REVIEW 4 major objections 4 minor 86 references
Defending Against Diverse Attacks in Federated Learning Through Consensus-Based Bi-Level Optimization
T0 review · 4 major / 4 minor · reviewed 2026-08-11 · deepseek-v4-flash
Pith's one-line read This paper claims that consensus-based bi-level optimization lets benign federated agents converge to the robust model even when malicious agents attack arbitrarily.
desk verdict Genuine mean-field robustness theorem for fixed G, but the FedCB2O algorithm's personalized G_j escapes the theory, so the practical robustness claim rests on experiments alone. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing object is the consensus point $m^{{G,L}}$_{α,β}(ρ): a weighted average of particle positions inside the quantile sublevel set Q^L_β[ρ], weighted by exp(-αG(θ)). It combines a lower-level filter (only models with small loss relative to a quantile survive) with an upper-level filter (among survivors, models with small robustness score dominate). The extension of the quantitative quantile Laplace principle (Proposition 2.3) and the attack-control bound (Proposition 2.5) are what turn the presence of malicious mass into exponentially small error terms, leaving the benign dynamics to contract toward θ*_good at the rate inherited from the attack-free CB2O proof.
What would settle it
Run the FedCB2O algorithm with the personalized robustness criterion (3.15) under label-flipping attacks and check whether benign agents continue to assign non-negligible weight to poisoned models as α is increased as prescribed by (2.23); if those weights do not decay toward zero, the convergence guarantee does not transfer to the deployed criterion.
Extended reading notes
Core claim
The central claim is Theorem 2.2: in the mean-field limit, the law of benign agents converges exponentially fast in squared Wasserstein distance to the target model θ*_good, the minimizer of the robustness criterion G among global minimizers of the loss L, even though malicious agents are modeled with arbitrary drift and diffusion. The theorem localizes the effect of attacks: after a robust quantile Laplace bound splits the consensus error into benign and malicious parts, a separate control proposition shows the malicious contribution decays like exp(-αu) under the farfield growth condition A6 on G. The proof yields explicit hyperparameter rules: β must be below a threshold proportional to w_b (the benign fraction), and α must exceed a threshold whose dominant term is log(w_m/w_b · R_K^G / $\sqrt$(ε)).
Load-bearing premise
The convergence theorem is proven for a fixed, shared robustness criterion G, while the deployed FedCB2O algorithm weights models with a personalized criterion G_j that depends on each agent's own changing model, and the paper explicitly leaves the theory for that criterion to future work.
Editorial extensions
If this is right
- A user of CB2O can defend against a broad class of attacks by choosing β proportional to the fraction of benign agents and α above the explicit logarithmic threshold, without knowing which agents are malicious.
- Label-flipping attacks, which are hard to filter by average loss alone, are neutralized by the upper-level criterion in FedCB2O: experiments show source-class accuracy rises from about 40% with FedCBO to about 56–58% and attack success rate drops.
- In the limit w_m → 0 and w_b → 1, the theorem's hyperparameter choices reduce to the attack-free CB2O settings, so the defense does not come at the cost of the original convergence guarantee.
- The agent selection mechanism that records each peer's historical loss performance is independent of the robustness criterion and can be slotted into other decentralized federated algorithms.
Reading between the lines
- If the personalized criterion G_j from (3.15) behaves empirically like the fixed G analyzed in Theorem 2.2, then the same defense should extend to agents with heterogeneous local datasets, a setting the paper flags as future work.
- Because the theorem's α threshold grows only logarithmically with the malicious-to-benign ratio, the framework predicts that a modest increase in selection sharpness compensates for a very large hostile minority; this is a testable quantitative prediction.
- The ProbSampling mechanism, which selects models by an exponential moving average of past losses, may be useful beyond robustness, for example to cut communication cost in any decentralized method that budgets downloads per round.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper proposes a bi-level optimization formulation (1.1) for robust federated learning, where the upper-level objective G encodes a robustness criterion and the lower-level objective L is the training loss. The main theoretical result, Theorem 2.2, states that the mean-field CB2O dynamics (1.7)-(1.8) converge in Wasserstein distance to the robust minimizer θ*_good even when a fraction wm of agents behave adversarially, provided the hyperparameters β and α are chosen according to (2.20) and (2.23). The proof extends the quantitative Laplace principle of the authors' earlier CB2O paper [27] and adds Assumption A6 on the far-field growth of G. On the practical side, the paper introduces FedCB2O, an algorithm for decentralized clustered federated learning that combines FedCBO with a robustness-weighted consensus point, a probabilistic agent-selection mechanism (ProbSampling), and a personalized robustness criterion G_j (Remark 3.6). Experiments on rotated EMNIST with label-flipping attacks compare FedCB2O against FedCBO and two Oracle baselines.
