USENIX Security2025Top-tier venue
DP-BREM: Differentially-Private and Byzantine-Robust Federated Learning with Client Momentum
Xiaolan Gu, Ming Li, Li Xiong
Abstract
Federated Learning (FL) allows multiple participating clients to train machine learning models collaboratively while keeping their datasets local and only exchanging the gradient or model updates with a coordinating server. Existing FL protocols are vulnerable to attacks that aim to compromise data privacy and/or model robustness. Recently proposed defenses focused on ensuring either privacy or robustness, but not both. In this paper, we focus on simultaneously achieving differential privacy (DP) and Byzantine robustness for cross-silo FL, based on the idea of learning from history. The robustness is achieved via client momentum, which averages the updates of each client over time, thus reducing the variance of the honest clients and exposing the small malicious perturbations of Byzantine clients that are undetectable in a single round but accumulate over time. In our initial solution DP-BREM, DP is achieved by adding noise to the aggregated momentum, and we account for the privacy cost from the momentum, which is different from the conventional DP-SGD that accounts for the privacy cost from the gradient. Since DP-BREM assumes a trusted server (who can obtain clients' local models or updates), we further develop the final solution called DP-BREM+, which achieves the same DP and robustness properties as DP-BREM without a trusted server by utilizing secure aggregation techniques, where DP noise is securely and jointly generated by the clients. Both theoretical analysis and experimental results demonstrate that our proposed protocols achieve better privacy-utility tradeoff and stronger Byzantine robustness than several baseline methods, under different DP budgets and attack settings.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 59052ffc-7752-4ce4-bb56-490aa77c1dcbCited by top-tier papers2
- DP-FedAdamW: An Efficient Optimizer for Differentially Private Federated Large ModelsJin Liu, Ning Xi, Yinbin Miao, Junkang LiuCVPR 2026 · 1 citation
- Towards Trustworthy Federated Learning with Untrusted ParticipantsYoussef Allouah, Rachid Guerraoui, John StephanICML 2025
Builds on11
- Deep Learning with Differential PrivacyMartín Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan et al.CCS 2016 · 7,620 citations
- Exploiting Unintended Feature Leakage in Collaborative LearningLuca Melis, Congzheng Song, Emiliano De Cristofaro, Vitaly ShmatikovS&P 2019 · 1,736 citations
- Attack of the Tails: Yes, You Really Can Backdoor Federated LearningHongyi Wang, Kartik Sreenivasan, Shashank Rajput, Harit Vishwakarma et al.NeurIPS 2020 · 862 citations
- Learning from History for Byzantine Robust OptimizationSai Praneeth Karimireddy, Lie He, Martin JaggiICML 2021 · 247 citations
- Differentially Private Meta-LearningJeffrey Li, Mikhail Khodak, Sebastian Caldas, Ameet TalwalkarICLR 2020 · 125 citations
Related papers
- Towards the Robustness of Differentially Private Federated LearningTao Qi, Huili Wang, Yongfeng HuangAAAI 2024 · 30 citations
- Practical Differentially Private and Byzantine-resilient Federated LearningZihang Xiang, Tianhao Wang, Wanyu Lin, Di WangSIGMOD 2023 · 22 citations
- Do We Really Need to Design New Byzantine-robust Aggregation Rules?Minghong Fang, Seyedsina Nabavirazavi, Zhuqing Liu, Wei Sun et al.NDSS 2025
- Dual Defense: Enhancing Privacy and Mitigating Poisoning Attacks in Federated LearningRunhua Xu, Shiqi Gao, Chao Li, James Joshi et al.NeurIPS 2024 · 29 citations
- Local Model Poisoning Attacks to Byzantine-Robust Federated LearningMinghong Fang, Xiaoyu Cao, Jinyuan Jia, Neil Zhenqiang GongUSENIX Security 2020
