Byzantine-Robust and Differentially Private Federated Optimization under Weaker Assumptions

Rustem Islamov, Grigory Malinovsky, Alexander Gaponov, Aurelien Lucchi, Peter Richtárik, Eduard Gorbunov
Proceedings of the 42nd Conference on Uncertainty in Artificial Intelligence, PMLR 337:2378-2441, 2026.

Abstract

Federated Learning (FL) enables heterogeneous clients to collaboratively train a shared model without centralizing their raw data, offering an inherent level of privacy. However, gradients and model updates can still leak sensitive information, while malicious servers may mount adversarial attacks such as Byzantine manipulation. These vulnerabilities highlight the need to address differential privacy ({DP}) and Byzantine robustness within a unified framework. Existing approaches, however, often rely on unrealistic assumptions such as bounded gradients, require auxiliary server-side datasets, or fail to provide convergence guarantees. We address these limitations by proposing Byz-Clip21-SGD2M, a new algorithm that integrates robust aggregation with double momentum and carefully designed clipping. We prove high-probability convergence guarantees under standard $L$-smoothness and $\sigma$-sub-{Gaussian} gradient noise assumptions, thereby relaxing conditions that dominate prior work. Our analysis recovers state-of-the-art convergence rates in the absence of adversaries and improves utility guarantees under Byzantine and {DP} settings. Empirical evaluations on CNN and MLP models trained on {MNIST} further validate the effectiveness of our approach.

Cite this Paper


BibTeX
@InProceedings{pmlr-v337-islamov26a, title = {Byzantine-Robust and Differentially Private Federated Optimization under Weaker Assumptions}, author = {Islamov, Rustem and Malinovsky, Grigory and Gaponov, Alexander and Lucchi, Aurelien and Richt\'{a}rik, Peter and Gorbunov, Eduard}, booktitle = {Proceedings of the 42nd Conference on Uncertainty in Artificial Intelligence}, pages = {2378--2441}, year = {2026}, editor = {Perković, Emilija and Malinsky, Daniel}, volume = {337}, series = {Proceedings of Machine Learning Research}, month = {17--21 Aug}, publisher = {PMLR}, pdf = {https://raw.githubusercontent.com/mlresearch/v337/main/assets/islamov26a/islamov26a.pdf}, url = {https://proceedings.mlr.press/v337/islamov26a.html}, abstract = {Federated Learning (FL) enables heterogeneous clients to collaboratively train a shared model without centralizing their raw data, offering an inherent level of privacy. However, gradients and model updates can still leak sensitive information, while malicious servers may mount adversarial attacks such as Byzantine manipulation. These vulnerabilities highlight the need to address differential privacy ({DP}) and Byzantine robustness within a unified framework. Existing approaches, however, often rely on unrealistic assumptions such as bounded gradients, require auxiliary server-side datasets, or fail to provide convergence guarantees. We address these limitations by proposing Byz-Clip21-SGD2M, a new algorithm that integrates robust aggregation with double momentum and carefully designed clipping. We prove high-probability convergence guarantees under standard $L$-smoothness and $\sigma$-sub-{Gaussian} gradient noise assumptions, thereby relaxing conditions that dominate prior work. Our analysis recovers state-of-the-art convergence rates in the absence of adversaries and improves utility guarantees under Byzantine and {DP} settings. Empirical evaluations on CNN and MLP models trained on {MNIST} further validate the effectiveness of our approach.} }
Endnote
%0 Conference Paper %T Byzantine-Robust and Differentially Private Federated Optimization under Weaker Assumptions %A Rustem Islamov %A Grigory Malinovsky %A Alexander Gaponov %A Aurelien Lucchi %A Peter Richtárik %A Eduard Gorbunov %B Proceedings of the 42nd Conference on Uncertainty in Artificial Intelligence %C Proceedings of Machine Learning Research %D 2026 %E Emilija Perković %E Daniel Malinsky %F pmlr-v337-islamov26a %I PMLR %P 2378--2441 %U https://proceedings.mlr.press/v337/islamov26a.html %V 337 %X Federated Learning (FL) enables heterogeneous clients to collaboratively train a shared model without centralizing their raw data, offering an inherent level of privacy. However, gradients and model updates can still leak sensitive information, while malicious servers may mount adversarial attacks such as Byzantine manipulation. These vulnerabilities highlight the need to address differential privacy ({DP}) and Byzantine robustness within a unified framework. Existing approaches, however, often rely on unrealistic assumptions such as bounded gradients, require auxiliary server-side datasets, or fail to provide convergence guarantees. We address these limitations by proposing Byz-Clip21-SGD2M, a new algorithm that integrates robust aggregation with double momentum and carefully designed clipping. We prove high-probability convergence guarantees under standard $L$-smoothness and $\sigma$-sub-{Gaussian} gradient noise assumptions, thereby relaxing conditions that dominate prior work. Our analysis recovers state-of-the-art convergence rates in the absence of adversaries and improves utility guarantees under Byzantine and {DP} settings. Empirical evaluations on CNN and MLP models trained on {MNIST} further validate the effectiveness of our approach.
APA
Islamov, R., Malinovsky, G., Gaponov, A., Lucchi, A., Richtárik, P. & Gorbunov, E.. (2026). Byzantine-Robust and Differentially Private Federated Optimization under Weaker Assumptions. Proceedings of the 42nd Conference on Uncertainty in Artificial Intelligence, in Proceedings of Machine Learning Research 337:2378-2441 Available from https://proceedings.mlr.press/v337/islamov26a.html.

Related Material