Towards Understanding Generalization of Federated Adversarial Learning: Perspective of Algorithmic Stability
Yongkang Yang, Chang Cao, Ke Zhang, Han Li, Hong Chen, Rushi Lan
摘要
Federated Adversarial Learning (FAL) enhances model robustness by integrating adversarial training into the federated learning framework. Despite recent advances proposing efficient FAL algorithms, existing work has mainly focused on convergence properties, with limited understanding of their generalization capabilities. To address this, we present the unified theoretical framework for analyzing FAL generalization through the lens of algorithmic stability. We first analyze general FAL algorithms based on stochastic gradient descent (SGD) and derive perturbationdependent generalization bounds, which reveal that stronger adversarial attacks can lead to degraded generalization. To mitigate the impact of adversarial perturbations, we leverage Moreau envelope optimization and establish a perturbationindependent bound, demonstrating its efficacy in simultaneously enhancing both robustness and generalization. Finally, we extend our analysis to the practical black-box setting, demonstrating that zeroth-order optimization techniques can effectively maintain both robustness and generalization even without local gradient access.
Table 1. Comparison of stability bounds for Adversarial Learning algorithms ( nmin-Minimum local sample size; Dmax-Maximum heterogeneity measure; (N/m)-number of clients; p-Moreau parameter; ℓ-convexity constant; n-local sample size; T -number of rounds; δ-attack radius; µ-approximation error; η-step size). Algorithm Federated Training Mechanism Analysis Tool Step Size Stability Bound AT (Xing et al., 2021a) No SGD On-average stability Constant (η) O δ η √ T n + δ ηT n 2 AT (Xiao et al., 2022) No SGD Uniform stability Constant (1/L w ) O T Lwn + δT Lw FAL (Ding et al., 2025) Yes SGD + SSA On-average stability Diminishing O δT log T 1 + Dmax m nmin + T √ log T m nmin FAL (Ding et al., 2025) Yes SGD + RSA On-average stability Diminishing O T 1/4 log T √ Q + T 3/4 +T (δDmax) 1/3 m nmin FAL (Ours) Yes SGD Uniform stability Diminishing (O(1/t)) O 1 nN + δ T 1/2 log T FalME (Ours) Yes SGD + Moreau Uniform stability Diminishing (O(1/t)) O p p-ℓ 1 N n + 1 n T 1/2 log T FalZO (Ours) Yes SGD + Zeroth-order Uniform stability Diminishing (O(1/t)) O 1 nN + µ + δ T 1/2 log T
unavailable or prohibitively costly (Chen et al., 2017;Ilyas et al., 2018). This obstructs optimization and undermines robust generalization under adversarial perturbations.
To address the above challenges, we systematically analyze the generalization of FAL optimization algorithms via a rigorous stability framework tailored for non-convex settings.
Our core contributions are as follows.
• We first demonstrate that standard SGD applied to non-smooth adversarial objectives yields generalization bounds that scale with attack intensity. To mitigate the impact of adversarial perturbations, we incorporate Moreau-envelope smoothing by regularizing the empirical robust loss via a quadratic proximal term. This formulation enables stability bounds independent of the attack strength δ, thereby improving both robustness and generalization.
• Moreover, to adress gradient inaccessibility in blackbox deployments, we employ zeroth-order (ZO) adversarial training. This extension eliminates reliance on explicit gradients, thereby broadening applicability to privacy-constrained federated environments. We demonstrate that, although the stronger convergence guarantees of first-order methods, our ZO framework remains theoretically, enabling robust learning solely through black-box queries.
• Extensive experiments on benchmark datasets corroborate our theoretical findings. We show that the Moreauenvelope optimizer significantly narrows the robustgeneralization gap and outperforms standard SGD in adversarial accuracy. Furthermore, we demonstrate that our ZO variant maintains competitive robustness and generalization in gradient-free environments.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper14
- Overfitting in adversarially robust deep learningLeslie Rice, Eric Wong, J. Zico KolterICML 2020 · 被引用 935 次
- Attack of the Tails: Yes, You Really Can Backdoor Federated LearningHongyi Wang, Kartik Sreenivasan, Shashank Rajput, Harit Vishwakarma 等NeurIPS 2020 · 被引用 862 次
- Generalized Federated Learning via Sharpness Aware MinimizationZhe Qu, Xingyu Li, Rui Duan, Yao Liu 等ICML 2022 · 被引用 219 次
- Understanding Robust Overfitting of Adversarial Training and BeyondChaojian Yu, Bo Han, Li Shen, Jun Yu 等ICML 2022 · 被引用 78 次
- On the Algorithmic Stability of Adversarial TrainingYue Xing, Qifan Song, Guang ChengNeurIPS 2021 · 被引用 74 次
相关 Paper
- Uniformly Stable Algorithms for Adversarial Training and BeyondJiancong Xiao, Jiawei Zhang, Zhi-Quan Luo, Asuman E. OzdaglarICML 2024 · 被引用 2 次
- How Does the Smoothness Approximation Method Facilitate Generalization for Federated Adversarial Learning?Wenjun Ding, Ying An, Lixing Chen, Shichao Kan 等AAAI 2025 · 被引用 1 次
- Fine-Grained Theoretical Analysis of Federated Zeroth-Order OptimizationJun Chen, Hong Chen, Bin Gu, Hao DengNeurIPS 2023 · 被引用 11 次
- Federated Adversarial Learning: A Framework with Convergence AnalysisXiaoxiao Li, Zhao Song, Jiaming YangICML 2023 · 被引用 36 次
- Stability and Generalization of Adversarial Training for Shallow Neural Networks with Smooth ActivationKaibo Zhang, Yunjuan Wang, Raman AroraNeurIPS 2024 · 被引用 5 次
