Pith. sign in

REVIEW 2 cited by

Privacy-Preserving Aggregation for Decentralized Learning with Byzantine-Robustness

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2404.17970 v1 pith:B5E3YP6F submitted 2024-04-27 cs.CR cs.AI

classification cs.CRcs.AI
keywords byzantineclientsmodelupdateslearningsecuredlattacksdecentralized
verification ladder T0 review T1 audit T2 compute T3 formal

Signed reviews

No signed human review yet.

0 comments
read the original abstract

Decentralized machine learning (DL) has been receiving an increasing interest recently due to the elimination of a single point of failure, present in Federated learning setting. Yet, it is threatened by the looming threat of Byzantine clients who intentionally disrupt the learning process by broadcasting arbitrary model updates to other clients, seeking to degrade the performance of the global model. In response, robust aggregation schemes have emerged as promising solutions to defend against such Byzantine clients, thereby enhancing the robustness of Decentralized Learning. Defenses against Byzantine adversaries, however, typically require access to the updates of other clients, a counterproductive privacy trade-off that in turn increases the risk of inference attacks on those same model updates. In this paper, we introduce SecureDL, a novel DL protocol designed to enhance the security and privacy of DL against Byzantine threats. SecureDL~facilitates a collaborative defense, while protecting the privacy of clients' model updates through secure multiparty computation. The protocol employs efficient computation of cosine similarity and normalization of updates to robustly detect and exclude model updates detrimental to model convergence. By using MNIST, Fashion-MNIST, SVHN and CIFAR-10 datasets, we evaluated SecureDL against various Byzantine attacks and compared its effectiveness with four existing defense mechanisms. Our experiments show that SecureDL is effective even in the case of attacks by the malicious majority (e.g., 80% Byzantine clients) while preserving high training accuracy.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Sensitivity Curve Maximization: Attacking Robust Aggregators in Distributed Learning

    cs.LG 2024-12 conditional novelty 6.0 of 10

    A sensitivity-curve maximization attack, when aligned across training rounds, degrades robust aggregators like IOS and Huber M-estimation and can force accuracy down to chance level.

  2. ImprovDML: Improved Trade-off in Private Byzantine-Resilient Distributed Machine Learning

    cs.LG 2025-06 conditional novelty 5.0 of 10

    ImprovDML is a decentralized SGD framework that uses resilient vector consensus aggregation and Gaussian noise, with concentrated geo-privacy analysis, achieving Byzantine resilience and a better privacy-accuracy trad...

Pith tools