cs.LGSep 14, 2025

On the Escaping Efficiency of Distributed Adversarial Training Algorithms

Authors: Ying Cao, Kun Yuan, Ali H. Sayed

Organizations: Institute of Electrical and Micro Engineering in EPFL, Lausanne · Center for Machine Learning Research (CMLR) in Peking University

Abstract

Adversarial training has been widely studied in recent years due to its role in improving model robustness against adversarial attacks. This paper focuses on comparing different distributed adversarial training algorithms--including centralized and decentralized strategies--within multi-agent learning environments. Previous studies have highlighted the importance of model flatness in determining robustness. To this end, we develop a general theoretical framework to study the escaping efficiency of these algorithms from local minima, which is closely related to the flatness of the resulting models. We show that when the perturbation bound is sufficiently small (i.e., when the attack strength is relatively mild) and a large batch size is used, decentralized adversarial training algorithms--including consensus and diffusion--are guaranteed to escape faster from local minima than the centralized strategy, thereby favoring flatter minima. However, as the perturbation bound increases, this trend may no longer hold. In the simulation results, we illustrate our theoretical findings and systematically compare the performance of models obtained through decentralized and centralized adversarial training algorithms. The results highlight the potential of decentralized strategies to enhance the robustness of models in distributed settings.

Figures & tables

Appendix figures & tables24 assets

Supplementary material from the paper’s appendix.

Appendix

Explore similar work

CardsList
  1. Decentralized SGD with Controlled Disagreement Finds Flatter Minima

    Feb 2, 2026Zesen Wang, Mikael JohanssonDecentralized LearningStochastic Gradient Descent

  2. Robust Alignment: Harmonizing Clean Accuracy and Adversarial Robustness in Adversarial Training

    Apr 29, 2026Yanyun Wang, Qingqing Ye, Li Liu +2Adversarial TrainingHarmonization

  3. \mathsf{VISTA}: Decentralized Machine Learning in Adversary Dominated Environments

    May 8, 2026Hanzaleh Akbari Nodehi, Parsa Moradi, Soheil Mohajer +1Bounded AdversaryAdversarial Robustness