Significance. If Theorem 2.2 is correct, it constitutes a meaningful extension of the mean-field convergence theory of consensus-based optimization to settings with malicious agents, and it gives concrete, falsifiable hyperparameter scaling predictions (β ∝ wb, α increasing logarithmically with wm/wb). The proof is a structured extension of [27] and the paper provides code for reproducibility. However, the significance is substantially reduced by the gap between the theoretical object and the deployed algorithm: Theorem 2.2 covers a fixed, non-personalized G and a deterministic quantile filter, while FedCB2O uses a personalized, time-varying G_j and a stochastic selection heuristic. The experiments cover only one attack type (label-flipping) and show a partial defense (source-class accuracy and ASR remain noticeably worse than the Oracle Min baseline). The overclaim in the abstract and introduction that the algorithm is robust against 'diverse attacks' is therefore not fully supported.
major comments (4)
- [Remark 3.6 and Theorem 2.2] The robustness guarantee of Theorem 2.2 applies to the mean-field CB2O dynamics (1.7)-(1.8) with a fixed, non-personalized G satisfying Assumptions A1-A6. The FedCB2O algorithm evaluated in Section 3.5 uses the personalized criterion G_j(θ; θ_j) = max_c eL_{j,c}(θ) - eL_{j,c}(θ_j) defined in Remark 3.6, which depends on the agent's own current model θ_j. The paper explicitly states 'We leave the theoretical analysis of frameworks incorporating upper-level objectives similar to (3.15) for future work.' Consequently, Theorem 2.2 does not cover the algorithm whose robustness is the paper's practical claim, and the experimental results in Tables 1-2 cannot be attributed to the theory. This gap is load-bearing because the abstract and introduction advertise convergence and robustness for the proposed algorithm, not merely for an idealized mean-field system.
- [Section 3.4, Algorithm 2 and Remark 3.4] The consensus step (3.13) replaces the quantile sub-level set Q^L_β of (1.4) with the ProbSampling heuristic, which selects M models according to historical performance P^n_j with temperature κ. Remark 3.4 offers only an analogy between κ and β, not a proof that the probabilistic selection approximates the quantile filter. Even if Theorem 2.2 were extended to a non-personalized G, the stochastic, finite-M selection is a further departure from the deterministic mean-field dynamics, and no finite-N or finite-M analysis is provided. Thus the theory does not justify the agent-selection mechanism used in the experiments.
- [Section 3.5, Table 1] The experimental evidence does not fully support the claim that FedCB2O 'effectively mitigates' the label-flipping attack or performs comparably to the idealized baselines. FedCB2O achieves source-class accuracy 55.73 ± 2.94% and ASR 38.73 ± 3.42%, whereas Oracle Min (malicious agents removed) achieves 63.53 ± 1.97% and 31.08 ± 2.64%. The gap is roughly 8 percentage points in source-class accuracy and 7.7 points in ASR. This is a substantial residual vulnerability, not a demonstration that the defense is comparable to an attack-free system, and it should be discussed quantitatively.
- [Abstract and Section 1.1] The claim of robustness against 'a diverse range of attacks' is overbroad. Theorem 2.2 treats arbitrary malicious-agent dynamics for a fixed robustness criterion G, but the choice of G is attack-specific: the paper states that 'different choices of G may be required to defend against different types of attacks.' The only empirical attack studied is label-flipping, and the robustness criterion (3.15) is specifically designed to counter that attack. No experiment with a different attack type (e.g., backdoor or model poisoning) is reported, and the paper does not characterize the class of attacks for which G_j is effective. The 'diverse attacks' claim should be tempered or supported by additional experiments.
minor comments (4)
- [Proposition 2.5, proof] In the proof of (2.18), the integrand is written with ∥θ - θ̃_good∥_2, while the statement uses ∥θ - θ*_good∥_2; since θ̃_good ∈ B_{r_G}(θ*_good), these are not identical, and the derivation should either align the notation or add the extra r_G term explicitly.
- [Remark 3.2] Remark 3.2 asserts that the mean-field convergence results 'can be extended' to FedCB2O by combining [12] with Theorem 2.2, but no proof or precise statement is given. This is presented as a remark rather than a theorem; please clarify whether this is a formal claim or an informal outlook.
