Federated Adversarial Learning: A Framework with Convergence Analysis
Xiaoxiao Li, Zhao Song, Jiaming Yang
Abstract
Federated learning (FL) is a trending training paradigm to utilize decentralized training data. FL allows clients to update model parameters locally for several epochs, then share them to a global model for aggregation. This training paradigm with multi-local step updating before aggregation exposes unique vulnerabilities to adversarial attacks. Adversarial training is a popular and effective method to improve the robustness of networks against adversaries. In this work, we formulate a general form of federated adversarial learning (FAL) that is adapted from adversarial learning in the centralized setting. On the client side of FL training, FAL has an inner loop to generate adversarial samples for adversarial training and an outer loop to update local model parameters. On the server side, FAL aggregates local model updates and broadcast the aggregated model. We design a global robust training loss and formulate FAL training as a min-max optimization problem. Unlike the convergence analysis in classical centralized training that relies on the gradient direction, it is significantly harder to analyze the convergence in FAL for three reasons: 1) the complexity of min-max optimization, 2) model not updating in the gradient direction due to the multi-local updates on the client-side before aggregation and 3) inter-client heterogeneity. We address these challenges by using appropriate gradient approximation and coupling techniques and present the convergence analysis in the over-parameterized regime. Our main result theoretically shows that the minimum loss under our algorithm can converge to small with chosen learning rate and communication rounds. It is noteworthy that our analysis is feasible for non-IID clients.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 18f01bb9-6a86-414b-8926-3cf332c05e83Cited by top-tier papers3
- Sketching for First Order Method: Efficient Algorithm for Low-Bandwidth Channel and VulnerabilityZhao Song, Yitan Wang, Zheng Yu, Lichen ZhangICML 2023 · 35 citations
- How Does the Smoothness Approximation Method Facilitate Generalization for Federated Adversarial Learning?Wenjun Ding, Ying An, Lixing Chen, Shichao Kan et al.AAAI 2025 · 1 citation
- Accelerated Vertical Federated Adversarial Learning through Decoupling Layer-Wise DependenciesTianxing Man, Yu Bai, Ganyu Wang, Jinjie Fang et al.NeurIPS 2025
Builds on12
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 9,786 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Tackling the Objective Inconsistency Problem in Heterogeneous Federated OptimizationJianyu Wang, Qinghua Liu, Hao Liang, Gauri Joshi et al.NeurIPS 2020 · 2,231 citations
- Adaptive Federated OptimizationSashank J. Reddi, Zachary Charles, Manzil Zaheer, Zachary Garrett et al.ICLR 2021 · 1,917 citations
- FedBN: Federated Learning on Non-IID Features via Local Batch NormalizationXiaoxiao Li, Meirui Jiang, Xiaofei Zhang, Michael Kamp et al.ICLR 2021 · 1,166 citations
Related papers
- Combating Exacerbated Heterogeneity for Robust Models in Federated LearningJianing Zhu, Jiangchao Yao, Tongliang Liu, Quanming Yao et al.ICLR 2023 · 2 citations
- FedAS: Bridging Inconsistency in Personalized Federated LearningXiyuan Yang, Wenke Huang, Mang YeCVPR 2024 · 69 citations
- CalFAT: Calibrated Federated Adversarial Training with Label SkewnessChen Chen, Yuchen Liu, Xingjun Ma, Lingjuan LyuNeurIPS 2022 · 53 citations
- Towards Understanding Generalization of Federated Adversarial Learning: Perspective of Algorithmic StabilityYongkang Yang, Chang Cao, Ke Zhang, Han Li et al.ICML 2026
- CDMA: A Practical Cross-Device Federated Learning Algorithm for General Minimax ProblemsJiahao Xie, Chao Zhang, Zebang Shen, Weijie Liu et al.AAAI 2023 · 2 citations
