Pith. sign in

REVIEW 4 major objections 4 minor 86 references

Defending Against Diverse Attacks in Federated Learning Through Consensus-Based Bi-Level Optimization

T0 review · 4 major / 4 minor · reviewed 2026-08-11 · deepseek-v4-flash

Pith's one-line read This paper claims that consensus-based bi-level optimization lets benign federated agents converge to the robust model even when malicious agents attack arbitrarily.

desk verdict Genuine mean-field robustness theorem for fixed G, but the FedCB2O algorithm's personalized G_j escapes the theory, so the practical robustness claim rests on experiments alone. read the letter →

arxiv 2412.02535 v2 pith:RRILCGMA submitted 2024-12-03 cs.LG cs.CRcs.MAmath.AP

classification cs.LGcs.CRcs.MAmath.AP MSC 65K1090C2690C5635Q9035Q84
keywords federatedlearningconsensus-basedoptimizationbi-levelmean-fieldlimitadversarialattackslabel-flippingclusteredrobustaggregation
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper tries to establish that consensus-based bi-level optimization, an interacting-particle method in which agents move toward a weighted average of models with low loss and low robustness score, remains globally convergent when some fraction of agents behaves maliciously and arbitrarily. It proves this in the mean-field limit, with enough benign agents, provided the quantile width β scales with the benign fraction and the selection temperature α is raised according to an explicit logarithmic rule. On the practical side, it builds FedCB2O for clustered federated learning and tests it against label-flipping attacks on rotated EMNIST, where it reports source-class accuracy and attack success rates close to attack-free baselines. A sympathetic reader would take the contribution to be a parameter recipe that converts an attack-averse bi-level objective into a concrete defense protocol for decentralized training.

What carries the argument

The load-bearing object is the consensus point $m^{{G,L}}$_{α,β}(ρ): a weighted average of particle positions inside the quantile sublevel set Q^L_β[ρ], weighted by exp(-αG(θ)). It combines a lower-level filter (only models with small loss relative to a quantile survive) with an upper-level filter (among survivors, models with small robustness score dominate). The extension of the quantitative quantile Laplace principle (Proposition 2.3) and the attack-control bound (Proposition 2.5) are what turn the presence of malicious mass into exponentially small error terms, leaving the benign dynamics to contract toward θ*_good at the rate inherited from the attack-free CB2O proof.

What would settle it

Run the FedCB2O algorithm with the personalized robustness criterion (3.15) under label-flipping attacks and check whether benign agents continue to assign non-negligible weight to poisoned models as α is increased as prescribed by (2.23); if those weights do not decay toward zero, the convergence guarantee does not transfer to the deployed criterion.

Watch

Extended reading notes

Core claim

The central claim is Theorem 2.2: in the mean-field limit, the law of benign agents converges exponentially fast in squared Wasserstein distance to the target model θ*_good, the minimizer of the robustness criterion G among global minimizers of the loss L, even though malicious agents are modeled with arbitrary drift and diffusion. The theorem localizes the effect of attacks: after a robust quantile Laplace bound splits the consensus error into benign and malicious parts, a separate control proposition shows the malicious contribution decays like exp(-αu) under the farfield growth condition A6 on G. The proof yields explicit hyperparameter rules: β must be below a threshold proportional to w_b (the benign fraction), and α must exceed a threshold whose dominant term is log(w_m/w_b · R_K^G / $\sqrt$(ε)).

Load-bearing premise

The convergence theorem is proven for a fixed, shared robustness criterion G, while the deployed FedCB2O algorithm weights models with a personalized criterion G_j that depends on each agent's own changing model, and the paper explicitly leaves the theory for that criterion to future work.

Editorial extensions

If this is right

  • A user of CB2O can defend against a broad class of attacks by choosing β proportional to the fraction of benign agents and α above the explicit logarithmic threshold, without knowing which agents are malicious.
  • Label-flipping attacks, which are hard to filter by average loss alone, are neutralized by the upper-level criterion in FedCB2O: experiments show source-class accuracy rises from about 40% with FedCBO to about 56–58% and attack success rate drops.
  • In the limit w_m → 0 and w_b → 1, the theorem's hyperparameter choices reduce to the attack-free CB2O settings, so the defense does not come at the cost of the original convergence guarantee.
  • The agent selection mechanism that records each peer's historical loss performance is independent of the robustness criterion and can be slotted into other decentralized federated algorithms.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • If the personalized criterion G_j from (3.15) behaves empirically like the fixed G analyzed in Theorem 2.2, then the same defense should extend to agents with heterogeneous local datasets, a setting the paper flags as future work.
  • Because the theorem's α threshold grows only logarithmically with the malicious-to-benign ratio, the framework predicts that a modest increase in selection sharpness compensates for a very large hostile minority; this is a testable quantitative prediction.
  • The ProbSampling mechanism, which selects models by an exponential moving average of past losses, may be useful beyond robustness, for example to cut communication cost in any decentralized method that budgets downloads per round.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

