arXiv Machine Learning

Self-Creating Random Walks for Decentralized Learning under Pac-Man Attacks

arXiv:2601. 07674v2 Announce Type: replace-cross Abstract: Random walk (RW)-based algorithms have long been popular in distributed systems due to low overheads and scalability, with recent growing applications in decentralized learning.

arXiv Machine Learning
1d ago

On the Escaping Efficiency of Distributed Adversarial Training Algorithms

The paper compares distributed adversarial training algorithms—both centralized and decentralized—within multi‑agent learning environments. It introduces a theoretical framework to analyze how efficiently these algorithms escape local minima, a property linked to model flatness and robustness. The study finds that with small perturbation bounds and large batch sizes, decentralized methods (consensus and diffusion) escape local minima faster than centralized ones, but this advantage may diminish as attack strength increases.

By Ying Cao, Kun Yuan, Ali H. Sayed
arXiv AI
Sep 24

When Clients Are Orchestrated: Strategic Gradient Manipulation to Defeat Federated Learning Servers with Efficient Defense

The paper introduces Fed-ADR, a coordinated attack framework where a malicious orchestrator server directs heterogeneous adversarial clients to adapt their gradient updates in real time, thereby evading existing federated learning defenses and drastically reducing global model accuracy. It also presents a lightweight detection mechanism that estimates true client gradients from historical data to spot coordinated attacks, and an in-situ recovery method that restores model performance without restarting training. Experiments on MNIST, Fashion‑MNIST, and CIFAR‑10 show the attack can drop accuracy from over 90% to below 10%, while the defense can recover accuracy to above 90% within a few rounds at a computational cost at least 20× lower than retraining from scratch.

By Mohamed Shaaban, Ahmed Abdelnaby, Mohamed Elmahallawy
arXiv AI
Sep 1

Watch your steps: Dormant Adversarial Behaviors that Activate upon LLM Finetuning

The paper introduces FAB, an attack that uses meta‑learning to embed dormant adversarial behaviors into large language models (LLMs). These behaviors remain inactive until the model is finetuned by downstream users, at which point the model can exhibit unwanted actions such as unsolicited advertising, jailbreakability, or over‑refusal. FAB is shown to be effective across multiple LLMs and resilient to various finetuning settings.

By Thibaud Gloaguen, Mark Vero, Robin Staab, Martin Vechev
arXiv Machine Learning
Jul 17

PAC Learning in Turn-Based Stochastic Games with Reachability Objectives: A Decentralized Private Approach via Expected Conditional Distance

arXiv:2607. 14877v1 Announce Type: new Abstract: Reachability is the most fundamental logical objective, yet it is notoriously difficult to learn in reinforcement learning settings: even for Markov decision processes, PAC learning of reachability is impossible without additional assumptions.

By Ali Asadi, Krishnendu Chatterjee, Pavol Kebis
arXiv Machine Learning
Sep 4

A Nesterov-Accelerated Byzantine-Robust Federated Learning

The paper proposes Byrd-NAFL, a Byzantine‑robust federated learning algorithm that incorporates Nesterov’s momentum and resilient aggregation rules. It achieves fast and safe convergence under non‑convex, smooth loss functions with relaxed gradient assumptions, and provides a finite‑time convergence guarantee. Experiments show that Byrd-NAFL outperforms existing methods in convergence speed, accuracy, and resilience to various malicious attacks.

By Lihan Xu, Xiaoyi Fan, Gang Wang, Runhao Zeng, Xiping Hu, Yanjie Dong
arXiv Machine Learning
Sep 14

Inverting Self-Triggered Control: Adversarial Reinforcement Learning for Sparse Denial-of-Service Attacks

The paper introduces an adversarial reinforcement learning framework that learns the sparsest Denial-of-Service (DoS) attack schedule capable of destabilizing self‑triggered reinforcement learning controllers (RL‑STC). It proves a lower bound on the minimum number of jamming actions needed to force a crash and demonstrates that the learned adversary consistently defeats four different defenders—one LQR and three RL‑STC—across Pendulum, CartPole, and Quadrotor2D environments, outperforming greedy and periodic baselines in jam‑time‑per‑failure. The study also shows that the adversary remains effective under Gaussian observation noise and limited state information.

By Adam Haroon, Erick J. Rodr\'iguez-Seda, Tristan Schuler, Cody Fleming