acceptodds
Under review as a conference paper at ICLR 2027

Statistic Preservation Does Not Identify Attack-Suppression Preservation in Composed Federated-Learning Defences

Abstract

Federated learning composes defences never designed together. Does the downstream defence still suppress the attack? **A preserved statistic is not preserved suppression.** The natural answer asks whether the downstream defense's own statistic is preserved under composition, and it fails structurally rather than statistically. Admitting a composition because one constituent already suppresses the attack selects on the outcome to be explained. The counterfactual identification required is then absent, so the comparison is missing at any . The fix is a design, not a better statistic: hold the downstream defence and attack fixed, and intervene upstream. Ignoring this costs not power but the sign. On one `coord_median` cell, the outcome-gated design moves where the within-defence one moves (, both intervals exclude zero). Against ourselves: with the aggregate magnitude held fixed, the is , and both agree in sign. The reversal replicates on the same cell on CIFAR-100; a composition-level replication there was attempted and did not carry. Decision change is neither necessary nor sufficient for suppression to move. One aggregator's selection flips repeatedly while admitting no adversary; another's is bit-identical while attack success falls. Oracle-free, a Krum decision flip alone raises ASR by , so both need an oracle no server has. This is identification, deliberately scoped to committed attacks and controlled interventions, and not a deployable security test or a predictor of adaptive robustness.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.