Pith. sign in

REVIEW 2 cited by

Adversarial training in communication constrained federated learning

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2103.01319 v1 pith:SNZHXU3J submitted 2021-03-01 cs.LG cs.AI

classification cs.LGcs.AI
keywords adversarialfederatedmodeltrainingcommunicationlearningsettingagents
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Federated learning enables model training over a distributed corpus of agent data. However, the trained model is vulnerable to adversarial examples, designed to elicit misclassification. We study the feasibility of using adversarial training (AT) in the federated learning setting. Furthermore, we do so assuming a fixed communication budget and non-iid data distribution between participating agents. We observe a significant drop in both natural and adversarial accuracies when AT is used in the federated setting as opposed to centralized training. We attribute this to the number of epochs of AT performed locally at the agents, which in turn effects (i) drift between local models; and (ii) convergence time (measured in number of communication rounds). Towards this end, we propose FedDynAT, a novel algorithm for performing AT in federated setting. Through extensive experimentation we show that FedDynAT significantly improves both natural and adversarial accuracy, as well as model convergence time by reducing the model drift.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Enhancing Privacy in Decentralized Min-Max Optimization: A Differentially Private Approach

    cs.LG 2025-08 reject novelty 6.0 of 10

    DPMixSGD injects calibrated Gaussian noise into local gradient estimates to make decentralized nonconvex-strongly-concave min-max optimization differentially private, while claiming to preserve the STORM convergence rate.

  2. FedAPT: Federated Adversarial Prompt Tuning for Vision-Language Models

    cs.CV 2025-09 conditional novelty 5.0 of 10

    FedAPT improves adversarial robustness of federated prompt tuning for CLIP by generating visual prompts from text prompts under a global-label beacon, with reported gains of up to 11.49% under PGD-100.

Pith tools