End-to-End Verifiable and Robust Federated Learning
cs.LG
Submitted: 2026-09-14
Updated: 2026-09-14
Comments: Conference, 21 pages, 9 figures, 5 tables
Code: https://github.com/TalwalkarLab/leaf
License: http://creativecommons.org/licenses/by/4.0/
The gist: Federated learning enables multiple parties to train a shared model without centralizing raw data with the help of an aggregator, but introduces integrity risks once participants or infrastructure
Terminology
Abstract
Federated learning enables multiple parties to train a shared model without centralizing raw data with the help of an aggregator, but introduces integrity risks once participants or infrastructure are not fully trustworthy. Two requirements are particularly important: robustness to poisoned or Byzantine client updates, and verifiability of the aggregator so that clients or third parties can audit the reported aggregation without learning individual updates. Existing work has largely treated these goals separately, and efficient public verifiability for robust, outlier-excluding aggregation remains limited. We present a verifiable federated learning protocol that makes a robust aggregation pipeline publicly auditable. Our design combines cryptographic commitments with non-interactive zero-knowledge proofs to certify both (i) cosine-similarity-based outlier exclusion and (ii) aggregation over the selected set, without revealing individual client updates to verifiers. In experiments under representative poisoning attacks, our method maintains high accuracy, with an average accuracy loss below 4% across the evaluated configurations, while keeping verification overhead practical: proof artifacts can be generated and verified within minutes at the scale studied. In summary, our results show that robust outlier exclusion and public verifiability can be jointly achieved in a federated learning setting.
Sources
- LEAF: A Benchmark for Federated Settings
- FLAegis: A Two-Layer Defense Framework for Federated Learning Against Poisoning Attacks
- FLTrust: Byzantine-robust Federated Learning via Trust Bootstrapping
- Mitigating Sybils in Federated Learning Poisoning
- Byzantine-Robust Learning on Heterogeneous Datasets via Bucketing
- Threats to Federated Learning: A Survey
- The Hidden Vulnerability of Distributed Learning in Byzantium
Related papers
- Polynomial-Augmented Neural Networks (PANNs) with Weak Orthogonality Constraints for Enhanced Function and PDE Approximation
- AIRL-S: Unifying Reinforcement Learning and Search-Based Test-Time Scaling via Adversarial Inverse Reinforcement Learning
- Transformers as Bayesian In-Context Experimenters: Smoothness-Adaptive Efficient ATE Estimation
- Convergence issues in Relational Concept Analysis based on AOC-posets
- Beliefs Beyond Posteriors: Local-Consistency Optimisation for Bayesian Neural Networks
- Understanding Diffusion Models via Ratio-Based Function Approximation with SignReLU Networks