- [Section 2.3, Eq. (2.20)] The choice of β in (2.20) depends on the initial benign mass ρ^b_0(B_{r_{H,ε}/2}(θ*_good)) and on the constants p_{H,ε}, T*, but the paper does not explain how a practitioner would estimate these quantities in a federated setting where the benign distribution is unknown; a comment on practical hyperparameter selection would be useful.
- [Figure 5] The font sizes in the bar charts of Figure 5 are very small, and the legend labels are difficult to read; please enlarge the figures or provide a tabular version of the selection-frequency data.
Circularity Check
No circular derivation: Theorem 2.2 is a genuine extension of the same-authors' CB2O result, and the FedCB2O experiments are a designed-defense validation, not a prediction forced by the theorem.
full rationale
The central theoretical result, Theorem 2.2, is proved for the mean-field CB2O dynamics (1.7)-(1.8) with a fixed, non-personalized G under Assumptions A1-A6. Its proof imports the quantile Laplace principle, the benign-mass lower bound, and the Lyapunov estimates from [27] as lemmas; these are parameter-free statements with stated assumptions that do not include the target robustness claim, so citing them is normal mathematical dependency rather than circularity. The new content, Propositions 2.3 and 2.5, genuinely bounds the malicious density's contribution using the new growth condition A6, and the hyperparameter choices (2.20) and (2.23) are derived to make those bounds small; the convergence conclusion does not reduce to the definition of m^{G,L}_{alpha,beta} or to a fitted parameter. The paper explicitly flags that the personalized robustness criterion G_j used in the FedCB2O algorithm is not covered by the theory (Remark 3.6: 'We leave the theoretical analysis of frameworks incorporating upper-level objectives similar to (3.15) for future work'), and Remark 3.4 offers only an analogy between kappa and beta. This is a scope gap between the theorem (fixed G) and the deployed algorithm (personalized, time-varying G_j), not a circular step: the experimental defense is deliberately designed for label-flipping and tested on label-flipping, which is a standard design-and-validate protocol. No equation in the paper is equivalent to its inputs by construction.
Assumptions & free parameters
free parameters (4)
- alpha (CB2O temperature) =
10 in experiments
- beta (quantile threshold) =
replaced by kappa=2 and zeta=0.5 in ProbSampling
- TG (switch round for robustness criterion) =
30
- lambda1, lambda2, gamma, tau, M =
10, 1, 0.004, 5, 20
assumptions (4)
- domain assumption The fraction of malicious agents wm and benign wb is known to the designer of the training protocol, so that beta and alpha can be set as in (2.20) and (2.23).
- domain assumption The mean-field limit N to infinity is descriptive of finite-agent behavior, i.e., propagation of chaos holds for the CB2O system with malicious agents.
- ad hoc to paper The personalized robustness criterion Gj in (3.15) behaves like the fixed G in Theorem 2.2, so the convergence guarantee transfers to FedCB2O.
- ad hoc to paper Assumption A6 (growth of G in the farfield) holds for the chosen robustness criteria.
Cite this review
Pith. "Pith review of Defending Against Diverse Attacks in Federated Learning Through Consensus-Based Bi-Level Optimization." pith.science (2026). https://pith.science/paper/RRILCGMA
@misc{pith2026241202535,
author = {Pith},
title = {Pith review of: Defending Against Diverse Attacks in Federated Learning Through Consensus-Based Bi-Level Optimization},
year = {2026},
howpublished = {\url{https://pith.science/paper/RRILCGMA}},
note = {Machine review of arXiv:2412.02535}
}
abstract
Adversarial attacks pose significant challenges in many machine learning applications, particularly in the setting of distributed training and federated learning, where malicious agents seek to corrupt the training process with the goal of jeopardizing and compromising the performance and reliability of the final models. In this paper, we address the problem of robust federated learning in the presence of such attacks by formulating the training task as a bi-level optimization problem. We conduct a theoretical analysis of the resilience of consensus-based bi-level optimization (CB$^2$O), an interacting multi-particle metaheuristic optimization method, in adversarial settings. Specifically, we provide a global convergence analysis of CB$^2$O in mean-field law in the presence of malicious agents, demonstrating the robustness of CB$^2$O against a diverse range of attacks. Thereby, we offer insights into how specific hyperparameter choices enable to mitigate adversarial effects. On the practical side, we extend CB$^2$O to the clustered federated learning setting by proposing FedCB$^2$O, a novel interacting multi-particle system, and design a practical algorithm that addresses the demands of real-world applications. Extensive experiments demonstrate the robustness of the FedCB$^2$O algorithm against label-flipping attacks in decentralized clustered federated learning scenarios, showcasing its effectiveness in practical contexts.
