| @article{boudou2025generalization, |
| title={Byzantine Failures Harm the Generalization of Robust Distributed Learning Algorithms More Than Data Poisoning}, |
| author={Boudou, Thomas and Le Bars, Batiste and Gupta, Nirupam and Bellet, Aur{\'e}lien}, |
| journal={arXiv preprint arXiv:2506.18020v2}, |
| year={2025} |
| } |
| |
| @article{Sabater2022a, |
| author = {C\'esar Sabater and Aur\'elien Bellet and Jan Ramon}, |
| title = {{A}n {A}ccurate, {S}calable and {V}erifiable {P}rotocol for {F}ederated {D}ifferentially {P}rivate {A}veraging}, |
| journal = {Machine Learning}, |
| year = {2022}, |
| volume = {111}, |
| pages = {4249--4293} |
| } |
| |
| @inproceedings{DBLP:conf/ccs/AbbaszadehPK024, |
| author = {Kasra Abbaszadeh and Christodoulos Pappas and Jonathan Katz and Dimitrios Papadopoulos}, |
| title = {Zero-Knowledge Proofs of Training for Deep Neural Networks}, |
| booktitle = {CCS}, |
| year = {2024} |
| } |
| |
| @inproceedings{Shamsabadi2024a, |
| author = {Ali Shahin Shamsabadi and Gefei Tan and Tudor Ioan Cebere and Aurélien Bellet and Hamed Haddadi and Nicolas Papernot and Xiao Wang and Adrian Weller}, |
| title = {{C}onfidential-{DP}proof: {C}onfidential {P}roof of {D}ifferentially {P}rivate {T}raining}, |
| booktitle = {ICLR}, |
| year = {2024} |
| } |
| |
| |
| @book{bach-ltfp, |
| title={Learning Theory from First Principles}, |
| author={Bach, F.}, |
| series={Adaptive Computation and Machine Learning series}, |
| year={2024}, |
| publisher={MIT Press} |
| } |
| |
| @book{boucheron2013concentration, |
| title={Concentration Inequalities: A Nonasymptotic Theory of Independence}, |
| author={Boucheron, S. and Lugosi, G. and Massart, P.}, |
| year={2013}, |
| publisher={Oxford University Press} |
| } |
| |
| @book{rudin, |
| author = {Rudin, Walter}, |
| title = {Real and complex analysis, 3rd ed.}, |
| year = {1987}, |
| publisher = {McGraw-Hill, Inc.}, |
| } |
| |
| @book{Vershynin_2018, |
| place={Cambridge}, |
| series={Cambridge Series in Statistical and Probabilistic Mathematics}, |
| title={High-Dimensional Probability: An Introduction with Applications in Data Science}, |
| publisher={Cambridge University Press}, |
| author={Vershynin, Roman}, |
| year={2018}, |
| } |
| |
| @InProceedings{NIPS2007_bottou_bousquet, |
| author = {Bottou, L\'{e}on and Bousquet, Olivier}, |
| booktitle = {NeurIPS}, |
| title = {The Tradeoffs of Large Scale Learning}, |
| year = {2007} |
| } |
| |
| @InProceedings{pmlr-v202-allouah23a, |
| title = {On the Privacy-Robustness-Utility Trilemma in Distributed Learning}, |
| author = {Allouah, Youssef and Guerraoui, Rachid and Gupta, Nirupam and Pinot, Rafael and Stephan, John}, |
| booktitle = {ICML}, |
| year = {2023}, |
| } |
| |
| @InProceedings{pmlr-v235-le-bars24a, |
| title = {Improved Stability and Generalization Guarantees of the Decentralized {SGD} Algorithm}, |
| author = {Le Bars, Batiste and Bellet, Aur\'{e}lien and Tommasi, Marc and Scaman, Kevin and Neglia, Giovanni}, |
| booktitle = {ICML}, |
| year = {2024}, |
| } |
| |
| @InProceedings{pmlr-v151-noble22a, |
| title = {Differentially Private Federated Learning on Heterogeneous Data}, |
| author = {Noble, Maxence and Bellet, Aur\'elien and Dieuleveut, Aymeric}, |
| booktitle = {AISTATS}, |
| year = {2022}, |
| } |
| |
| @article{MAL-083, |
| year = {2021}, |
| volume = {14}, |
| journal = {Foundations and Trends® in Machine Learning}, |
| title = {Advances and Open Problems in Federated Learning}, |
| number = {1–2}, |
| pages = {1-210}, |
| author = {Peter Kairouz and H. Brendan McMahan and Brendan Avent and Aurélien Bellet and Mehdi Bennis and Arjun Nitin Bhagoji and Kallista Bonawitz and Zachary Charles and Graham Cormode and Rachel Cummings and Rafael G. L. D’Oliveira and Hubert Eichner and Salim El Rouayheb and David Evans and Josh Gardner and Zachary Garrett and Adrià Gascón and Badih Ghazi and Phillip B. Gibbons and Marco Gruteser and Zaid Harchaoui and Chaoyang He and Lie He and Zhouyuan Huo and Ben Hutchinson and Justin Hsu and Martin Jaggi and Tara Javidi and Gauri Joshi and Mikhail Khodak and Jakub Konecný and Aleksandra Korolova and Farinaz Koushanfar and Sanmi Koyejo and Tancrède Lepoint and Yang Liu and Prateek Mittal and Mehryar Mohri and Richard Nock and Ayfer Özgür and Rasmus Pagh and Hang Qi and Daniel Ramage and Ramesh Raskar and Mariana Raykova and Dawn Song and Weikang Song and Sebastian U. Stich and Ziteng Sun and Ananda Theertha Suresh and Florian Tramèr and Praneeth Vepakomma and Jianyu Wang and Li Xiong and Zheng Xu and Qiang Yang and Felix X. Yu and Han Yu and Sen Zhao} |
| } |
| |
| @InProceedings{pmlr-v206-allouah23a, |
| title = {Fixing by Mixing: A Recipe for Optimal Byzantine ML under Heterogeneity}, |
| author = {Allouah, Youssef and Farhadkhani, Sadegh and Guerraoui, Rachid and Gupta, Nirupam and Pinot, Rafael and Stephan, John}, |
| booktitle = {AISTATS}, |
| year = {2023}, |
| } |
| |
| @inproceedings{iclr-2020-coherent-gradient, |
| author = {Chatterjee, Satrajit}, |
| booktitle = {ICLR}, |
| title = {Coherent gradients: An approach to understanding generalization in gradient descentbased optimization}, |
| year = {2020}, |
| conference = {ICLR}, |
| } |
| |
| @article{Cheu2018DistributedDP, |
| title={Distributed Differential Privacy via Shuffling}, |
| author={Albert Cheu and Adam D. Smith and Jonathan Ullman and David Zeber and Maxim Zhilyaev}, |
| journal={EUROCRYPT}, |
| year={2018}, |
| } |
| |
| |
| @InProceedings{pmlr-v151-cyffers22a, |
| title = { Privacy Amplification by Decentralization }, |
| author = {Cyffers, Edwige and Bellet, Aur\'elien}, |
| booktitle = {AISTATS}, |
| year = {2022}, |
| } |
| |
| |
| @InProceedings{pmlr-v202-farhadkhani23a, |
| title = {Robust Collaborative Learning with Linear Gradient Overhead}, |
| author = {Farhadkhani, Sadegh and Guerraoui, Rachid and Gupta, Nirupam and Hoang, L\^{e}-Nguy\^{e}n and Pinot, Rafael and Stephan, John}, |
| booktitle = {ICML}, |
| year = {2023}, |
| } |
| |
| |
| @InProceedings{pmlr-v162-farhadkhani22a, |
| title = {{B}yzantine Machine Learning Made Easy By Resilient Averaging of Momentums}, |
| author = {Farhadkhani, Sadegh and Guerraoui, Rachid and Gupta, Nirupam and Pinot, Rafael and Stephan, John}, |
| booktitle = {ICML}, |
| year = {2022}, |
| } |
| |
| @article{gerraoui-byzantine-primer, |
| author = {Guerraoui, Rachid and Gupta, Nirupam and Pinot, Rafael}, |
| title = {Byzantine Machine Learning: A Primer}, |
| year = {2024}, |
| volume = {56}, |
| number = {7}, |
| journal = {ACM Computing Surveys}, |
| articleno = {169}, |
| } |
| |
| @inproceedings{robustness-implies-privacy, |
| author = {Hopkins, Samuel B. and Kamath, Gautam and Majid, Mahbod and Narayanan, Shyam}, |
| title = {Robustness Implies Privacy in Statistical Estimation}, |
| year = {2023}, |
| booktitle = {STOC}, |
| } |
| |
| @article{pufferfish, |
| author = {Kifer, Daniel and Machanavajjhala, Ashwin}, |
| title = {Pufferfish: A framework for mathematical privacy definitions}, |
| year = {2014}, |
| publisher = {Association for Computing Machinery}, |
| address = {New York, NY, USA}, |
| volume = {39}, |
| number = {1}, |
| journal = {ACM Trans. Database Syst.}, |
| articleno = {3}, |
| numpages = {36}, |
| } |
| |
| |
| @InProceedings{pmlr-v54-mcmahan17a, |
| title = {{Communication-Efficient Learning of Deep Networks from Decentralized Data}}, |
| author = {McMahan, Brendan and Moore, Eider and Ramage, Daniel and Hampson, Seth and Arcas, Blaise Aguera y}, |
| booktitle = {AISTATS}, |
| year = {2017}, |
| } |
| |
| @InProceedings{pmlr-v235-pierquin24a, |
| title = {Rényi Pufferfish Privacy: General Additive Noise Mechanisms and Privacy Amplification by Iteration via Shift Reduction Lemmas}, |
| author = {Pierquin, Cl\'{e}ment and Bellet, Aur\'{e}lien and Tommasi, Marc and Boussard, Matthieu}, |
| booktitle = {ICML}, |
| year = {2024}, |
| } |
| |
| |
| @InProceedings{pmlr-v238-rammal24a, |
| title = {Communication Compression for {B}yzantine Robust Learning: New Efficient Algorithms and Improved Rates}, |
| author = {Rammal, Ahmad and Gruntkowska, Kaja and Fedin, Nikita and Gorbunov, Eduard and Richtarik, Peter}, |
| booktitle = {AISTATS}, |
| year = {2024}, |
| } |
| |
| @article{Rieke_2020, |
| title={The future of digital health with federated learning}, |
| volume={3}, |
| number={1}, |
| journal={npj Digital Medicine}, |
| publisher={Springer Science and Business Media LLC}, |
| author={Rieke, Nicola and Hancox, Jonny and Li, Wenqi and Milletarì, Fausto and Roth, Holger R. and Albarqouni, Shadi and Bakas, Spyridon and Galtier, Mathieu N. and Landman, Bennett A. and Maier-Hein, Klaus and Ourselin, Sébastien and Sheller, Micah and Summers, Ronald M. and Trask, Andrew and Xu, Daguang and Baust, Maximilian and Cardoso, M. Jorge}, |
| year={2020}} |
| |
| @inproceedings{NEURIPS2018_b440509a, |
| author = {Stich, Sebastian U and Cordonnier, Jean-Baptiste and Jaggi, Martin}, |
| booktitle = {NeurIPS}, |
| title = {Sparsified SGD with Memory}, |
| year = {2018} |
| } |
| |
| @inproceedings{NEURIPS2022_04b42392, |
