[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-121127-en":3,"doc-seo-121127-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":20,"is_downloadable":20,"audit_status":20,"page_count":21,"language":22,"language_code":23,"site_id":24,"html_lang":23,"table_of_contents":25,"faqs":26,"seo_title":27,"seo_description":14,"update_tm":28,"read_time":29},121127,8796095461610,"Oliver","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",8,"Research & Report","On the Conflict between Robustness and Learning in Collaborative Machine Learning - Research Paper","Collaborative Machine Learning (CML) enables joint model training while keeping participants’ training data private, but it faces a dual challenge: correctness for safety-critical decisions and resistance to potentially malicious contributors. This work formalizes two common classes of robust aggregators proposed for filtering harmful updates. The results show neither class achieves the intended protection—distance-based rules cannot reliably detect malicious inputs, and behavior/loss-based rules introduce a trade-off that blocks eliminating compromise without sacrificing learning.","On the Conflict between Robustness and Learning in Collaborative Machine Learning  \nMathilde Raynal SPRING Lab, EPFL Lausanne, Switzerland  \nCarmela Troncoso SPRING Lab, EPFL Lausanne, Switzerland  \narXiv :2402 . 13700v2 [ cs .LG] 26 Jul 2024  \nAbstract—Collaborative Machine Learning (CML) allows participants to jointly train a machine learning model while keeping their training data private. In many scenarios where CML is seen as the solution to privacy issues, such as healthrelated applications, safety is also a primary concern. To ensure that CML processes produce models that output correct and reliable decisions even in the presence of potentially untrusted participants, researchers propose to use robust aggregators to filter out malicious contributions that negatively influence the training process. In this work, we formalize the two prevalent forms of robust aggregators in the literature. We then show that neither can provide the intended protection: either they use distance-based metrics that cannot reliably identify malicious inputs to training; or use metrics based on the behavior of the loss function which create a conflict with the ability of CML participants to learn, i.e., they cannot eliminate the risk of compromise without preventing learning.  \nI. INTRODUCTION  \nCollaborative Machine Learning (CML) allows users to jointly train a machine learning model. The main argument to favor CML instead of centralized learning techniques is privacy: CML enables training of models without the users’ data leaving their device. In CML, users share model updates that act as learning proxies, e.g., gradients or model weights [47] . CML architectures differ in the means they orchestrate the sharing of updates amongst participants, with the main two approaches being server-aided (e.g., Federated Learning [47]), and peer-topeer (e.g., Decentralized Learning [43]) .  \nIn many applications where the privacy of CML is typically considered an advantage, robustness is a critical property – i.e., the reliability and correctness of the model output (e.g., prediction or classification result) . For example in health applications [1], [2], [21], [23], [31], [39], [55], [59], [63], [64], where incorrect diagnosis can threaten the life of patient; or in autonomous driving [18],[20],[27],[51],[53],[60],[78] where wrong predictions threaten the safety of passengers, bystanders, and the environment. Even in fields where robustness isnot essential for safety, it may be needed for economic reasons, such as avoiding manipulations that change content visibility in advertisement applications [42] or change credit risk prediction [28] .  \nLack of robustness may stem from either non-malicious failures, such as users having low-quality data or an unreliable network connection that prevents them from participating in the network; or from attacks performed by malicious participants whose goal is to influence the behaviour of the trained model(s) in some undesirable way. There is a  \nnumber of CML-tailored sophisticated functions to improve robustness [5], [12]–[14], [25], [26], [34]–[36], [40], [44], [46],[48], [50], [56], [69], [71]–[73], [75], [76], [78] – referred to as robust aggregators [36], byzantine resilient defenses [73], scoring mechanism [12], or even poisoning detectors [4] . These functions enable participants to evaluate the model updates they receive, and reject those that are deemed detrimental to the final model, i.e., participants learn as if there were only honest users in the network.  \nThe privacy of CML has been studied in depth [54], and there is a growing amount of attacks against state-ofthe-art robust aggregators [4], [11], [32], [36], [52], [70] and new robust aggregators protecting against state-of-theart attacks [4], [36], [40], [52], [76] . Yet, there is no formal study of robustness in collaborative scenarios. Existing work focuses solely in proving the efficiency of state-of-the-art robust aggregators against a selection ","cbCaiv9OobicBZbA","https://ap.wps.com/l/cbCaiv9OobicBZbA","pdf",928760,1,16,"English","en",105,"# Introduction\n## Collaborative Machine Learning and Privacy\n## Robustness as a Critical Property\n## Robust Aggregators and Defenses\n## Gaps in Formal Study and Evaluation\n# Contributions and Key Findings","[{\"question\":\"What problem does the document address in collaborative machine learning?\",\"answer\":\"It addresses the conflict between robustness (reliable model outputs) and learning (participants’ ability to train effectively) in collaborative machine learning under potentially untrusted participants.\"},{\"question\":\"What two prevalent forms of robust aggregators are formalized?\",\"answer\":\"The document formalizes two forms: distance-based aggregators that use distance metrics to judge updates, and behavior or loss-function-based aggregators that assess robustness through loss/error behavior.\"},{\"question\":\"Why do the proposed robust aggregators fail to provide the intended protection?\",\"answer\":\"Distance-based metrics cannot reliably identify malicious inputs, while loss/behavior-based metrics create a trade-off where preventing compromise also prevents participants from learning effectively.\"}]","On the Conflict between Robustness and Learning in Collaborative Machine Learning - Research Paper | PDF",1785733892,40,{"code":4,"msg":31,"data":32},"ok",{"site_id":24,"language":23,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"on-the-conflict-between-robustness-and-learning-in-collaborative-machine-learning-research-paper","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":20},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/on-the-conflict-between-robustness-and-learning-in-collaborative-machine-learning-research-paper/121127/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":23,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-08-04","2026-08-03",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What problem does the document address in collaborative machine learning?","Question",{"text":76,"@type":77},"It addresses the conflict between robustness (reliable model outputs) and learning (participants’ ability to train effectively) in collaborative machine learning under potentially untrusted participants.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"What two prevalent forms of robust aggregators are formalized?",{"text":81,"@type":77},"The document formalizes two forms: distance-based aggregators that use distance metrics to judge updates, and behavior or loss-function-based aggregators that assess robustness through loss/error behavior.",{"name":83,"@type":74,"acceptedAnswer":84},"Why do the proposed robust aggregators fail to provide the intended protection?",{"text":85,"@type":77},"Distance-based metrics cannot reliably identify malicious inputs, while loss/behavior-based metrics create a trade-off where preventing compromise also prevents participants from learning effectively.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":24},{"code":4,"msg":5,"data":93},[94,98,102,106,111,116,120,123,128,131,135],{"id":20,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":107,"doc_module":4,"doc_module_name":46,"category_name":108,"show_sort_weight":109,"slug":110},5,"Comic",60,"comic",{"id":112,"doc_module":4,"doc_module_name":46,"category_name":113,"show_sort_weight":114,"slug":115},6,"Technology",50,"technology",{"id":117,"doc_module":4,"doc_module_name":46,"category_name":118,"show_sort_weight":29,"slug":119},7,"Healthcare","healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":107,"slug":138},19,"General","general"]