arXiv Machine Learning By Pravija Raj P V, Ashish Gupta, Andrea Augello, Sajal K. Das

Upholding Robustness in Federated Learning: Trends, Emerging Strategies, and Research Opportunities

Read the original on arXiv Machine Learning →

The paper reviews the state of robustness in Federated Learning (FL), highlighting its vulnerability to performance degradation, data theft, and aggregation attacks. It presents a comprehensive framework that includes a threat-centric view of attack surfaces, a taxonomy of robust aggregation methods (distinguishing outcome‑centric from security‑centric approaches), and a layered taxonomy of defensive strategies. The authors also scrutinize current evaluation practices and outline key applications and open research challenges to steer future work.

Machine-generated by The Flow from the publisher's headline and feed description — not written or checked by a human. The full article lives at arXiv Machine Learning.

arXiv Machine Learning
Aug 27

Rethinking the Transferable Adversarial Attacks and Robust Defense in Federated Learning

The paper investigates how adversarial examples transfer between client models in federated learning and explores the relationship between these examples and client data distributions. It proposes a defense strategy based on adversarial training that leverages the transferability of model robustness. Experiments on real-life datasets demonstrate that the new attack and defense methods outperform existing state‑of‑the‑art approaches.

By Zuobin Xiong, Deval Mukherjee, Homook Cho, Wei Li
Hugging Face Trending Papers
Sep 2

Differentially private federated learning with Byzantine-robust aggregation: A cross-domain framework for secure model training in banking and healthcare systems

The paper introduces DP‑BR‑FedAvg, a federated learning framework that combines Gaussian‑mechanism differential privacy with a coordinate‑wise trimmed‑mean Byzantine‑robust aggregation rule. It is evaluated on a simulated cross‑institutional classification task for fraud and clinical‑risk scoring, showing that plain FedAvg fails when a quarter of twenty clients are Byzantine, while DP‑BR‑FedAvg recovers more signal and bounds privacy loss. The study demonstrates that privacy and robustness interact, and system design for regulated, adversarial, cross‑institutional settings must account for this interaction.