acceptodds
Under review as a conference paper at ICLR 2027

Byzantine-Robust Federated Learning with Privacy-Compatible Adaptive Client Selection via Thompson Sampling

Abstract

Byzantine-robust federated learning must decide, in every round, whose updates to admit into aggregation, and this decision has two error modes that pull against each other: rejecting a benign client, and accepting a malicious one. Under non-IID data, benign clients with atypical local distributions are statistically hard to separate from anomalies, so rules that suppress outliers incur persistent false rejections, whereas relaxing them admits attacks optimized to lie inside the benign distribution. Privacy protection tightens the conflict, because the per-update statistics these rules operate on are perturbed, encrypted, or secret-shared; existing defenses respond by rebuilding the detection rule around one specific privacy primitive. We propose BRFL-TS, which changes where the detection evidence comes from: rather than inspecting individual updates, it infers client reliability from the utility of aggregates. Clients are treated as arms of a multiple-play bandit, Thompson Sampling draws client subsets as combinatorial arms, each subset is aggregated into a candidate model that clients score on their own data, and an adaptive reward-and-penalty rule converts subset-level scores into client-level Beta posteriors. Posterior uncertainty keeps early misjudgements refutable, so false rejections decay instead of persisting, while evidence accumulated across rounds exposes stealthy attackers that survive any single round. Because the server never inspects an individual update, the same procedure runs unchanged under differential privacy, homomorphic encryption, and secure multi-party computation. We prove that the active selection domain coincides with the benign client set—no benign client rejected and no Byzantine client accepted—in all but an fraction of the training rounds, and show empirically that BRFL-TS keeps both error rates low across eight Byzantine attacks, increasing data heterogeneity, and all three privacy primitives.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.