4 major / 4 minor

Summary. The paper proposes a bi-level optimization formulation (1.1) for robust federated learning, where the upper-level objective G encodes a robustness criterion and the lower-level objective L is the training loss. The main theoretical result, Theorem 2.2, states that the mean-field CB2O dynamics (1.7)-(1.8) converge in Wasserstein distance to the robust minimizer θ*_good even when a fraction wm of agents behave adversarially, provided the hyperparameters β and α are chosen according to (2.20) and (2.23). The proof extends the quantitative Laplace principle of the authors' earlier CB2O paper [27] and adds Assumption A6 on the far-field growth of G. On the practical side, the paper introduces FedCB2O, an algorithm for decentralized clustered federated learning that combines FedCBO with a robustness-weighted consensus point, a probabilistic agent-selection mechanism (ProbSampling), and a personalized robustness criterion G_j (Remark 3.6). Experiments on rotated EMNIST with label-flipping attacks compare FedCB2O against FedCBO and two Oracle baselines.

Significance. If Theorem 2.2 is correct, it constitutes a meaningful extension of the mean-field convergence theory of consensus-based optimization to settings with malicious agents, and it gives concrete, falsifiable hyperparameter scaling predictions (β ∝ wb, α increasing logarithmically with wm/wb). The proof is a structured extension of [27] and the paper provides code for reproducibility. However, the significance is substantially reduced by the gap between the theoretical object and the deployed algorithm: Theorem 2.2 covers a fixed, non-personalized G and a deterministic quantile filter, while FedCB2O uses a personalized, time-varying G_j and a stochastic selection heuristic. The experiments cover only one attack type (label-flipping) and show a partial defense (source-class accuracy and ASR remain noticeably worse than the Oracle Min baseline). The overclaim in the abstract and introduction that the algorithm is robust against 'diverse attacks' is therefore not fully supported.

major comments (4)
  1. [Remark 3.6 and Theorem 2.2] The robustness guarantee of Theorem 2.2 applies to the mean-field CB2O dynamics (1.7)-(1.8) with a fixed, non-personalized G satisfying Assumptions A1-A6. The FedCB2O algorithm evaluated in Section 3.5 uses the personalized criterion G_j(θ; θ_j) = max_c eL_{j,c}(θ) - eL_{j,c}(θ_j) defined in Remark 3.6, which depends on the agent's own current model θ_j. The paper explicitly states 'We leave the theoretical analysis of frameworks incorporating upper-level objectives similar to (3.15) for future work.' Consequently, Theorem 2.2 does not cover the algorithm whose robustness is the paper's practical claim, and the experimental results in Tables 1-2 cannot be attributed to the theory. This gap is load-bearing because the abstract and introduction advertise convergence and robustness for the proposed algorithm, not merely for an idealized mean-field system.
  2. [Section 3.4, Algorithm 2 and Remark 3.4] The consensus step (3.13) replaces the quantile sub-level set Q^L_β of (1.4) with the ProbSampling heuristic, which selects M models according to historical performance P^n_j with temperature κ. Remark 3.4 offers only an analogy between κ and β, not a proof that the probabilistic selection approximates the quantile filter. Even if Theorem 2.2 were extended to a non-personalized G, the stochastic, finite-M selection is a further departure from the deterministic mean-field dynamics, and no finite-N or finite-M analysis is provided. Thus the theory does not justify the agent-selection mechanism used in the experiments.
  3. [Section 3.5, Table 1] The experimental evidence does not fully support the claim that FedCB2O 'effectively mitigates' the label-flipping attack or performs comparably to the idealized baselines. FedCB2O achieves source-class accuracy 55.73 ± 2.94% and ASR 38.73 ± 3.42%, whereas Oracle Min (malicious agents removed) achieves 63.53 ± 1.97% and 31.08 ± 2.64%. The gap is roughly 8 percentage points in source-class accuracy and 7.7 points in ASR. This is a substantial residual vulnerability, not a demonstration that the defense is comparable to an attack-free system, and it should be discussed quantitatively.
  4. [Abstract and Section 1.1] The claim of robustness against 'a diverse range of attacks' is overbroad. Theorem 2.2 treats arbitrary malicious-agent dynamics for a fixed robustness criterion G, but the choice of G is attack-specific: the paper states that 'different choices of G may be required to defend against different types of attacks.' The only empirical attack studied is label-flipping, and the robustness criterion (3.15) is specifically designed to counter that attack. No experiment with a different attack type (e.g., backdoor or model poisoning) is reported, and the paper does not characterize the class of attacks for which G_j is effective. The 'diverse attacks' claim should be tempered or supported by additional experiments.
minor comments (4)
  1. [Proposition 2.5, proof] In the proof of (2.18), the integrand is written with ∥θ - θ̃_good∥_2, while the statement uses ∥θ - θ*_good∥_2; since θ̃_good ∈ B_{r_G}(θ*_good), these are not identical, and the derivation should either align the notation or add the extra r_G term explicitly.
  2. [Remark 3.2] Remark 3.2 asserts that the mean-field convergence results 'can be extended' to FedCB2O by combining [12] with Theorem 2.2, but no proof or precise statement is given. This is presented as a remark rather than a theorem; please clarify whether this is a formal claim or an informal outlook.
  3. [Section 2.3, Eq. (2.20)] The choice of β in (2.20) depends on the initial benign mass ρ^b_0(B_{r_{H,ε}/2}(θ*_good)) and on the constants p_{H,ε}, T*, but the paper does not explain how a practitioner would estimate these quantities in a federated setting where the benign distribution is unknown; a comment on practical hyperparameter selection would be useful.
  4. [Figure 5] The font sizes in the bar charts of Figure 5 are very small, and the legend labels are difficult to read; please enlarge the figures or provide a tabular version of the selection-frequency data.