| author = {Ye, Jiayuan and Shokri, Reza}, |
| booktitle = {NeurIPS}, |
| title = {Differentially Private Learning Needs Hidden State (Or Much Faster Convergence)}, |
| year = {2022} |
| } |
| |
| |
| @InProceedings{pmlr-v80-yin18a, |
| title = {{B}yzantine-Robust Distributed Learning: Towards Optimal Statistical Rates}, |
| author = {Yin, Dong and Chen, Yudong and Kannan, Ramchandran and Bartlett, Peter}, |
| booktitle = {ICML}, |
| year = {2018}, |
| } |
| |
| @article{Hu_2024, |
| title={Federated Learning With Sparsified Model Perturbation: Improving Accuracy Under Client-Level Differential Privacy}, |
| volume={23}, |
| number={8}, |
| journal={IEEE Transactions on Mobile Computing}, |
| publisher={Institute of Electrical and Electronics Engineers (IEEE)}, |
| author={Hu, Rui and Guo, Yuanxiong and Gong, Yanmin}, |
| year={2024}, |
| pages={8242–8255} |
| } |
| |
| @inproceedings{Mironov_2017, |
| title={Rényi Differential Privacy}, |
| booktitle={IEEE Computer Security Foundations Symposium}, |
| publisher={IEEE}, |
| author={Mironov, Ilya}, |
| year={2017}} |
| |
| @InProceedings{dwork-dp-2006, |
| author="Dwork, Cynthia |
| and McSherry, Frank |
| and Nissim, Kobbi |
| and Smith, Adam", |
| title="Calibrating Noise to Sensitivity in Private Data Analysis", |
| booktitle="Theory of Cryptography", |
| year="2006", |
| publisher="Springer Berlin Heidelberg", |
| address="Berlin, Heidelberg", |
| pages="265--284", |
| } |
| |
| @inproceedings{Abadi_2016, series={CCS’16}, |
| title={Deep Learning with Differential Privacy}, |
| booktitle={Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security (CCS)}, |
| publisher={ACM}, |
| author={Abadi, Martin and Chu, Andy and Goodfellow, Ian and McMahan, H. Brendan and Mironov, Ilya and Talwar, Kunal and Zhang, Li}, |
| year={2016}, |
| collection={CCS’16} |
| } |
| |
| @inbook{Murtagh_2015, |
| title={The Complexity of Computing the Optimal Composition of Differential Privacy}, |
| booktitle={Theory of Cryptography}, |
| publisher={Springer Berlin Heidelberg}, |
| author={Murtagh, Jack and Vadhan, Salil}, |
| year={2015}, |
| pages={157–175} |
| } |
| |
| @inbook{Kawaguchi_2022, |
| title={Generalization in Deep Learning}, |
| booktitle={Mathematical Aspects of Deep Learning}, |
| publisher={Cambridge University Press}, |
| author={Kawaguchi, K. and Bengio, Y. and Kaelbling, L.}, |
| year={2022}, |
| pages={112–148} |
| } |
| |
| |
| @book{bookguerraoui2024robust, |
| title={Robust Machine Learning: Distributed Methods for Safe AI}, |
| author={Guerraoui, R. and Gupta, N. and Pinot, R.}, |
| series={Machine Learning: Foundations, Methodologies, and Applications Series}, |
| year={2024}, |
| publisher={Springer Nature Singapore, Imprint: Springer} |
| } |
| |
| @article{dong2022gaussian, |
| title={Gaussian differential privacy}, |
| author={Dong, Jinshuo and Roth, Aaron and Su, Weijie J}, |
| journal={Journal of the Royal Statistical Society: Series B (Statistical Methodology)}, |
| volume={84}, |
| number={1}, |
| pages={3--37}, |
| year={2022}, |
| } |
| |
| @article{gopi2021numerical, |
| title={Numerical composition of differential privacy}, |
| author={Gopi, Sivakanth and Lee, Yin Tat and Wutschitz, Lukas}, |
| journal={NeurIPS}, |
| year={2021} |
| } |
| |
| @misc{dpcausalproperty, |
| title={Differential Privacy as a Causal Property}, |
| author={Michael Carl Tschantz and Shayak Sen and Anupam Datta}, |
| year={2019}, |
| eprint={1710.05899}, |
| archivePrefix={arXiv}, |
| } |
| |
| @inproceedings{Lowy2021PrivateFL, |
| title={Private Federated Learning Without a Trusted Server: Optimal Algorithms for Convex Losses}, |
| author={Andrew Lowy and Meisam Razaviyayn}, |
| booktitle={ICLR}, |
| year={2021}, |
| } |
| |
| |
| @InProceedings{pmlr-v206-lowy23a, |
| title = {Private Non-Convex Federated Learning Without a Trusted Server}, |
| author = {Lowy, Andrew and Ghafelebashi, Ali and Razaviyayn, Meisam}, |
| booktitle = {AISTATS}, |
| year = {2023}, |
| } |
| |
| @article{Bousquet2002StabilityAG, |
| title={Stability and Generalization}, |
| author={Olivier Bousquet and Andr{\'e} Elisseeff}, |
| journal={JMLR}, |
| year={2002}, |
| volume={2}, |
| pages={499-526}, |
| } |
| |
| |
| @InProceedings{pmlr-v125-bousquet20b, |
| title = {Sharper Bounds for Uniformly Stable Algorithms}, |
| author = {Bousquet, Olivier and Klochkov, Yegor and Zhivotovskiy, Nikita}, |
| booktitle = {COLT}, |
| year = {2020}, |
| } |
| |
| |
| @InProceedings{pmlr-v80-kuzborskij18a, |
| title = {Data-Dependent Stability of Stochastic Gradient Descent}, |
| author = {Kuzborskij, Ilja and Lampert, Christoph}, |
| booktitle = {ICML}, |
| year = {2018}, |
| } |
| |
| @inproceedings{kothari2022private, |
| title={Private robust estimation by stabilizing convex relaxations}, |
| author={Kothari, Pravesh and Manurangsi, Pasin and Velingker, Ameya}, |
| booktitle={COLT}, |
| year={2022}, |
| } |
| |
| @article{balle2018privacy, |
| title={Privacy amplification by subsampling: Tight analyses via couplings and divergences}, |
| author={Balle, Borja and Barthe, Gilles and Gaboardi, Marco}, |
| journal={NeurIPS}, |
| year={2018} |
| } |
| |
| @inproceedings{feldman2018privacy, |
| title={Privacy amplification by iteration}, |
| author={Feldman, Vitaly and Mironov, Ilya and Talwar, Kunal and Thakurta, Abhradeep}, |
| booktitle={FOCS}, |
| year={2018}, |
| organization={IEEE} |
| } |
| |
| @inproceedings{lei2020fine, |
| title={Fine-grained analysis of stability and generalization for stochastic gradient descent}, |
| author={Lei, Yunwen and Ying, Yiming}, |
| booktitle={ICML}, |
| year={2020}, |
| } |
| |
| @inproceedings{karimireddy2021learning, |
| title={Learning from history for byzantine robust optimization}, |
| author={Karimireddy, Sai Praneeth and He, Lie and Jaggi, Martin}, |
| booktitle={ICML}, |
| year={2021}, |
| } |
| |
| @article{wang2016privacylearning, |
| title={Learning with differential privacy: Stability, learnability and the sufficiency and necessity of ERM principle}, |
| author={Wang, Yu-Xiang and Lei, Jing and Fienberg, Stephen E}, |
| journal={JMLR}, |
| volume={17}, |
| number={183}, |
| pages={1--40}, |
| year={2016} |
| } |
| |
| @article{JMLR:v11:shalev-shwartz10a, |
| author = {Shai Shalev-Shwartz and Ohad Shamir and Nathan Srebro and Karthik Sridharan}, |
| title = {Learnability, Stability and Uniform Convergence}, |
| journal = {JMLR}, |
| year = {2010}, |
| volume = {11}, |
| number = {90}, |
| pages = {2635--2670}, |
| } |
| |
| @inproceedings{feldman2020does, |
| title={Does learning require memorization? a short tale about a long tail}, |
| author={Feldman, Vitaly}, |
| booktitle={Proceedings of the 52nd Annual ACM SIGACT Symposium on Theory of Computing}, |
| pages={954--959}, |
| year={2020} |
| } |
| |
| @article{zhang2021understanding, |
| title={Understanding deep learning (still) requires rethinking generalization}, |
| author={Zhang, Chiyuan and Bengio, Samy and Hardt, Moritz and Recht, Benjamin and Vinyals, Oriol}, |
| journal={Communications of the ACM}, |
| volume={64}, |
| number={3}, |
| pages={107--115}, |
| year={2021}, |
| publisher={ACM New York, NY, USA} |
| } |
| |
| @article{allouah2023can, |
| title={Can Machines Learn Robustly, Privately, and Efficiently?}, |
| author={Allouah, Youssef and Guerraoui, Rachid and Stephan, John}, |
| journal={arXiv preprint arXiv:2312.14712}, |
| year={2023} |
| } |
| |
| |
| @article{farhadkhani2024relevance, |
| title={On the Relevance of Byzantine Robust Optimization Against Data Poisoning}, |
| author={Farhadkhani, Sadegh and Guerraoui, Rachid and Gupta, Nirupam and Pinot, Rafael}, |
| journal={arXiv preprint arXiv:2405.00491}, |
| year={2024} |
| } |
| |
| @inproceedings{dworkprivacyrobust, |
| author = {Dwork, Cynthia and Lei, Jing}, |
| title = {Differential privacy and robust statistics}, |
| year = {2009}, |
| booktitle = {STOC}, |
| } |
| |
| @inproceedings{asi2023robustness2privacy, |
| title={From robustness to privacy and back}, |
| author={Asi, Hilal and Ullman, Jonathan and Zakynthinou, Lydia}, |
| booktitle={ICML}, |
| year={2023}, |
| } |
| |
| @inproceedings{NEURIPS2020_instanceoptimality, |
| author = {Asi, Hilal and Duchi, John C}, |
| booktitle = {NeurIPS}, |
| title = {Instance-optimality in differential privacy via approximate inverse sensitivity mechanisms}, |
| year = {2020} |
| } |
| |
| @article{georgiev2022privacyimpliesrobustness, |
| title={Privacy induces robustness: Information-computation gaps and sparse mean estimation}, |
| author={Georgiev, Kristian and Hopkins, Samuel}, |
| journal={NeurIPS}, |
| year={2022} |
| } |
| |
| @inproceedings{alabi2023privatelyrobust, |
| title={Privately estimating a Gaussian: Efficient, robust, and optimal}, |
| author={Alabi, Daniel and Kothari, Pravesh K and Tankala, Pranay and Venkat, Prayaag and Zhang, Fred}, |
| booktitle={STOC}, |
| year={2023} |
| } |
| |
| @article{liu2021robustanddp, |
| title={Robust and differentially private mean estimation}, |
| author={Liu, Xiyang and Kong, Weihao and Kakade, Sham and Oh, Sewoong}, |
| journal={NeurIPS}, |
