Towards Understanding Generalization of Federated Adversarial Learning: Perspective of Algorithmic Stability
Yongkang Yang, Chang Cao, Ke Zhang, Han Li, Hong Chen, Rushi Lan
Abstract
Federated Adversarial Learning (FAL) enhances model robustness by integrating adversarial training into the federated learning framework. Despite recent advances proposing efficient FAL algorithms, existing work has mainly focused on convergence properties, with limited understanding of their generalization capabilities. To address this, we present the unified theoretical framework for analyzing FAL generalization through the lens of algorithmic stability. We first analyze general FAL algorithms based on stochastic gradient descent (SGD) and derive perturbationdependent generalization bounds, which reveal that stronger adversarial attacks can lead to degraded generalization. To mitigate the impact of adversarial perturbations, we leverage Moreau envelope optimization and establish a perturbationindependent bound, demonstrating its efficacy in simultaneously enhancing both robustness and generalization. Finally, we extend our analysis to the practical black-box setting, demonstrating that zeroth-order optimization techniques can effectively maintain both robustness and generalization even without local gradient access.
Table 1. Comparison of stability bounds for Adversarial Learning algorithms ( nmin-Minimum local sample size; Dmax-Maximum heterogeneity measure; (N/m)-number of clients; p-Moreau parameter; ℓ-convexity constant; n-local sample size; T -number of rounds; δ-attack radius; µ-approximation error; η-step size). Algorithm Federated Training Mechanism Analysis Tool Step Size Stability Bound AT (Xing et al., 2021a) No SGD On-average stability Constant (η) O δ η √ T n + δ ηT n 2 AT (Xiao et al., 2022) No SGD Uniform stability Constant (1/L w ) O T Lwn + δT Lw FAL (Ding et al., 2025) Yes SGD + SSA On-average stability Diminishing O δT log T 1 + Dmax m nmin + T √ log T m nmin FAL (Ding et al., 2025) Yes SGD + RSA On-average stability Diminishing O T 1/4 log T √ Q + T 3/4 +T (δDmax) 1/3 m nmin FAL (Ours) Yes SGD Uniform stability Diminishing (O(1/t)) O 1 nN + δ T 1/2 log T FalME (Ours) Yes SGD + Moreau Uniform stability Diminishing (O(1/t)) O p p-ℓ 1 N n + 1 n T 1/2 log T FalZO (Ours) Yes SGD + Zeroth-order Uniform stability Diminishing (O(1/t)) O 1 nN + µ + δ T 1/2 log T
unavailable or prohibitively costly (Chen et al., 2017;Ilyas et al., 2018). This obstructs optimization and undermines robust generalization under adversarial perturbations.
To address the above challenges, we systematically analyze the generalization of FAL optimization algorithms via a rigorous stability framework tailored for non-convex settings.
Our core contributions are as follows.
• We first demonstrate that standard SGD applied to non-smooth adversarial objectives yields generalization bounds that scale with attack intensity. To mitigate the impact of adversarial perturbations, we incorporate Moreau-envelope smoothing by regularizing the empirical robust loss via a quadratic proximal term. This formulation enables stability bounds independent of the attack strength δ, thereby improving both robustness and generalization.
• Moreover, to adress gradient inaccessibility in blackbox deployments, we employ zeroth-order (ZO) adversarial training. This extension eliminates reliance on explicit gradients, thereby broadening applicability to privacy-constrained federated environments. We demonstrate that, although the stronger convergence guarantees of first-order methods, our ZO framework remains theoretically, enabling robust learning solely through black-box queries.
• Extensive experiments on benchmark datasets corroborate our theoretical findings. We show that the Moreauenvelope optimizer significantly narrows the robustgeneralization gap and outperforms standard SGD in adversarial accuracy. Furthermore, we demonstrate that our ZO variant maintains competitive robustness and generalization in gradient-free environments.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on14
- Overfitting in adversarially robust deep learningLeslie Rice, Eric Wong, J. Zico KolterICML 2020 · 935 citations
- Attack of the Tails: Yes, You Really Can Backdoor Federated LearningHongyi Wang, Kartik Sreenivasan, Shashank Rajput, Harit Vishwakarma et al.NeurIPS 2020 · 862 citations
- Generalized Federated Learning via Sharpness Aware MinimizationZhe Qu, Xingyu Li, Rui Duan, Yao Liu et al.ICML 2022 · 219 citations
- Understanding Robust Overfitting of Adversarial Training and BeyondChaojian Yu, Bo Han, Li Shen, Jun Yu et al.ICML 2022 · 78 citations
- On the Algorithmic Stability of Adversarial TrainingYue Xing, Qifan Song, Guang ChengNeurIPS 2021 · 74 citations
Related papers
- Uniformly Stable Algorithms for Adversarial Training and BeyondJiancong Xiao, Jiawei Zhang, Zhi-Quan Luo, Asuman E. OzdaglarICML 2024 · 2 citations
- How Does the Smoothness Approximation Method Facilitate Generalization for Federated Adversarial Learning?Wenjun Ding, Ying An, Lixing Chen, Shichao Kan et al.AAAI 2025 · 1 citation
- Fine-Grained Theoretical Analysis of Federated Zeroth-Order OptimizationJun Chen, Hong Chen, Bin Gu, Hao DengNeurIPS 2023 · 11 citations
- Federated Adversarial Learning: A Framework with Convergence AnalysisXiaoxiao Li, Zhao Song, Jiaming YangICML 2023 · 36 citations
- Stability and Generalization of Adversarial Training for Shallow Neural Networks with Smooth ActivationKaibo Zhang, Yunjuan Wang, Raman AroraNeurIPS 2024 · 5 citations
