发表机构
Columbia University; University of Copenhagen; Sorbonne Université; Université Paris Cité; CNRS(哥伦比亚大学; 哥本哈根大学; 索邦大学; 巴黎西岱大学; 法国国家科学研究中心)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文从统计模型推导联邦回归中梯度异质性的动力学界限,并证明在对抗客户端比例小于1/2时,任何$(f,\kappa)$-鲁棒聚合器经样本预热后仍能收敛。
AI 中文摘要
联邦学习(FL)本质上是异质的:诚实客户端可能具有不同的数据生成模型。此外,对抗性客户端可以通过共享任意更新使异质性更加显著。现有分析通常通过梯度不相似性条件来控制统计异质性与对抗行为之间的相互作用。然而,潜在界限是先验施加的,即使对于最小二乘回归也可能产生保守的保证。我们转而从线性和非线性回归的统计模型出发,在每一轮使用新鲜数据样本推导梯度异质性。我们的界限区分了诚实客户端真实模型参数之间的异质性、有限样本标签噪声和初始化。然后我们证明,对于任何具有系数 $\kappa = O(f/n)$ 的 $(f,\kappa)$-鲁棒聚合器,其中 $f$ 是对抗性客户端的数量,$n$ 是客户端总数(且 $f/n < 1/2$),在显式样本预热后收敛成立。
英文摘要
Federated learning (FL) is intrinsically heterogeneous: honest clients may have different data-generating models. On top of that, adversarial clients can make heterogeneity even more pronounced by sharing arbitrary updates. Existing analyses typically control the interaction between statistical heterogeneity and adversarial behavior through gradient-dissimilarity conditions. However, the underlying bound is imposed a priori and may yield conservative guarantees even for least-squares regression. We instead derive the gradient heterogeneity from the statistical model of linear and nonlinear regression with fresh data samples at every round. Our bounds separate heterogeneity among the honest clients' ground-truth model parameters, finite-sample label noise, and initialization. We then demonstrate that, for any $(f,κ)$-robust aggregator with coefficient $κ= O(f/n)$, where $f$ is the number of adversarial clients and $n$ the total number of clients (with $f/n < 1/2$), convergence holds after an explicit sample burn-in.