Fetching the paper…
Reading the bibliography…
In federated learning, multiple client devices jointly learn a machine learning model: each client device maintains a local model for its local training dataset, while a master device maintains a global model via aggregating the local models from the client devices.
The Sybil attack
John R. Douceur · 2002
Earlier work this paper cites.
Can machine learning be secure?
Marco Barreno, Blaine Nelson, Russell Sears, Anthony D Joseph, and J Doug Tygar · 2006
Earlier work this paper cites.
Casting out demons: Sanitizing training data for anomaly sensors
Gabriela F. Cretu, Angelos Stavrou, Michael E. Locasto, Salvatore J. Stolfo, and Angelos D. Keromytis · 2008
Earlier work this paper cites.
Exploiting machine learning to subvert your spam filter
B. Nelson, M. Barreno, F. J. Chi, A. D. Joseph, B. I. P. Rubinstein, U. Saini, C. Sutton, J. D. Tygar, and K. Xia · 2008
Earlier work this paper cites.
Antidote: understanding and defending against poisoning of anomaly detectors
Benjamin IP Rubinstein, Blaine Nelson, Ling Huang, Anthony D Joseph, Shing-hon Lau, Satish Rao, Nina Taft, and JD Tygar · 2009
Earlier work this paper cites.
The security of machine learning
Marco Barreno, Blaine Nelson, Anthony D Joseph, and JD Tygar · 2010
Earlier work this paper cites.
Poisoning attacks against support vector machines
Battista Biggio, Blaine Nelson, and Pavel Laskov · 2012
Earlier work this paper cites.
Large scale distributed deep networks
Jeffrey Dean, Greg S. Corrado, Rajat Monga, Kai Chen, Matthieu Devin, Quoc V. Le, Mark Z. Mao, Marc’Aurelio Ranzato, Andrew Senior, Paul Tucker, Ke Yang, and Andrew Y. Ng · 2012
Earlier work this paper cites.
Poisoning attacks to compromise face templates
Battista Biggio, Luca Didaci, Giorgio Fumera, and Fabio Roli · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2013
Earlier work this paper cites.
Robust logistic regression and classification
Jiashi Feng, Huan Xu, Shie Mannor, and Shuicheng Yan · 2014
Earlier work this paper cites.
Privacy in pharmacogenetics: An end-to-end case study of personalized warfarin dosing
Matthew Fredrikson, Eric Lantz, Somesh Jha, Simon Lin, David Page, and Thomas Ristenpart · 2014
Earlier work this paper cites.
Explaining and harnessing adversarial examples
Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy · 2014
Earlier work this paper cites.
Practical evasion of a learning-based classifier: A case study
Nedim Srndic and Pavel Laskov · 2014
Earlier work this paper cites.
Hacking smart machines with smarter ones: How to extract meaningful data from machine learning classifiers
Giuseppe Ateniese, Luigi V Mancini, Angelo Spognardi, Antonio Villani, Domenico Vitali, and Giovanni Felici · 2015
Earlier work this paper cites.
Mxnet: A flexible and efficient machine learning library for heterogeneous distributed systems
Tianqi Chen, Mu Li, Yutian Li, Min Lin, Naiyan Wang, Minjie Wang, Tianjun Xiao, Bing Xu, Chiyuan Zhang, and Zheng Zhang · 2015
Earlier work this paper cites.
Model inversion attacks that exploit confidence information and basic countermeasures
Matt Fredrikson, Somesh Jha, and Thomas Ristenpart · 2015
Earlier work this paper cites.
Is feature selection secure against training data poisoning?
Huang Xiao, Battista Biggio, Gavin Brown, Giorgio Fumera, Claudia Eckert, and Fabio Roli · 2015
Earlier work this paper cites.
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2016
Earlier work this paper cites.
Multi-class texture analysis in colorectal cancer histology
Jakob Nikolas Kather, Cleo-Aron Weis, Francesco Bianconi, Susanne M Melchers, Lothar R Schad, Timo Gaiser, Alexander Marx, and Frank Gerrit Zöllner · 2016
Earlier work this paper cites.
Federated learning: Strategies for improving communication efficiency
Jakub Konečný, H. Brendan McMahan, Felix X. Yu, Peter Richtárik, Ananda Theertha Suresh, and Dave Bacon · 2016
Earlier work this paper cites.
Data poisoning attacks on factorization-based collaborative filtering
Bo Li, Yining Wang, Aarti Singh, and Yevgeniy Vorobeychik · 2016
Earlier work this paper cites.
Cracking classifiers for evasion: A case study on the google’s phishing pages filter
Bin Liang, Miaoqiang Su, Wei You, Wenchang Shi, and Gang Yang · 2016
Cited alongside, same era.
The limitations of deep learning in adversarial settings
Nicolas Papernot, Patrick McDaniel, Somesh Jha, Matt Fredrikson, Z. Berkay Celik, and Ananthram Swami · 2016
Cited alongside, same era.
Distillation as a defense to adversarial perturbations against deep neural networks
Nicolas Papernot, Patrick McDaniel, Xi Wu, Somesh Jha, and Ananthram Swami · 2016
Cited alongside, same era.
Accessorize to a crime: Real and stealthy attacks on state-of-the-art face recognition
Mahmood Sharif, Sruti Bhagavatula, Lujo Bauer, and K Michael Reiter · 2016
Cited alongside, same era.
