<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>robust aggregation &#8211; Science</title>
	<atom:link href="https://scienmag.com/tag/robust-aggregation/feed/" rel="self" type="application/rss+xml" />
	<link>https://scienmag.com</link>
	<description></description>
	<lastBuildDate>Mon, 21 Sep 2026 00:10:08 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.1</generator>

<image>
	<url>https://scienmag.com/wp-content/uploads/2024/07/cropped-scienmag_ico-32x32.jpg</url>
	<title>robust aggregation &#8211; Science</title>
	<link>https://scienmag.com</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">73899611</site>	<item>
		<title>Graph Neural Networks Spot Poisoned Clients in Federated Learning Before They Sabotage the Model</title>
		<link>https://scienmag.com/graph-neural-networks-spot-poisoned-clients-in-federated-learning-before-they-sabotage-the-model/</link>
		
		<dc:creator><![CDATA[Veronica Carney]]></dc:creator>
		<pubDate>Mon, 21 Sep 2026 00:10:08 +0000</pubDate>
				<category><![CDATA[Technology and Engineering]]></category>
		<category><![CDATA[backdoor attack prevention]]></category>
		<category><![CDATA[backdoor attacks]]></category>
		<category><![CDATA[Byzantine resilience]]></category>
		<category><![CDATA[Byzantine-resilient]]></category>
		<category><![CDATA[Byzantine-resilient aggregation]]></category>
		<category><![CDATA[collaborative AI model robustness]]></category>
		<category><![CDATA[federated learning]]></category>
		<category><![CDATA[GRAB-FL]]></category>
		<category><![CDATA[Graph Neural Networks]]></category>
		<category><![CDATA[Graph-aware]]></category>
		<category><![CDATA[graph-aware anomaly detection]]></category>
		<category><![CDATA[machine learning security]]></category>
		<category><![CDATA[malicious client identification]]></category>
		<category><![CDATA[model integrity in federated systems]]></category>
		<category><![CDATA[neural network security]]></category>
		<category><![CDATA[poisoned client detection]]></category>
		<category><![CDATA[poisoning attacks]]></category>
		<category><![CDATA[privacy-preserving machine learning]]></category>
		<category><![CDATA[robust aggregation]]></category>
		<category><![CDATA[secure federated model training]]></category>
		<category><![CDATA[self-supervised learning]]></category>
		<category><![CDATA[trust modeling]]></category>
		<guid isPermaLink="false">https://scienmag.com/?p=204456</guid>

					<description><![CDATA[Researchers have developed GRAB-FL, a graph-aware federated learning framework that uses graph neural networks to assign trust scores to client updates, boosting robustness against Byzantine poisoning and backdoor attacks.]]></description>
										<content:encoded><![CDATA[<p>Federated learning has become one of the most influential paradigms in modern machine learning precisely because it promises something that seemed impossible a decade ago: training powerful shared models without ever collecting users&#8217; raw data. Instead of shipping private information to a central server, each participant trains locally and transmits only model updates, allowing smartphones, hospitals, and industrial systems to contribute to a collective intelligence while their underlying data remains at home. Yet this architectural elegance creates a dangerous blind spot. Because the server never inspects the training data, it must judge clients purely by the numerical updates they submit, and a malicious participant can exploit that opacity to degrade the global model or quietly implant hidden backdoors that trigger misbehavior under attacker-chosen conditions.</p>
<p>Researchers at Ajman University, the University of Jordan, the University of Sharjah, and Jordan University of Science and Technology have now introduced a framework designed to close this gap. In a study published in Neural Computing and Applications, Salam Fraihat and colleagues present GRAB-FL, a graph-aware, Byzantine-resilient aggregation scheme that treats the population of client updates not as a bag of independent vectors but as a living network of relationships. By modeling how each update relates to every other update through dynamic, multi-view similarity graphs, the system learns continuous trust scores that separate honest participants from adversaries, even when those adversaries adapt their behavior in response to what the global model is doing.</p>