Figures
Figures from the paper (2 more)
Reference graph
Works this paper leans on
-
[27]
N. Garc ´ ıa Trillos, S. Li, K. Riedl, and Y. Zhu. CB2O: Consensus-based bi-level optimization. arXiv preprint arXiv:2411.13394, 2024
arXiv 2024
-
[1]
Bagdasaryan, A
E. Bagdasaryan, A. Veit, Y. Hua, D. Estrin, and V. Shmatikov. How to backdoor federated learning. In International conference on artificial intelligence and statistics , pages 2938–2948. PMLR, 2020
2020
-
[2]
Bailo, A
R. Bailo, A. Barbaro, S. N. Gomes, K. Riedl, T. Roith, C. Totzeck, and U. Vaes. CBX: Python and Julia packages for consensus-based interacting particle methods. Journal of Open Source Software , 9(98):6611, 2024
2024
-
[3]
Barbieri, S
L. Barbieri, S. Savazzi, M. Brambilla, and M. Nicoli. Decentralized federated learning for extended sensing in 6G connected vehicles. Vehicular Communications, 33:100396, 2022
2022
-
[4]
E. T. M. Beltr´ an,´A. L. P. G´ omez, C. Feng, P. M. S. S´ anchez, S. L. Bernal, G. Bovet, M. G. P´ erez, G. M. P´ erez, and A. H. Celdr´ an. Fedstellar: A platform for decentralized federated learning.Expert Systems with Applications , 242:122861, 2024
2024
-
[5]
E. T. M. Beltr´ an, M. Q. P´ erez, P. M. S. S´ anchez, S. L. Bernal, G. Bovet, M. G. P´ erez, G. M. P´ erez, and A. H. Celdr´ an. Decentralized federated learning: Fundamentals, state of the art, frameworks, trends, and challenges. IEEE Communications Surveys & Tutorials , 2023
2023
-
[6]
A. N. Bhagoji, S. Chakraborty, P. Mittal, and S. Calo. Analyzing federated learning through an adversarial lens. In International conference on machine learning , pages 634–643. PMLR, 2019
2019
-
[7]
B. Biggio, I. Corona, D. Maiorca, B. Nelson, N. ˇSrndi´ c, P. Laskov, G. Giacinto, and F. Roli. Evasion attacks against machine learning at test time. In Machine Learning and Knowledge Discovery in Databases: European Conference, ECML PKDD 2013, Prague, Czech Republic, September 23-27, 2013, Proceedings, Part III 13 , pages 387–402. Springer, 2013
work page 2013
Show all 86 references
-
[8]
Biggio, B
B. Biggio, B. Nelson, and P. Laskov. Poisoning attacks against support vector machines. In Inter- national Conference on Machine Learning , 2012
2012
-
[9]
Blanchard, E
P. Blanchard, E. M. El Mhamdi, R. Guerraoui, and J. Stainer. Machine learning with adversaries: Byzantine tolerant gradient descent. Advances in neural information processing systems , 30, 2017
2017
-
[10]
Cao and N
X. Cao and N. Z. Gong. Mitigating evasion attacks to deep neural networks via region-based clas- sification. In Proceedings of the 33rd Annual Computer Security Applications Conference , pages 278–287, 2017
2017
-
[11]
J. A. Carrillo, Y.-P. Choi, C. Totzeck, and O. Tse. An analytical framework for consensus-based global optimization method. Math. Models Methods Appl. Sci. , 28(6):1037–1066, 2018
2018
-
[12]
J. A. Carrillo, N. Garc ´ ıa Trillos, S. Li, and Y. Zhu. FedCBO: Reaching group consensus in clustered federated learning through consensus-based optimization. Journal of Machine Learning Research , 25(214):1–51, 2024
2024
-
[13]
J. A. Carrillo, S. Jin, L. Li, and Y. Zhu. A consensus-based global optimization method for high dimensional machine learning problems. ESAIM Control Optim. Calc. Var. , 27(suppl.):Paper No. S5, 22, 2021
2021
-
[14]
D. Chen, D. Gao, Y. Xie, X. Pan, Z. Li, Y. Li, B. Ding, and J. Zhou. Fs-real: Towards real-world cross-device federated learning. In Proceedings of the 29th ACM SIGKDD Conference on Knowledge Discovery and Data Mining , pages 3829–3841, 2023
2023
-
[15]
W. Chen, S. Horv´ ath, and P. Richt´ arik. Optimal client sampling for federated learning.Transactions on Machine Learning Research, 2022
2022
-
[16]
X. Chen, C. Liu, B. Li, K. Lu, and D. Song. Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526 , 2017. 27
2017 arXiv
-
[17]
Cohen, S
G. Cohen, S. Afshar, J. Tapson, and A. Van Schaik. Emnist: Extending mnist to handwritten letters. In 2017 international joint conference on neural networks (IJCNN) , pages 2921–2926. IEEE, 2017
2017
