A federation using median aggregation grows from four banks to twelve with more varied books — is it better protected?
answer
- two effects, opposite directions
- a fraction of more clients is more clients
- each new book widens the honest range
- which side is the bound derived from
- spread, not head count, is binding
basics
~20 sTwo effects run opposite ways. A fixed number of malicious silos becomes a smaller share, which helps. But honest updates spread further apart, enlarging the region an adversary hides in, and that spread is what the guarantee rests on.
solid answer
~40 sGrowth improves the counting story and worsens the separability story. On counting: a tolerated fraction of a larger population is a larger absolute number of participants, and an adversary holding a fixed number of silos now controls a smaller share — genuinely better. On separability: each new bank with a different book pushes the honest updates further apart, so the region that survives a coordinate-wise median grows, and the amount of harm that fits inside it unremarkably grows with it. The rule's bound is derived from honest updates clustering, so separability is the binding constraint, and it is the one that got worse. Practically: the tolerance figure computed for the four-bank population does not carry over, and I would re-measure the honest spread after onboarding rather than assume more participants means more safety.
go deeper
Recall that the rule's protection depends on honest updates looking similar, so adding participants who look different is not automatically a gain.
Be able to separate the two effects — dilution of the adversary's share versus widening of the honest spread — and say which one the bound is derived from.
Show that you would re-measure the honest spread after onboarding and restate what the rule buys, rather than carrying an old tolerance figure forward.
Own the consequence for admission policy: every structurally different member you admit widens the region an adversary can hide in, and any tightening you apply lands hardest on that same member.
## The intuition that has to be corrected More participants sounds like more safety: a minority is a smaller minority, majorities are harder to overwhelm, the median is computed over more values. Some of that is true. The part that decides the answer is not. ## What genuinely improves with scale The tolerance a robust aggregation rule states is a **fraction** of the participating clients. Applied to a larger population it permits a larger absolute number of malicious participants, and an adversary who controls a fixed number of silos — say three — falls from a quarter of a four-bank federation to a quarter of twelve, then to a smaller share as more join. If the adversary's reach is bounded by how many organisations they can compromise or enrol, then growing the honest population dilutes them. That is a real improvement and it is worth saying out loud. ## What gets worse, and why it dominates The rule's bound is not derived from the head count. It is derived from honest updates **clustering**: the adversary must either sit inside a tight honest range, in which case their update is nearly honest and moves nothing, or step outside it, in which case ordering removes them. Every new participant with a genuinely different book pushes the honest updates further apart. The region that survives the rule widens, and the set of consequential updates that are nonetheless unremarkable in position grows with it. So growth pushes on both sides of the same guarantee: it raises the number of malicious participants the rule can absorb, and it lowers the amount of malice the rule can *detect* in any one of them. Since detection is what the bound is built on, spread is the binding constraint, and spread is the side that deteriorated. ## Whether the population even is more varied The answer depends on which twelve. Twelve banks with similar retail books in one market may cluster nearly as tightly as four did, in which case the counting improvement is real and largely uncompensated. Twelve institutions spanning retail, correspondent and private banking across several jurisdictions do not; each addition buys a little dilution and pays for it with a much wider honest range. The question is not the participant count but what onboarding did to the spread, and that is answerable with a measurement rather than an argument. ## The measurable version of the question The quantity to track is the spread of honest client updates set against the size of update that would actually change the model's behaviour. When that ratio is small, the rule is doing real work: harmful updates stick out. When it grows past one, the rule is doing bookkeeping: a harmful update fits comfortably inside the honest range. There is no participant count at which the rule becomes worthless — there is a *spread* at which it does, and six wildly different institutions can reach it while sixty similar ones do not. ## What this means operationally A tolerance figure is computed for a population. Change the population and it has to be re-established, exactly as a performance number would be. Concretely, after each onboarding round: re-measure the honest spread, restate what the rule is buying, and be explicit that the protection has the form *an adversary must stay small and look like everyone else* — a sentence whose second clause gets easier for the adversary every time "everyone else" looks less alike. There is also a fairness edge worth naming. As the spread widens, the honest participant who looks least like the others is increasingly indistinguishable from a malicious one under any position-based rule, so any tightening aimed at the adversary lands on that participant first. Growth therefore does not only weaken the guarantee; it concentrates the cost of trying to restore it on the newest and most different member. ## The answer in one line More clients dilute the adversary's share and widen the honest spread at the same time; the guarantee rests on the spread, so more varied participants means less protection, not more, and the number in the old design doc no longer describes this federation.
- Is there a federation size at which the rule becomes worthless?Not a size — a spread. The rule stops buying anything once an update that would actually change the model's behaviour fits comfortably inside the honest range. Six wildly different institutions can reach that point while sixty similar ones never do. The quantity to watch is the honest spread relative to a consequential update, not the participant count.
- What do you tell the consortium when two more banks are about to join?That the tolerance figure was computed for the old population and does not carry over; that the honest spread should be re-measured after onboarding; and that the protection has the shape 'an adversary must stay small and look like everyone else', whose second half gets easier for the adversary every time everyone else looks less alike.
saying these in an interview costs you the question
- Says more participants always means more robustness
- Reasons only about the tolerated fraction and never the honest spread
- Assumes a tolerance measured once stays valid after onboarding
- Forgets that the most different honest member absorbs any tightening
- Treats participant count and update diversity as the same variable