The paper investigates how adversarial examples transfer between client models in federated learning and explores the relationship between these examples and client data distributions. It proposes a defense strategy based on adversarial training that leverages the transferability of model robustness. Experiments on real-life datasets demonstrate that the new attack and defense methods outperform existing state‑of‑the‑art approaches.
By Zuobin Xiong, Deval Mukherjee, Homook Cho, Wei Li
arXiv:2506. 18020v3 Announce Type: replace Abstract: Robust distributed learning algorithms aim to maintain reliable performance despite the presence of misbehaving workers.
By Thomas Boudou, Batiste Le Bars, Nirupam Gupta, Aur\'elien Bellet
The paper introduces a robust decentralized federated distillation approach that allows heterogeneous client models to collaborate using predictions on shared unlabeled public data. Each client evaluates received predictions across three modalities—class prediction, boundary decision, and prediction correlation—filters unreliable clients, assigns reliability-based weights, and constructs modality-specific teachers. The method validates distillation gradients against supervised gradients from private data, removes conflicting gradients, and proves convergence under Byzantine attacks, achieving improved accuracy on CIFAR-10 and CIFAR-100 under non‑IID data and malicious conditions.
By Xiao Ma, Hong Shen, Hui Tian, Wei Ke, Wenqi Lyu
arXiv:2609.36660v1 Announce Type: new
Abstract: We study federated learning (FL) with adversarial clients, where the goal is to minimize the average loss of the honest (non-adversarial) clients witho...
By Leonardo F. Toso, James Anderson, Rafael Pinot, Nirupam Gupta
arXiv:2502.07977v3 Announce Type: replace
Abstract: Empirical risk minimization (ERM) is a cornerstone of modern machine learning. This paper focuses on the man-in-the-middle (MITM) attack, wherein a...
By Cheng Fang, Rishabh Dixit, Waheed U. Bajwa, Mert G\"urb\"uzbalaban
The development of federated learning (FL) techniques has helped improve the privacy preservation of users' data and extended the applications of machine learning models. However, the involvement of a...
arXiv:2601. 07674v2 Announce Type: replace-cross Abstract: Random walk (RW)-based algorithms have long been popular in distributed systems due to low overheads and scalability, with recent growing applications in decentralized learning.
By Xingran Chen, Parimal Parag, Rohit Bhagat, Salim El Rouayheb
The paper introduces Fed-ADR, a coordinated attack framework where a malicious orchestrator server directs heterogeneous adversarial clients to adapt their gradient updates in real time, thereby evading existing federated learning defenses and drastically reducing global model accuracy. It also presents a lightweight detection mechanism that estimates true client gradients from historical data to spot coordinated attacks, and an in-situ recovery method that restores model performance without restarting training. Experiments on MNIST, Fashion‑MNIST, and CIFAR‑10 show the attack can drop accuracy from over 90% to below 10%, while the defense can recover accuracy to above 90% within a few rounds at a computational cost at least 20× lower than retraining from scratch.
By Mohamed Shaaban, Ahmed Abdelnaby, Mohamed Elmahallawy
arXiv:2609.07312v1 Announce Type: new
Abstract: This paper proposes a robust decentralized personalized federated learning method R-DPFL, that enables clients to reduce the impact of Byzantine attack...
By Xiao Ma, Hong Shen, Hui Tian, Wenqi Lyu, Wei Ke
arXiv:2606. 04399v1 Announce Type: new Abstract: In the paradigm of decentralized learning, a group of agents collaborate to train a global model using distributed datasets without a central server.
By Yunsheng Yuan, Xue Xiao, Lina Wang, Feng Li
The paper studies federated learning where honest clients have heterogeneous data-generating models and adversarial clients can exacerbate this heterogeneity by sending arbitrary updates. It derives new bounds on gradient heterogeneity for linear and nonlinear regression, separating effects from honest clients’ model differences, label noise, and initialization. The authors show that for any (f,κ)-robust aggregator with κ = O(f/n) (where f is the number of adversarial clients and n the total number of clients, with f/n < 1/2), convergence is guaranteed after an explicit sample burn‑in period.
By Leonardo F. Toso, James Anderson, Nirupam Gupta, Rafael Pinot
The paper investigates the impact of label‑flipping attacks on distributed machine learning, where an adversary can only flip a limited number of training labels. It formalizes the attack as a per‑round constrained optimization problem, derives a greedy label‑selection rule for logistic regression, and shows that this rule is provably optimal under mean aggregation. Experiments demonstrate that optimized label flipping can significantly degrade model accuracy, outperforming random flips, and that the attack transfers to other robust aggregators such as coordinate‑wise median and trimmed mean.
By Abdessamad El-Kabid, El-Mahdi El-Mhamdi