<p>The technical problem the team tackles is known as Byzantine behavior, a term borrowed from distributed computing that describes participants who may act arbitrarily, including maliciously. Existing defenses typically rely on coordinate-wise statistics such as trimmed means, distance-based selection rules like Multi-Krum, trusted reference gradients as in FLTrust, or fixed pairwise similarity comparisons. These approaches have proven useful, but they share a structural weakness: they extract signals from the updates themselves without modeling the higher-order structure of the update population. Under non-IID data distributions, where honest clients naturally produce very different updates, and under coordinated attacks in which adversaries deliberately mimic benign statistics, these signals can become fragile and unreliable.</p>
<p>GRAB-FL reframes the detection problem through the lens of graph learning. On every aggregation round, the server constructs similarity graphs whose nodes are individual client updates and whose edges encode how alike those updates are across multiple views or feature representations. An attention-based graph neural network then processes these graphs, learning not only from each node&#8217;s own update-level features but also from relational patterns that emerge across the network. The intuition is subtle but powerful: a lone poisoned update might masquerade as benign when compared to any single neighbor, but coordinated attackers inevitably leave traces in the topology of the graph, forming clusters or exhibiting relationship patterns that honest, independently trained updates do not display.</p>
<p>A central design constraint is the threat model itself. The authors situate GRAB-FL in a bounded gray-box setting, meaning adversaries may observe the trajectory of the global model and adapt their submissions over time, but they cannot inspect the server-side trust states that the framework maintains. This assumption reflects a realistic class of attacks: sophisticated adversaries who track the evolving global model can craft updates that look plausible in any given round. GRAB-FL counters this adaptivity with an online trust model trained through self-supervised pseudo-labels derived from robust consensus statistics. Crucially, these pseudo-labels are reliability-gated: when the update population is unstable or highly dispersed, the system treats its own weak supervision as too noisy and skips the learning step rather than trusting potentially corrupted signals.</p>
<p>Once the graph neural network produces continuous trust scores, the framework does not discard conventional robust aggregation. Instead, the trust scores act as soft weights inside a base aggregation pipeline that can incorporate established filters such as Multi-Krum, trimmed mean, or Bulyan. This hybrid design means GRAB-FL inherits the theoretical guarantees of those base rules, including their standard bounded-adversary configuration requirements, while adding an adaptive layer that no fixed rule provides. Notably, the framework requires no trusted validation dataset, no ground-truth attack labels, and no attack-specific hyperparameter tuning, which distinguishes it from defenses that must be reconfigured for each anticipated threat.</p>
<p>The empirical evaluation spans five benchmarks: MNIST, Fashion-MNIST, CIFAR-10, a human activity recognition dataset, and APBench2, a standardized benchmark for availability poisoning attacks. The results are striking. Under an attack scenario with twenty percent Byzantine clients, GRAB-FL raises CIFAR-10 accuracy to 71.4 percent, compared with 65.8 percent for FLTrust and 63.2 percent for Bulyan. Against backdoor attacks, which attempt to implant hidden triggers that cause targeted misclassification while leaving overall accuracy intact, GRAB-FL reduces the attack success rate to just 11.3 percent, a substantial improvement that matters enormously for safety-critical deployments.</p>
<p>Detection performance is equally impressive. At a diagnostic threshold used solely for post-hoc reporting, the framework correctly identifies malicious clients with 91.7 percent accuracy while maintaining a false-positive rate of only 6.4 percent, meaning few honest participants are unfairly penalized. Sweeping the detection threshold across its range yields an area under the ROC curve of 0.957 and a precision-recall AUC of 0.881, indicating that the trust scores rank malicious updates reliably rather than merely separating them at one convenient operating point. The computational cost is modest: GRAB-FL adds roughly eighteen percent server-side runtime in the reported setup and, importantly, no additional communication rounds, preserving the communication efficiency that makes federated learning practical in the first place.</p>