Circularity Check

0 steps flagged · score 0.0 of 10

No circular derivation: Theorem 2.2 is a genuine extension of the same-authors' CB2O result, and the FedCB2O experiments are a designed-defense validation, not a prediction forced by the theorem.

full rationale

The central theoretical result, Theorem 2.2, is proved for the mean-field CB2O dynamics (1.7)-(1.8) with a fixed, non-personalized G under Assumptions A1-A6. Its proof imports the quantile Laplace principle, the benign-mass lower bound, and the Lyapunov estimates from [27] as lemmas; these are parameter-free statements with stated assumptions that do not include the target robustness claim, so citing them is normal mathematical dependency rather than circularity. The new content, Propositions 2.3 and 2.5, genuinely bounds the malicious density's contribution using the new growth condition A6, and the hyperparameter choices (2.20) and (2.23) are derived to make those bounds small; the convergence conclusion does not reduce to the definition of m^{G,L}_{alpha,beta} or to a fitted parameter. The paper explicitly flags that the personalized robustness criterion G_j used in the FedCB2O algorithm is not covered by the theory (Remark 3.6: 'We leave the theoretical analysis of frameworks incorporating upper-level objectives similar to (3.15) for future work'), and Remark 3.4 offers only an analogy between kappa and beta. This is a scope gap between the theorem (fixed G) and the deployed algorithm (personalized, time-varying G_j), not a circular step: the experimental defense is deliberately designed for label-flipping and tested on label-flipping, which is a standard design-and-validate protocol. No equation in the paper is equivalent to its inputs by construction.

Assumptions & free parameters 4 free parameters · 4 assumptions · 0 invented entities

The central theorem rests on the mean-field limit, knowledge of attacker fractions, and a fixed robustness criterion; the practical algorithm introduces a personalized criterion and tuned hyperparameters that are outside the theorem's scope.

free parameters (4)
  • alpha (CB2O temperature) = 10 in experiments
    The theorem requires alpha > alpha0 with alpha0 depending on wm/wb and epsilon; the experiments fix alpha=10 without connecting to the theorem.
  • beta (quantile threshold) = replaced by kappa=2 and zeta=0.5 in ProbSampling
    The theorem requires beta small relative to the benign fraction; the algorithm uses a historical selection likelihood with temperature kappa and EMA weight zeta instead of the quantile beta.
  • TG (switch round for robustness criterion) = 30
    Tuned on validation/test performance across {0, 20, 30, 40}; not derived from theory, and it determines when the defense activates.
  • lambda1, lambda2, gamma, tau, M = 10, 1, 0.004, 5, 20
    Standard algorithm hyperparameters chosen by hand; central to the experimental behavior but not to the theorem.
assumptions (4)
  • domain assumption The fraction of malicious agents wm and benign wb is known to the designer of the training protocol, so that beta and alpha can be set as in (2.20) and (2.23).
    The theorem's alpha0 depends explicitly on log(wm/wb) and beta0 on wb; no method is provided to estimate these in a real FL system.
  • domain assumption The mean-field limit N to infinity is descriptive of finite-agent behavior, i.e., propagation of chaos holds for the CB2O system with malicious agents.
    Theorem 2.2 is stated for laws rho_b and rho_m in the mean-field; the paper does not prove finite-N convergence.
  • ad hoc to paper The personalized robustness criterion Gj in (3.15) behaves like the fixed G in Theorem 2.2, so the convergence guarantee transfers to FedCB2O.
    The paper does not prove this and explicitly defers it to future work (Remark 3.6).
  • ad hoc to paper Assumption A6 (growth of G in the farfield) holds for the chosen robustness criteria.
    A6 is introduced in this paper; it is a regularity and growth condition that may not hold for the max-of-class-loss function Gj used in experiments.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Defending Against Diverse Attacks in Federated Learning Through Consensus-Based Bi-Level Optimization." pith.science (2026). https://pith.science/paper/RRILCGMA

@misc{pith2026241202535,
  author       = {Pith},
  title        = {Pith review of: Defending Against Diverse Attacks in Federated Learning Through Consensus-Based Bi-Level Optimization},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/RRILCGMA}},
  note         = {Machine review of arXiv:2412.02535}
}
abstract

