Federated Adversarial Learning: A Framework with Convergence Analysis
Xiaoxiao Li, Zhao Song, Jiaming Yang
摘要
Federated learning (FL) is a trending training paradigm to utilize decentralized training data. FL allows clients to update model parameters locally for several epochs, then share them to a global model for aggregation. This training paradigm with multi-local step updating before aggregation exposes unique vulnerabilities to adversarial attacks. Adversarial training is a popular and effective method to improve the robustness of networks against adversaries. In this work, we formulate a general form of federated adversarial learning (FAL) that is adapted from adversarial learning in the centralized setting. On the client side of FL training, FAL has an inner loop to generate adversarial samples for adversarial training and an outer loop to update local model parameters. On the server side, FAL aggregates local model updates and broadcast the aggregated model. We design a global robust training loss and formulate FAL training as a min-max optimization problem. Unlike the convergence analysis in classical centralized training that relies on the gradient direction, it is significantly harder to analyze the convergence in FAL for three reasons: 1) the complexity of min-max optimization, 2) model not updating in the gradient direction due to the multi-local updates on the client-side before aggregation and 3) inter-client heterogeneity. We address these challenges by using appropriate gradient approximation and coupling techniques and present the convergence analysis in the over-parameterized regime. Our main result theoretically shows that the minimum loss under our algorithm can converge to small with chosen learning rate and communication rounds. It is noteworthy that our analysis is feasible for non-IID clients.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Sketching for First Order Method: Efficient Algorithm for Low-Bandwidth Channel and VulnerabilityZhao Song, Yitan Wang, Zheng Yu, Lichen ZhangICML 2023 · 被引用 35 次
- How Does the Smoothness Approximation Method Facilitate Generalization for Federated Adversarial Learning?Wenjun Ding, Ying An, Lixing Chen, Shichao Kan 等AAAI 2025 · 被引用 1 次
- Accelerated Vertical Federated Adversarial Learning through Decoupling Layer-Wise DependenciesTianxing Man, Yu Bai, Ganyu Wang, Jinjie Fang 等NeurIPS 2025
它引用的顶会 Paper12
- Towards Evaluating the Robustness of Neural NetworksNicholas Carlini, David A. WagnerS&P 2017 · 被引用 9,786 次
- Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacksFrancesco Croce, Matthias HeinICML 2020 · 被引用 2,337 次
- Tackling the Objective Inconsistency Problem in Heterogeneous Federated OptimizationJianyu Wang, Qinghua Liu, Hao Liang, Gauri Joshi 等NeurIPS 2020 · 被引用 2,231 次
- Adaptive Federated OptimizationSashank J. Reddi, Zachary Charles, Manzil Zaheer, Zachary Garrett 等ICLR 2021 · 被引用 1,917 次
- FedBN: Federated Learning on Non-IID Features via Local Batch NormalizationXiaoxiao Li, Meirui Jiang, Xiaofei Zhang, Michael Kamp 等ICLR 2021 · 被引用 1,166 次
相关 Paper
- Combating Exacerbated Heterogeneity for Robust Models in Federated LearningJianing Zhu, Jiangchao Yao, Tongliang Liu, Quanming Yao 等ICLR 2023 · 被引用 2 次
- FedAS: Bridging Inconsistency in Personalized Federated LearningXiyuan Yang, Wenke Huang, Mang YeCVPR 2024 · 被引用 69 次
- CalFAT: Calibrated Federated Adversarial Training with Label SkewnessChen Chen, Yuchen Liu, Xingjun Ma, Lingjuan LyuNeurIPS 2022 · 被引用 53 次
- Towards Understanding Generalization of Federated Adversarial Learning: Perspective of Algorithmic StabilityYongkang Yang, Chang Cao, Ke Zhang, Han Li 等ICML 2026
- CDMA: A Practical Cross-Device Federated Learning Algorithm for General Minimax ProblemsJiahao Xie, Chao Zhang, Zebang Shen, Weijie Liu 等AAAI 2023 · 被引用 2 次
