byzantine-robust aggregation

Designs, implements, and analyzes aggregation algorithms that remain correct and performant when some contributors act arbitrarily or maliciously, using techniques such as coordinate-wise or approximate median aggregation. Develops and evaluates rules and proofs that tolerate malicious participant updates and mitigate model-poisoning or other Byzantine attacks while preserving overall aggregate accuracy.

byzantine-robustaggregation

Recent Skill Trend

Momentum and market value over time
Trending
Score
No comparison yet
0.56
Oct 01, 2026Oct 01, 2026
Career
Value
No comparison yet
$200K/year
Oct 01, 2026Oct 01, 2026

Must-Read Papers

Most classic and influential ideas
View more

A Practical and Secure Byzantine Robust Aggregator

Jun 29, 2025
DZ
De Zhang Lee
🏛️ National University of Singapore

In machine learning, data poisoning induces high-dimensional gradient anomalies—specifically, an ε-fraction of arbitrary, adaptive Byzantine-corrupted gradients. Method: We propose a quasi-linear-time robust mean estimation algorithm that requires no prior distributional assumptions or hand-tuned thresholds. It integrates adaptive outlier detection with Byzantine-resilient aggregation to achieve near-optimal bias bound O(ε√d) under ε-corruption. Contribution/Results: This is the first Byzantine-robust aggregator achieving both quasi-linear time complexity and statistically optimal accuracy. It is plug-and-play within standard distributed training pipelines. Experiments across ten canonical poisoning attacks demonstrate significant improvements in model robustness while maintaining high computational efficiency.

Computing robust average of high-dimensional vectors with outliersEnabling practical use in standard neural network trainingProvably bounding bias in final average despite corrupted vectors

Unified Breakdown Analysis for Byzantine Robust Gossip

Oct 14, 2024
RG
Renaud Gaucher
🏛️ Ecole polytechnique | Institut Polytechnique de Paris | Inria | Univ. Grenoble Alpes | CNRS

Byzantine node attacks severely compromise robustness in decentralized machine learning. Method: This paper proposes F-RG, a general robust framework that—first in the literature—systematically defines and analyzes the theoretical upper bound of the breakdown point in decentralized settings. Leveraging robust aggregation theory and Byzantine fault-tolerant consensus, we design CS_ours, a novel aggregation rule ensuring convergence while achieving near-optimal breakdown point, significantly outperforming existing methods such as NNA. Contribution/Results: We theoretically prove that CS_ours attains the information-theoretic limit of Byzantine resilience. Empirically, under both standard and customized decentralized attacks, CS_ours-RG achieves up to a 32% accuracy improvement across multiple benchmark datasets. The strong alignment between theoretical guarantees and empirical performance validates the framework’s efficacy and practical relevance.

Analyzing Byzantine robustness in decentralized machine learningEstablishing upper bounds for adversary tolerance in algorithmsIntroducing CS+ aggregation rule for near-optimal breakdown resistance

This work addresses the lack of systematic and reproducible benchmarks for evaluating robustness in federated learning across diverse datasets and model architectures. It introduces the first comprehensive evaluation matrix comprising 500 experimental configurations, spanning five aggregation methods, five datasets, five model architectures, and four attack types—including sign-flipping, Gaussian noise, and BadNets backdoor attacks. Through rigorous reproduction and log-based auditing, the study systematically compares method performance under both clean and adversarial conditions. Results show that Trimmed Mean achieves the highest average accuracy (76.02%) in clean settings, while Krum demonstrates superior robustness against specific attacks. The analysis also uncovers critical implementation flaws—such as the misuse of the TTLR metric and inconsistencies between prediction and aggregation updates in FedPARETO—thereby significantly enhancing the transparency and auditability of robustness evaluations in federated learning.

aggregation robustnessbackdoor attacksevaluation benchmark

Do We Really Need to Design New Byzantine-robust Aggregation Rules?

Jan 29, 2025
MF
Minghong Fang
🏛️ University of Louisville | Florida International University | University of North Texas | Wichita State University | Rochester Institute of Technology

In federated learning, Byzantine clients launching poisoning attacks can severely degrade the robustness of existing aggregation rules. To address this, we propose FoundationFL—a framework that preserves standard robust aggregators (e.g., Trimmed-mean, Median) without modifying their logic; instead, the server generates synthetic model updates, which are jointly aggregated with clients’ local updates. We provide the first theoretical proof that enhancing input quality alone—without designing new aggregation rules—significantly improves Byzantine resilience of classical robust aggregators. FoundationFL guarantees convergence under Byzantine threats and empirically demonstrates substantial improvements in poisoning resistance across multiple real-world datasets, while maintaining high model accuracy and low communication overhead. The framework thus achieves strong effectiveness, generalizability, and practicality.