Adversarial attacks pose significant challenges in many machine learning applications, particularly in the setting of distributed training and federated learning, where malicious agents seek to corrupt the training process with the goal of jeopardizing and compromising the performance and reliability of the final models. In this paper, we address the problem of robust federated learning in the presence of such attacks by formulating the training task as a bi-level optimization problem. We conduct a theoretical analysis of the resilience of consensus-based bi-level optimization (CB$^2$O), an interacting multi-particle metaheuristic optimization method, in adversarial settings. Specifically, we provide a global convergence analysis of CB$^2$O in mean-field law in the presence of malicious agents, demonstrating the robustness of CB$^2$O against a diverse range of attacks. Thereby, we offer insights into how specific hyperparameter choices enable to mitigate adversarial effects. On the practical side, we extend CB$^2$O to the clustered federated learning setting by proposing FedCB$^2$O, a novel interacting multi-particle system, and design a practical algorithm that addresses the demands of real-world applications. Extensive experiments demonstrate the robustness of the FedCB$^2$O algorithm against label-flipping attacks in decentralized clustered federated learning scenarios, showcasing its effectiveness in practical contexts.

Figures

Figures reproduced from arXiv: 2412.02535 by the authors.

Figure 1
Figure 1. A pictogram of the decentralized federated learning (DFL) paradigm. [PITH_FULL_IMAGE:figures/full_fig_p002_1.png] view at source ↗
Figure 2
Figure 2. An illustration of malicious agents performing a label-flipping attack in a decentralized clustered [PITH_FULL_IMAGE:figures/full_fig_p016_2.png] view at source ↗
Figure 3
Figure 3. An illustration of a successful LF attack. A malicious agent [PITH_FULL_IMAGE:figures/full_fig_p018_3.png] view at source ↗
Figures from the paper (2 more)
Figure 4
Figure 4. Figure 4: Samples of the rotated EMNIST dataset. Each row contains samples from one rotation. [PITH_FULL_IMAGE:figures/full_fig_p022_4.png]
Figure 5
Figure 5. Figure 5: (a) and (c): Average frequency at which benign agents select models from other benign or malicious agents within the same or a different cluster in the FedCBO/FedCB2O algorithm. For example, the dark blue (orange) bar with labeled “Cluster 1 Benign” (in x-axis) represe…

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

86 extracted references · 68 canonical work pages

  1. [27]

    Garc ´ ıa Trillos, S

    N. Garc ´ ıa Trillos, S. Li, K. Riedl, and Y. Zhu. CB2O: Consensus-based bi-level optimization. arXiv preprint arXiv:2411.13394, 2024

  2. [1]

    Bagdasaryan, A

    E. Bagdasaryan, A. Veit, Y. Hua, D. Estrin, and V. Shmatikov. How to backdoor federated learning. In International conference on artificial intelligence and statistics , pages 2938–2948. PMLR, 2020

  3. [2]

    Bailo, A

    R. Bailo, A. Barbaro, S. N. Gomes, K. Riedl, T. Roith, C. Totzeck, and U. Vaes. CBX: Python and Julia packages for consensus-based interacting particle methods. Journal of Open Source Software , 9(98):6611, 2024

  4. [3]

    Barbieri, S

    L. Barbieri, S. Savazzi, M. Brambilla, and M. Nicoli. Decentralized federated learning for extended sensing in 6G connected vehicles. Vehicular Communications, 33:100396, 2022

  5. [4]

    E. T. M. Beltr´ an,´A. L. P. G´ omez, C. Feng, P. M. S. S´ anchez, S. L. Bernal, G. Bovet, M. G. P´ erez, G. M. P´ erez, and A. H. Celdr´ an. Fedstellar: A platform for decentralized federated learning.Expert Systems with Applications , 242:122861, 2024

  6. [5]

    E. T. M. Beltr´ an, M. Q. P´ erez, P. M. S. S´ anchez, S. L. Bernal, G. Bovet, M. G. P´ erez, G. M. P´ erez, and A. H. Celdr´ an. Decentralized federated learning: Fundamentals, state of the art, frameworks, trends, and challenges. IEEE Communications Surveys & Tutorials , 2023

  7. [6]

    A. N. Bhagoji, S. Chakraborty, P. Mittal, and S. Calo. Analyzing federated learning through an adversarial lens. In International conference on machine learning , pages 634–643. PMLR, 2019

  8. [7]

    Biggio, I

    B. Biggio, I. Corona, D. Maiorca, B. Nelson, N. ˇSrndi´ c, P. Laskov, G. Giacinto, and F. Roli. Evasion attacks against machine learning at test time. In Machine Learning and Knowledge Discovery in Databases: European Conference, ECML PKDD 2013, Prague, Czech Republic, September 23-27, 2013, Proceedings, Part III 13 , pages 387–402. Springer, 2013

Show all 86 references
  1. [8]

    Biggio, B

    B. Biggio, B. Nelson, and P. Laskov. Poisoning attacks against support vector machines. In Inter- national Conference on Machine Learning , 2012

