Federated Robustness Propagation: Sharing Adversarial Robustness in Heterogeneous Federated Learning
Junyuan Hong, Haotao Wang, Zhangyang Wang, Jiayu Zhou
Abstract
Federated learning (FL) emerges as a popular distributed learning schema that learns a model from a set of participating users without sharing raw data. One major challenge of FL comes with heterogeneous users, who may have distributionally different (or non-iid) data and varying computation resources. As federated users would use the model for prediction, they often demand the trained model to be robust against malicious attackers at test time. Whereas adversarial training (AT) provides a sound solution for centralized learning, extending its usage for federated users has imposed significant challenges, as many users may have very limited training data and tight computational budgets, to afford the data-hungry and costly AT. In this paper, we study a novel FL strategy: propagating adversarial robustness from rich-resource users that can afford AT, to those with poor resources that cannot afford it, during federated learning. We show that existing FL techniques cannot be effectively integrated with the strategy to propagate robustness among non-iid users and propose an efficient propagation approach by the proper use of batch-normalization. We demonstrate the rationality and effectiveness of our method through extensive experiments. Especially, the proposed method is shown to grant federated models remarkable robustness even when only a small portion of users afford AT during learning. Source code will be released.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 19060737-c3d4-4d22-b382-4c606826edf2Cited by top-tier papers8
- Federated Recommendation with Explicitly Encoding Item BiasZhihao Wang, He Bai, Wenke Huang, Duantengchuan Li et al.AAAI 2025 · 10 citations
- How Does the Smoothness Approximation Method Facilitate Generalization for Federated Adversarial Learning?Wenjun Ding, Ying An, Lixing Chen, Shichao Kan et al.AAAI 2025 · 1 citation
- FedKDMR: Robust Federated Learning via Joint Knowledge Distillation & Model RecombinationWenhao Li, Christos Anagnostopoulos, Shameem A. Puthiya Parambath, Kevin BrysonKDD 2026
- Less is More: Federated Graph Learning with Alleviating Topology Heterogeneity from A Causal PerspectiveLele Fu, Bowen Deng, Sheng Huang, Tianchi Liao et al.ICML 2025
- Towards Understanding Generalization of Federated Adversarial Learning: Perspective of Algorithmic StabilityYongkang Yang, Chang Cao, Ke Zhang, Han Li et al.ICML 2026
Builds on17
- On the Convergence of FedAvg on Non-IID DataXiang Li, Kaixuan Huang, Wenhao Yang, Shusen Wang et al.ICLR 2020 · 2,930 citations
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 2,337 citations
- Moment Matching for Multi-Source Domain AdaptationXingchao Peng, Qinxun Bai, Xide Xia, Zijun Huang et al.ICCV 2019 · 2,239 citations
- Inverting Gradients - How easy is it to break privacy in federated learning?Jonas Geiping, Hartmut Bauermeister, Hannah Dröge, Michael MoellerNeurIPS 2020 · 1,822 citations
- Personalized Federated Learning with Moreau EnvelopesCanh T. Dinh, Nguyen Hoang Tran, Tuan Dung NguyenNeurIPS 2020 · 1,542 citations
Related papers
- Robust Federated Learning: The Case of Affine Distribution ShiftsAmirhossein Reisizadeh, Farzan Farnia, Ramtin Pedarsani, Ali JadbabaieNeurIPS 2020 · 196 citations
- Federated Adversarial Learning: A Framework with Convergence AnalysisXiaoxiao Li, Zhao Song, Jiaming YangICML 2023 · 36 citations
- Delving into the Adversarial Robustness of Federated LearningJie Zhang, Bo Li, Chen Chen, Lingjuan Lyu et al.AAAI 2023 · 62 citations
- Byzantine-Robust Learning on Heterogeneous Datasets via BucketingSai Praneeth Karimireddy, Lie He, Martin JaggiICLR 2022 · 192 citations
- ShapleyFL: Robust Federated Learning Based on Shapley ValueQiheng Sun, Xiang Li, Jiayao Zhang, Li Xiong et al.KDD 2023 · 57 citations