Federated LearningMalicious ParticipantsModel Integrity

Mean Aggregator is More Robust than Robust Aggregators under Label Poisoning Attacks on Distributed Heterogeneous Data

Apr 21, 2024
JP
Jie Peng
🏛️ Sun Yat-Sen University | Harvard University | Imperial College London

This work investigates aggregator robustness against label-flipping poisoning attacks in distributed heterogeneous learning. Addressing multi-source heterogeneous data, we theoretically establish—for the first time—that under sufficient heterogeneity, the standard mean aggregator achieves order-optimal learning error and outperforms mainstream robust aggregators (e.g., Krum, Median) in poisoning resilience—a finding that challenges the conventional wisdom that robust aggregators are inherently superior. Methodologically, we integrate distributed optimization modeling, formal characterization of label-flipping attacks, and theoretical analysis of statistical heterogeneity. Through rigorous error-bound derivation and extensive experiments across diverse heterogeneity settings, we demonstrate that the mean aggregator consistently surpasses existing robust alternatives, achieving both theoretical optimality and empirical effectiveness.

Accuracy MaintenanceDistributed LearningLabel Poisoning Attack

Latest Papers

What's happening recently
View more

This work addresses the reliance of Byzantine fault-tolerant aggregation on global ordering, associativity, and continuity in coordinator-free settings by proposing a consensus-free, verifiable robust aggregation mechanism. It introduces a content-addressed OR-Set and a monotonic, self-certifying set of misbehavior evidence, thereby extending strong eventual consistency for the first time to non-associative and stochastic aggregation functions. Accountability is achieved through a novel selection mechanism combining data lattices and evidence lattices. The system leverages CRDT replication, fixed-point integer arithmetic, hash-based canonical ordering, content-hash decoupling, and offline-verifiable signatures. Evaluated in a 10-node environment with three Byzantine nodes, it passes all 16 adversarial tests, achieving byte-level consistent aggregation results and partition recovery capability.

Byzantine accountabilityconsensus-free aggregationnon-associative aggregation

This work addresses the challenge of simultaneously ensuring parameter confidentiality and Byzantine robustness in large-scale decentralized learning. The authors propose Giskard, a novel protocol that, for the first time, achieves Byzantine-robust aggregation with sublinear communication complexity while preserving the privacy of model parameters. Giskard organizes participants into a logarithmic-depth committee tree and, within each committee, combines BGW-style secure multiparty computation with distributed binary search to perform coordinate-wise approximate median aggregation. Theoretical analysis establishes the protocol’s security and correctness, and empirical evaluation demonstrates that, at scales involving millions of participants, Giskard tolerates up to $n/4$ Byzantine nodes, substantially reduces communication overhead, and maintains high model utility.

Byzantine robustnessconfidential aggregationdecentralized learning

This work addresses the vulnerability of distance-based robust aggregation methods in federated learning—such as Krum—to adaptive backdoor attacks. To exploit this weakness, the authors propose Krum-Proxy, a novel attack strategy that employs a two-stage optimization process to craft malicious model updates that closely mimic the distribution of benign updates while simultaneously residing in regions favored by the aggregation mechanism, thereby evading detection. The key innovation lies in decoupling the attack objective from geometric structure optimization and incorporating mechanisms such as neighbor proxy modeling, anchor-guided alignment, and norm-variance projection constraints. Experimental results demonstrate that Krum-Proxy significantly increases attack success rates on standard federated learning benchmarks while preserving high model accuracy on clean data, thereby exposing critical security limitations in current robust aggregators.

Adversarial ClientsBackdoor AttacksByzantine-Robust Aggregation

This work addresses the challenge of securely excluding historical updates from compromised nodes in traditional Byzantine fault-tolerant CRDTs without violating causal consistency. The authors propose a fine-grained trust model that, for the first time in Byzantine CRDTs, decouples identity trust from content trust. By integrating deterministic reconstruction, public-key-based identity verification, and a semantics-aware update filtering mechanism, the approach enables selective inclusion or exclusion of updates. This design supports application-level policies and effectively mitigates Byzantine behavior and faulty nodes while strictly preserving causal consistency, thereby significantly enhancing the robustness and flexibility of decentralized systems in post-compromise scenarios.

Byzantine CRDTscausal consistencyfine-grained trust

Hot Scholars

JA

John Augustine

Professor, Indian Institute of Technology Madras
theoretical computer sciencedistributed computingdistributed trustByzantine fault tolerance
BL

Benny Lo

Imperial College London
Body Sensor NetworksPervasive ComputingWireless Sensor NetworksComputer Vision
FD

Fabrizio Durante

Dipartimento di Matematica e Fisica "Ennio De Giorgi", Università del Salento
CopulasDependence ModelingMachine LearningCompound Events