  2. [9]

    Blanchard, E

    P. Blanchard, E. M. El Mhamdi, R. Guerraoui, and J. Stainer. Machine learning with adversaries: Byzantine tolerant gradient descent. Advances in neural information processing systems , 30, 2017

  3. [10]

    Cao and N

    X. Cao and N. Z. Gong. Mitigating evasion attacks to deep neural networks via region-based clas- sification. In Proceedings of the 33rd Annual Computer Security Applications Conference , pages 278–287, 2017

  4. [11]

    J. A. Carrillo, Y.-P. Choi, C. Totzeck, and O. Tse. An analytical framework for consensus-based global optimization method. Math. Models Methods Appl. Sci. , 28(6):1037–1066, 2018

  5. [12]

    J. A. Carrillo, N. Garc ´ ıa Trillos, S. Li, and Y. Zhu. FedCBO: Reaching group consensus in clustered federated learning through consensus-based optimization. Journal of Machine Learning Research , 25(214):1–51, 2024

  6. [13]

    J. A. Carrillo, S. Jin, L. Li, and Y. Zhu. A consensus-based global optimization method for high dimensional machine learning problems. ESAIM Control Optim. Calc. Var. , 27(suppl.):Paper No. S5, 22, 2021

  7. [14]

    D. Chen, D. Gao, Y. Xie, X. Pan, Z. Li, Y. Li, B. Ding, and J. Zhou. Fs-real: Towards real-world cross-device federated learning. In Proceedings of the 29th ACM SIGKDD Conference on Knowledge Discovery and Data Mining , pages 3829–3841, 2023

  8. [15]

    W. Chen, S. Horv´ ath, and P. Richt´ arik. Optimal client sampling for federated learning.Transactions on Machine Learning Research, 2022

  9. [16]

    X. Chen, C. Liu, B. Li, K. Lu, and D. Song. Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526 , 2017. 27

  10. [17]

    Cohen, S

    G. Cohen, S. Afshar, J. Tapson, and A. Van Schaik. Emnist: Extending mnist to handwritten letters. In 2017 international joint conference on neural networks (IJCNN) , pages 2921–2926. IEEE, 2017

  11. [18]

    S. Dai, S. I. Alam, R. Balakrishnan, K. Lee, S. Banerjee, and N. Himayat. Online federated learning based object detection across autonomous vehicles in a virtual world. In 2023 IEEE 20th Consumer Communications & Networking Conference (CCNC) , pages 919–920. IEEE, 2023

  12. [19]

    Dorigo and C

    M. Dorigo and C. Blum. Ant colony optimization theory: A survey. Theoret. Comput. Sci. , 344(2- 3):243–278, 2005

  13. [20]

    X. Fan, Y. Wang, Y. Huo, and Z. Tian. Cb-dsl: Communication-efficient and byzantine-robust distributed swarm learning on non-iid data. IEEE Transactions on Cognitive Communications and Networking, 2023

  14. [21]

    M. Fang, X. Cao, J. Jia, and N. Gong. Local model poisoning attacks to {Byzantine-Robust} federated learning. In 29th USENIX security symposium (USENIX Security 20) , pages 1605–1622, 2020

  15. [22]

    Fornasier, T

    M. Fornasier, T. Klock, and K. Riedl. Convergence of anisotropic consensus-based optimization in mean-field law. In J. L. J. Laredo, J. I. Hidalgo, and K. O. Babaagba, editors, Applications of Evolutionary Computation - 25th European Conference, EvoApplications 2022, Held as P...

  16. [23]

    Fornasier, T

    M. Fornasier, T. Klock, and K. Riedl. Consensus-Based Optimization Methods Converge Globally. SIAM J. Optim. , 34(3):2973–3004, 2024

  17. [24]

    Fraboni, R

    Y. Fraboni, R. Vidal, and M. Lorenzi. Free-rider attacks on model aggregation in federated learning. In International Conference on Artificial Intelligence and Statistics , pages 1846–1854. PMLR, 2021

  18. [25]

    L. Fu, H. Zhang, G. Gao, M. Zhang, and X. Liu. Client selection in federated learning: Principles, challenges, and opportunities. IEEE Internet of Things Journal , 2023

  19. [26]

    C. Fung, C. J. Yoon, and I. Beschastnikh. The limitations of federated learning in sybil settings. In 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2020) , pages 301–316, 2020

  20. [28]

    Geiping, H

    J. Geiping, H. Bauermeister, H. Dr¨ oge, and M. Moeller. Inverting gradients-how easy is it to break privacy in federated learning? Advances in neural information processing systems , 33:16937–16947, 2020

  21. [29]

    Ghosh, J

    A. Ghosh, J. Chung, D. Yin, and K. Ramchandran. An efficient framework for clustered federated learning. In H. Larochelle, M. Ranzato, R. Hadsell, M. Balcan, and H. Lin, editors, Advances in Neural Information Processing Systems , volume 33, pages 19586–19597. Curran Associate...

