Towards Trustworthy Federated Learning

📅 2025-03-05
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This paper addresses the triple trust challenge in federated learning—Byzantine robustness, fairness, and privacy protection—and proposes the first unified framework that theoretically guarantees their joint optimization. Methodologically, it introduces (1) a two-sided norm-based screening (TNBS) mechanism to enhance robustness against malicious clients; (2) an integration of the q-FFL fairness objective with calibrated differential privacy noise injection, simultaneously preserving data privacy and mitigating inter-client performance disparity; and (3) a rigorous convergence analysis under realistic adversarial and heterogeneous settings. Extensive experiments on multiple real-world datasets demonstrate that the framework significantly outperforms state-of-the-art baselines: it maintains model accuracy while improving robustness (+12.7% clean-label attack resistance), fairness (Fairness Gap reduced by 38.5%), and privacy (ε ∈ [2, 8]). To our knowledge, this is the first approach to achieve provably convergent, empirically validated co-optimization of all three objectives.

Technology Category

Machine Learning: Distributed Machine Learning & Federated LearningNatural Language Processing: Safety and RobustnessComputer Vision: Adversarial Attacks & Robustness

Application Category

User Modeling, Personalization and Recommendation: Federated recommendation systems and personalizationSecurity and Privacy: Security and privacy of machine learning and AI applicationsResponsible Web: Data and user privacy-enhancing technologies for the Web
📝 Abstract
This paper develops a comprehensive framework to address three critical trustworthy challenges in federated learning (FL): robustness against Byzantine attacks, fairness, and privacy preservation. To improve the system's defense against Byzantine attacks that send malicious information to bias the system's performance, we develop a Two-sided Norm Based Screening (TNBS) mechanism, which allows the central server to crop the gradients that have the l lowest norms and h highest norms. TNBS functions as a screening tool to filter out potential malicious participants whose gradients are far from the honest ones. To promote egalitarian fairness, we adopt the q-fair federated learning (q-FFL). Furthermore, we adopt a differential privacy-based scheme to prevent raw data at local clients from being inferred by curious parties. Convergence guarantees are provided for the proposed framework under different scenarios. Experimental results on real datasets demonstrate that the proposed framework effectively improves robustness and fairness while managing the trade-off between privacy and accuracy. This work appears to be the first study that experimentally and theoretically addresses fairness, privacy, and robustness in trustworthy FL.
Problem

Research questions and friction points this paper is trying to address.

Enhances robustness against Byzantine attacks in federated learning.
Promotes fairness using q-fair federated learning (q-FFL).
Ensures privacy preservation with differential privacy-based schemes.
Innovation

Methods, ideas, or system contributions that make the work stand out.

Two-sided Norm Based Screening for Byzantine attacks
q-fair Federated Learning for egalitarian fairness
Differential privacy scheme for data protection
🔎 Similar Papers
No similar papers found.
A
Alina Basharat
University of Texas Rio Grande Valley
Yijun Bian
Yijun Bian
University of Copenhagen
Ensemble LearningMachine LearningFairness in ML
P
Ping Xu
University of Texas Rio Grande Valley
Z
Zhi Tian
George Mason University