-
[18]
S. Dai, S. I. Alam, R. Balakrishnan, K. Lee, S. Banerjee, and N. Himayat. Online federated learning based object detection across autonomous vehicles in a virtual world. In 2023 IEEE 20th Consumer Communications & Networking Conference (CCNC) , pages 919–920. IEEE, 2023
2023
-
[19]
Dorigo and C
M. Dorigo and C. Blum. Ant colony optimization theory: A survey. Theoret. Comput. Sci. , 344(2- 3):243–278, 2005
2005
-
[20]
X. Fan, Y. Wang, Y. Huo, and Z. Tian. Cb-dsl: Communication-efficient and byzantine-robust distributed swarm learning on non-iid data. IEEE Transactions on Cognitive Communications and Networking, 2023
2023
-
[21]
M. Fang, X. Cao, J. Jia, and N. Gong. Local model poisoning attacks to {Byzantine-Robust} federated learning. In 29th USENIX security symposium (USENIX Security 20) , pages 1605–1622, 2020
2020
-
[22]
Fornasier, T
M. Fornasier, T. Klock, and K. Riedl. Convergence of anisotropic consensus-based optimization in mean-field law. In J. L. J. Laredo, J. I. Hidalgo, and K. O. Babaagba, editors, Applications of Evolutionary Computation - 25th European Conference, EvoApplications 2022, Held as P...
2022
-
[23]
Fornasier, T
M. Fornasier, T. Klock, and K. Riedl. Consensus-Based Optimization Methods Converge Globally. SIAM J. Optim. , 34(3):2973–3004, 2024
2024
-
[24]
Fraboni, R
Y. Fraboni, R. Vidal, and M. Lorenzi. Free-rider attacks on model aggregation in federated learning. In International Conference on Artificial Intelligence and Statistics , pages 1846–1854. PMLR, 2021
2021
-
[25]
L. Fu, H. Zhang, G. Gao, M. Zhang, and X. Liu. Client selection in federated learning: Principles, challenges, and opportunities. IEEE Internet of Things Journal , 2023
2023
-
[26]
C. Fung, C. J. Yoon, and I. Beschastnikh. The limitations of federated learning in sybil settings. In 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2020) , pages 301–316, 2020
2020
-
[28]
Geiping, H
J. Geiping, H. Bauermeister, H. Dr¨ oge, and M. Moeller. Inverting gradients-how easy is it to break privacy in federated learning? Advances in neural information processing systems , 33:16937–16947, 2020
2020
-
[29]
Ghosh, J
A. Ghosh, J. Chung, D. Yin, and K. Ramchandran. An efficient framework for clustered federated learning. In H. Larochelle, M. Ranzato, R. Hadsell, M. Balcan, and H. Lin, editors, Advances in Neural Information Processing Systems , volume 33, pages 19586–19597. Curran Associate...
2020
-
[30]
I. J. Goodfellow, J. Shlens, and C. Szegedy. Explaining and harnessing adversarial examples. In Y. Bengio and Y. LeCun, editors, 3rd International Conference on Learning Representations, ICLR 2015, San Diego, CA, USA, May 7-9, 2015, Conference Track Proceedings , 2015
2015
-
[31]
Grassi, H
S. Grassi, H. Huang, L. Pareschi, and J. Qiu. Mean-field particle swarm optimization. In Modeling and Simulation for Collective Dynamics , pages 127–193. World Scientific, 2023
2023
-
[32]
Hallaji, R
E. Hallaji, R. Razavi-Far, M. Saif, and E. Herrera-Viedma. Label noise analysis meets adversar- ial training: A defense against label poisoning in federated learning. Knowledge-Based Systems , 266:110384, 2023
2023
-
[33]
Hallaji, R
E. Hallaji, R. Razavi-Far, M. Saif, B. Wang, and Q. Yang. Decentralized federated learning: A survey on security and privacy. IEEE Transactions on Big Data , 2024
2024
-
[34]
L. He, A. Bian, and M. Jaggi. Cola: Decentralized linear learning. Advances in Neural Information Processing Systems, 31, 2018. 28
2018
-
[35]
Huang, J
H. Huang, J. Qiu, and K. Riedl. On the global convergence of particle swarm optimization methods. Appl. Math. Optim. , 88(2):Paper No. 30, 44, 2023
2023
-
[36]
N. M. Jebreel and J. Domingo-Ferrer. Fl-defender: Combating targeted attacks in federated learning. Knowledge-Based Systems, 260:110178, 2023
2023
-
[37]
N. M. Jebreel, J. Domingo-Ferrer, D. S´ anchez, and A. Blanco-Justicia. Lfighter: Defending against the label-flipping attack in federated learning. Neural Networks, 170:111–126, 2024
2024
-
[38]