<p>The authors are candid about the framework&#8217;s boundaries. Because graph construction requires access to individually submitted updates, GRAB-FL preserves raw-data locality but is not directly compatible with conventional secure aggregation protocols, which deliberately reveal only the aggregate of all updates and keep every individual contribution hidden. Reconciling per-client graph analysis with cryptographic privacy guarantees remains an open challenge, and the researchers position their work as a step within a broader design space rather than a final answer. Nevertheless, the combination of adaptivity, self-supervision, and compatibility with existing robust aggregation rules suggests a practical path forward for defenders facing increasingly strategic adversaries.</p>
<p>The significance of this work extends well beyond a single benchmark. Federated learning is rapidly expanding into 6G network security, drone-enabled learning systems, and healthcare informatics, domains where a successful poisoning attack could have severe real-world consequences. As attackers grow more adaptive and coordinated, static defenses built on fixed statistical assumptions will continue to erode. By teaching the aggregation server to see the hidden geometry of its clients&#8217; relationships, GRAB-FL demonstrates that the structure of the update population itself carries a defense signal, one that adversaries cannot easily fake without revealing themselves. In the ongoing arms race between collaborative machine learning and those who would corrupt it, that shift from inspecting individual updates to reasoning over relational patterns may prove decisive.</p>
<p><strong>Subject of Research:</strong> Byzantine-resilient federated learning using graph neural networks for adaptive detection of poisoning attacks</p>
<p><strong>Article Title:</strong> Graph-aware Byzantine-resilient aggregation for adaptive poisoning detection in federated learning</p>
<p><strong>Article References:</strong> Fraihat, S., Sanjalawe, Y., Yaseen, Q. M., Al-Betar, M. A., &amp; Naser Makhadmeh, S. (2026). Graph-aware Byzantine-resilient aggregation for adaptive poisoning detection in federated learning. <em>Neural Computing and Applications, 38</em>(18), Article 743. <a href="https://doi.org/10.1007/s00521-026-12446-9" rel="noopener noreferrer">https://doi.org/10.1007/s00521-026-12446-9</a></p>
<p><strong>Image Credits:</strong> AI Generated</p>
<p><strong>DOI:</strong> <a href="https://doi.org/10.1007/s00521-026-12446-9" rel="noopener noreferrer">10.1007/s00521-026-12446-9</a></p>
<p><strong>Keywords:</strong> federated learning, Byzantine resilience, graph neural networks, poisoning attacks, robust aggregation, trust modeling, backdoor attacks, machine learning security, GRAB-FL, self-supervised learning, Graph-aware, Byzantine-resilient</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">204456</post-id>	</item>
		<item>
		<title>Auditable certificates measure client update value in personalized federated learning</title>
		<link>https://scienmag.com/auditable-certificates-measure-client-update-value-in-personalized-federated-learning/</link>
		
		<dc:creator><![CDATA[Veronica Carney]]></dc:creator>
		<pubDate>Sun, 13 Sep 2026 01:31:58 +0000</pubDate>
				<category><![CDATA[Technology and Engineering]]></category>
		<category><![CDATA[auditability]]></category>
		<category><![CDATA[auditable certificates in machine learning]]></category>
		<category><![CDATA[client update utility measurement]]></category>
		<category><![CDATA[cross-client update validation]]></category>
		<category><![CDATA[Data Privacy]]></category>
		<category><![CDATA[data privacy in federated model training]]></category>
		<category><![CDATA[enhancing trust in federated learning]]></category>
		<category><![CDATA[FedAvg]]></category>
		<category><![CDATA[federated averaging improvement techniques]]></category>
		<category><![CDATA[federated learning]]></category>
		<category><![CDATA[Federated learning verification]]></category>
		<category><![CDATA[human activity recognition]]></category>
		<category><![CDATA[label corruption]]></category>
		<category><![CDATA[Machine learning]]></category>
		<category><![CDATA[model contribution attribution in federated networks]]></category>
		<category><![CDATA[model performance auditing in distributed systems]]></category>
		<category><![CDATA[negative log-likelihood]]></category>
		<category><![CDATA[personalized federated learning]]></category>
		<category><![CDATA[personalized federated learning security]]></category>
		<category><![CDATA[reliability certificates]]></category>
		<category><![CDATA[reliability metadata for client updates]]></category>
		<category><![CDATA[robust aggregation]]></category>
		<category><![CDATA[update utility]]></category>
		<category><![CDATA[verifiable model updates in federated systems]]></category>
		<guid isPermaLink="false">https://scienmag.com/?p=200484</guid>

					<description><![CDATA[A new study introduces auditable update-utility certificates that verifiably measure the value of each client's contribution in personalized federated learning across chemistry, image and human activity benchmarks.]]></description>
