arXiv論文メモ
新着一覧
stat.ML / cs.LG · 査読状況未確認

攻撃に強い連合回帰での勾配のばらつきを理論解析

On the Gradient Heterogeneity Dynamics of Adversarially Robust Federated Regression

Leonardo F. Toso, James Anderson, Nirupam Gupta, Rafael Pinot

この論文をやさしく読む

ひとことで言うと

連合学習で参加者ごとのデータの違いと悪意ある更新があるとき、回帰学習の収束条件を理論的に調べた。

何に役立つ?

攻撃に強い集約方法の収束保証を評価する際に、データの違い・雑音・初期値の影響を分けて考える助けになる。

この研究の面白いところ

勾配の違いに事前の上界を置く代わりに、毎ラウンド新しい標本を使う回帰の統計モデルから上界を導いた。

どこまで分かった?

悪意ある参加者が半数未満で、集約器の係数や標本の初期使用期間などの条件がある理論結果。実システムでの性能は要旨に示されていない。

v1のアブストラクトに基づくAI解説。日本語訳とは別に、用途の解釈を含みます。

アブストラクトの日本語訳

連合学習には本来、異質性がある。正直な参加者でも、データ生成モデルが異なる場合がある。さらに悪意ある参加者は任意の更新値を共有して、異質性を強められる。従来の解析では、統計的な異質性と攻撃的な振る舞いの相互作用を、勾配の非類似性に関する条件で制御することが多い。しかし、その上界はあらかじめ課されるため、最小二乗回帰でさえ保守的な保証になる可能性がある。本研究は、毎ラウンド新しいデータ標本を使う線形・非線形回帰の統計モデルから、勾配の異質性を導出する。得られた上界は、正直な参加者の真のモデルパラメータ間の異質性、有限標本のラベル雑音、初期値の影響を分けて表す。その上で、悪意ある参加者数をf、全参加者数をnとして f/n<1/2 のとき、係数κ=O(f/n)を持つ任意の(f,κ)ロバスト集約器について、明示的な標本の初期使用期間を経た後に収束することを示す。

v1の要旨から自動生成。本文の精読・人による確認は未実施。

初稿
2026-09-22(UTC)
最新改訂
2026-09-22 · v1
査読・掲載
査読状況未確認
arXivで読むPDF

更新履歴

取得できた版を表示。版の更新は査読済みを意味しません。過去版の本文差分は未解析です。

原文の要旨

Federated learning (FL) is intrinsically heterogeneous: honest clients may have different data-generating models. On top of that, adversarial clients can make heterogeneity even more pronounced by sharing arbitrary updates. Existing analyses typically control the interaction between statistical heterogeneity and adversarial behavior through gradient-dissimilarity conditions. However, the underlying bound is imposed a priori and may yield conservative guarantees even for least-squares regression. We instead derive the gradient heterogeneity from the statistical model of linear and nonlinear regression with fresh data samples at every round. Our bounds separate heterogeneity among the honest clients' ground-truth model parameters, finite-sample label noise, and initialization. We then demonstrate that, for any $(f,\kappa)$-robust aggregator with coefficient $\kappa = O(f/n)$, where $f$ is the number of adversarial clients and $n$ the total number of clients (with $f/n < 1/2$), convergence holds after an explicit sample burn-in.

arXiv ID: 2609.25705 / 要約の誤りについて