Tight Stability Bounds for Robust Distributed Learning: Byzantine Failures Hurt Generalization More than Data Poisoning
Abstract
Lay Summary
Training modern artificial intelligence requires multitudes of connected devices (or institutes) working together. However, some of these devices inevitably malfunction or get hacked. Researchers categorize these rogue devices into two groups: data poisoners, who feed the AI bad information but follow the training rules, and Byzantine attackers, who spy on communications and break all the rules. Researchers had previously developed a theory predicting that both types of attacks damaged the AI equally. This is surprising because Byzantine workers have more capabilities, and real-world tests consistently highlighted that AI models attacked by Byzantine devices performed significantly worse when tested on brand-new, unseen situations. We solve this paradox by providing the first mathematical proof showing why Byzantine attackers are more destructive to an AI’s performance guarantees. By proving this difference, our work provides a principled path for defending future AI systems.