										<content:encoded><![CDATA[<p>Federated learning has become one of the most consequential architectures in modern machine learning, allowing hospitals, banks, factories and smartphone networks to train shared models without moving sensitive data off site. Yet the approach has long carried an uncomfortable question: when a server blends updates from dozens or hundreds of clients, how can anyone verify that a particular contribution actually helped? A new study published in the International Journal of Data Science and Analytics by Koffka Khan of The University of the West Indies proposes an answer in the form of auditable cross-client update-utility certificates, a mechanism that attaches verifiable reliability metadata to every client update so that its predicted value for other participants can be measured, checked and defended after the fact.</p>
<p>The core idea is deceptively simple. In conventional federated averaging, known as FedAvg, the server weights client updates largely by data volume, with little regard for whether an update genuinely improves the model for everyone else. Khan&#8217;s framework instead asks other clients to evaluate each clipped update on disjoint certificate records, producing a point-gain estimate that reflects how much the update reduces error on data the contributing client never saw. These estimates become certificates: compact, auditable artifacts that trace a verifiable route from raw verifier evidence to the influence a client ultimately exerts on the aggregated model. Because the certificates are computed from held-out records and clipped updates, they resist both accidental miscalibration and deliberate manipulation.</p>
<p>The evidence for the approach is organized into three empirical stages, each designed to test a different layer of the claim. Stage I retains coefficient-level benchmarks across four domains, including public high-throughput chemistry spreadsheets, published voltage-controlled magnetic anisotropy source data, the Wisconsin Diagnostic Breast Cancer dataset and the Golub leukemia transcriptomic dataset. In the high-throughput chemistry setting, the certificate-weighted method delivered a 1.52 percent reduction in root-mean-squared error relative to federated averaging, a modest but consistent signal that utility-aware weighting can extract real gains even in small, heterogeneous scientific datasets.</p>
<p>Stage II moved to locked, confirmatory image experiments using Fashion-MNIST and CIFAR-10 with twenty non-identically distributed clients, forty rounds of training, and ten confirmatory random seeds. The non-IID design matters because real federated deployments rarely enjoy balanced data: each client&#8217;s distribution differs in ways that can poison naive averaging. Across all four dataset-scenario cells, point-gain weighting improved the negative log-likelihood, a strict probabilistic measure of prediction quality, over standard FedAvg. The study also examined a two-phase regime in which the server first pretrains a federated model and clients then fine-tune locally for personalization. Federated pretraining followed by local fine-tuning beat Local-only prediction in every image-dataset seed and regime, reinforcing the practical case for personalization pipelines built on trustworthy aggregation.</p>
<p>Stage III provided the most demanding test: an independent, frozen-configuration replication on the Human Activity Recognition Using Smartphones dataset from the UCI Machine Learning Repository, in which natural subject identifiers served as client partitions. The experiment ran 110 rounds with forty new random seeds, none of which were tuned after the configuration was locked. To stress the system under realistic data-quality threats, the researchers introduced fitting-label corruption, a scenario in which the labels a client uses to fit its update no longer reflect ground truth. Under this corruption, contextual marginal weighting reduced the participating-subject negative log-likelihood from 0.2199 under FedAvg and 0.1768 under an equal-access PointGainFedAvg control to 0.1730.</p>
<p>Those gains were not statistical noise. The paired improvements of 0.0468 over FedAvg and 0.00375 over the PointGainFedAvg control carried Holm-adjusted p-values of 3.64 times ten to the minus twelve and 0.00251 respectively, comfortably below conventional significance thresholds even after conservative correction for multiple comparisons. Crucially, natural performance remained within prespecified noninferiority margins, meaning the certificate machinery did not sacrifice accuracy on uncorrupted data in exchange for robustness under attack. That combination, significant gains under corruption without degradation under normal conditions, is precisely the profile regulators and industry operators demand from reliability mechanisms.</p>