| year={2021} |
| } |
| |
| @article{gu2023dpbrem, |
| title={DP-BREM: differentially-private and byzantine-robust federated learning with client momentum}, |
| author={Gu, Xiaolan and Li, Ming and Xiong, Li}, |
| journal={arXiv preprint arXiv:2306.12608}, |
| year={2023} |
| } |
| |
| @article{liu2024survey, |
| title={A survey on secure decentralized optimization and learning}, |
| author={Liu, Changxin and Bastianello, Nicola and Huo, Wei and Shi, Yang and Johansson, Karl H}, |
| journal={arXiv preprint arXiv:2408.08628}, |
| year={2024} |
| } |
| |
| @inproceedings{ye2024tradeoff, |
| title={On the tradeoff between privacy preservation and Byzantine-robustness in decentralized learning}, |
| author={Ye, Haoxiang and Zhu, Heng and Ling, Qing}, |
| booktitle={ICASSP}, |
| year={2024}, |
| organization={IEEE} |
| } |
| |
| @article{zhu2022bridging, |
| title={Bridging differential privacy and byzantine-robustness via model aggregation}, |
| author={Zhu, Heng and Ling, Qing}, |
| journal={arXiv preprint arXiv:2205.00107}, |
| year={2022} |
| } |
| |
| @inproceedings{hardt2016train, |
| title={Train faster, generalize better: Stability of stochastic gradient descent}, |
| author={Hardt, Moritz and Recht, Ben and Singer, Yoram}, |
| booktitle={ICML}, |
| year={2016}, |
| } |
| |
| @inproceedings{lugosi2022generalization, |
| title={Generalization bounds via convex analysis}, |
| author={Lugosi, G{\'a}bor and Neu, Gergely}, |
| booktitle={COLT}, |
| year={2022}, |
| } |
| |
| @article{minskertimothee2019excess, |
| title={Excess risk bounds in robust empirical risk minimization}, |
| author={Minsker, Stanislav and Mathieu, Timoth{\'e}e}, |
| journal={arXiv preprint arXiv:1910.07485}, |
| year={2019} |
| } |
| |
| @article{kawaguchi2017generalizationindl, |
| title={Generalization in deep learning}, |
| author={Kawaguchi, Kenji and Kaelbling, Leslie Pack and Bengio, Yoshua}, |
| journal={arXiv preprint arXiv:1710.05468}, |
| year={2017} |
| } |
| |
| @article{zhang2021understandingrethinkinggeneralization, |
| title={Understanding deep learning (still) requires rethinking generalization}, |
| author={Zhang, Chiyuan and Bengio, Samy and Hardt, Moritz and Recht, Benjamin and Vinyals, Oriol}, |
| journal={Communications of the ACM}, |
| volume={64}, |
| number={3}, |
| pages={107--115}, |
| year={2021}, |
| publisher={ACM New York, NY, USA} |
| } |
| |
| @inproceedings{feldman2020doeslearningrequirememorization, |
| title={Does learning require memorization? a short tale about a long tail}, |
| author={Feldman, Vitaly}, |
| booktitle={STOC}, |
| year={2020} |
| } |
| |
| @inproceedings{zhang2022stabilitytight, |
| title={Stability of sgd: Tightness analysis and improved bounds}, |
| author={Zhang, Yikai and Zhang, Wenjia and Bald, Sammy and Pingali, Vamsi and Chen, Chao and Goswami, Mayank}, |
| booktitle={UAI}, |
| year={2022}, |
| } |
| |
| @article{xu2012robustness, |
| title={Robustness and generalization}, |
| author={Xu, Huan and Mannor, Shie}, |
| journal={Machine learning}, |
| volume={86}, |
| pages={391--423}, |
| year={2012}, |
| publisher={Springer} |
| } |
| |
| @InProceedings{pmlr-v162-kawaguchi22a, |
| title = {Robustness Implies Generalization via Data-Dependent Generalization Bounds}, |
| author = {Kawaguchi, Kenji and Deng, Zhun and Luh, Kyle and Huang, Jiaoyang}, |
| booktitle = {ICML}, |
| year = {2022}, |
| } |
| |
| @InProceedings{pmlr-v161-he21a, |
| title = {Tighter Generalization Bounds for Iterative Differentially Private Learning Algorithms}, |
| author = {He, Fengxiang and Wang, Bohan and Tao, Dacheng}, |
| booktitle = {UAI}, |
| year = {2021}, |
| } |
| |
| @article{JMLR:v25:22-0068stabilitymomentum, |
| author = {Ali Ramezani-Kebrya and Kimon Antonakopoulos and Volkan Cevher and Ashish Khisti and Ben Liang}, |
| title = {On the Generalization of Stochastic Gradient Descent with Momentum}, |
| journal = {JMLR}, |
| year = {2024}, |
| volume = {25}, |
| number = {22}, |
| pages = {1--56}, |
| } |
| |
| @inproceedings{ijcai2021p427stabilityrcd, |
| title = {Stability and Generalization for Randomized Coordinate Descent}, |
| author = {Wang, Puyu and Wu, Liang and Lei, Yunwen}, |
| booktitle = {IJCAI}, |
| publisher = {International Joint Conferences on Artificial Intelligence Organization}, |
| pages = {3104--3110}, |
| year = {2021}, |
| } |
| |
| @inproceedings{nikolakakis2023beyond, |
| title={Beyond Lipschitz: Sharp Generalization and Excess Risk Bounds for Full-Batch {GD}}, |
| author={Konstantinos Nikolakakis and Farzin Haddadpour and Amin Karbasi and Dionysios Kalogerias}, |
| booktitle={ICLR}, |
| year={2023}, |
| } |
| |
| @inproceedings{NIPS2010_76cf99d3_sbrero_selfbounding, |
| author = {Srebro, Nathan and Sridharan, Karthik and Tewari, Ambuj}, |
| booktitle = {NeurIPS}, |
| title = {Smoothness, Low Noise and Fast Rates}, |
| volume = {23}, |
| year = {2010} |
| } |
| |
| @article{ying2017unregularized_selfbounding, |
| title={Unregularized online learning algorithms with general loss functions}, |
| author={Ying, Yiming and Zhou, Ding-Xuan}, |
| journal={Applied and Computational Harmonic Analysis}, |
| volume={42}, |
| number={2}, |
| pages={224--244}, |
| year={2017}, |
| publisher={Elsevier} |
| } |
| |
| @inproceedings{karimi2016linear, |
| title={Linear convergence of gradient and proximal-gradient methods under the polyak-{\l}ojasiewicz condition}, |
| author={Karimi, Hamed and Nutini, Julie and Schmidt, Mark}, |
| booktitle={Machine Learning and Knowledge Discovery in Databases}, |
| pages={795--811}, |
| year={2016}, |
| organization={Springer} |
| } |
| |
| |
| @inproceedings{deng2021toward, |
| title={Toward better generalization bounds with locally elastic stability}, |
| author={Deng, Zhun and He, Hangfeng and Su, Weijie}, |
| booktitle={ICML}, |
| year={2021}, |
| } |
| |
| @misc{bassily2022noneuclideandifferentiallyprivatestochastic, |
| title={Non-Euclidean Differentially Private Stochastic Convex Optimization: Optimal Rates in Linear Time}, |
| author={Raef Bassily and Cristóbal Guzmán and Anupama Nandi}, |
| year={2022}, |
| eprint={2103.01278}, |
| archivePrefix={arXiv}, |
| } |
| |
| @article{chandramoorthy2022generalizationstatisticalstability, |
| title={On the generalization of learning algorithms that do not converge}, |
| author={Chandramoorthy, Nisha and Loukas, Andreas and Gatmiry, Khashayar and Jegelka, Stefanie}, |
| journal={NeurIPS}, |
| volume={35}, |
| pages={34241--34257}, |
| year={2022} |
| } |
| |
| @inproceedings{zhang2022neuralinvariantmeasure, |
| title={Neural network weights do not converge to stationary points: An invariant measure perspective}, |
| author={Zhang, Jingzhao and Li, Haochuan and Sra, Suvrit and Jadbabaie, Ali}, |
| booktitle={ICML}, |
| year={2022}, |
| } |
| |
| @article{chen2018stabilityconvergencetradeoff, |
| title={Stability and convergence trade-off of iterative optimization algorithms}, |
| author={Chen, Yuansi and Jin, Chi and Yu, Bin}, |
| journal={arXiv preprint arXiv:1804.01619}, |
| year={2018} |
| } |
| |
| |
| @article{bassily2019private, |
| title={Private stochastic convex optimization with optimal rates}, |
| author={Bassily, Raef and Feldman, Vitaly and Talwar, Kunal and Guha Thakurta, Abhradeep}, |
| journal={NeurIPS}, |
| year={2019} |
| } |
| |
| @InProceedings{pmlr-v65-raginsky17a, |
| title = {Non-convex learning via Stochastic Gradient Langevin Dynamics: a nonasymptotic analysis}, |
| author = {Raginsky, Maxim and Rakhlin, Alexander and Telgarsky, Matus}, |
| booktitle = {COLT}, |
| year = {2017}, |
| } |
| |
| @InProceedings{pmlr-v75-mou18a, |
| title = {Generalization Bounds of SGLD for Non-convex Learning: Two Theoretical Viewpoints}, |
| author = {Mou, Wenlong and Wang, Liwei and Zhai, Xiyu and Zheng, Kai}, |
| booktitle = {COLT}, |
| year = {2018}, |
| } |
| |
| |
| @article{POLYAK19641, |
| title = {Some methods of speeding up the convergence of iteration methods}, |
| journal = {USSR Computational Mathematics and Mathematical Physics}, |
| volume = {4}, |
| number = {5}, |
| pages = {1-17}, |
| year = {1964}, |
| author = {B.T. Polyak}, |
| } |
| |
| @inproceedings{sun2024understanding, |
| title={Understanding generalization of federated learning via stability: Heterogeneity matters}, |
| author={Sun, Zhenyu and Niu, Xiaochun and Wei, Ermin}, |
| booktitle={AISTATS}, |
| year={2024}, |
| } |
| |
| @inproceedings{yin2018byzantine, |
| title={Byzantine-robust distributed learning: Towards optimal statistical rates}, |
| author={Yin, Dong and Chen, Yudong and Kannan, Ramchandran and Bartlett, Peter}, |
| booktitle={ICML}, |
| year={2018}, |
| } |
| |
| @InProceedings{zhu2023byzantinerobustfederatedlearningoptimal, |
| title = {Byzantine-Robust Federated Learning with Optimal Statistical Rates}, |
| author = {Zhu, Banghua and Wang, Lun and Pang, Qi and Wang, Shuai and Jiao, Jiantao and Song, Dawn and Jordan, Michael I.}, |
| booktitle = {AISTATS}, |
| year = {2023}, |
| } |
| |
| |
| |
| @INPROCEEDINGS{ye10889327, |
| author={Ye, Haoxiang and Sun, Tao and Ling, Qing}, |
| booktitle={ICASSP}, |
