提出更实用的抗拜占庭联邦学习聚合条件,提升系统鲁棒性。
Practical Validity Conditions for Byzantine-Tolerant Federated Learning

- 引入最小包围球有效性条件,替代传统凸包约束。
- 证明当多数客户端诚实(n>2t)时,松弛版MEB条件可实现。
- 为均值、中位数等常用聚合器提供理论保障,适合实际部署。
鲁棒聚合是抗拜占庭联邦学习的核心操作。为确保聚合质量不受数据分布或攻击影响,需引入有效性条件,提供输出位置的几何保证。传统凸有效性要求输出位于诚实向量的凸包内,虽理论强但受限于维度,且不兼容多数实际聚合规则。本文提出最小包围球(MEB)有效性条件及其乘法松弛形式c-MEB,其中c为常数。我们发现精确MEB仍韧性有限,而松弛c-MEB在多数客户端诚实(n > 2t)时可达。给出最优MinMax-MEB规则,满足c < √2,并为最小直径平均、中位点和几何中位数等标准聚合器提供显式松弛MEB保证。最后,将MEB有效性与先前研究中的凸、松弛凸和盒有效性关联,构建了分布式计算中几何有效性条件的系统图谱。结果表明,松弛MEB有效性连接了分布式系统与抗拜占庭聚合规则,是凸有效性在实际中的可行替代。
原文摘要 · Abstract (English)
Robust aggregation is the core operation in Byzantine-tolerant federated learning. To ensure the quality of aggregation independently of data distribution or attacks, validity conditions are needed. They provide geometric guarantees of where the output of the aggregation must lie. The widespread convex validity requires the output to lie in the convex hull of the honest vectors. Although this guarantee is strong in theory, it is poorly suited to modern federated learning systems, as it has dimension-dependent resilience and excludes many practical aggregation rules. We introduce the minimum enclosing ball (MEB) validity condition for robust aggregation, as well as its multiplicative relaxation, $c$-MEB validity, where $c$ is a constant. We show that exact MEB validity still suffers from limited resilience, while relaxed $c$-MEB validity is achievable if a majority of clients is honest, i.e. $n>2t$. We give an optimal MinMax-MEB rule for the relaxed condition with the bound $c<\sqrt{2}$ and prove explicit relaxed-MEB guarantees for standard aggregators including minimum-diameter averaging, medoid and geometric median. Finally, we relate MEB validity to convex, relaxed-convex and box validity studied in prior literature, thus providing a systematic map of geometric validity conditions for Byzantine-robust aggregation. Our results show that relaxed MEB validity connects validity conditions in distributed computing and Byzantine-tolerant aggregation rules, and offers a practical alternative to convex validity.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。