History-Guided Directional Aggregation for Byzantine-Robust Federated Learning
Abstract
Defending federated learning against untargeted poisoning requires suppressing malicious influence while preserving useful information from clients with non-IID data. We propose History-Guided Directional Aggregation (HGDA), which uses a small trusted server dataset to assess clients over time and weight the distinct update directions they currently submit. At each communication round, the server trains a copy of the global model on this dataset to obtain reference updates at two checkpoints. HGDA separately accumulates positive and negative alignments between client and reference updates within a sliding window to score each client. Each current direction receives the largest score among the clients submitting it, so repeated submissions share an aggregation weight while nearby directions remain separate. The server uses the aggregated directions to update the global model with its own optimizer, independently of client and reference update magnitudes. HGDA requires no estimate of the Byzantine population. We analyze convergence with server Adam, showing how residual adversarial influence and local-training error affect progress on the benign clients' objective. Experiments on five datasets demonstrate broad Byzantine robustness across diverse poisoning attacks and Byzantine fractions under full and partial participation, with strong accuracy where representative baselines severely degrade or collapse. HGDA remains effective under poisoning when the trusted dataset is not representative of client data and has incomplete class coverage. It also demonstrates resilience to scheduled and adaptive on-off attacks, in which clients alternate between benign training and poisoning.
Then back it, or bet against it.
Related papers
Open the market on this paper to see 7 more related papers.