Stealing machine learning models via prediction apis
Florian Tramèr, Fan Zhang, Ari Juels, Michael K Reiter, and Thomas Ristenpart · 2016
Cited alongside, same era.
Certified defenses for data poisoning attacks
Jacob Steinhardt, Pang Wei Koh, and Percy Liang · 2017
Later among the works it cites.
Feature squeezing: Detecting adversarial examples in deep neural networks
Weilin Xu, David Evans, and Yanjun Qi · 2017
Later among the works it cites.
Fake co-visitation injection attacks to recommender systems
Guolei Yang, Neil Zhenqiang Gong, and Ying Cai · 2017
Later among the works it cites.
Synthesizing robust adversarial examples
Anish Athalye, Logan Engstrom, Andrew Ilyas, and Kevin Kwok · 2018
Later among the works it cites.
How to backdoor federated learning
Eugene Bagdasaryan, Andreas Veit, Yiqing Hua, Deborah Estrin, and Vitaly Shmatikov · 2018
Later among the works it cites.
Poisoning attacks to graph-based recommender systems
Minghong Fang, Guolei Yang, Neil Zhenqiang Gong, and Jia Liu · 2018
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Peva Blanchard, El Mahdi El Mhamdi, Rachid Guerraoui, and Julien Stainer · 2017
Cited alongside, same era.
Mitigating evasion attacks to deep neural networks via region-based classification
Xiaoyu Cao and Neil Zhenqiang Gong · 2017
Cited alongside, same era.
Towards evaluating the robustness of neural networks
Nicholas Carlini and David Wagner · 2017
Cited alongside, same era.
Targeted backdoor attacks on deep learning systems using data poisoning
Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song · 2017
Cited alongside, same era.
Distributed statistical machine learning in adversarial settings: Byzantine gradient descent
Yudong Chen, Lili Su, and Jiaming Xu · 2017
Cited alongside, same era.
UCI machine learning repository, 2017
Dheeru Dua and Casey Graff · 2017
Cited alongside, same era.
On the (statistical) detection of adversarial examples
Kathrin Grosse, Praveen Manoharan, Nicolas Papernot, Michael Backes, and Patrick McDaniel · 2017
Cited alongside, same era.
Later among the works it cites.
Mitigating sybils in federated learning poisoning
Clement Fung, Chris J.M. Yoon, and Ivan Beschastnikh · 2018
Later among the works it cites.
Property inference attacks on fully connected neural networks using permutation invariant representations
Karan Ganju, Qi Wang, Wei Yang, Carl A. Gunter, and Nikita Borisov · 2018
Later among the works it cites.
Manipulating machine learning: Poisoning attacks and countermeasures for regression learning
Matthew Jagielski, Alina Oprea, Battista Biggio, Chang Liu, Cristina Nita-Rotaru, and Bo Li · 2018
Later among the works it cites.
Trojaning attack on neural networks
Yingqi Liu, Shiqing Ma, Yousra Aafer, Wen-Chuan Lee, Juan Zhai, Weihang Wang, and Xiangyu Zhang · 2018
Later among the works it cites.
The hidden vulnerability of distributed learning in byzantium
El Mahdi El Mhamdi, Rachid Guerraoui, and Sébastien Rouault · 2018
Later among the works it cites.
Knock knock, who’s there? membership inference on aggregate location data
Apostolos Pyrgelis, Carmela Troncoso, and Emiliano De Cristofaro · 2018
Later among the works it cites.
Poison frogs! targeted clean-label poisoning attacks on neural networks
Ali Shafahi, W Ronny Huang, Mahyar Najibi, Octavian Suciu, Christoph Studer, Tudor Dumitras, and Tom Goldstein · 2018
Later among the works it cites.
When does machine learning fail? generalized transferability for evasion and poisoning attacks
Octavian Suciu, Radu Marginean, Yigitcan Kaya, Hal Daume III, and Tudor Dumitras · 2018
Later among the works it cites.
Spectral signatures in backdoor attacks
Brandon Tran, Jerry Li, and Aleksander Madry · 2018
Later among the works it cites.
Stealing hyperparameters in machine learning
Binghui Wang and Neil Zhenqiang Gong · 2018
Later among the works it cites.
Byzantine-robust distributed learning: Towards optimal statistical rates
Dong Yin, Yudong Chen, Kannan Ramchandran, and Peter Bartlett · 2018
Later among the works it cites.
Analyzing federated learning through an adversarial lens
Arjun Bhagoji, Supriyo Chakraborty, Prateek Mittal, and Seraphin Calo · 2019
Closest in time.
Exploiting unintended feature leakage in collaborative learning
Luca Melis, Congzheng Song, Emiliano De Cristofaro, and Vitaly Shmatikov · 2019
Closest in time.
Comprehensive privacy analysis of deep learning: Stand-alone and federated learning under passive and active white-box inference attacks
Milad Nasr, Reza Shokri, and Amir Houmansadr · 2019
Closest in time.
Attacking graph-based classification via manipulating the graph structure
Binghui Wang and Neil Zhenqiang Gong · 2019
Closest in time.
Fall of empires: Breaking byzantine-tolerant sgd by inner product manipulation
Cong Xie, Sanmi Koyejo, and Indranil Gupta · 2019
Closest in time.