arXiv:2603.23472cs.LGcs.CR2026-03

提出新算法同时抗恶意攻击和保护隐私,收敛性更强。

Byzantine-Robust and Differentially Private Federated Optimization under Weaker Assumptions

  • 结合双重动量与自适应裁剪,提升鲁棒性
  • 在标准平滑性假设下实现高概率收敛
  • 适合注重安全与隐私的联邦学习场景

联邦学习允许异构客户端协作训练共享模型而无需集中原始数据,具有天然隐私优势。然而,梯度与模型更新仍可能泄露敏感信息,恶意服务器可能发起拜占庭攻击。因此需在统一框架中兼顾差分隐私(DP)与拜占庭鲁棒性。现有方法常依赖不现实的有界梯度假设、需额外服务器数据集,或缺乏收敛保证。本文提出 Byz-Clip21-SGD2M 算法,融合鲁棒聚合与双重动量,并设计精细裁剪机制。在标准 $L$-光滑性和 $σ$-亚高斯梯度噪声假设下,证明了高概率收敛性,放宽了以往工作的限制条件。分析恢复了无对抗情况下的最优收敛率,并在拜占庭与差分隐私设置下提升了效用保证。在 MNIST 上使用 CNN 与 MLP 模型的实验证明了方法的有效性。

原文摘要 · Abstract (English)

Federated Learning (FL) enables heterogeneous clients to collaboratively train a shared model without centralizing their raw data, offering an inherent level of privacy. However, gradients and model updates can still leak sensitive information, while malicious servers may mount adversarial attacks such as Byzantine manipulation. These vulnerabilities highlight the need to address differential privacy (DP) and Byzantine robustness within a unified framework. Existing approaches, however, often rely on unrealistic assumptions such as bounded gradients, require auxiliary server-side datasets, or fail to provide convergence guarantees. We address these limitations by proposing Byz-Clip21-SGD2M, a new algorithm that integrates robust aggregation with double momentum and carefully designed clipping. We prove high-probability convergence guarantees under standard $L$-smoothness and $σ$-sub-Gaussian gradient noise assumptions, thereby relaxing conditions that dominate prior work. Our analysis recovers state-of-the-art convergence rates in the absence of adversaries and improves utility guarantees under Byzantine and DP settings. Empirical evaluations on CNN and MLP models trained on MNIST further validate the effectiveness of our approach.

联邦学习差分隐私拜占庭鲁棒优化算法

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。