Ditto: Fair and Robust Federated Learning Through Personalization
Tian LiShengyuan HuAhmad BeiramiVirginia Smith
Introduces Ditto, a scalable personalized federated learning framework that resolves the competing constraints of device fairness and defense against data and model poisoning attacks in statistically heterogeneous networks.
Federated learning enables multiple remote devices to train a shared machine learning model collaboratively without centralizing their local data. In real-world enterprise deployments, these networks face significant statistical diversity because user data varies widely across devices. System operators must simultaneously satisfy multiple operational requirements: high model accuracy, fairness (ensuring uniform performance across all participating devices), and robustness (defending against malicious data or model poisoning attacks). Existing methods address fairness and defense in isolation, but these objectives directly conflict. Prior fair approaches overfit to corrupted participants by giving them extra weight, while traditional robust defenses often filter out rare, benign data distributions, causing severe performance disparities.
The article demonstrates how a personalized federated learning framework can inherently resolve the conflict between fairness and robustness. It proposes and evaluates Ditto, a multi-task learning approach that optimizes a local model for each device while regularizing it to stay close to an aggregate global model.
To evaluate the approach, the authors developed a mathematical analysis for linear models and carried out extensive empirical experiments across standard vision and language federated learning benchmarks, including FEMNIST, Fashion-MNIST, CelebA, and StackOverflow. The evaluation covered both convex and non-convex models under three common attack categories: label poisoning, random updates, and model replacement. The authors compared Ditto against state-of-the-art fair algorithms, robust aggregation baselines, and recent personalization techniques.
The investigation produced several key findings. First, personalization inherently improves resilience to attacks: Ditto achieved an average absolute test accuracy improvement of about 6 percentage points over the strongest robust defense baseline across all datasets and attack scenarios. Second, Ditto enhanced network fairness, reducing the variance in test accuracy across devices by approximately 10% while raising absolute test accuracy by 5 percentage points relative to state-of-the-art fair baselines on clean data. Third, under aggressive model poisoning where standard fair and global methods suffered catastrophic performance drops or failed to converge, Ditto maintained stable, high performance. Fourth, Ditto matched or exceeded alternative personalization methods without adding computational complexity, and it delivered further performance gains when combined directly with standard robust aggregation defenses.
These findings indicate that addressing data diversity through lightweight personalization allows organizations to resolve the trade-off between security and fair service delivery. In practical terms, Ditto protects system accuracy against adversarial devices without sacrificing performance on benign users who possess atypical data patterns. Because it shares only the standard updates required by base federated learning algorithms, it also avoids communication overhead and preserves existing privacy protections.
Organizations deploying federated learning systems should consider adopting personalized objectives like Ditto as a modular enhancement to their current pipelines. Engineering teams should implement local hyperparameter selection using on-device validation data, using smaller regularization values when attacks are suspected to allow benign devices to decouple from a compromised global model. When operating in high-threat environments, teams should combine personalized objectives with server-side robust aggregators for defense-in-depth.
These conclusions are supported by theoretical proofs on linear models and consistent empirical outcomes across diverse benchmarks. However, leaders should note that the evaluation assumes devices can reasonably distinguish attack intensity to tune regularization parameters, and the study focused primarily on training-time data and model poisoning. Further validation is recommended before deployment against other threat models, such as targeted backdoor attacks.
- Paper: Federated Optimization in Heterogeneous Networks, Tian Li et al. (2018). It introduces proximal regularization in federated optimization to address statistical and systems heterogeneity, providing the foundational optimization framework adapted by Ditto for local personalization.
- Paper: Federated Multi-Task Learning, Virginia Smith et al. (2017). It establishes the multi-task formulation for distributed learning across heterogeneous edge devices, motivating Ditto's formulation of personalized federated objectives.
- Paper: Local Model Poisoning Attacks to Byzantine-Robust Federated Learning, Minghong Fang et al. (2019). It analyzes model poisoning attacks against robust federated learning aggregation, establishing key threat models and robustness challenges evaluated in Ditto.
- Paper: Byzantine-Robust Distributed Learning: Towards Optimal Statistical Rates, Dong Yin et al. (2018). It provides theoretical rates and robust aggregation baselines (trimmed mean and median) against Byzantine failures that serve as core comparison methods in Ditto.
- Paper: LEAF: A Benchmark for Federated Settings, Sebastian Caldas et al. (2018). It provides the benchmark suite and evaluation metrics for statistical heterogeneity across federated datasets that are directly used to validate Ditto.
- Paper: Communication-Efficient Learning of Deep Networks from Decentralized Data, H. B. McMahan et al. (2016). It introduces standard Federated Averaging (FedAvg), the core baseline and foundational algorithm upon which federated learning extensions are constructed.
- Paper: Personalized Federated Learning with Moreau Envelopes, Canh T. Dinh et al. (2020). It develops pFedMe using Moreau envelope regularization for personalized federated learning, offering a closely related bi-level optimization alternative to the personalized formulations in Ditto.
- Paper: Federated Learning on Non-IID Data Silos: An Experimental Study, Qinbin Li et al. (2021). It provides an experimental benchmark analyzing the effects of non-IID distributions on federated learning algorithms, extending the evaluation of client heterogeneity challenges studied in Ditto.
- Paper: Model-Contrastive Federated Learning, Qinbin Li et al. (2021). It introduces model-contrastive learning to correct local model drift in heterogeneous federated settings, building on research addressing statistical heterogeneity.
- Paper: Tackling the Objective Inconsistency Problem in Heterogeneous Federated Optimization, Jianyu Wang et al. (2020). It tackles objective inconsistency and client drift in heterogeneous federated optimization through normalized averaging, continuing the study of optimization trade-offs in non-IID networks.
