arXiv Machine Learning

Byzantine-Robust Federated RAG via Aligned Calibration and Fixed-Membership Conformal Prediction

This paper introduces a Byzantine‑robust federated retrieval‑augmented generation (RAG) framework that uses aligned calibration and fixed‑membership conformal prediction to ensure that the answer set contains the correct answer with a chosen probability, even when some nodes are compromised. By having all nodes score the same calibration questions and retaining only candidates that could be kept by a plausible group of honest nodes, the method guarantees correctness in finite samples and produces smaller answer sets than simpler approaches. Experiments on medical exam question‑answering tasks with language‑model nodes demonstrate that the method meets the target coverage whenever the number of misbehaving nodes does not exceed the declared bound, while plain averaging often fails.

arXiv AI
Sep 24

Meet, Compare, or Abstain: LatWeave for Deterministic Multi-Hop Question Answering on Knowledge Lattices

LatWeave is a deterministic multi‑hop question‑answering framework that structures knowledge into a multidimensional lattice and reduces QA to three operators—meet, compare, and abstain—while limiting LLM use to extraction and planning. It achieves near‑lossless performance on complete knowledge benchmarks (e.g., MetaQA) and strong results on templated multi‑hop datasets (e.g., 2WikiMultihopQA), while transparently handling incomplete knowledge through abstention. The approach offers reproducible, auditable answer paths with no performance penalty within its operating envelope.

By Yuze Ren, Shaoheng Fan, Tao Wang, Yabo Yan, Han Han
arXiv Machine Learning
Aug 13

LODESTAR: Trustworthy Entropy Is Navigated, Not Merely Measured -- Reinforced Polarizer Keeps a Frozen LLM from Being Confidently Misled by the Wrong Evidence

arXiv:2608. 11922v1 Announce Type: cross Abstract: Predictive-distribution entropy makes a strong selection rule in retrieval-augmented question answering: across five QA benchmarks, keeping the candidate answer that a frozen respondent LLM produces with the lowest answer-token entropy lifts mean answer $F_1$ from 0.

By Po-Jen Ko, Che-Cheng Wu, Hung-Chun Hsu, Li-Yang Chang, Chuan-Ju Wang
arXiv Machine Learning
Jul 14

Byzantine Accountability Without Consensus: Strong Eventual Consistency for Non-Associative, Stochastic, Robust Aggregation

arXiv:2607. 10305v1 Announce Type: cross Abstract: Byzantine-robust aggregation rules such as multi-Krum assume a central coordinator, and decentralising them is obstructed by the rules themselves: they are globally coupled, non-associative, and discontinuous, so an ulpscale perturbation can flip the selected subset, moving the output by a non-vanishing amount.

By Ryan Gillespie
arXiv AI
Sep 10

PAC-Private Autoregressive Generation: Calibrating Noise to Ensemble Disagreement

The paper introduces PAC‑Private Autoregressive Generation, a method that calibrates noise based on ensemble disagreement across overlapping ‘worlds’ of a private corpus, thereby extending PAC privacy from classification to text generation. By training adapters on a frozen public model and using posterior‑weighted disagreement to add noise only when predictions vary, the approach achieves strong privacy guarantees while preserving most of the fine‑tuning benefit. Experiments on WikiText‑103 with GPT‑2‑small show 74 % of the fine‑tuning gain retained with a per‑token budget of 2⁻³², and membership‑inference success bounded to 51.08 % after one million tokens, outperforming PMixED under matched conditions.

By Mina Mirzadehsarcheshmeh, Amir Keyvan Khandani
arXiv Machine Learning
Sep 7

Conformity Breaks Conformal Prediction

A new study shows that conformal certificates can become invalid when a large language model (LLM) is influenced by peers who unanimously provide a wrong answer, even though the question itself remains unchanged. This phenomenon, termed a score‑mechanism shift, reveals that a model’s calibration for single‑agent scoring does not hold in multi‑agent settings, leading to a drop in coverage from 90% to 74% under unanimous‑wrong peers. The shift also allows attackers to target low‑confidence items, nearly halving coverage for that subgroup while keeping overall averages deceptively high, and can cause systems to act confidently on incorrect answers. whyItMatters":"The findings expose a critical vulnerability in conformal prediction for multi‑agent LLM systems, undermining their reliability and safety in real‑world applications."

By Yibo Hu, Hanyu Su
arXiv AI
Aug 28

Why RAGs Hallucinate: Penalty-Aware Evaluation of Retrieval-Augmented Generation Systems with Knowledge-Gap Canaries

The paper introduces a penalty‑aware evaluation framework for Retrieval‑Augmented Generation (RAG) systems that uses asymmetric scoring, knowledge‑gap canaries, and a failure‑attribution pipeline. Applying this framework to three commercial RAG products and a baseline on SimpleQA‑Verified, the authors find that while overall accuracy is similar across systems, canary violation rates vary dramatically, showing that systems differ more in when they answer than in what they answer. The study demonstrates that penalty‑aware scoring can reorder system rankings and is robust across different penalty settings.

By Alden Do Rosario, Hussein Younes, Felipe Pires