SupplementaryMaterial
–Neural Information Processing Systems
For RFA of [5], the maximum iteration is set to 10. In this setup, the learning rate is decayed for all three schemes (Sageflow,RFA,FedAvg). The number of poisoned images inabatch is20, and we do not decay the learningratehere. Figure 1 shows theperformance under theno-scaled backdoor attack with only adversaries (nostragglers). The loss associated with a poisoned device increases if we increase the scale factor from 0.1 to 10.
Neural Information Processing Systems
Feb-7-2026, 08:46:06 GMT
- Country:
- North America > United States > Virginia (0.04)
- Industry:
- Health & Medicine (0.48)
- Information Technology > Security & Privacy (0.35)
- Technology: