Trial and Trust: Addressing Byzantine Attacks with Comprehensive Defense Strategy

πŸ“… 2025-05-12
πŸ“ˆ Citations: 0
✨ Influential: 0
πŸ“„ PDF
πŸ€– AI Summary
This paper addresses the problem of Byzantine clients injecting malicious model updates in federated learning, which causes global model divergence. We propose a novel anomaly update filtering mechanism that integrates dynamic trust scoring with a probing function. To our knowledge, this is the first method provably convergent even when Byzantine clients constitute a majority (>50%)β€”a previously unsolved challenge. The approach is compatible with standard local training, partial client participation, and adaptive optimizers such as Adam and RMSProp. Rigorous theoretical analysis establishes convergence guarantees under heterogeneous settings. Furthermore, the algorithm is designed for broad adaptability across diverse system and statistical heterogeneities. Extensive experiments on synthetic benchmarks and real-world medical ECG datasets demonstrate that our method achieves significantly higher robustness against strong Byzantine attacks than state-of-the-art baselines, while matching the convergence speed and accuracy of classical federated algorithms in benign (attack-free) environments.

Technology Category

Application Category

πŸ“ Abstract
Recent advancements in machine learning have improved performance while also increasing computational demands. While federated and distributed setups address these issues, their structure is vulnerable to malicious influences. In this paper, we address a specific threat, Byzantine attacks, where compromised clients inject adversarial updates to derail global convergence. We combine the trust scores concept with trial function methodology to dynamically filter outliers. Our methods address the critical limitations of previous approaches, allowing functionality even when Byzantine nodes are in the majority. Moreover, our algorithms adapt to widely used scaled methods like Adam and RMSProp, as well as practical scenarios, including local training and partial participation. We validate the robustness of our methods by conducting extensive experiments on both synthetic and real ECG data collected from medical institutions. Furthermore, we provide a broad theoretical analysis of our algorithms and their extensions to aforementioned practical setups. The convergence guarantees of our methods are comparable to those of classical algorithms developed without Byzantine interference.
Problem

Research questions and friction points this paper is trying to address.

Combating Byzantine attacks in federated learning systems
Dynamic outlier filtering using trust scores and trial functions
Ensuring convergence despite majority Byzantine node presence
Innovation

Methods, ideas, or system contributions that make the work stand out.

Combines trust scores with trial functions
Filters outliers dynamically in federated learning
Works with scaled methods like Adam
πŸ”Ž Similar Papers
No similar papers found.
Gleb Molodtsov
Gleb Molodtsov
Researcher
Daniil Medyakov
Daniil Medyakov
Unknown affiliation
Optimization
S
Sergey Skorik
Ivannikov Institute for System Programming of the RAS
N
Nikolas Khachaturov
Ivannikov Institute for System Programming of the RAS
S
Shahane Tigranyan
Ivannikov Institute for System Programming of the RAS
V
Vladimir Aletov
Ivannikov Institute for System Programming of the RAS, Moscow Institute of Physics and Technology
A
Aram Avetisyan
Ivannikov Institute for System Programming of the RAS
M
Martin TakÑč
Mohamed bin Zayed University of Artificial Intelligence
Aleksandr Beznosikov
Aleksandr Beznosikov
PhD, Basic Research of Artificial Intelligence Lab
OptimizationMachine Learning