High Dimensional Distributed Gradient Descent with Arbitrary Number of Byzantine Attackers
Wenyu Liu, Tianqiang Huang, Pengfei Zhang, Zong Ke, Minghui Min, Puning Zhao
Abstract
Adversarial attacks pose a major challenge to distributed learning systems, prompting the development of numerous robust learning methods. However, most existing approaches suffer from the curse of dimensionality, i.e. the error increases with the number of model parameters. In this paper, we make a progress towards high dimensional problems, under arbitrary number of Byzantine attackers. The cornerstone of our design is a direct high dimensional semi-verified mean estimation method. The idea is to identify a subspace with large variance. The components of the mean value perpendicular to this subspace are estimated using corrupted gradient vectors uploaded from worker machines, while the components within this subspace are estimated using auxiliary dataset. As a result, a combination of large corrupted dataset and small clean dataset yields significantly better performance than using them separately. We then apply this method as the aggregator for distributed learning problems. The theoretical analysis shows that compared with existing solutions, our method gets rid of sqrtd dependence on the dimensionality, and achieves minimax optimal statistical rates. Numerical results validate our theory as well as the effectiveness of the proposed method.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 372cc252-22cb-44d8-8f7b-4b7ee942a6ddCited by top-tier papers3
- BlackMirror: Black-Box Backdoor Detection for Text-to-Image Models via Instruction-Response DeviationFeiran Li, Qianqian Xu, Shilong Bao, Zhiyong Yang et al.CVPR 2026 · 2 citations
- Path Matters: Unveiling Geometric Implicit Bias via Curvature-Aware Sparse View OptimizationCanran Xiao, Liaoyuan Fan, Yanbin Li, Jing Tang et al.ICLR 2026
- LiD-FL: Towards List-Decodable Federated LearningHong Liu, Liren Shan, Han Bao, Ronghui You et al.AAAI 2025
Builds on8
- Feature Inference Attack on Model Predictions in Vertical Federated LearningXinjian Luo, Yuncheng Wu, Xiaokui Xiao, Beng Chin OoiICDE 2021 · 212 citations
- Zeno++: Robust Fully Asynchronous SGDCong Xie, Sanmi Koyejo, Indranil GuptaICML 2020 · 137 citations
- Outlier Robust Mean Estimation with Subgaussian Rates via StabilityIlias Diakonikolas, Daniel M. Kane, Ankit PensiaNeurIPS 2020 · 76 citations
- List-Decodable Mean Estimation in Nearly-PCA TimeIlias Diakonikolas, Daniel Kane, Daniel Kongsgaard, Jerry Li et al.NeurIPS 2021 · 18 citations
- List Decodable Mean Estimation in Nearly Linear TimeYeshwanth Cherapanamjeri, Sidhanth Mohanty, Morris YauFOCS 2020 · 13 citations
Related papers
- Flag Aggregator: Scalable Distributed Training under Failures and Augmented Losses using Convex OptimizationHamidreza Almasi, Harsh Mishra, Balajee Vamanan, Sathya N. RaviICLR 2024
- Attacking Byzantine Robust Aggregation in High DimensionsSarthak Choudhary, Aashish Kolluri, Prateek SaxenaS&P 2024 · 4 citations
- On the Tension between Byzantine Robustness and No-Attack Accuracy in Distributed LearningYi-Rui Yang, Chang-Wei Shi, Wu-Jun LiICML 2025
- Byzantine-Resilient High-Dimensional SGD with Local Iterations on Heterogeneous DataDeepesh Data, Suhas N. DiggaviICML 2021 · 49 citations
- A Practical and Secure Byzantine Robust AggregatorDe Zhang Lee, Aashish Kolluri, Prateek Saxena, Ee-Chien ChangCCS 2025
