Byzantine-Robust Federated RAG via Aligned Calibration and Fixed-Membership Conformal Prediction

πŸ“… 2026-09-27
πŸ“ˆ Citations: 0
✨ Influential: 0
πŸ“„ PDF
πŸ€– AI Summary
This study addresses the vulnerability of federated retrieval-augmented generation (RAG) systems to Byzantine adversaries that maliciously manipulate scoring mechanisms, thereby compromising system integrity. To mitigate this threat, we propose a robust federated RAG framework grounded in fixed-member conformal prediction. Unlike conventional approaches, our method eliminates the assumption of universally honest nodes by aligning benign node behaviors during a calibration phase, providing rigorous theoretical guarantees even under finite-sample conditions. This work integrates federated learning, conformal prediction, and Byzantine fault tolerance into a unified paradigm. Empirical evaluations on tasks such as medical question answering demonstrate that the proposed framework achieves target coverage rates while generating candidate sets significantly more compact than those produced by existing methods, effectively enhancing the system’s resilience against adversarial attacks.
πŸ“ Abstract
Retrieval-augmented generation (RAG) lets language models answer questions more accurately by consulting relevant documents. Many valuable collections, such as medical records, cannot be pooled because of privacy rules. Federated RAG leaves each collection with its owner, or node, which scores candidate answers from its own documents; a central hub combines the scores. Some nodes, called Byzantine, may be compromised, faulty, or misled by instructions hidden in documents, and report arbitrary scores. Conformal prediction returns a set containing the correct answer with a chosen probability, using a cutoff set in a calibration step on questions with known answers. An unknown group of nodes, no larger than a declared bound, may misreport both in this step and at query time. Existing methods assume every node is honest or protect only the calibration step. We observe that the honest nodes are the same in both steps. The hub therefore has all nodes score the same calibration questions, and keeps a candidate only if some plausible group of honest nodes, using its own scores in both steps, would keep it. We prove that the resulting sets contain the correct answer with the chosen probability in finite samples, whatever the Byzantine nodes report. No method using the same information can return smaller sets without risking the loss of an answer the honest nodes support. If nodes fail at random, the guarantee weakens only by the probability that more nodes fail than declared. In simulations, on real question-answering tasks including medical exams, and with language models as nodes, some hijacked, our sets reached the target whenever no more nodes misbehaved than declared, while plain averaging could miss it. They were also clearly smaller than those of simpler methods with the same protection, most of all when the declared bound was generous, so a cautious bound costs little.
Problem

Research questions and friction points this paper is trying to address.

Federated RAG
Byzantine robustness
Conformal prediction
Retrieval-augmented generation
Privacy-preserving
Innovation

Methods, ideas, or system contributions that make the work stand out.

Byzantine-Robust Federated RAG
Conformal Prediction
Aligned Calibration
Fixed-Membership
Retrieval-Augmented Generation
πŸ’Ό Related Jobs
No related jobs found.