| title={Generalization Guarantee of Decentralized Learning with Heterogeneous Data}, |
| year={2025}, |
| } |
| |
| @ARTICLE{ye10834510, |
| author={Ye, Haoxiang and Ling, Qing}, |
| journal={IEEE Transactions on Signal Processing}, |
| title={Generalization Error Matters in Decentralized Learning Under Byzantine Attacks}, |
| year={2025}, |
| volume={73}, |
| number={}, |
| pages={843-857}, |
| } |
| |
| @INPROCEEDINGS{ye10447047, |
| author={Ye, Haoxiang and Zhu, Heng and Ling, Qing}, |
| booktitle={ICASSP}, |
| title={On the Tradeoff Between Privacy Preservation and Byzantine-Robustness in Decentralized Learning}, |
| year={2024}, |
| } |
| |
| @inproceedings{NEURIPS2024_1b96f013_lowerbound_stability, |
| author = {Wang, Rongzhen and Zheng, Chenyu and Wu, Guoqiang and Min, Xu and Zhang, Xiaolu and Zhou, Jun and Li, Chongxuan}, |
| booktitle = {NeurIPS}, |
| title = {Lower Bounds of Uniform Stability in Gradient-Based Bilevel Algorithms for Hyperparameter Optimization}, |
| year = {2024} |
| } |
| |
| |
| @InProceedings{pmlr-v134-neu21a, |
| title = {Information-Theoretic Generalization Bounds for Stochastic Gradient Descent}, |
| author = {Neu, Gergely and Dziugaite, Gintare Karolina and Haghifam, Mahdi and Roy, Daniel M.}, |
| booktitle = {COLT}, |
| year = {2021}, |
| } |
| |
| |
| @InProceedings{pmlr-v178-lugosi22a, |
| title = {Generalization Bounds via Convex Analysis}, |
| author = {Lugosi, Gabor and Neu, Gergely}, |
| booktitle = {COLT}, |
| year = {2022}, |
| } |
| |
| @article{russo2019much, |
| title={How much does your data exploration overfit? Controlling bias via information usage}, |
| author={Russo, Daniel and Zou, James}, |
| journal={IEEE Transactions on Information Theory}, |
| volume={66}, |
| number={1}, |
| pages={302--323}, |
| year={2019}, |
| publisher={IEEE} |
| } |
| |
| |
| @InProceedings{pmlr-v51-russo16, |
| title = {Controlling Bias in Adaptive Data Analysis Using Information Theory}, |
| author = {Russo, Daniel and Zou, James}, |
| booktitle = {AISTATS}, |
| year = {2016}, |
| } |
| |
| @article{JMLR:v24:21-1396-additive-noise-channels-gen, |
| author = {Hao Wang and Rui Gao and Flavio P. Calmon}, |
| title = {Generalization Bounds for Noisy Iterative Algorithms Using Properties of Additive Noise Channels}, |
| journal = {JMLR}, |
| year = {2023}, |
| volume = {24}, |
| number = {26}, |
| pages = {1--43}, |
| } |
| |
| @article{JMLR:v6:elisseeff05a, |
| author = {Andre Elisseeff and Theodoros Evgeniou and Massimiliano Pontil}, |
| title = {Stability of Randomized Learning Algorithms}, |
| journal = {JMLR}, |
| year = {2005}, |
| volume = {6}, |
| number = {3}, |
| pages = {55--79}, |
| } |
| |
| @article{vapnik74theory, |
| title={Theory of pattern recognition}, |
| author={Vapnik, Vladimir and Chervonenkis, Alexey}, |
| year={1974}, |
| journal = {Nauka}, |
| } |
| |
| @article{DevroyeWagner79, |
| author = {Devroye, Luc and Wagner, T.}, |
| year = {1979}, |
| month = {10}, |
| pages = {601 - 604}, |
| title = {Distribution-Free Performance Bounds for Potential Function Rules}, |
| volume = {IT-25}, |
| journal = {IEEE Transactions on Information Theory}, |
| } |
| |
| @article{RogersWagner78, |
| author = {Rogers, William and Wagner, T.}, |
| year = {1978}, |
| month = {05}, |
| pages = {}, |
| title = {A Finite Sample Distribution-Free Performance Bound for Local Discrimination Rules}, |
| volume = {6}, |
| journal = {The Annals of Statistics}, |
| } |
| |
| @article{baruch2019ALIE, |
| title={A little is enough: Circumventing defenses for distributed learning}, |
| author={Baruch, Gilad and Baruch, Moran and Goldberg, Yoav}, |
| journal={NeurIPS}, |
| year={2019} |
| } |
| |
| @inproceedings{xie2020FOE, |
| title={Fall of empires: Breaking byzantine-tolerant sgd by inner product manipulation}, |
| author={Xie, Cong and Koyejo, Oluwasanmi and Gupta, Indranil}, |
| booktitle={UAI}, |
| year={2020}, |
| } |
| |
| |
| @inproceedings{allen2020byzantineLF-SF, |
| title={Byzantine-Resilient Non-Convex Stochastic Gradient Descent}, |
| author={Allen-Zhu, Zeyuan and Ebrahimianghazani, Faeze and Li, Jerry and Alistarh, Dan}, |
| booktitle={ICLR}, |
| year={2021}, |
| } |
| |
| |
| |
| @InProceedings{pmlr-v80-charles18a, |
| title = {Stability and Generalization of Learning Algorithms that Converge to Global Optima}, |
| author = {Charles, Zachary and Papailiopoulos, Dimitris}, |
| booktitle = {ICML}, |
| year = {2018}, |
| } |
| |
| @article{alquier2024user, |
| title={User-friendly Introduction to PAC-Bayes Bounds}, |
| author={Alquier, Pierre}, |
| journal={Foundations and Trends{\textregistered} in Machine Learning}, |
| volume={17}, |
| number={2}, |
| pages={174--303}, |
| year={2024}, |
| publisher={Now Publishers} |
| } |
| |
| @book{vapnik1998statistical, |
| title={Statistical learning theory}, |
| author={Vapnik, Vladimir N}, |
| year={1998}, |
| publisher={Wiley-interscience} |
| } |
| |
| @article{mcallester1999pac, |
| title={PAC-Bayesian model averaging}, |
| author={McAllester, David A}, |
| journal={Machine Learning}, |
| volume={37}, |
| number={3}, |
| pages={275--299}, |
| year={1999}, |
| publisher={Springer} |
| } |
| |
| @article{goldwasser1989knowledge, |
| title={The knowledge complexity of interactive proof systems}, |
| author={Goldwasser, Shafi and Micali, Silvio and Rackoff, Charles}, |
| journal={SIAM Journal on Computing}, |
| volume={18}, |
| number={1}, |
| pages={186--208}, |
| year={1989}, |
| } |
| |
| @inproceedings{karimireddy2022byzantinerobust, |
| title={Byzantine-Robust Learning on Heterogeneous Datasets via Bucketing}, |
| author={Sai Praneeth Karimireddy and Lie He and Martin Jaggi}, |
| booktitle={ICLR}, |
| year={2022}, |
| } |
| |
| @article{lamport1982byzantine, |
| title={The Byzantine Generals Problem}, |
| author={Lamport, Leslie and Shostak, Robert and Pease, Marshall}, |
| journal={ACM Transactions on Programming Languages and Systems}, |
| volume={4}, |
| number={3}, |
| pages={382--401}, |
| year={1982} |
| } |
| |
| @inproceedings{farhadkhani2024brief, |
| title={Brief announcement: a case for byzantine machine learning}, |
| author={Farhadkhani, Sadegh and Guerraoui, Rachid and Gupta, Nirupam and Pinot, Rafael}, |
| booktitle={PODC}, |
| year={2024} |
| } |
| |
| @inproceedings{shejwalkar2021manipulating, |
| title={Manipulating the byzantine: Optimizing model poisoning attacks and defenses for federated learning}, |
| author={Shejwalkar, Virat and Houmansadr, Amir}, |
| booktitle={NDSS}, |
| year={2021} |
| } |
| |
| @article{allouah2023robust, |
| title={Robust distributed learning: Tight error bounds and breakdown point under data heterogeneity}, |
| author={Allouah, Youssef and Guerraoui, Rachid and Gupta, Nirupam and Pinot, Rafa{\"e}l and Rizk, Geovani}, |
| journal={NeurIPS}, |
| year={2023} |
| } |
| |
| @article{chen2017distributed, |
| title={Distributed statistical machine learning in adversarial settings: Byzantine gradient descent}, |
| author={Chen, Yudong and Su, Lili and Xu, Jiaming}, |
| journal={Proceedings of the ACM on Measurement and Analysis of Computing Systems}, |
| volume={1}, |
| number={2}, |
| pages={1--25}, |
| year={2017}, |
| } |
| |
| @inproceedings{steinhardt2018resilience, |
| title={Resilience: A Criterion for Learning in the Presence of Arbitrary Outliers$\}, |
| author={Steinhardt, Jacob and Charikar, Moses and Valiant, Gregory}, |
| booktitle={ITCS}, |
| year={2018}, |
| } |
| |
| @inproceedings{gorbunov2023variance, |
| title={Variance Reduction is an Antidote to Byzantines: Better Rates, Weaker Assumptions and Communication Compression as a Cherry on the Top}, |
| author={Eduard Gorbunov and Samuel Horv{\'a}th and Peter Richt{\'a}rik and Gauthier Gidel}, |
| booktitle={ICLR}, |
| year={2023}, |
| } |
| |
| @article{alistarh2018byzantine, |
| title={Byzantine stochastic gradient descent}, |
| author={Alistarh, Dan and Allen-Zhu, Zeyuan and Li, Jerry}, |
| journal={NeurIPS}, |
| year={2018} |
| } |
| |
| @inproceedings{guerraoui2018hidden, |
| title={The hidden vulnerability of distributed learning in byzantium}, |
| author={Guerraoui, Rachid and Rouault, S{\'e}bastien and others}, |
| booktitle={ICML}, |
| year={2018}, |
| } |
| |
| @inproceedings{farhadkhani2022equivalence, |
| title={An equivalence between data poisoning and byzantine gradient attacks}, |
| author={Farhadkhani, Sadegh and Guerraoui, Rachid and Villemaud, Oscar and others}, |
| booktitle={ICML}, |
| year={2022}, |
| } |
| |
| @inproceedings{pinocchio-zkp, |
| author = {Parno, Bryan and Howell, Jon and Gentry, Craig and Raykova, Mariana}, |
| year = {2013}, |
| pages = {238-252}, |
| title = {Pinocchio: Nearly Practical Verifiable Computation}, |
| volume = {59}, |
| journal = {IEEE Symposium on Security and Privacy}, |
| } |
| |
| @article{zkpThaler22, |
| author = {Justin Thaler}, |
| title = {Proofs, Arguments, and Zero-Knowledge}, |
| journal = {Foundations and Trends{\textregistered} in Privacy and Security}, |
| volume = {4}, |
| number = {2-4}, |
| pages = {117--660}, |
| year = {2022}, |
| } |
| |
