arXiv:2607. 01492v1 Announce Type: new Abstract: Recent work has established a fundamental trilemma between Byzantine robustness, local differential privacy (LDP), and optimization error in distributed learning.
By Thomas Boudou, Batiste Le Bars, Nirupam Gupta, Aur\'elien Bellet
The paper proposes Byrd-NAFL, a Byzantine‑robust federated learning algorithm that incorporates Nesterov’s momentum and resilient aggregation rules. It achieves fast and safe convergence under non‑convex, smooth loss functions with relaxed gradient assumptions, and provides a finite‑time convergence guarantee. Experiments show that Byrd-NAFL outperforms existing methods in convergence speed, accuracy, and resilience to various malicious attacks.
By Lihan Xu, Xiaoyi Fan, Gang Wang, Runhao Zeng, Xiping Hu, Yanjie Dong
Federated learning distributes data among $n$ clients, making it vulnerable to malicious attacks and data heterogeneity, which together pose challenges for robust learning. To tackle this issue, centered clipping and Huber aggregators have been exploited for Byzantine robustness.
arXiv:2607. 10970v1 Announce Type: new Abstract: Federated learning distributes data among $n$ clients, making it vulnerable to malicious attacks and data heterogeneity, which together pose challenges for robust learning.
By Zhi-Yong Wang, Hao Nan Sheng, Werner Stefan, Hing Cheung So, Linqi Song, Weitao Xu
arXiv:2609.36660v1 Announce Type: new
Abstract: We study federated learning (FL) with adversarial clients, where the goal is to minimize the average loss of the honest (non-adversarial) clients witho...
By Leonardo F. Toso, James Anderson, Rafael Pinot, Nirupam Gupta
arXiv:2412. 07151v1 Announce Type: cross Abstract: Distributed model training needs to be adapted to challenges such as the straggler effect and Byzantine attacks.
By Jiahe Yan, Pratik Chaudhari, Leonard Kleinrock
The paper compares distributed adversarial training algorithms—both centralized and decentralized—within multi‑agent learning environments. It introduces a theoretical framework to analyze how efficiently these algorithms escape local minima, a property linked to model flatness and robustness. The study finds that with small perturbation bounds and large batch sizes, decentralized methods (consensus and diffusion) escape local minima faster than centralized ones, but this advantage may diminish as attack strength increases.
By Ying Cao, Kun Yuan, Ali H. Sayed
The paper investigates how adversarial examples transfer between client models in federated learning and explores the relationship between these examples and client data distributions. It proposes a defense strategy based on adversarial training that leverages the transferability of model robustness. Experiments on real-life datasets demonstrate that the new attack and defense methods outperform existing state‑of‑the‑art approaches.
By Zuobin Xiong, Deval Mukherjee, Homook Cho, Wei Li
The paper investigates how the strategic placement of Byzantine nodes in decentralized federated learning (DFL) affects the propagation of malicious influence across the communication graph. It introduces Byzantine Placement Influence (BPI), a measure that captures cumulative exposure of honest nodes to Byzantine sources over time, and develops algorithms to optimize BPI across various network structures and attack types. Experiments demonstrate that BPI-guided placements consistently yield highly damaging configurations, highlighting the importance of considering node placement in DFL threat models.
By Edoardo Gabrielli, Gabriele Tolomei
Dealing simultaneously with confidentiality and Byzantine behaviors in decentralized learning is a challenging problem. Indeed, in decentralized learning, clients train a machine learning model while keeping their data locally and share their model parameters or gradients with a set of neighbors.
arXiv:2609.07312v1 Announce Type: new
Abstract: This paper proposes a robust decentralized personalized federated learning method R-DPFL, that enables clients to reduce the impact of Byzantine attack...
By Xiao Ma, Hong Shen, Hui Tian, Wenqi Lyu, Wei Ke
arXiv:2602. 18396v2 Announce Type: replace Abstract: We propose PRISM-FCP (Partial shaRing and robust calIbration with Statistical Margins for Federated Conformal Prediction), a communication-efficient Byzantine-robust federated conformal prediction framework that uses partial model sharing to mitigate stochastic model-poisoning attacks during training and histogram-based filtering to mitigate adversarial calibration submissions.
By Ehsan Lari, Reza Arablouei, Stefan Werner