M. S. Jere, T. Farnan, and F. Koushanfar. A taxonomy of attacks on federated learning. IEEE Security & Privacy , 19(2):20–28, 2021
2021
-
[39]
Jiang, W
Y. Jiang, W. Zhang, and Y. Chen. Data quality detection mechanism against label flipping attacks in federated learning. IEEE Transactions on Information Forensics and Security , 18:1625–1637, 2023
2023
-
[40]
S. Jin, L. Li, and J.-G. Liu. Random batch methods (rbm) for interacting particle systems. Journal of Computational Physics , 400:108877, 2020
2020
-
[41]
Kairouz, H
P. Kairouz, H. B. McMahan, B. Avent, A. Bellet, M. Bennis, A. N. Bhagoji, K. A. Bonawitz, Z. Charles, G. Cormode, R. Cummings, R. G. L. D’Oliveira, H. Eichner, S. E. Rouayheb, D. Evans, J. Gardner, Z. Garrett, A. Gasc´ on, B. Ghazi, P. B. Gibbons, M. Gruteser, Z. Harchaoui, C....
2021
-
[42]
Karagulyan, E
A. Karagulyan, E. Shulgin, A. Sadiev, and P. Richt´ arik. SPAM: Stochastic proximal point method with momentum variance reduction for non-convex cross-device federated learning. arXiv preprint arXiv:2405.20127, 2024
2024 arXiv
-
[43]
S. P. Karimireddy, M. Jaggi, S. Kale, M. Mohri, S. Reddi, S. U. Stich, and A. T. Suresh. Breaking the centralized barrier for cross-device federated learning. Advances in Neural Information Processing Systems, 34:28663–28676, 2021
2021
-
[44]
Kasneci, K
E. Kasneci, K. Seßler, S. K¨ uchemann, M. Bannert, D. Dementieva, F. Fischer, U. Gasser, G. Groh, S. G¨ unnemann, E. H¨ ullermeier, S. Krusche, G. Kutyniok, T. Michaeli, C. Nerdel, J. Pfeffer, O. Po- quet, M. Sailer, A. Schmidt, T. Seidel, S. Matthias, J. Weller, J. Kuhn, and ...
2023
-
[45]
J. Kennedy. The particle swarm: social adaptation of knowledge. In Proceedings of 1997 IEEE International Conference on Evolutionary Computation , pages 303–308. IEEE, 1997
1997
-
[46]
Kennedy and R
J. Kennedy and R. Eberhart. Particle swarm optimization. In Proceedings of International Confer- ence on Neural Networks (ICNN’95), Perth, WA, Australia, November 27 - December 1, 1995 , pages 1942–1948. IEEE, 1995
1995
-
[48]
Koneˇ cn` y, H
J. Koneˇ cn` y, H. B. McMahan, D. Ramage, and P. Richt´ arik. Federated optimization: Distributed machine learning for on-device intelligence. arXiv preprint arXiv:1610.02527 , 2016
2016 arXiv
-
[49]
Kovalev, A
D. Kovalev, A. Koloskova, M. Jaggi, P. Richtarik, and S. Stich. A linearly convergent algorithm for decentralized optimization: Sending less bits for free! In International Conference on Artificial Intelligence and Statistics , pages 4087–4095. PMLR, 2021
2021
-
[50]
D. Li, W. E. Wong, W. Wang, Y. Yao, and M. Chau. Detection and mitigation of label-flipping attacks in federated learning systems with KPCA and K-means. In2021 8th International Conference on Dependable Systems and Their Applications (DSA) , pages 551–559. IEEE, 2021. 29
2021
-
[51]
X. Li, Z. Qu, S. Zhao, B. Tang, Z. Lu, and Y. Liu. Lomar: A local defense against poisoning attack on federated learning. IEEE Transactions on Dependable and Secure Computing , 20(1):437–450, 2021
2021
-
[52]
Z. Lian, Q. Yang, W. Wang, Q. Zeng, M. Alazab, H. Zhao, and C. Su. DEEP-FEL: Decentralized, efficient and privacy-enhanced federated edge learning for healthcare cyber physical systems. IEEE Transactions on Network Science and Engineering , 9(5):3558–3569, 2022
2022
-
[53]
G. Long, M. Xie, T. Shen, T. Zhou, X. Wang, and J. Jiang. Multi-center federated learning: clients clustering for better personalization. World Wide Web , 26(1):481–500, 2023
2023
-
[54]
L. Lyu, H. Yu, J. Zhao, and Q. Yang. Threats to Federated Learning, pages 3–16. Springer Interna- tional Publishing, Cham, 2020
2020
-
[55]
J. Ma, G. Long, T. Zhou, J. Jiang, and C. Zhang. On the convergence of clustered federated learning. arXiv preprint arXiv:2202.06187 , 2022
2022 arXiv
-
[56]
McMahan, E
B. McMahan, E. Moore, D. Ramage, S. Hampson, and B. A. y. Arcas. Communication-Efficient Learning of Deep Networks from Decentralized Data. In A. Singh and J. Zhu, editors, Proceedings of the 20th International Conference on Artificial Intelligence and Statistics , volume 54 o...