  22. [30]

    I. J. Goodfellow, J. Shlens, and C. Szegedy. Explaining and harnessing adversarial examples. In Y. Bengio and Y. LeCun, editors, 3rd International Conference on Learning Representations, ICLR 2015, San Diego, CA, USA, May 7-9, 2015, Conference Track Proceedings , 2015

  23. [31]

    Grassi, H

    S. Grassi, H. Huang, L. Pareschi, and J. Qiu. Mean-field particle swarm optimization. In Modeling and Simulation for Collective Dynamics , pages 127–193. World Scientific, 2023

  24. [32]

    Hallaji, R

    E. Hallaji, R. Razavi-Far, M. Saif, and E. Herrera-Viedma. Label noise analysis meets adversar- ial training: A defense against label poisoning in federated learning. Knowledge-Based Systems , 266:110384, 2023

  25. [33]

    Hallaji, R

    E. Hallaji, R. Razavi-Far, M. Saif, B. Wang, and Q. Yang. Decentralized federated learning: A survey on security and privacy. IEEE Transactions on Big Data , 2024

  26. [34]

    L. He, A. Bian, and M. Jaggi. Cola: Decentralized linear learning. Advances in Neural Information Processing Systems, 31, 2018. 28

  27. [35]

    Huang, J

    H. Huang, J. Qiu, and K. Riedl. On the global convergence of particle swarm optimization methods. Appl. Math. Optim. , 88(2):Paper No. 30, 44, 2023

  28. [36]

    N. M. Jebreel and J. Domingo-Ferrer. Fl-defender: Combating targeted attacks in federated learning. Knowledge-Based Systems, 260:110178, 2023

  29. [37]

    N. M. Jebreel, J. Domingo-Ferrer, D. S´ anchez, and A. Blanco-Justicia. Lfighter: Defending against the label-flipping attack in federated learning. Neural Networks, 170:111–126, 2024

  30. [38]

    M. S. Jere, T. Farnan, and F. Koushanfar. A taxonomy of attacks on federated learning. IEEE Security & Privacy , 19(2):20–28, 2021

  31. [39]

    Jiang, W

    Y. Jiang, W. Zhang, and Y. Chen. Data quality detection mechanism against label flipping attacks in federated learning. IEEE Transactions on Information Forensics and Security , 18:1625–1637, 2023

  32. [40]

    S. Jin, L. Li, and J.-G. Liu. Random batch methods (rbm) for interacting particle systems. Journal of Computational Physics , 400:108877, 2020

  33. [41]

    Kairouz, H

    P. Kairouz, H. B. McMahan, B. Avent, A. Bellet, M. Bennis, A. N. Bhagoji, K. A. Bonawitz, Z. Charles, G. Cormode, R. Cummings, R. G. L. D’Oliveira, H. Eichner, S. E. Rouayheb, D. Evans, J. Gardner, Z. Garrett, A. Gasc´ on, B. Ghazi, P. B. Gibbons, M. Gruteser, Z. Harchaoui, C....

  34. [42]

    Karagulyan, E

    A. Karagulyan, E. Shulgin, A. Sadiev, and P. Richt´ arik. SPAM: Stochastic proximal point method with momentum variance reduction for non-convex cross-device federated learning. arXiv preprint arXiv:2405.20127, 2024

  35. [43]

    S. P. Karimireddy, M. Jaggi, S. Kale, M. Mohri, S. Reddi, S. U. Stich, and A. T. Suresh. Breaking the centralized barrier for cross-device federated learning. Advances in Neural Information Processing Systems, 34:28663–28676, 2021

  36. [44]

    Kasneci, K

    E. Kasneci, K. Seßler, S. K¨ uchemann, M. Bannert, D. Dementieva, F. Fischer, U. Gasser, G. Groh, S. G¨ unnemann, E. H¨ ullermeier, S. Krusche, G. Kutyniok, T. Michaeli, C. Nerdel, J. Pfeffer, O. Po- quet, M. Sailer, A. Schmidt, T. Seidel, S. Matthias, J. Weller, J. Kuhn, and ...

  37. [45]

    J. Kennedy. The particle swarm: social adaptation of knowledge. In Proceedings of 1997 IEEE International Conference on Evolutionary Computation , pages 303–308. IEEE, 1997

  38. [46]

    Kennedy and R

    J. Kennedy and R. Eberhart. Particle swarm optimization. In Proceedings of International Confer- ence on Neural Networks (ICNN’95), Perth, WA, Australia, November 27 - December 1, 1995 , pages 1942–1948. IEEE, 1995

  39. [48]

    Koneˇ cn` y, H

    J. Koneˇ cn` y, H. B. McMahan, D. Ramage, and P. Richt´ arik. Federated optimization: Distributed machine learning for on-device intelligence. arXiv preprint arXiv:1610.02527 , 2016

  40. [49]

