Practical Differentially Private and Byzantine-resilient Federated Learning
Zihang Xiang, Tianhao Wang, Wanyu Lin, Di Wang
Abstract
Privacy and Byzantine resilience are two indispensable requirements for a federated learning (FL) system. Although there have been extensive studies on privacy and Byzantine security in their own track, solutions that consider both remain sparse. This is due to difficulties in reconciling privacy-preserving and Byzantine-resilient algorithms. In this work, we propose a solution to such a two-fold issue. We use our version of differentially private stochastic gradient descent (DP-SGD) algorithm to preserve privacy and then apply our Byzantine-resilient algorithms. We note that while existing works follow this general approach, an in-depth analysis on the interplay between DP and Byzantine resilience has been ignored, leading to unsatisfactory performance. Specifically, for the random noise introduced by DP, previous works strive to reduce its seemingly detrimental impact on the Byzantine aggregation. In contrast, we leverage the random noise to construct a first-stage aggregation that effectively rejects many existing Byzantine attacks. Moreover, based on another property of our DP variant, we form a second-stage aggregation which provides a final sound filtering. Our protocol follows the principle of co-designing both DP and Byzantine resilience. We provide both theoretical proof and empirical experiments to show our protocol is effective: retaining high accuracy while preserving the DP guarantee and Byzantine resilience. Compared with the previous work, our protocol 1) achieves significantly higher accuracy even in a high privacy regime; 2) works well even when up to 90% distributive workers are Byzantine.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3ebe0e32-2c3f-46ec-a563-034fbff5e39eCited by top-tier papers8
- Cross-silo Federated Learning with Record-level Personalized Differential PrivacyJunxu Liu, Jian Lou, Li Xiong, Jinfei Liu et al.CCS 2024 · 15 citations
- Secure and Verifiable Data Collaboration with Low-Cost Zero-Knowledge ProofsYizheng Zhu, Yuncheng Wu, Zhaojing Luo, Beng Chin Ooi et al.VLDB 2024 · 14 citations
- Revisiting Differentially Private Hyper-parameter TuningZihang Xiang, Tianhao Wang, Cheng-Long Wang, Di WangNDSS 2026 · 7 citations
- Benchmarking Secure Sampling Protocols for Differential PrivacyYucheng Fu, Tianhao WangCCS 2024 · 5 citations
- Hounding Data Diversity: Towards Participant Selection in Vertical Federated LearningXiaokai Zhou, Xiao Yan, Fangcheng Fu, Xinyan Li et al.ICDE 2025 · 1 citation
Builds on23
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Membership Inference Attacks Against Machine Learning ModelsReza Shokri, Marco Stronati, Congzheng Song, Vitaly ShmatikovS&P 2017 · 5,137 citations
- Trojaning Attack on Neural NetworksYingqi Liu, Shiqing Ma, Yousra Aafer, Wen-Chuan Lee et al.NDSS 2018 · 1,377 citations
- Manipulating Machine Learning: Poisoning Attacks and Countermeasures for Regression LearningMatthew Jagielski, Alina Oprea, Battista Biggio, Chang Liu et al.S&P 2018 · 867 citations
- Numerical Composition of Differential PrivacySivakanth Gopi, Yin Tat Lee, Lukas WutschitzNeurIPS 2021 · 259 citations
Related papers
- Towards the Robustness of Differentially Private Federated LearningTao Qi, Huili Wang, Yongfeng HuangAAAI 2024 · 30 citations
- DP-BREM: Differentially-Private and Byzantine-Robust Federated Learning with Client MomentumXiaolan Gu, Ming Li, Li XiongUSENIX Security 2025
- On the Byzantine-Resilience of Distillation-Based Federated LearningChristophe Roux, Max Zimmer, Sebastian PokuttaICLR 2025
- BASGD: Buffered Asynchronous SGD for Byzantine LearningYi-Rui Yang, Wu-Jun LiICML 2021 · 33 citations
- Noise-Aware Algorithm for Heterogeneous Differentially Private Federated LearningSaber Malekmohammadi, Yaoliang Yu, Yang CaoICML 2024 · 10 citations