<p>Perhaps the most striking result concerns auditability itself. The marginal certificate reproduced on a disjoint audit split with a Spearman correlation of 0.980, indicating that the utility scores computed during training faithfully predict utility measured on entirely separate records. Furthermore, as the researchers increased the level of label corruption, the certificate value declined even after controlling for certificate size and entropy, demonstrating that the score tracks genuine update quality rather than superficial statistics of the update. In other words, the certificate behaves like an instrument: it responds to the signal it claims to measure, and it can be re-verified by an independent auditor using data the original evaluation never touched.</p>
<p>The implications extend well beyond benchmark datasets. Federated learning now underpins multi-institutional medical imaging collaborations, fraud detection in electronic payment streams, condition monitoring in the Industrial Internet of Things, and privacy-preserving analytics across smartphone fleets. In each of these settings, a single corrupted or adversarial client can silently degrade a shared model, and existing Byzantine-robust aggregation schemes typically reject outliers without explaining why. Update-utility certificates invert that logic: instead of merely filtering bad actors, they generate positive, auditable evidence of value, giving every participant a defensible account of why each client&#8217;s contribution was weighted as it was. For regulated industries, that audit trail could prove as important as the accuracy gains themselves, since it aligns federated aggregation with emerging accountability and data-governance requirements.</p>
<p>The study also situates itself within the broader trajectory of personalized federated learning research. Prior approaches, from SCAFFOLD&#8217;s controlled averaging to FedBN&#8217;s local batch normalization and variational Bayesian personalization, have attacked the heterogeneity problem from the optimization and modeling sides. Khan&#8217;s contribution addresses the trust side, supplying the reliability metadata that personalized pipelines need before they can safely aggregate. The work draws on a long lineage of multisensor data fusion, robust statistics and differential privacy, and it deliberately uses only public secondary datasets, from chemistry reaction yields to smartphone accelerometer readings, analyzed in de-identified form. The author reports no competing interests and no specific funding, and the experiments relied exclusively on data whose creators are publicly acknowledged.</p>
<p>Taken together, the three stages establish a replicated pattern rather than a one-off result: point-gain improvements confirmed across seeds and datasets, an aggregate-context benefit on natural client partitions under label-quality degradation, and an auditable route from verifier evidence to client influence. As federated deployments scale into domains where a wrong prediction carries clinical, financial or safety consequences, mechanisms that make the value of every update verifiable may shift from a research curiosity to a baseline requirement. The certificate framework suggests that the next generation of federated systems will not merely average their clients&#8217; work; they will be able to prove, record by record, why that averaging was justified.</p>
<p><strong>Subject of Research:</strong> Auditable update-utility certificates for improving aggregation and accountability in personalized federated learning</p>
<p><strong>Article Title:</strong> Auditable update-utility certificates for personalized federated learning</p>
<p><strong>Article References:</strong> Khan, K. (2026). Auditable update-utility certificates for personalized federated learning. <em>International Journal of Data Science and Analytics, 22</em>(1), Article 295. <a href="https://doi.org/10.1007/s41060-026-01264-w" rel="noopener noreferrer">https://doi.org/10.1007/s41060-026-01264-w</a></p>
<p><strong>Image Credits:</strong> AI Generated</p>
<p><strong>DOI:</strong> <a href="https://doi.org/10.1007/s41060-026-01264-w" rel="noopener noreferrer">10.1007/s41060-026-01264-w</a></p>
<p><strong>Keywords:</strong> federated learning, personalized federated learning, update utility, reliability certificates, auditability, FedAvg, label corruption, negative log-likelihood, human activity recognition, data privacy, robust aggregation, machine learning</p>
]]></content:encoded>
					
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">200484</post-id>	</item>
	</channel>
</rss>