    Kovalev, A

    D. Kovalev, A. Koloskova, M. Jaggi, P. Richtarik, and S. Stich. A linearly convergent algorithm for decentralized optimization: Sending less bits for free! In International Conference on Artificial Intelligence and Statistics , pages 4087–4095. PMLR, 2021

  41. [50]

    D. Li, W. E. Wong, W. Wang, Y. Yao, and M. Chau. Detection and mitigation of label-flipping attacks in federated learning systems with KPCA and K-means. In2021 8th International Conference on Dependable Systems and Their Applications (DSA) , pages 551–559. IEEE, 2021. 29

  42. [51]

    X. Li, Z. Qu, S. Zhao, B. Tang, Z. Lu, and Y. Liu. Lomar: A local defense against poisoning attack on federated learning. IEEE Transactions on Dependable and Secure Computing , 20(1):437–450, 2021

  43. [52]

    Z. Lian, Q. Yang, W. Wang, Q. Zeng, M. Alazab, H. Zhao, and C. Su. DEEP-FEL: Decentralized, efficient and privacy-enhanced federated edge learning for healthcare cyber physical systems. IEEE Transactions on Network Science and Engineering , 9(5):3558–3569, 2022

  44. [53]

    G. Long, M. Xie, T. Shen, T. Zhou, X. Wang, and J. Jiang. Multi-center federated learning: clients clustering for better personalization. World Wide Web , 26(1):481–500, 2023

  45. [54]

    L. Lyu, H. Yu, J. Zhao, and Q. Yang. Threats to Federated Learning, pages 3–16. Springer Interna- tional Publishing, Cham, 2020

  46. [55]

    J. Ma, G. Long, T. Zhou, J. Jiang, and C. Zhang. On the convergence of clustered federated learning. arXiv preprint arXiv:2202.06187 , 2022

  47. [56]

    McMahan, E

    B. McMahan, E. Moore, D. Ramage, S. Hampson, and B. A. y. Arcas. Communication-Efficient Learning of Deep Networks from Decentralized Data. In A. Singh and J. Zhu, editors, Proceedings of the 20th International Conference on Artificial Intelligence and Statistics , volume 54 o...

  48. [57]

    M. Nasr, R. Shokri, and A. Houmansadr. Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning. In 2019 IEEE symposium on security and privacy (SP) , pages 739–753. IEEE, 2019

  49. [58]

    Nguyen, T

    A. Nguyen, T. Do, M. Tran, B. X. Nguyen, C. Duong, T. Phan, E. Tjiputra, and Q. D. Tran. Deep federated learning for autonomous driving. In 2022 IEEE Intelligent Vehicles Symposium (IV), pages 1824–1830. IEEE, 2022

  50. [59]

    Onoszko, G

    N. Onoszko, G. Karlsson, O. Mogren, and E. L. Zec. Decentralized federated learning of deep neural networks on non-iid data. arXiv preprint arXiv:2107.08517 , 2021

  51. [60]

    Park, D.-J

    J. Park, D.-J. Han, M. Choi, and J. Moon. Sageflow: Robust federated learning against both stragglers and adversaries. Advances in neural information processing systems , 34:840–851, 2021

  52. [61]

    S. Park, Y. Suh, and J. Lee. FedPSO: Federated learning using particle swarm optimization to reduce communication costs. Sensors, 21(2), 2021

  53. [62]

    Pillutla, S

    K. Pillutla, S. M. Kakade, and Z. Harchaoui. Robust aggregation for federated learning. IEEE Transactions on Signal Processing, 70:1142–1154, 2022

  54. [63]

    Pinnau, C

    R. Pinnau, C. Totzeck, O. Tse, and S. Martin. A consensus-based model for global optimization and its mean-field limit. Math. Models Methods Appl. Sci. , 27(1):183–204, 2017

  55. [64]

    K. Riedl. Leveraging memory effects and gradient information in consensus-based optimisation: On global convergence in mean-field law. European J. Appl. Math. , 35(4):483–514, 2024

  56. [65]

    K. Riedl. Mathematical Foundations of Interacting Multi-Particle Systems for Optimization . PhD thesis, Technical University of Munich, 2024

  57. [66]

    Riedl, T

    K. Riedl, T. Klock, C. Geldhauser, and M. Fornasier. Gradient is All You Need? arXiv preprint arXiv:2306.09778, 2023

  58. [67]

    Riedl, T

    K. Riedl, T. Klock, C. Geldhauser, and M. Fornasier. How Consensus-Based Optimization can be Interpreted as a Stochastic Relaxation of Gradient Descent. ICML Workshop Differentiable Almost Everything: Differentiable Relaxations, Algorithms, Operators, and Simulators , 2024

  59. [68]

    Rodr ´ ıguez-Barroso, D

    N. Rodr ´ ıguez-Barroso, D. Jim´ enez-L´ opez, M. V. Luz´ on, F. Herrera, and E. Mart ´ ınez-C´ amara. Survey on federated learning threats: Concepts, taxonomy on attacks and defences, experimental study and challenges. Information Fusion, 90:148–173, 2023

