arXiv Machine Learning

Robustifying Asynchronous SGD via Soft Throttling

arXiv Machine Learning
Sep 4

A Nesterov-Accelerated Byzantine-Robust Federated Learning

The paper proposes Byrd-NAFL, a Byzantine‑robust federated learning algorithm that incorporates Nesterov’s momentum and resilient aggregation rules. It achieves fast and safe convergence under non‑convex, smooth loss functions with relaxed gradient assumptions, and provides a finite‑time convergence guarantee. Experiments show that Byrd-NAFL outperforms existing methods in convergence speed, accuracy, and resilience to various malicious attacks.

By Lihan Xu, Xiaoyi Fan, Gang Wang, Runhao Zeng, Xiping Hu, Yanjie Dong
arXiv Machine Learning
Sep 23

Communication-Efficient Byzantine-Robust Federated Conformal Prediction via Partial Sharing

PRISM‑FCP is a federated conformal prediction framework that achieves Byzantine robustness while reducing communication costs. It does so by partially sharing model updates—transmitting only a subset of parameters per round—to dampen the influence of poisoned clients during training, and by filtering out suspected Byzantine clients during calibration using histogram‑based techniques. Experiments on synthetic data and UCI datasets show that PRISM‑FCP maintains near‑nominal coverage and offers favorable trade‑offs between communication overhead and predictive performance.

By Ehsan Lari, Reza Arablouei, Stefan Werner
arXiv Machine Learning
Sep 25

BRFID: Toward Byzantine-Robust Federated Intrusion Detection

The paper investigates the effects of label‑flipping poisoning attacks in a three‑client federated intrusion detection system (IDS) trained on CICIDS2017 with non‑IID attack subtype distributions. Flipping 60% of training labels from a single Byzantine client reduces the attacker’s own detection accuracy from 99.96% to 84.33%, while the federated global ensemble remains stable across all tested poison rates. The study shows that the self‑compromise signal can be detected as an anomaly, enabling Byzantine client identification without target data exfiltration, and notes that the current aggregation uses a Federated Forest rather than FedAvg, with future work planned to extend to parametric classifiers.

By Asmah Muallem, Firdous Kausar, Sajid Hussain, Lei Qian