| @inproceedings{liu2021approximate, |
| title={Approximate byzantine fault-tolerance in distributed optimization}, |
| author={Liu, Shuo and Gupta, Nirupam and Vaidya, Nitin H}, |
| booktitle={PODC}, |
| year={2021} |
| } |
| |
| @inproceedings{bassily2020stability, |
| title={Stability of stochastic gradient descent on nonsmooth convex losses}, |
| author={Bassily, Raef and Feldman, Vitaly and Guzm{\'a}n, Crist{\'o}bal and Talwar, Kunal}, |
| booktitle={NeurIPS}, |
| year={2020} |
| } |
| |
| @inproceedings{karimi2016linear-PL, |
| title={Linear convergence of gradient and proximal-gradient methods under the polyak-{\l}ojasiewicz condition}, |
| author={Karimi, Hamed and Nutini, Julie and Schmidt, Mark}, |
| booktitle={ECML PKDD}, |
| year={2016}, |
| } |
| |
| |
| @inproceedings{247652-fang-pois, |
| author = {Minghong Fang and Xiaoyu Cao and Jinyuan Jia and Neil Gong}, |
| title = {Local Model Poisoning Attacks to {Byzantine-Robust} Federated Learning}, |
| booktitle = {USENIX Security}, |
| year = {2020}, |
| pages = {1605--1622}, |
| } |
| |
| |
| @inproceedings{allouah2025towards, |
| title={Towards Trustworthy Federated Learning with Untrusted Participants}, |
| author={Allouah, Youssef and Guerraoui, Rachid and Stephan, John}, |
| booktitle={ICML}, |
| year={2025}, |
| } |
| |
| |
| @inproceedings{blanchard-ml-with-adversaries, |
| author = {Blanchard, Peva and El Mhamdi, El Mahdi and Guerraoui, Rachid and Stainer, Julien}, |
| booktitle = {NeurIPS}, |
| title = {Machine Learning with Adversaries: Byzantine Tolerant Gradient Descent}, |
| year = {2017} |
| } |
| |
| |
| @InProceedings{pmlr-v180-zhang22b, |
| title = {Stability of {SGD}: Tightness analysis and improved bounds}, |
| author = {Zhang, Yikai and Zhang, Wenjia and Bald, Sammy and Pingali, Vamsi and Chen, Chao and Goswami, Mayank}, |
| booktitle = {UAI}, |
| year = {2022}, |
| } |
| |
| |
| @inproceedings{song2021evading, |
| title={Evading the curse of dimensionality in unconstrained private glms}, |
| author={Song, Shuang and Steinke, Thomas and Thakkar, Om and Thakurta, Abhradeep}, |
| booktitle={AISTATS}, |
| year={2021}, |
| } |
| |
| |
| |
| |
| |
| @article{allouah2024boosting, |
| title={Boosting Robustness by Clipping Gradients in Distributed Learning}, |
| author={Allouah, Youssef and Guerraoui, Rachid and Gupta, Nirupam and Jellouli, Ahmed and Rizk, Geovani and Stephan, John}, |
| journal={arXiv preprint arXiv:2405.14432}, |
| year={2024} |
| } |
| |
| @article{karimireddy2020byzantineMimic, |
| title={Byzantine-robust learning on heterogeneous datasets via bucketing}, |
| author={Karimireddy, Sai Praneeth and He, Lie and Jaggi, Martin}, |
| journal={arXiv preprint arXiv:2006.09365}, |
| year={2020} |
| } |
| |
| @inproceedings{jung2024newanalysisdifferentialprivacys, |
| title={A new analysis of differential privacy’s generalization guarantees}, |
| author={Jung, Christopher and Ligett, Katrina and Neel, Seth and Roth, Aaron and Sharifi-Malvajerdi, Saeed and Shenfeld, Moshe}, |
| booktitle={STOC}, |
| year={2021} |
| } |
| |
| @article{chi-squared-concentration, |
| author = {Laurent, B. and Massart, Pascal}, |
| year = {2000}, |
| month = {10}, |
| pages = {}, |
| title = {Adaptive estimation of a quadratic functional by model selection}, |
| volume = {28}, |
| journal = {Annals of Statistics}, |
| } |
| |
| @article{rudelson2013hanson, |
| title={Hanson-Wright inequality and sub-Gaussian concentration}, |
| author={Rudelson, Mark and Vershynin, Roman}, |
| year={2013} |
| } |
| |
| @book{vershynin_high-dimensional_2018, |
| location = {Cambridge}, |
| title = {High-Dimensional Probability: An Introduction with Applications in Data Science}, |
| isbn = {978-1-108-41519-4}, |
| series = {Cambridge Series in Statistical and Probabilistic Mathematics}, |
| publisher = {Cambridge University Press}, |
| author = {Vershynin, Roman}, |
| date = {2018}, |
| } |
| |
| @article{koltchinskii2017concentration, |
| title={Concentration inequalities and moment bounds for sample covariance operators}, |
| author={Koltchinskii, Vladimir and Lounici, Karim}, |
| journal={Bernoulli}, |
| pages={110--133}, |
| year={2017}, |
| publisher={JSTOR} |
| } |
| |
| @article{paul-spiked-covariance, |
| author = {Debashis Paul}, |
| journal = {Statistica Sinica}, |
| number = {4}, |
| pages = {1617--1642}, |
| publisher = {Institute of Statistical Science, Academia Sinica}, |
| title = {ASYMPTOTICS OF SAMPLE EIGENSTRUCTURE FOR A LARGE DIMENSIONAL SPIKED COVARIANCE MODEL}, |
| volume = {17}, |
| year = {2007} |
| } |
| |
| |
| @article{baik2005phase, |
| title={Phase transition of the largest eigenvalue for nonnull complex sample covariance matrices}, |
| author={BAIK, Jinho and BEN AROUS, G{\'e}rard and PECHE, Sandrine}, |
| journal={Annals of probability}, |
| volume={33}, |
| number={5}, |
| pages={1643--1697}, |
| year={2005} |
| } |
| |
| @article{Cochran_1934, |
| title={The distribution of quadratic forms in a normal system, with applications to the analysis of covariance}, |
| volume={30}, |
| number={2}, |
| journal={Mathematical Proceedings of the Cambridge Philosophical Society}, |
| author={Cochran, W. G.}, |
| year={1934}, |
| pages={178–191} |
| } |
| |
| @article{li2023robustnessandprivacy, |
| title={On robustness and local differential privacy}, |
| author={Li, Mengchu and Berrett, Thomas B and Yu, Yi}, |
| journal={The Annals of Statistics}, |
| volume={51}, |
| number={2}, |
| pages={717--737}, |
| year={2023}, |
| publisher={Institute of Mathematical Statistics} |
| } |
| |
| @article{kamath2024broader, |
| title={The broader landscape of robustness in algorithmic statistics}, |
| author={Kamath, Gautam}, |
| journal={IEEE BITS the Information Theory Magazine}, |
| year={2025}, |
| } |
| |
| @inproceedings{xie2023unraveling, |
| title={Unraveling the connections between privacy and certified robustness in federated learning against poisoning attacks}, |
| author={Xie, Chulin and Long, Yunhui and Chen, Pin-Yu and Li, Qinbin and Koyejo, Sanmi and Li, Bo}, |
| booktitle={CCS}, |
| year={2023} |
| } |
| |
| @article{huber-strong-contamination, |
| author = {Peter J. Huber}, |
| journal = {The Annals of Mathematical Statistics}, |
| number = {6}, |
| pages = {1753--1758}, |
| publisher = {Institute of Mathematical Statistics}, |
| title = {A Robust Version of the Probability Ratio Test}, |
| volume = {36}, |
| year = {1965} |
| } |
| |
| @book{Diakonikolas_Kane_2023, |
| place={Cambridge}, |
| title={Algorithmic High-Dimensional Robust Statistics}, |
| publisher={Cambridge University Press}, |
| author={Diakonikolas, Ilias and Kane, Daniel M.}, |
| year={2023} |
| } |
| |
| @article{kearns-li-strong-contamination, |
| author = {Kearns, Michael and Li, Ming}, |
| title = {Learning in the Presence of Malicious Errors}, |
| journal = {SIAM Journal on Computing}, |
| volume = {22}, |
| number = {4}, |
| pages = {807-837}, |
| year = {1993}, |
| } |
| |
| @inproceedings{asi_instanceopti, |
| author = {Asi, Hilal and Duchi, John C}, |
| booktitle = {NeurIPS}, |
| title = {Instance-optimality in differential privacy via approximate inverse sensitivity mechanisms}, |
| year = {2020} |
| } |
| |
| @article{kumar2025privateGMlineartime, |
| title={Private Geometric Median in Nearly-Linear Time}, |
| author={Kumar, Syamantak and Liu, Daogao and Tian, Kevin and Yang, Chutong}, |
| journal={NeurIPS}, |
| year={2026} |
| } |
| |
| @article{haghifam2024privateGM, |
| title={Private geometric median}, |
| author={Haghifam, Mahdi and Steinke, Thomas and Ullman, Jonathan}, |
| journal={NeurIPS}, |
| year={2024} |
| } |
| |
| @article{wang2022PTRrenyi, |
| title={Renyi differential privacy of propose-test-release and applications to private and robust machine learning}, |
| author={Wang, Jiachen T and Mahloujifar, Saeed and Wang, Shouda and Jia, Ruoxi and Mittal, Prateek}, |
| journal={NeurIPS}, |
| year={2022} |
| } |
| |
| @article{bun2019average-tm-inverse-sensitivity, |
| title={Average-case averages: Private algorithms for smooth sensitivity and mean estimation}, |
| author={Bun, Mark and Steinke, Thomas}, |
| journal={NeurIPS}, |
| year={2019} |
| } |
| |
| @article{eberle2016reflection, |
| title={Reflection couplings and contraction rates for diffusions}, |
| author={Eberle, Andreas}, |
| journal={Probability theory and related fields}, |
| volume={166}, |
| number={3}, |
| pages={851--886}, |
| year={2016}, |
| publisher={Springer} |
| } |
| |
| @book{couplings-Lindvall1992Lectures, |
| title={Lectures on the Coupling Method}, |
| author={Torgny Lindvall}, |
| series={Dover Books on Mathematics Series}, |
| year={2002}, |
| publisher={Dover Publications, Incorporated} |
| } |
| |
| @misc{couplings-thorisson, |
| author = {Thorisson, Hermann.}, |
| keywords = {Random variables ; Stochastic processes}, |
| publisher = {Springer}, |
| series = {Probability and its applications}, |
| title = {Coupling, stationarity, and regeneration}, |
| year = {2000}, |
| } |
| |
| @article{farghly2021time, |
| title={Time-independent generalization bounds for SGLD in non-convex settings}, |