  60. [69]

    Ruan and C

    Y. Ruan and C. Joe-Wong. Fedsoft: Soft clustered federated learning with proximal local updating. In Proceedings of the AAAI Conference on Artificial Intelligence, volume 36, pages 8124–8131, 2022. 30

  61. [70]

    Sattler, K

    F. Sattler, K. M¨ uller, and W. Samek. Clustered federated learning: Model-agnostic distributed multi- task optimization under privacy constraints. IEEE Trans. Neural Networks Learn. Syst., 32(8):3710– 3722, 2021

  62. [71]

    Shammar, X

    E. Shammar, X. Cui, and M. A. Al-qaness. Swarm learning: A survey of concepts, applications, and trends. arXiv preprint arXiv:2405.00556 , 2024

  63. [72]

    Shejwalkar and A

    V. Shejwalkar and A. Houmansadr. Manipulating the byzantine: Optimizing model poisoning attacks and defenses for federated learning. In NDSS, 2021

  64. [73]

    Shumailov, Z

    I. Shumailov, Z. Shumaylov, D. Kazhdan, Y. Zhao, N. Papernot, M. A. Erdogdu, and R. J. Anderson. Manipulating SGD with data ordering attacks. In M. Ranzato, A. Beygelzimer, Y. N. Dauphin, P. Liang, and J. W. Vaughan, editors, Advances in Neural Information Processing Systems 3...

  65. [74]

    Steinhardt, P

    J. Steinhardt, P. W. W. Koh, and P. S. Liang. Certified defenses for data poisoning attacks.Advances in neural information processing systems , 30, 2017

  66. [75]

    T. Sun, D. Li, and B. Wang. Decentralized federated averaging. IEEE Transactions on Pattern Analysis and Machine Intelligence , 45(4):4289–4301, 2022

  67. [76]

    Z. Sun, P. Kairouz, A. T. Suresh, and H. B. McMahan. Can you really backdoor federated learning? arXiv preprint arXiv:1911.07963 , 2019

  68. [77]

    Szegedy, W

    C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. J. Goodfellow, and R. Fergus. Intriguing properties of neural networks. In Y. Bengio and Y. LeCun, editors, 2nd International Conference on Learning Representations, ICLR 2014, Banff, AB, Canada, April 14-16, 2014, C...

  69. [78]

    A. J. Thirunavukarasu, D. S. J. Ting, K. Elangovan, L. Gutierrez, T. F. Tan, and D. S. W. Ting. Large language models in medicine. Nature medicine, 29(8):1930–1940, 2023

  70. [79]

    Tolpegin, S

    V. Tolpegin, S. Truex, M. E. Gursoy, and L. Liu. Data poisoning attacks against federated learning systems. In Computer Security–ESORICS 2020: 25th European Symposium on Research in Computer Security, ESORICS 2020, Guildford, UK, September 14–18, 2020, Proceedings, Part I 25, ...

  71. [80]

    H. Wang, K. Sreenivasan, S. Rajput, H. Vishwakarma, S. Agarwal, J.-y. Sohn, K. Lee, and D. Papail- iopoulos. Attack of the tails: Yes, you really can backdoor federated learning. Advances in Neural Information Processing Systems, 33:16070–16084, 2020

  72. [81]

    Y. Wang, Z. Tian, X. Fan, Z. Cai, C. Nowzari, and K. Zeng. Distributed swarm learning for edge internet of things. IEEE Communications Magazine , 2024

  73. [82]

    Z. Wu, Q. Ling, T. Chen, and G. B. Giannakis. Federated variance-reduced stochastic gradient descent with robustness to byzantine attacks. IEEE Transactions on Signal Processing , 68:4583– 4596, 2020

  74. [83]

    C. Xie, K. Huang, P.-Y. Chen, and B. Li. Dba: Distributed backdoor attacks against federated learning. In International conference on learning representations , 2019

  75. [84]

    W. Yang, N. Wang, Z. Guan, L. Wu, X. Du, and M. Guizani. A practical cross-device federated learning framework over 5G networks. IEEE Wireless Communications , 29(6):128–134, 2022

  76. [85]

    D. Yin, Y. Chen, R. Kannan, and P. Bartlett. Byzantine-robust distributed learning: Towards optimal statistical rates. In International conference on machine learning, pages 5650–5659. PMLR, 2018

  77. [86]

    Zhang, B

    J. Zhang, B. Chen, X. Cheng, H. T. T. Binh, and S. Yu. Poisongan: Generative poisoning attacks against federated learning in edge computing systems. IEEE Internet of Things Journal , 8(5):3310– 3322, 2020. 31

  78. [87]

    Zhang, J

    J. Zhang, J. Chen, D. Wu, B. Chen, and S. Yu. Poisoning attack in federated learning using generative adversarial nets. In 2019 18th IEEE international conference on trust, security and privacy in computing and communications/13th IEEE international conference on big data scie...

Pith tools

Reviewed August 11, 2026 · model on record in the stance chip above.