Geovani Rizk

dblp:259/2889 · DBLP profile ↗
← Back
6ranked-venue papers
2as first author
5since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 6 · 2 first-author · 5 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Artificial intelligence
6 papers
Efficient and distributed learning · 58% Optimization for machine learning · 17% Reinforcement learning · 10%
Theoretical computer science
3 papers
Algorithmic game theory and mechanism design · 100%

Topics — the 19 heaviest of 20, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Machine learning › Efficient and distributed learning
federated learning
1.622025
Adaptive Gradient Clipping for Robust Federated Learning · ICLR 2025
Byzantine-Robust Federated Learning: Impact of Client Subsampling and Local Updates · ICML 2024
Machine learning › Optimization for machine learning › adaptive optimization
adaptive gradient clipping
0.912025
Adaptive Gradient Clipping for Robust Federated Learning · ICLR 2025
Machine learning › Optimization for machine learning
gradient clipping
0.912025
Adaptive Gradient Clipping for Robust Federated Learning · ICLR 2025
Machine learning › Efficient and distributed learning › federated learning
robust federated learning
0.912025
Adaptive Gradient Clipping for Robust Federated Learning · ICLR 2025
Machine learning › Efficient and distributed learning › federated learning › robust federated learning
byzantine-robust federated learning
0.812024
Byzantine-Robust Federated Learning: Impact of Client Subsampling and Local Updates · ICML 2024
Machine learning › Efficient and distributed learning › federated learning › client selection
client sampling
0.812024
Byzantine-Robust Federated Learning: Impact of Client Subsampling and Local Updates · ICML 2024
Machine learning › Efficient and distributed learning
local updates
0.812024
Byzantine-Robust Federated Learning: Impact of Client Subsampling and Local Updates · ICML 2024
Machine learning › Efficient and distributed learning › federated learning
data heterogeneity
0.712023
Robust Distributed Learning: Tight Error Bounds and Breakdown Point under Data Heterogeneity · NeurIPS 2023
Machine learning › Efficient and distributed learning › distributed training
robust distributed learning
0.712023
Robust Distributed Learning: Tight Error Bounds and Breakdown Point under Data Heterogeneity · NeurIPS 2023
Machine learning › Reinforcement learning
multi-agent reinforcement learning
0.612022
An $\alpha$-No-Regret Algorithm For Graphical Bilinear Bandits · NeurIPS 2022
Algorithmic game theory and mechanism design › regret minimization
no-regret algorithms
0.612022
An $\alpha$-No-Regret Algorithm For Graphical Bilinear Bandits · NeurIPS 2022
Algorithmic game theory and mechanism design
regret minimization
0.612022
An $\alpha$-No-Regret Algorithm For Graphical Bilinear Bandits · NeurIPS 2022
Machine learning › Trustworthy machine learning › adversarial machine learning
adversarial defense
0.412020
Randomization matters How to defend against strong adversarial attacks · ICML 2020
Machine learning › Trustworthy machine learning › robustness
adversarial robustness
0.412020
Randomization matters How to defend against strong adversarial attacks · ICML 2020
Machine learning › Probabilistic and Bayesian machine learning
probabilistic classifier
0.412020
Randomization matters How to defend against strong adversarial attacks · ICML 2020
Algorithmic game theory and mechanism design › solution concepts in games › equilibrium concepts
nash equilibrium
0.412020
Randomization matters How to defend against strong adversarial attacks · ICML 2020
Algorithmic game theory and mechanism design
zero-sum game
0.412020
Randomization matters How to defend against strong adversarial attacks · ICML 2020
Machine learning › Learning theory › generalization error
learning error bounds
0.212023
Robust Distributed Learning: Tight Error Bounds and Breakdown Point under Data Heterogeneity · NeurIPS 2023
Algorithmic game theory and mechanism design
multi-armed bandit
0.112021
Best Arm Identification in Graphical Bilinear Bandits · ICML 2021