| author={Farghly, Tyler and Rebeschini, Patrick}, |
| journal={NeurIPS}, |
| year={2021} |
| } |
| |
| @book{wainwright2019high, |
| title={High-dimensional statistics: A non-asymptotic viewpoint}, |
| author={Wainwright, Martin J}, |
| volume={48}, |
| year={2019}, |
| publisher={Cambridge university press} |
| } |
| |
| @article{gonzalez2025byzfl, |
| title={Byzfl: Research framework for robust federated learning}, |
| author={Gonz{\'a}lez, Marc and Guerraoui, Rachid and Pinot, Rafael and Rizk, Geovani and Stephan, John and Ta{\"\i}ani, Fran{\c{c}}ois}, |
| journal={arXiv preprint arXiv:2505.24802}, |
| year={2025} |
| } |
| |
| @article{li2020federated_synthetic_data, |
| title={Federated optimization in heterogeneous networks}, |
| author={Li, Tian and Sahu, Anit Kumar and Zaheer, Manzil and Sanjabi, Maziar and Talwalkar, Ameet and Smith, Virginia}, |
| journal={MLSys}, |
| year={2020} |
| } |
| |
| @article{zhang2026understanding, |
| title={Understanding the Impact of Differentially Private Training on Memorization of Long-Tailed Data}, |
| author={Zhang, Jiaming and Xie, Huanyi and Ding, Meng and Fu, Shaopeng and Liu, Jinyan and Wang, Di}, |
| journal={arXiv preprint arXiv:2602.03872}, |
| year={2026} |
| } |
| |
| @article{bagdasaryan2019differential, |
| title={Differential privacy has disparate impact on model accuracy}, |
| author={Bagdasaryan, Eugene and Poursaeed, Omid and Shmatikov, Vitaly}, |
| journal={NeurIPS}, |
| year={2019} |
| } |
| |
| @article{zhang2022closer, |
| title={A closer look at the calibration of differentially private learners}, |
| author={Zhang, Hanlin and Li, Xuechen and Sen, Prithviraj and Roukos, Salim and Hashimoto, Tatsunori}, |
| journal={arXiv preprint arXiv:2210.08248}, |
| year={2022} |
| } |
| |
| |
| @article{duchi2013local, |
| title={Local privacy, data processing inequalities, and statistical minimax rates}, |
| author={Duchi, John C and Jordan, Michael I and Wainwright, Martin J}, |
| journal={arXiv preprint arXiv:1302.3203}, |
| year={2013} |
| } |
| |
| @article{krizhevsky2009learningCIFAR, |
| title={Learning multiple layers of features from tiny images}, |
| author={Krizhevsky, Alex}, |
| institution={University of Toronto}, |
| year={2009} |
| } |
| |
| @article{lecun1998mnist, |
| author={Lecun, Y. and Bottou, L. and Bengio, Y. and Haffner, P.}, |
| journal={Proceedings of the IEEE}, |
| title={Gradient-based learning applied to document recognition}, |
| year={1998}, |
| volume={86}, |
| number={11}, |
| pages={2278-2324}, |
| } |
| |
| @article{wang-LDP-JMLR:v21:19-253, |
| author = {Di Wang and Marco Gaboardi and Adam Smith and Jinhui Xu}, |
| title = {Empirical Risk Minimization in the Non-interactive Local Model of Differential Privacy}, |
| journal = {JMLR}, |
| year = {2020}, |
| volume = {21}, |
| number = {200}, |
| pages = {1--39}, |
| } |
| |
| @InProceedings{pmlr-v130-girgis21a, |
| title = { Shuffled Model of Differential Privacy in Federated Learning }, |
| author = {Girgis, Antonious and Data, Deepesh and Diggavi, Suhas and Kairouz, Peter and Theertha Suresh, Ananda}, |
| booktitle = {AISTATS}, |
| year = {2021}, |
| } |
| |
| @article{attia2021algorithmic, |
| title={Algorithmic instabilities of accelerated gradient descent}, |
| author={Attia, Amit and Koren, Tomer}, |
| journal={NeurIPS}, |
| year={2021} |
| } |
| |
| @article{duchi2011adaptive, |
| title={Adaptive subgradient methods for online learning and stochastic optimization.}, |
| author={Duchi, John and Hazan, Elad and Singer, Yoram}, |
| journal={JMLR}, |
| volume={12}, |
| number={7}, |
| year={2011} |
| } |
| |
| @book{Evans1992MeasureTA, |
| title={Measure Theory and Fine Properties of Functions, Revised Edition}, |
| author={Evans, L.C. and Gariepy, R.F.}, |
| series={Textbooks in Mathematics}, |
| year={2015}, |
| publisher={CRC Press} |
| } |
| |
| @book{rockafellar1998variational, |
| title={Variational analysis}, |
| author={Rockafellar, R Tyrrell and Wets, Roger JB}, |
| year={1998}, |
| series={Grundlehren der mathematischen Wissenschaften}, |
| publisher={Springer Berlin, Heidelberg} |
| } |
| |
| @book{rockafellar1970convex, |
| author = {R. Tyrrell Rockafellar}, |
| title = {Convex Analysis}, |
| series = {Princeton Mathematical Series}, |
| volume = {28}, |
| publisher = {Princeton University Press}, |
| year = {1970} |
| } |
| |
| @book{Garcia_Horn_2017, |
| place={Cambridge}, |
| series={Cambridge Mathematical Textbooks}, |
| title={A Second Course in Linear Algebra}, |
| publisher={Cambridge University Press}, |
| author={Garcia, Stephan Ramon and Horn, Roger A.}, |
| year={2017}, |
| collection={Cambridge Mathematical Textbooks} |
| } |
| |
| @book{bauschke2020correction, |
| title={Convex Analysis and Monotone Operator Theory in Hilbert Spaces}, |
| author={Bauschke, H.H. and Combettes, P.L.}, |
| series={CMS Books in Mathematics}, |
| year={2017}, |
| publisher={Springer International Publishing} |
| } |
| |
| @article{bauschke2009baillon, |
| title={The Baillon-Haddad Theorem Revisited}, |
| author={Bauschke, Heinz H and Combettes, Patrick L}, |
| journal={Journal of Convex Analysis}, |
| volume={17}, |
| number={3\&4}, |
| pages={781--787}, |
| year={2010} |
| } |
| |
| @article{combettes2018monotone, |
| title={Monotone operator theory in convex optimization}, |
| author={Combettes, Patrick L}, |
| journal={Mathematical Programming}, |
| volume={170}, |
| number={1}, |
| pages={177--206}, |
| year={2018}, |
| publisher={Springer} |
| } |
| |
| @article{schur1905neue, |
| title={Neue Begr{\"u}ndung der Theorie der Gruppencharaktere}, |
| author={Schur, I.}, |
| series={Sitzungsberichte der K{\"o}niglich-Preussischen Akademie der Wissenschaften zu Berlin}, |
| year={1905} |
| } |
| |
| @inproceedings{koloskova2023revisitingclipping, |
| title={Revisiting gradient clipping: Stochastic bias and tight convergence guarantees}, |
| author={Koloskova, Anastasia and Hendrikx, Hadrien and Stich, Sebastian U}, |
| booktitle={ICML}, |
| year={2023}, |
| } |
| |
| @inproceedings{papernot2021tempered, |
| title={Tempered sigmoid activations for deep learning with differential privacy}, |
| author={Papernot, Nicolas and Thakurta, Abhradeep and Song, Shuang and Chien, Steve and Erlingsson, {\'U}lfar}, |
| booktitle={AAAI}, |
| year={2021} |
| } |
| |
| @inproceedings{zhang2019clippingacceleratestraining, |
| title={Why Gradient Clipping Accelerates Training: A Theoretical Justification for Adaptivity}, |
| author={Zhang, Jingzhao and He, Tianxing and Sra, Suvrit and Jadbabaie, Ali}, |
| booktitle={ICLR}, |
| year={2020} |
| } |
| |
| @article{bagdasaryan2019differentialdisparateimpactonaccuracy, |
| title={Differential privacy has disparate impact on model accuracy}, |
| author={Bagdasaryan, Eugene and Poursaeed, Omid and Shmatikov, Vitaly}, |
| journal={NeurIPS}, |
| year={2019} |
| } |
| |
| @inproceedings{allouah2024adaptiveclipping, |
| title={Adaptive gradient clipping for robust federated learning}, |
| author={Allouah, Youssef and Guerraoui, Rachid and Gupta, Nirupam and Jellouli, Ahmed and Rizk, Geovani and Stephan, John}, |
| booktitle={ICLR}, |
| year={2025} |
| } |
| |
| @inproceedings{zhang2022understandingclippingfedavg, |
| title={Understanding clipping for federated learning: Convergence and client-level differential privacy}, |
| author={Zhang, Xinwei and Chen, Xiangyi and Hong, Mingyi and Wu, Zhiwei Steven and Yi, Jinfeng}, |
| booktitle={ICML}, |
| year={2022} |
| } |
| |
| @article{chen2020understandingclipping, |
| title={Understanding gradient clipping in private sgd: A geometric perspective}, |
| author={Chen, Xiangyi and Wu, Steven Z and Hong, Mingyi}, |
| journal={NeurIPS}, |
| year={2020} |
| } |
| |
| @article{MIGNOT1976130, |
| title = {Contrôle dans les inéquations variationelles elliptiques}, |
| journal = {Journal of Functional Analysis}, |
| volume = {22}, |
| number = {2}, |
| pages = {130-185}, |
| year = {1976}, |
| issn = {0022-1236}, |
| author = {F Mignot}, |
| } |
| |
| @Article{ |
| albamb96, |
| author = { Alberti, Giovanni and Ambrosio, Luigi }, |
| title = { A Geometrical Approach to Monotone Functions in $\mathbb{R}^n$ }, |
| journal = { Math. Zeit. }, |
| year = { 1996 }, |
| volume = { 230 (1999) }, |
| pages = { 259-316 }, |
| } |
| |
| @inproceedings{Bauschke2011ConvexAA, |
| title={Convex Analysis and Monotone Operator Theory in Hilbert Spaces}, |
| author={Heinz H. Bauschke and Patrick L. Combettes}, |
| booktitle={CMS Books in Mathematics}, |
| year={2011}, |
| } |
| |
| @book{EvansGariepy2015, |
| title = {Measure Theory and Fine Properties of Functions}, |
| author = {Evans, Lawrence C. and Gariepy, Ronald F.}, |
| year = {2015}, |
| edition = {Revised Edition}, |
| publisher = {Chapman and Hall/CRC}, |
| } |
| |
| @book{facchinei2007finite, |
| title={Finite-Dimensional Variational Inequalities and Complementarity Problems}, |
| author={Facchinei, F. and Pang, J.S.}, |
| series={Springer Series in Operations Research and Financial Engineering}, |
| year={2007}, |
| publisher={Springer New York} |