2017
-
[57]
M. Nasr, R. Shokri, and A. Houmansadr. Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning. In 2019 IEEE symposium on security and privacy (SP) , pages 739–753. IEEE, 2019
2019
-
[58]
Nguyen, T
A. Nguyen, T. Do, M. Tran, B. X. Nguyen, C. Duong, T. Phan, E. Tjiputra, and Q. D. Tran. Deep federated learning for autonomous driving. In 2022 IEEE Intelligent Vehicles Symposium (IV), pages 1824–1830. IEEE, 2022
2022
-
[59]
Onoszko, G
N. Onoszko, G. Karlsson, O. Mogren, and E. L. Zec. Decentralized federated learning of deep neural networks on non-iid data. arXiv preprint arXiv:2107.08517 , 2021
2021 arXiv
-
[60]
Park, D.-J
J. Park, D.-J. Han, M. Choi, and J. Moon. Sageflow: Robust federated learning against both stragglers and adversaries. Advances in neural information processing systems , 34:840–851, 2021
2021
-
[61]
S. Park, Y. Suh, and J. Lee. FedPSO: Federated learning using particle swarm optimization to reduce communication costs. Sensors, 21(2), 2021
2021
-
[62]
Pillutla, S
K. Pillutla, S. M. Kakade, and Z. Harchaoui. Robust aggregation for federated learning. IEEE Transactions on Signal Processing, 70:1142–1154, 2022
2022
-
[63]
Pinnau, C
R. Pinnau, C. Totzeck, O. Tse, and S. Martin. A consensus-based model for global optimization and its mean-field limit. Math. Models Methods Appl. Sci. , 27(1):183–204, 2017
2017
-
[64]
K. Riedl. Leveraging memory effects and gradient information in consensus-based optimisation: On global convergence in mean-field law. European J. Appl. Math. , 35(4):483–514, 2024
2024
-
[65]
K. Riedl. Mathematical Foundations of Interacting Multi-Particle Systems for Optimization . PhD thesis, Technical University of Munich, 2024
2024
-
[66]
Riedl, T
K. Riedl, T. Klock, C. Geldhauser, and M. Fornasier. Gradient is All You Need? arXiv preprint arXiv:2306.09778, 2023
2023
-
[67]
Riedl, T
K. Riedl, T. Klock, C. Geldhauser, and M. Fornasier. How Consensus-Based Optimization can be Interpreted as a Stochastic Relaxation of Gradient Descent. ICML Workshop Differentiable Almost Everything: Differentiable Relaxations, Algorithms, Operators, and Simulators , 2024
2024
-
[68]
Rodr ´ ıguez-Barroso, D
N. Rodr ´ ıguez-Barroso, D. Jim´ enez-L´ opez, M. V. Luz´ on, F. Herrera, and E. Mart ´ ınez-C´ amara. Survey on federated learning threats: Concepts, taxonomy on attacks and defences, experimental study and challenges. Information Fusion, 90:148–173, 2023
2023
-
[69]
Ruan and C
Y. Ruan and C. Joe-Wong. Fedsoft: Soft clustered federated learning with proximal local updating. In Proceedings of the AAAI Conference on Artificial Intelligence, volume 36, pages 8124–8131, 2022. 30
2022
-
[70]
Sattler, K
F. Sattler, K. M¨ uller, and W. Samek. Clustered federated learning: Model-agnostic distributed multi- task optimization under privacy constraints. IEEE Trans. Neural Networks Learn. Syst., 32(8):3710– 3722, 2021
2021
-
[71]
Shammar, X
E. Shammar, X. Cui, and M. A. Al-qaness. Swarm learning: A survey of concepts, applications, and trends. arXiv preprint arXiv:2405.00556 , 2024
2024 arXiv
-
[72]
Shejwalkar and A
V. Shejwalkar and A. Houmansadr. Manipulating the byzantine: Optimizing model poisoning attacks and defenses for federated learning. In NDSS, 2021
2021
-
[73]
Shumailov, Z
I. Shumailov, Z. Shumaylov, D. Kazhdan, Y. Zhao, N. Papernot, M. A. Erdogdu, and R. J. Anderson. Manipulating SGD with data ordering attacks. In M. Ranzato, A. Beygelzimer, Y. N. Dauphin, P. Liang, and J. W. Vaughan, editors, Advances in Neural Information Processing Systems 3...
