Towards Trustworthy Federated Learning with Untrusted Participants
Youssef Allouah, Rachid Guerraoui, John Stephan
Abstract
Resilience against malicious participants and data privacy are essential for trustworthy federated learning, yet achieving both with good utility typically requires the strong assumption of a trusted central server. This paper shows that a significantly weaker assumption suffices: each pair of participants shares a randomness seed unknown to others. In a setting where malicious participants may collude with an untrusted server, we propose CAFCOR, an algorithm that integrates robust gradient aggregation with correlated noise injection, using shared randomness between participants. We prove that CAFCOR achieves strong privacyutility trade-offs, significantly outperforming local differential privacy (DP) methods, which do not make any trust assumption, while approaching central DP utility, where the server is fully trusted. Empirical results on standard benchmarks validate CAFCOR's practicality, showing that privacy and robustness can coexist in distributed systems without sacrificing utility or trusting the server. Assumption 2.2 (Bounded variance). There exists σ > 0 such that for each honest worker w i , i ∈ H, and all θ Assumption 2.3 (Bounded gradients). There exists C > 0 such that ∀θ ∈ R d , i ∈ H, and x ∈ D i , ∥∇ℓ(θ; x)∥ ≤ C.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2d04a1f1-553e-445c-b484-bccea81ee048Cited by top-tier papers2
- Tight Stability Bounds for Robust Distributed Learning: Byzantine Failures Hurt Generalization More than Data PoisoningThomas Boudou, Batiste Le Bars, Nirupam Gupta, Aurélien BelletICML 2026 · 3 citations
- SecureGate: Learning When to Reveal PII Safely via Token-Gated Dual-Adapters for Federated LLMsMohamed Shaaban, Mohamed ElmahallawyACL 2026
Builds on19
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Practical Secure Aggregation for Privacy-Preserving Machine LearningKallista A. Bonawitz, Vladimir Ivanov, Ben Kreuter, Antonio Marcedone et al.CCS 2017 · 3,936 citations
- SCAFFOLD: Stochastic Controlled Averaging for Federated LearningSai Praneeth Karimireddy, Satyen Kale, Mehryar Mohri, Sashank J. Reddi et al.ICML 2020 · 3,875 citations
- Exploiting Unintended Feature Leakage in Collaborative LearningLuca Melis, Congzheng Song, Emiliano De Cristofaro, Vitaly ShmatikovS&P 2019 · 1,736 citations
- Deep Models Under the GAN: Information Leakage from Collaborative Deep LearningBriland Hitaj, Giuseppe Ateniese, Fernando Pérez-CruzCCS 2017 · 1,581 citations
Related papers
- Towards the Robustness of Differentially Private Federated LearningTao Qi, Huili Wang, Yongfeng HuangAAAI 2024 · 30 citations
- Noise-Aware Algorithm for Heterogeneous Differentially Private Federated LearningSaber Malekmohammadi, Yaoliang Yu, Yang CaoICML 2024 · 10 citations
- On the Privacy-Robustness-Utility Trilemma in Distributed LearningYoussef Allouah, Rachid Guerraoui, Nirupam Gupta, Rafael Pinot et al.ICML 2023 · 33 citations
- Private Federated Learning Without a Trusted Server: Optimal Algorithms for Convex LossesAndrew Lowy, Meisam RazaviyaynICLR 2023 · 2 citations
- DP-BREM: Differentially-Private and Byzantine-Robust Federated Learning with Client MomentumXiaolan Gu, Ming Li, Li XiongUSENIX Security 2025
