Pith. sign in

REVIEW 2 cited by

Do We Really Need to Design New Byzantine-robust Aggregation Rules?

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2501.17381 v1 pith:GO3TBCCT submitted 2025-01-29 cs.CR cs.DCcs.LG

classification cs.CRcs.DCcs.LG
keywords aggregationmodelrulesattacksclientsfoundationflupdatesbyzantine-robust
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Federated learning (FL) allows multiple clients to collaboratively train a global machine learning model through a server, without exchanging their private training data. However, the decentralized aspect of FL makes it susceptible to poisoning attacks, where malicious clients can manipulate the global model by sending altered local model updates. To counter these attacks, a variety of aggregation rules designed to be resilient to Byzantine failures have been introduced. Nonetheless, these methods can still be vulnerable to sophisticated attacks or depend on unrealistic assumptions about the server. In this paper, we demonstrate that there is no need to design new Byzantine-robust aggregation rules; instead, FL can be secured by enhancing the robustness of well-established aggregation rules. To this end, we present FoundationFL, a novel defense mechanism against poisoning attacks. FoundationFL involves the server generating synthetic updates after receiving local model updates from clients. It then applies existing Byzantine-robust foundational aggregation rules, such as Trimmed-mean or Median, to combine clients' model updates with the synthetic ones. We theoretically establish the convergence performance of FoundationFL under Byzantine settings. Comprehensive experiments across several real-world datasets validate the efficiency of our FoundationFL method.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. A Weighted Loss Approach to Robust Federated Learning under Data Heterogeneity

    cs.LG 2025-06 conditional novelty 6.0 of 10

    Reweighting each local loss by the ratio of a shared target label distribution to the local label distribution aligns honest gradients and sharply improves Byzantine robustness under label skew.

  2. FedGraM: Defending Against Untargeted Attacks in Federated Learning via Embedding Gram Matrix

    cs.LG 2025-05 conditional novelty 5.0 of 10

    A server that keeps one example per class can detect and drop malicious federated-learning clients by measuring how separated their learned embeddings are, via the norm of a Gram matrix.

Pith tools