Methods — techniques the papers use, named apart from their topics

upper confidence bound · 1.1optimism in the face of uncertainty · 1.1random sampling · 1.0decentralized allocation · 1.0game theory · 0.9adversarial training · 0.9robust aggregation · 0.8convergence analysis · 0.8distributed gradient descent · 0.7breakdown point analysis · 0.7PGD attack · 0.4
YearPublicationVenuePosition
2025 Adaptive Gradient Clipping for Robust Federated Learning
abstract
Robust federated learning aims to maintain reliable performance despite the presence of adversarial or misbehaving workers. While state-of-the-art (SOTA) robust distributed gradient descent (Robust-DGD) methods were proven theoretically optimal, their empirical success has often relied on pre-aggregation gradient clipping. However, existing static clipping strategies yield inconsistent results: enhancing robustness against some attacks while being ineffective or even detrimental against others. To address this limitation, we propose a principled adaptive clipping strategy, Adaptive Robust Clipping (ARC), which dynamically adjusts clipping thresholds based on the input gradients. We prove that ARC not only preserves the theoretical robustness guarantees of SOTA Robust-DGD methods but also provably improves asymptotic convergence when the model is well-initialized. Extensive experiments on benchmark image classification tasks confirm these theoretical insights, demonstrating that ARC significantly enhances robustness, particularly in highly heterogeneous and adversarial settings.
Youssef Allouah, Rachid Guerraoui, Nirupam Gupta, Ahmed Jellouli, Geovani Rizk, John Stephan
ICLR5
2024 Byzantine-Robust Federated Learning: Impact of Client Subsampling and Local Updates
abstract
The possibility of adversarial (a.k.a., Byzantine) clients makes federated learning (FL) prone to arbitrary manipulation. The natural approach to robustify FL against adversarial clients is to replace the simple averaging operation at the server in the standard $\mathsf{FedAvg}$ algorithm by a robust averaging rule. While a significant amount of work has been devoted to studying the convergence of federated robust averaging (which we denote by $\mathsf{FedRo}$), prior work has largely ignored the impact of client subsampling and local steps, two fundamental FL characteristics. While client subsampling increases the effective fraction of Byzantine clients, local steps increase the drift between the local updates computed by honest (i.e., non-Byzantine) clients. Consequently, a careless deployment of $\mathsf{FedRo}$ could yield poor performance. We validate this observation by presenting an in-depth analysis of $\mathsf{FedRo}$ tightly analyzing the impact of client subsampling and local steps. Specifically, we present a sufficient condition on client subsampling for nearly-optimal convergence of $\mathsf{FedRo}$ (for smooth non-convex loss). Also, we show that the rate of improvement in learning accuracy diminishes with respect to the number of clients subsampled, as soon as the sample size exceeds a threshold value. Interestingly, we also observe that under a careful choice of step-sizes, the learning error due to Byzantine clients decreases with the number of local steps. We validate our theory by experiments on the FEMNIST and CIFAR-$10$ image classification tasks.
Youssef Allouah, Sadegh Farhadkhani, Rachid Guerraoui, Nirupam Gupta, Rafael Pinot, Geovani Rizk, Sasha Voitovych
ICML6
2023 Robust Distributed Learning: Tight Error Bounds and Breakdown Point under Data Heterogeneity
abstract
The theory underlying robust distributed learning algorithms, designed to resist adversarial machines, matches empirical observations when data is homogeneous. Under data heterogeneity however, which is the norm in practical scenarios, established lower bounds on the learning error are essentially vacuous and greatly mismatch empirical observations. This is because the heterogeneity model considered is too restrictive and does not cover basic learning tasks such as least-squares regression. We consider in this paper a more realistic heterogeneity model, namely $(G,B)$-gradient dissimilarity, and show that it covers a larger class of learning problems than existing theory. Notably, we show that the breakdown point under heterogeneity is lower than the classical fraction $\frac{1}{2}$. We also prove a new lower bound on the learning error of any distributed learning algorithm. We derive a matching upper bound for a robust variant of distributed gradient descent, and empirically show that our analysis reduces the gap between theory and practice.
Youssef Allouah, Rachid Guerraoui, Nirupam Gupta, Rafael Pinot, Geovani Rizk
NeurIPS5
2022 An $\alpha$-No-Regret Algorithm For Graphical Bilinear Bandits
abstract
We propose the first regret-based approach to the \emph{Graphical Bilinear Bandits} problem, where $n$ agents in a graph play a stochastic bilinear bandit game with each of their neighbors. This setting reveals a combinatorial NP-hard problem that prevents the use of any existing regret-based algorithm in the (bi-)linear bandit literature. In this paper, we fill this gap and present the first regret-based algorithm for graphical bilinear bandits using the principle of optimism in the face of uncertainty. Theoretical analysis of this new method yields an upper bound of $\tilde{O}(\sqrt{T})$ on the $\alpha$-regret and evidences the impact of the graph structure on the rate of convergence. Finally, we show through various experiments the validity of our approach.
Geovani Rizk, Igor Colin, Albert Thomas 0001, Rida Laraki, Yann Chevaleyre
NeurIPS1
2021 Best Arm Identification in Graphical Bilinear Bandits
abstract
We introduce a new graphical bilinear bandit problem where a learner (or a \emph{central entity}) allocates arms to the nodes of a graph and observes for each edge a noisy bilinear reward representing the interaction between the two end nodes. We study the best arm identification problem in which the learner wants to find the graph allocation maximizing the sum of the bilinear rewards. By efficiently exploiting the geometry of this bandit problem, we propose a \emph{decentralized} allocation strategy based on random sampling with theoretical guarantees. In particular, we characterize the influence of the graph structure (e.g. star, complete or circle) on the convergence rate and propose empirical experiments that confirm this dependency.
Geovani Rizk, Albert Thomas 0001, Igor Colin, Rida Laraki, Yann Chevaleyre
ICML1
2020 Randomization matters How to defend against strong adversarial attacks
abstract
\emph{Is there a classifier that ensures optimal robustness against all adversarial attacks?} This paper tackles this question by adopting a game-theoretic point of view. We present the adversarial attacks and defenses problem as an \emph{infinite} zero-sum game where classical results (\emph{e.g.} Nash or Sion theorems) do not apply. We demonstrate the non-existence of a Nash equilibrium in our game when the classifier and the Adversary are both deterministic, hence giving a negative answer to the above question in the deterministic regime. Nonetheless, the question remains open in the randomized regime. We tackle this problem by showing that any deterministic classifier can be outperformed by a randomized one. This gives arguments for using randomization, and leads us to a simple method for building randomized classifiers that are robust to state-or-the-art adversarial attacks. Empirical results validate our theoretical analysis, and show that our defense method considerably outperforms Adversarial Training against strong adaptive attacks, by achieving 0.55 accuracy under adaptive PGD-attack on CIFAR10, compared to 0.42 for Adversarial training.
Rafael Pinot, Raphael Ettedgui, Geovani Rizk, Yann Chevaleyre, Jamal Atif
ICML3