A federated round needs a pinned base model and auditable participation rules before distributed updates can be combined.
Federated rounds: eligible clients, base models and update identity
Define the round as an immutable unit
A fleet of field scanners trains a defect classifier on local observations while raw images stay on devices. Give each round an ID, base-model digest, feature schema, local-training configuration, eligibility policy, deadline and aggregation rule. A client update belongs to exactly one base digest and round; accepting a delayed update from an earlier round changes the meaning of the aggregate. Run lineage applies even though training data is not centralized, while edge manifests pin the software devices can execute.
Select for availability without hiding bias
Eligible devices may need adequate charge, an approved network and a current app version. Record the number eligible, sampled, accepted, failed and timed out by device class and region. A fleet with poor connectivity may be underrepresented; do not call a random sample of available devices representative of every site. Use privacy-safe aggregates for coverage reporting. Define a minimum participation floor by relevant cohort before promotion, and hold the round if one region contributes too little evidence. Slice gates help interpret that gap.
Validate update envelopes
Require a signed or otherwise authenticated client identity, authorized base digest, tensor shape, finite numeric values, declared example count and update size limit. Authentication alone does not prove an update is benign. Keep abnormal-norm and repeated-payload signals for investigation without asserting that every outlier is an attack. Where the threat model requires it, use a reviewed secure aggregation or privacy mechanism; merely leaving raw data on devices is not a privacy guarantee. Source quarantine offers a comparable hold-and-review pattern.
Close the round deliberately
At deadline, freeze accepted update IDs, rejects and dropout counts. Aggregate only accepted updates under the recorded rule, then evaluate the new global model on independent data and affected cohorts before rollout. Never merge late updates into an already evaluated artifact. Aggregation controls handle dropout and contribution limits; the project includes devices that return after the round closes.
Implementation
def admit_client_update(update, round_manifest, accepted_ids):
if update["update_id"] in accepted_ids:
return "reject:duplicate"
if update["round_id"] != round_manifest["round_id"]:
return "reject:wrong-round"
if update["base_digest"] != round_manifest["base_digest"]:
return "reject:stale-base"
if update["tensor_shape"] != round_manifest["tensor_shape"]:
return "reject:shape"
if not update["authenticated"] or update["example_count"] <= 0:
return "reject:identity-or-count"
return "accept"
round_manifest = {"round_id": "scanner-round-47", "base_digest": "defect-r8",
"tensor_shape": (128,)}
update = {"update_id": "scanner-82-r47", "round_id": "scanner-round-47",
"base_digest": "defect-r8", "tensor_shape": (128,),
"authenticated": True, "example_count": 39}
assert admit_client_update(update, round_manifest, set()) == "accept"
assert admit_client_update({**update, "base_digest": "defect-r7"},
round_manifest, set()) == "reject:stale-base"
Performance and operating cost
The envelope gate is O(1) time and space before payload inspection; checking each tensor value costs O(d) for d parameters. Round coordination uses network bandwidth proportional to participating clients times model-update bytes. Tight deadlines reduce waiting but can bias participation toward well-connected devices; measure the tradeoff rather than hiding it in a success count.
Common Mistakes
- Aggregating a delayed update against a different base model.
- Treating available-device sampling as a representative sample of all users.
- Assuming local data storage alone guarantees update privacy.
- Evaluating one aggregate and then quietly adding late updates to it.
Read next
- Federated aggregation: dropout, contribution caps and privacy limits
- Project: coordinate a field-scanner federated training round
- Training manifests: link data, code, configuration and artifact
- Edge model releases: pin runtime, preprocessing and cohort
- Training source admission: provenance, trust tiers and quarantine
