guangdong and Hong Kong Universities “1+1+1” Joint Research Collaboration Scheme, Project under Grant 2025A0505000001, in part by the Initiation Grant for Faculty Niche Research Areas 2023/24 under Grant RC-FNRA-IG/23-24/COMM/01, in part by the Early Career Scheme (ECS) through the Research Grants Council of HKSAR under Grant HKBU 22202423, in part by General Research Fund (GRF) through the Research Grants Council of HKSAR under Grant HKBU 12203425, in part by Germany/Hong Kong Joint Research Scheme sponsored by the Research Grants Council of Hong Kong and the German Academic Exchange Service of Germany under Grant G-HKBU203/22, in part by EU Horizon Europe CoDECO Project under Grant 101092696, and in part by the Startup Grant (Tier 1) for New Academics AY2020/21 of Hong Kong Baptist University.
Publisher Copyright:
© 2025 IEEE
PY - 2026/6
Y1 - 2026/6
N2 - Motivated by real-world applications, we study the problem of decentralized online learning with dynamic feedback delays in the presence of malicious data generators under different threat models. In this problem, multiple agents collaborate to classify the features of streaming data samples generated online and receive dynamically delayed feedback on the ground-truth labels. While some data generators are benign, others—due to internal motives or external factors such as cyberattacks—may maliciously manipulate data features to compromise the classification performance. In this work, we first investigate the targeted attacks by malicious data generators, i.e., feature manipulation with aims to gain preferred classification outcomes from the agents. In response, we propose two robust algorithms, RDOC-TO and RDOC-TC, countering ordinary and clairvoyant adversaries that can access certain outdated and the latest classification models of the agents, respectively. Subsequently, we address the untargeted attacks by malicious data generators, which aim to disrupt the classification outcomes without targeting any particular class, by proposing another algorithm, RDOC-U. Our theoretical analysis establishes that all three proposed algorithms achieve sublinear regret bounds. The evaluations conducted in the application of network traffic classification with two real-world datasets demonstrate the competitiveness of the proposed algorithms compared to advanced baselines.
AB - Motivated by real-world applications, we study the problem of decentralized online learning with dynamic feedback delays in the presence of malicious data generators under different threat models. In this problem, multiple agents collaborate to classify the features of streaming data samples generated online and receive dynamically delayed feedback on the ground-truth labels. While some data generators are benign, others—due to internal motives or external factors such as cyberattacks—may maliciously manipulate data features to compromise the classification performance. In this work, we first investigate the targeted attacks by malicious data generators, i.e., feature manipulation with aims to gain preferred classification outcomes from the agents. In response, we propose two robust algorithms, RDOC-TO and RDOC-TC, countering ordinary and clairvoyant adversaries that can access certain outdated and the latest classification models of the agents, respectively. Subsequently, we address the untargeted attacks by malicious data generators, which aim to disrupt the classification outcomes without targeting any particular class, by proposing another algorithm, RDOC-U. Our theoretical analysis establishes that all three proposed algorithms achieve sublinear regret bounds. The evaluations conducted in the application of network traffic classification with two real-world datasets demonstrate the competitiveness of the proposed algorithms compared to advanced baselines.
KW - Decentralized online learning
KW - dynamic delay
KW - feature manipulation
KW - targeted attack
KW - untargeted attack
UR - https://www.scopus.com/pages/publications/105025945565
U2 - 10.1109/TMC.2025.3642873
DO - 10.1109/TMC.2025.3642873
M3 - Journal article
SN - 2161-9875
VL - 25
SP - 7611
EP - 7625
JO - IEEE Transactions on Mobile Computing
JF - IEEE Transactions on Mobile Computing
IS - 6
ER -