[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-118294-en":3,"doc-seo-118294-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":4,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},118294,7971461740886,"Theodore","https://ap-avatar.wpscdn.com/davatar_3d24733baf745e90a7e4bdd5f77d97b2",8,"Research & Report","Benchmark and Framework for Byzantine Machine Learning - Spring 2024","Distributed machine learning is increasingly used to train large-scale models, yet not every participant client has benevolent intentions. When adversarial clients contribute updates, robust defenses are required, but many existing approaches have not undergone exhaustive evaluation across realistic settings. This project proposes a protocol and methodology to benchmark and assess current defenses, demonstrating that state-of-the-art aggregation can succeed in some environments while failing in others. The results aim to quantify defensive effectiveness under diverse conditions and guide future improvements.","École Polytechnique Fédérale de Lausanne Universitat Politècnica de Catalunya  \nBenchmark and Framework for Byzantine Machine  \nLearning  \nAuthor:  \nMarc Gonzalez Vidal  \nDirector:  \nPr. Rachid Guerraoui  \nCo-Director & Tutor:  \nDr. Geovani Rizk & John Stephan  \nSpecialisation:  \nComputer Science  \nSpring 2024  \nAbstract  \nThe application of distributed machine learning is becoming increasingly prevalent in the training of large-scale machine learning models. A further issue is that not all clients engaged in model training always have benevolent intentions. In such cases, it is imperative that we are able to defend ourselves against any attacks that may be launched by these clients. Indeed, there are already a number of proposed defences that claim to be highly effective; however, they have yet to be subjected to exhaustive testing. The objective of this project is to demonstrate that, despite the efficacy of state-of-the-art aggregations in certain environments, there are others where the model is unable to learn and where it is not possible to defend against malicious clients. The objective of this project is to demonstrate the efficacy of a novel protocol and methodology for evaluating existing defenses. This approach will enable us to determine the extent to which these defenses are effective in diverse environments.  \nContents  \n1 Introduction 4  \n1.1 Introduction to Machine Learning .......................... 4  \n1.2 Introduction to Federated Learning and Byzantine Machine Learning ........ 4  \n2 Target and Contributions 5  \n3 Planning 5  \n4 Background 6  \n4.1 Background on Machine Learning .......................... 6  \n4.2 Background on Federated Learning .......................... 8  \n4.3 Background on Byzantine Machine Learning .................... 10  \n5 Framework 11  \n5.1 Framework targets .................................. 11  \n5.2 Framework technologies ............................... 12  \n5.3 Framework modules ................................. 12  \n5.4 Framework testing .................................. 13  \n6 Benchmark setup 14  \n6.1 Benchmark motivation ................................ 14  \n6.2 Algorithm and aggregation rules ........................... 14  \n6.3 Byzantine Attacks ................................... 14  \n6.4 Datasets and Data Heterogeneity ........................... 15  \n6.5 Models ........................................ 15  \n6.6 Machine and Environment .............................. 16  \n6.7 Summary of Benchmark ............................... 16  \n7 Experimental Protocol and Evaluation 17  \n8 Results of Benchmark 17  \n8.1 Vanilla Results .................................... 18  \n8.2 Coordinate-wise Median ............................... 18  \n8.3 Coordinate-wise Trimmed Mean ........................... 20  \n8.4 Geometric Median .................................. 22  \n8.5 Multi-Krum ...................................... 24  \n8.6 Centered Clipping ................................... 26  \n8.7 Real Byzantine Border ................................ 28  \n9 Conclusions of Benchmark 30  \n9.1 Evaluation of results and limitation of existing methods ............... 30  \n9.2 Ranking of aggregations ............................... 30  \n10 New Attacks 32  \n10.1 Label-Sliding ..................................... 32  \n10.2 Betrayal ........................................ 32  \n11 Future Work 33  \n12 Cost of performing the benchmark 33  \n13 Apendices 38  \n13.1 Setting of experiment ................................. 38  \n1 Introduction  \n1.1 Introduction to Machine Learning  \nSupervised machine learning is a paradigm of artificial intelligence that diverges from traditional programming methods. Instead of explicitly telling the computer how to perform a task through code, we employ a model, typically a neural network, and define the task it needs to accomplish. Model performance is evaluated based on a predefined metric, providing feedback on how well or poorly it is performing.  \nThis approach essential","cbCainJHC0Qrzrwd","https://ap.wps.com/l/cbCainJHC0Qrzrwd","pdf",978482,1,42,"English","en",105,"# Introduction\n## Introduction to Machine Learning\n## Introduction to Federated Learning and Byzantine Machine Learning\n# Target and Contributions\n# Planning\n# Background\n## Background on Machine Learning\n## Background on Federated Learning\n## Background on Byzantine Machine Learning\n# Framework\n## Framework targets\n## Framework technologies\n## Framework modules\n## Framework testing\n# Benchmark setup\n## Benchmark motivation\n## Algorithm and aggregation rules\n## Byzantine Attacks\n## Datasets and Data Heterogeneity\n## Models\n## Machine and Environment\n## Summary of Benchmark\n# Experimental Protocol and Evaluation\n# Results of Benchmark\n## Vanilla Results\n## Coordinate-wise Median\n## Coordinate-wise Trimmed Mean\n## Geometric Median\n## Multi-Krum\n## Centered Clipping\n## Real Byzantine Border\n# Conclusions of Benchmark\n## Evaluation of results and limitation of existing methods\n## Ranking of aggregations\n# New Attacks\n## Label-Sliding\n## Betrayal\n# Future Work\n# Cost of performing the benchmark\n# Apendices\n## Setting of experiment","[{\"question\":\"What problem does the project address in distributed/byzantine machine learning?\",\"answer\":\"Clients involved in model training may behave maliciously. The project focuses on evaluating how well existing aggregation defenses withstand such Byzantine attacks.\"},{\"question\":\"How does the project propose to evaluate existing defenses?\",\"answer\":\"It introduces a benchmarking protocol and methodology designed to measure defensive effectiveness across multiple environments and conditions, rather than relying on untested claims.\"},{\"question\":\"Which aggregation methods and attacks are included in the benchmark results?\",\"answer\":\"The document lists aggregation baselines such as coordinate-wise median, trimmed mean, geometric median, Multi-Krum, and centered clipping, and it includes new attacks like label-sliding and betrayal.\"}]","Benchmark and Framework for Byzantine Machine Learning - Spring 2024 | PDF",1785682858,106,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"benchmark-and-framework-for-byzantine-machine-learning-spring-2024","",{"@graph":36,"@context":85},[37,54,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/benchmark-and-framework-for-byzantine-machine-learning-spring-2024/118294/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":62,"encodingFormat":61,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-02",true,{"@type":65,"interactionType":66,"userInteractionCount":4},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does the project address in distributed/byzantine machine learning?","Question",{"text":75,"@type":76},"Clients involved in model training may behave maliciously. The project focuses on evaluating how well existing aggregation defenses withstand such Byzantine attacks.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does the project propose to evaluate existing defenses?",{"text":80,"@type":76},"It introduces a benchmarking protocol and methodology designed to measure defensive effectiveness across multiple environments and conditions, rather than relying on untested claims.",{"name":82,"@type":73,"acceptedAnswer":83},"Which aggregation methods and attacks are included in the benchmark results?",{"text":84,"@type":76},"The document lists aggregation baselines such as coordinate-wise median, trimmed mean, geometric median, Multi-Krum, and centered clipping, and it includes new attacks like label-sliding and betrayal.","https://schema.org",{"og:url":52,"og:type":87,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":89,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]