2021
-
[74]
Steinhardt, P
J. Steinhardt, P. W. W. Koh, and P. S. Liang. Certified defenses for data poisoning attacks.Advances in neural information processing systems , 30, 2017
2017
-
[75]
T. Sun, D. Li, and B. Wang. Decentralized federated averaging. IEEE Transactions on Pattern Analysis and Machine Intelligence , 45(4):4289–4301, 2022
2022
-
[76]
Z. Sun, P. Kairouz, A. T. Suresh, and H. B. McMahan. Can you really backdoor federated learning? arXiv preprint arXiv:1911.07963 , 2019
1911 arXiv
-
[77]
Szegedy, W
C. Szegedy, W. Zaremba, I. Sutskever, J. Bruna, D. Erhan, I. J. Goodfellow, and R. Fergus. Intriguing properties of neural networks. In Y. Bengio and Y. LeCun, editors, 2nd International Conference on Learning Representations, ICLR 2014, Banff, AB, Canada, April 14-16, 2014, C...
2014
-
[78]
A. J. Thirunavukarasu, D. S. J. Ting, K. Elangovan, L. Gutierrez, T. F. Tan, and D. S. W. Ting. Large language models in medicine. Nature medicine, 29(8):1930–1940, 2023
1930
-
[79]
Tolpegin, S
V. Tolpegin, S. Truex, M. E. Gursoy, and L. Liu. Data poisoning attacks against federated learning systems. In Computer Security–ESORICS 2020: 25th European Symposium on Research in Computer Security, ESORICS 2020, Guildford, UK, September 14–18, 2020, Proceedings, Part I 25, ...
2020
-
[80]
H. Wang, K. Sreenivasan, S. Rajput, H. Vishwakarma, S. Agarwal, J.-y. Sohn, K. Lee, and D. Papail- iopoulos. Attack of the tails: Yes, you really can backdoor federated learning. Advances in Neural Information Processing Systems, 33:16070–16084, 2020
2020
-
[81]
Y. Wang, Z. Tian, X. Fan, Z. Cai, C. Nowzari, and K. Zeng. Distributed swarm learning for edge internet of things. IEEE Communications Magazine , 2024
2024
-
[82]
Z. Wu, Q. Ling, T. Chen, and G. B. Giannakis. Federated variance-reduced stochastic gradient descent with robustness to byzantine attacks. IEEE Transactions on Signal Processing , 68:4583– 4596, 2020
2020
-
[83]
C. Xie, K. Huang, P.-Y. Chen, and B. Li. Dba: Distributed backdoor attacks against federated learning. In International conference on learning representations , 2019
2019
-
[84]
W. Yang, N. Wang, Z. Guan, L. Wu, X. Du, and M. Guizani. A practical cross-device federated learning framework over 5G networks. IEEE Wireless Communications , 29(6):128–134, 2022
2022
-
[85]
D. Yin, Y. Chen, R. Kannan, and P. Bartlett. Byzantine-robust distributed learning: Towards optimal statistical rates. In International conference on machine learning, pages 5650–5659. PMLR, 2018
2018
-
[86]
Zhang, B
J. Zhang, B. Chen, X. Cheng, H. T. T. Binh, and S. Yu. Poisongan: Generative poisoning attacks against federated learning in edge computing systems. IEEE Internet of Things Journal , 8(5):3310– 3322, 2020. 31
2020
-
[87]
Zhang, J
J. Zhang, J. Chen, D. Wu, B. Chen, and S. Yu. Poisoning attack in federated learning using generative adversarial nets. In 2019 18th IEEE international conference on trust, security and privacy in computing and communications/13th IEEE international conference on big data scie...
2019
Reviewed August 11, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.