| } |
| |
| @book{brezis2010functional, |
| title={Functional Analysis, Sobolev Spaces and Partial Differential Equations}, |
| author={Brezis, H.}, |
| series={Universitext}, |
| year={2010}, |
| publisher={Springer New York} |
| } |
| |
| @article{rockafellar1969local, |
| title={Local boundedness of nonlinear, monotone operators.}, |
| author={Rockafellar, R Tyrrell}, |
| journal={Michigan Mathematical Journal}, |
| volume={16}, |
| number={4}, |
| pages={397--407}, |
| year={1969}, |
| publisher={University of Michigan, Department of Mathematics} |
| } |
| |
| @article{Borwein1989LocalBO, |
| title={Local boundedness of monotone operators under minimal hypotheses}, |
| author={Jonathan Michael Borwein and Simon Fitzpatrick}, |
| journal={Bulletin of the Australian Mathematical Society}, |
| year={1989}, |
| volume={39}, |
| pages={439 - 441}, |
| } |
| |
| @book{conn2009introduction, |
| title={Introduction to Derivative-Free Optimization}, |
| author={Conn, A.R. and Scheinberg, K. and Vicente, L.N.}, |
| series={MOS-SIAM Series on Optimization}, |
| year={2009}, |
| publisher={Society for Industrial and Applied Mathematics} |
| } |
| |
| @book{leoni2017first, |
| title={A first course in Sobolev spaces}, |
| author={Leoni, Giovanni}, |
| year={2017}, |
| publisher={American Mathematical Society} |
| } |
| |
| @article{privacy-convex, |
| author = {Altschuler, Jason M. and Bok, Jinho and Talwar, Kunal}, |
| title = {On the Privacy of Noisy Stochastic Gradient Descent for Convex Optimization}, |
| journal = {SIAM Journal on Computing}, |
| volume = {53}, |
| number = {4}, |
| pages = {969-1001}, |
| year = {2024}, |
| } |
| |
| @InProceedings{pmlr-v130-qian21a, |
| title = { Understanding Gradient Clipping In Incremental Gradient Methods }, |
| author = {Qian, Jiang and Wu, Yuren and Zhuang, Bojin and Wang, Shaojun and Xiao, Jing}, |
| booktitle = {AISTATS}, |
| year = {2021}, |
| } |
| |
| @article{alistarh2017qsgd, |
| title={QSGD: Communication-efficient SGD via gradient quantization and encoding}, |
| author={Alistarh, Dan and Grubic, Demjan and Li, Jerry and Tomioka, Ryota and Vojnovic, Milan}, |
| journal={NeurIPS}, |
| year={2017} |
| } |
| |
| @article{kingma2017adammethodstochasticoptimization, |
| title={Adam: A method for stochastic optimization}, |
| author={Kingma, Diederik P and Ba, Jimmy}, |
| journal={ICLR}, |
| year={2015} |
| } |
| |
| @InProceedings{pmlr-v119-karimireddy20a-scaffold, |
| title = {{SCAFFOLD}: Stochastic Controlled Averaging for Federated Learning}, |
| author = {Karimireddy, Sai Praneeth and Kale, Satyen and Mohri, Mehryar and Reddi, Sashank and Stich, Sebastian and Suresh, Ananda Theertha}, |
| booktitle = {ICML}, |
| year = {2020}, |
| } |
| |
| @book{sutton2018reinforcement, |
| title={Reinforcement Learning, second edition: An Introduction}, |
| author={Sutton, R.S. and Barto, A.G.}, |
| series={Adaptive Computation and Machine Learning series}, |
| year={2018}, |
| publisher={MIT Press} |
| } |
| |
| @inproceedings{mohri2019agnostic, |
| title={Agnostic federated learning}, |
| author={Mohri, Mehryar and Sivek, Gary and Suresh, Ananda Theertha}, |
| booktitle={ICML}, |
| year={2019}, |
| } |
| |
| @InProceedings{pmlr-v119-martinez20a, |
| title = {Minimax Pareto Fairness: A Multi Objective Perspective}, |
| author = {Martinez, Natalia and Bertran, Martin and Sapiro, Guillermo}, |
| booktitle = {ICML}, |
| year = {2020}, |
| } |
| |
| @inproceedings{zhao2015stochastic, |
| title={Stochastic optimization with importance sampling for regularized loss minimization}, |
| author={Zhao, Peilin and Zhang, Tong}, |
| booktitle={ICML}, |
| year={2015}, |
| } |
| |
| @InProceedings{pmlr-v70-namkoong17a, |
| title = {Adaptive Sampling Probabilities for Non-Smooth Optimization}, |
| author = {Hongseok Namkoong and Aman Sinha and Steve Yadlowsky and John C. Duchi}, |
| booktitle = {ICML}, |
| year = {2017}, |
| } |
| |
| @article{FREUND1997119, |
| title = {A Decision-Theoretic Generalization of On-Line Learning and an Application to Boosting}, |
| journal = {Journal of Computer and System Sciences}, |
| volume = {55}, |
| number = {1}, |
| pages = {119-139}, |
| year = {1997}, |
| author = {Yoav Freund and Robert E Schapire}, |
| } |
| |
| @inproceedings{reddi2018convergenceadam, |
| title={On the Convergence of Adam and Beyond}, |
| author={Reddi, Sashank J and Kale, Satyen and Kumar, Sanjiv}, |
| booktitle={ICLR}, |
| year={2018} |
| } |
| |
| @article{primer-monotone, |
| author = {Ryu, Ernest and Boyd, Stephen}, |
| year = {2016}, |
| month = {01}, |
| pages = {3-43}, |
| title = {A Primer on Monotone Operator Methods}, |
| volume = {15}, |
| journal = {Applied and computational mathematics} |
| } |
| |
| @inproceedings{karimireddy2019error, |
| title={Error feedback fixes signsgd and other gradient compression schemes}, |
| author={Karimireddy, Sai Praneeth and Rebjock, Quentin and Stich, Sebastian and Jaggi, Martin}, |
| booktitle={ICML}, |
| year={2019}, |
| } |
| |
| @inproceedings{luoadaptive, |
| title={Adaptive Gradient Methods with Dynamic Bound of Learning Rate}, |
| author={Luo, Liangchen and Xiong, Yuanhao and Liu, Yan and Sun, Xu}, |
| booktitle={ICLR}, |
| year={2019}, |
| } |
| |
| @inproceedings{mescheder2018GANtraining, |
| title={Which training methods for GANs do actually converge?}, |
| author={Mescheder, Lars and Geiger, Andreas and Nowozin, Sebastian}, |
| booktitle={ICML}, |
| year={2018}, |
| } |
| |
| @InProceedings{pmlr-v202-mansour23a, |
| title = {Random Classification Noise does not defeat All Convex Potential Boosters Irrespective of Model Choice}, |
| author = {Mansour, Yishay and Nock, Richard and Williamson, Robert}, |
| booktitle = {ICML}, |
| year = {2023}, |
| } |
| |
| @article{Long2008RandomCN, |
| title={Random classification noise defeats all convex potential boosters}, |
| author={Philip M. Long and Rocco A. Servedio}, |
| journal={Machine Learning}, |
| year={2008}, |
| volume={78}, |
| pages={287-304}, |
| } |
| |
| @inproceedings{gidelvariational2019, |
| title={A Variational Inequality Perspective on Generative Adversarial Networks}, |
| author={Gidel, Gauthier and Berard, Hugo and Vignoud, Ga{\"e}tan and Vincent, Pascal and Lacoste-Julien, Simon}, |
| booktitle={ICLR}, |
| year={2019}, |
| } |
| |
| @article{zhang2022adam, |
| title={Adam can converge without any modification on update rules}, |
| author={Zhang, Yushun and Chen, Congliang and Shi, Naichen and Sun, Ruoyu and Luo, Zhi-Quan}, |
| journal={NeurIPS}, |
| year={2022} |
| } |
| |
| @article{dieuleveut2020bridging, |
| title={Bridging the gap between constant step size stochastic gradient descent and markov chains}, |
| author={Dieuleveut, Aymeric and Durmus, Alain and Bach, Francis}, |
| journal={The Annals of Statistics}, |
| volume={48}, |
| number={3}, |
| pages={1348--1382}, |
| year={2020} |
| } |
| |
| @inproceedings{NIPS2011_40008b9a-moulines, |
| author = {Moulines, Eric and Bach, Francis}, |
| booktitle = {NeurIPS}, |
| editor = {J. Shawe-Taylor and R. Zemel and P. Bartlett and F. Pereira and K.Q. Weinberger}, |
| title = {Non-Asymptotic Analysis of Stochastic Approximation Algorithms for Machine Learning}, |
| volume = {24}, |
| year = {2011} |
| } |
| |
| @article{needell2014stochastic, |
| title={Stochastic gradient descent, weighted sampling, and the randomized Kaczmarz algorithm}, |
| author={Needell, Deanna and Srebro, Nathan and Ward, Rachel}, |
| journal={NeurIPS}, |
| year={2014} |
| } |
| |
| @inproceedings{schliserman2022stability, |
| title={Stability vs implicit bias of gradient methods on separable data and beyond}, |
| author={Schliserman, Matan and Koren, Tomer}, |
| booktitle={COLT}, |
| year={2022}, |
| } |
| |
| @InProceedings{pmlr-v80-hashimoto18a, |
| title = {Fairness Without Demographics in Repeated Loss Minimization}, |
| author = {Hashimoto, Tatsunori and Srivastava, Megha and Namkoong, Hongseok and Liang, Percy}, |
| booktitle = {ICML}, |
| year = {2018}, |
| } |
| |
| @article{heavy-ball-limit-cycle, |
| author = {Lessard, Laurent and Recht, Benjamin and Packard, Andrew}, |
| title = {Analysis and Design of Optimization Algorithms via Integral Quadratic Constraints}, |
| journal = {SIAM Journal on Optimization}, |
| volume = {26}, |
| number = {1}, |
| pages = {57-95}, |
| year = {2016}, |
| } |
| |
| @inproceedings{li2019convergence, |
| title={On the convergence of stochastic gradient descent with adaptive stepsizes}, |
| author={Li, Xiaoyu and Orabona, Francesco}, |
| booktitle={AISTATS}, |
| year={2019}, |
| } |
| |
| @inproceedings{mertikopoulosoptimistic, |
| title={Optimistic mirror descent in saddle-point problems: Going the extra (gradient) mile}, |
| author={Mertikopoulos, Panayotis and Lecouat, Bruno and Zenati, Houssam and Foo, Chuan-Sheng and Chandrasekhar, Vijay and Piliouras, Georgios}, |
| booktitle={ICLR}, |
| year={2019} |
| } |
| |
| @inproceedings{gidel2019negative, |
| title={Negative momentum for improved game dynamics}, |
| author={Gidel, Gauthier and Hemmat, Reyhane Askari and Pezeshki, Mohammad and Le Priol, R{\'e}mi and Huang, Gabriel and Lacoste-Julien, Simon and Mitliagkas, Ioannis}, |
| booktitle={AISTATS}, |
| year={2019}, |
| } |
| |
| @article{maheshwari2023fairgrad, |
| title={FairGrad: Fairness Aware Gradient Descent}, |
| author={Maheshwari, Gaurav and Perrot, Micha{\"e}l}, |
| journal={TMLR}, |
| year={2023} |
| } |
| |
| @article{wilson2017marginal, |
| title={The marginal value of adaptive gradient methods in machine learning}, |
| author={Wilson, Ashia C and Roelofs, Rebecca and Stern, Mitchell and Srebro, Nati and Recht, Benjamin}, |
| journal={NeurIPS}, |
| year={2017} |
| } |
| |
| @article{defazio2014saga, |
| title={SAGA: A fast incremental gradient method with support for non-strongly convex composite objectives}, |
| author={Defazio, Aaron and Bach, Francis and Lacoste-Julien, Simon}, |
| journal={NeurIPS}, |
| year={2014} |
| } |
| |
| @article{bolte2022curiosities, |
| title={Curiosities and counterexamples in smooth convex optimization}, |
| author={Bolte, J{\'e}r{\^o}me and Pauwels, Edouard}, |
| journal={Mathematical Programming}, |
| volume={195}, |
| number={1}, |
| pages={553--603}, |
| year={2022}, |
| publisher={Springer} |
| } |
| |
| @inproceedings{lei2023stabilityncvxnsmooth, |
| title={Stability and generalization of stochastic optimization with nonconvex and nonsmooth problems}, |
| author={Lei, Yunwen}, |
| booktitle={COLT}, |
| year={2023}, |
| } |
| |
| @article{lei-clipping, |
| author = {Shuang Zeng and Yunwen Lei}, |
| title = {Stochastic Gradient Methods: Bias, Stability and Generalization}, |
| journal = {JMLR}, |
| year = {2026}, |
| volume = {27}, |
| number = {6}, |
| pages = {1--55}, |
| } |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| @article{altschuler-dp, |
| author = {Altschuler, Jason M. and Bok, Jinho and Talwar, Kunal}, |
| title = {On the Privacy of Noisy Stochastic Gradient Descent for Convex Optimization}, |
| journal = {SIAM Journal on Computing}, |
| volume = {53}, |
| number = {4}, |
| pages = {969-1001}, |
| year = {2024}, |
| } |
| |
| @article{JMLR:v27:24-0637-yunwei-stability-clipping, |
| author = {Shuang Zeng and Yunwen Lei}, |
| title = {Stochastic Gradient Methods: Bias, Stability and Generalization}, |
| journal = {JMLR}, |
| year = {2026}, |
| volume = {27}, |
| number = {6}, |
| pages = {1--55}, |
| } |
| |
| @article{kornowski2026gradient-last-iterate-speed-cv, |
| title={Gradient Descent's Last Iterate is Often (slightly) Suboptimal}, |
| author={Kornowski, Guy and Shamir, Ohad}, |
| journal={arXiv preprint arXiv:2604.13870}, |
| year={2026} |
| } |
| |
| @article{doi:10.1137/24M1717762-last-iterate-cv, |
| author = {Zamani, Moslem and Glineur, Fran\c{c}ois}, |
| title = {Exact Convergence Rate of the Last Iterate in Subgradient Methods}, |
| journal = {SIAM Journal on Optimization}, |
| volume = {35}, |
| number = {3}, |
| pages = {2182-2201}, |
| year = {2025}, |
| } |
| |
| @article{preobrazhenskaia2026last-iterate-adagrad, |
| title={Last Iterate Convergence of AdaGrad-Norm for Convex Non-Smooth Optimization}, |
| author={Preobrazhenskaia, Margarita and Sidorov, Makar and Preobrazhenskii, Igor and Gorbunov, Eduard}, |
| journal={arXiv preprint arXiv:2604.10728}, |
| year={2026} |
| } |
| |
| @article{needell2014stochastic-fixed-importance-sampling, |
| title={Stochastic gradient descent, weighted sampling, and the randomized Kaczmarz algorithm}, |
| author={Needell, Deanna and Srebro, Nathan and Ward, Rachel}, |
| journal={NeurIPS}, |
| year={2014} |
| } |
| |
| @inproceedings{thudi2024gradients, |
| title={Gradients look alike: Sensitivity is often overestimated in $\{$DP-SGD$\}$}, |
| author={Thudi, Anvith and Jia, Hengrui and Meehan, Casey and Shumailov, Ilia and Papernot, Nicolas}, |
| booktitle={USENIX Security}, |
| year={2024} |
| } |
| |
| @book{villani-ot, |
| year = {2009}, |
| author = {Villani,Cédric}, |
| booktitle = {Optimal transport : old and new}, |
| publisher = {Springer}, |
| series = {Grundlehren der mathematischen Wissenschaften}, |
| title = {Optimal Transport: Old and New}, |
| } |
| |
| @InProceedings{pmlr-v235-bok24a, |
| title = {Shifted Interpolation for Differential Privacy}, |
| author = {Bok, Jinho and Su, Weijie J and Altschuler, Jason}, |
| booktitle = {ICML}, |
| year = {2024}, |
| } |
| |
| @article{altschuler-bounded-privacy, |
| author = {Altschuler, Jason M. and Bok, Jinho and Talwar, Kunal}, |
| title = {On the Privacy of Noisy Stochastic Gradient Descent for Convex Optimization}, |
| journal = {SIAM Journal on Computing}, |
| volume = {53}, |
| number = {4}, |
| pages = {969-1001}, |
| year = {2024}, |
| } |
| |
| @InProceedings{pmlr-v267-dadi25a, |
| title = {Generalization of noisy {SGD} in unbounded non-convex settings}, |
| author = {Dadi, Leello Tadesse and Cevher, Volkan}, |
| booktitle = {ICML}, |
| year = {2025}, |
| } |
| |
| @inproceedings{li-after-mou-generalization, |
| title={On Generalization Error Bounds of Noisy Gradient Methods for Non-Convex Learning}, |
| author={Li, Jian and Luo, Xuanyuan and Qiao, Mingda}, |
| booktitle={ICLR}, |
| year = {2020}, |
| } |
| |
| @article{wang-SDPI-additive-noise-channels-gen, |
| author = {Hao Wang and Rui Gao and Flavio P. Calmon}, |
| title = {Generalization Bounds for Noisy Iterative Algorithms Using Properties of Additive Noise Channels}, |
| journal = {JMLR}, |
| year = {2023}, |
| volume = {24}, |
| number = {26}, |
| pages = {1--43}, |
| } |
| |
| @inproceedings{pensia2018generalization, |
| title={Generalization error bounds for noisy, iterative algorithms}, |
| author={Pensia, Ankit and Jog, Varun and Loh, Po-Ling}, |
| booktitle={IEEE International Symposium on Information Theory}, |
| year={2018}, |
| } |
| |
| @InProceedings{steinke2020reasoning, |
| title = {{R}easoning {A}bout {G}eneralization via {C}onditional {M}utual {I}nformation}, |
| author = {Steinke, Thomas and Zakynthinou, Lydia}, |
| booktitle = {COLT}, |
| year = {2020}, |
| } |
| |
| @inproceedings{lei2023stability, |
| title={Stability and generalization of stochastic optimization with nonconvex and nonsmooth problems}, |
| author={Lei, Yunwen}, |
| booktitle={COLT}, |
| year={2023}, |
| } |
| |
| @inproceedings{kang2022sharper-hp-dp, |
| title={Sharper utility bounds for differentially private models: Smooth and non-smooth}, |
| author={Kang, Yilin and Liu, Yong and Li, Jian and Wang, Weiping}, |
| booktitle={CIKM}, |
| year={2022} |
| } |
| |
| @article{wang2023-MI-plus-Stab, |
| title={Sample-conditioned hypothesis stability sharpens information-theoretic generalization bounds}, |
| author={Wang, Ziqiao and Mao, Yongyi}, |
| journal={NeurIPS}, |
| year={2023} |
| } |
| |
| @InProceedings{pmlr-v201-haghifam23a, |
| title = {Limitations of Information-Theoretic Generalization Bounds for Gradient Descent Methods in Stochastic Convex Optimization}, |
| author = {Haghifam, Mahdi and Rodr\'iguez-G\'alvez, Borja and Thobaben, Ragnar and Skoglund, Mikael and M. Roy, Daniel and Karolina Dziugaite, Gintare}, |
| booktitle = {ALT}, |
| year = {2023}, |
| } |
| |
| @article{bu2020tightening, |
| title={Tightening mutual information-based bounds on generalization error}, |
| author={Bu, Yuheng and Zou, Shaofeng and Veeravalli, Venugopal V}, |
| journal={IEEE Journal on Selected Areas in Information Theory}, |
| volume={1}, |
| number={1}, |
| pages={121--130}, |
| year={2020}, |
| publisher={IEEE} |
| } |
| |
| @article{rodriguez2021tighter-Wasserstein, |
| title={Tighter expected generalization error bounds via Wasserstein distance}, |
| author={Rodr{\'\i}guez G{\'a}lvez, Borja and Bassi, Germ{\'a}n and Thobaben, Ragnar and Skoglund, Mikael}, |
| journal={NeurIPS}, |
| year={2021} |
| } |
| |
| @article{haghifam2020sharpened, |
| title={Sharpened generalization bounds based on conditional mutual information and an application to noisy, iterative algorithms}, |
| author={Haghifam, Mahdi and Negrea, Jeffrey and Khisti, Ashish and Roy, Daniel M and Dziugaite, Gintare Karolina}, |
| journal={NeurIPS}, |
| year={2020} |
| } |
| |
| @article{xu2017information, |
| title={Information-theoretic analysis of generalization capability of learning algorithms}, |
| author={Xu, Aolin and Raginsky, Maxim}, |
| journal={NeurIPS}, |
| year={2017} |
| } |
| |
| @inproceedings{kairouz2015composition, |
| title={The composition theorem for differential privacy}, |
| author={Kairouz, Peter and Oh, Sewoong and Viswanath, Pramod}, |
| booktitle={ICML}, |
| year={2015}, |
| } |
| |
| @article{balle2019privacy-coupling, |
| title={Privacy amplification by mixing and diffusion mechanisms}, |
| author={Balle, Borja and Barthe, Gilles and Gaboardi, Marco and Geumlek, Joseph}, |
| journal={NeurIPS}, |
| year={2019} |
| } |
| |
| @article{diakonikolas2019robust, |
| title={Robust estimators in high-dimensions without the computational intractability}, |
| author={Diakonikolas, Ilias and Kamath, Gautam and Kane, Daniel and Li, Jerry and Moitra, Ankur and Stewart, Alistair}, |
| journal={SIAM Journal on Computing}, |
| volume={48}, |
| number={2}, |
| pages={742--864}, |
| year={2019}, |
| } |