Fetching the paper…
Reading the bibliography…
As data are increasingly being stored in different silos and societies becoming more aware of data privacy issues, the traditional centralized training of artificial intelligence (AI) models is facing efficiency and privacy challenges.
S. L. Warner, “Randomized response: A survey technique for eliminating evasive answer bias,” Journal of the American Statistical Association , vol. 60, no. 309, pp. 63–69, 1965
1965
Earlier work this paper cites.
R. L. Rivest, A. Shamir, and L. Adleman, “A method for obtaining digital signatures and public-key cryptosystems,” Communications of the ACM , vol. 21, no. 2, pp. 120–126, 1978
1978
Earlier work this paper cites.
L. Lamport, R. Shostak, and M. Pease, “The byzantine generals problem,” ACM Transactions on Programming Languages and Systems (TOPLAS) , vol. 4, no. 3, pp. 382–401, 1982
1982
Earlier work this paper cites.
A. C. Yao, “Protocols for secure computations,” in SFCS , 1982, pp. 160–164
1982
Earlier work this paper cites.
T. ElGamal, “A public key cryptosystem and a signature scheme based on discrete logarithms,” IEEE Transactions on Information Theory , vol. 31, no. 4, pp. 469–472, 1985
1985
Earlier work this paper cites.
P. Paillier et al. , “Public-key cryptosystems based on composite degree residuosity classes,” in Eurocrypt , vol. 99, 1999, pp. 223–238
1999
Earlier work this paper cites.
J. Vaidya and C. Clifton, “Privacy preserving association rule mining in vertically partitioned data,” in KDD , 2002, pp. 639–644
2002
Earlier work this paper cites.
J. R. Douceur, “The sybil attack,” in International Workshop on Peer-to-Peer Systems , 2002, pp. 251–260
2002
Earlier work this paper cites.
M. Kantarcioglu and C. Clifton, “Privacy-preserving distributed mining of association rules on horizontally partitioned data,” IEEE Transactions on Knowledge & Data Engineering , no. 9, pp. 1026–1037, 2004
2004
Earlier work this paper cites.
M. Barreno, B. Nelson, R. Sears, A. D. Joseph, and J. D. Tygar, “Can machine learning be secure?” in ICCS , 2006, pp. 16–25
2006
Earlier work this paper cites.
C. Dwork, F. McSherry, K. Nissim, and A. Smith, “Calibrating noise to sensitivity in private data analysis,” in Theory of cryptography conference , 2006, pp. 265–284
2006
Earlier work this paper cites.
C. Dwork, K. Kenthapadi, F. McSherry, I. Mironov, and M. Naor, “Our data, ourselves: Privacy via distributed noise generation,” in Annual International Conference on the Theory and Applications of Cryptographic Techniques , 2006, pp. 486–503
2006
Earlier work this paper cites.
B. Nelson, M. Barreno, F. J. Chi, A. D. Joseph, B. I. Rubinstein, U. Saini, C. A. Sutton, J. D. Tygar, and K. Xia, “Exploiting machine learning to subvert your spam filter.” LEET , vol. 8, pp. 1–9, 2008
2008
Earlier work this paper cites.
S. J. Pan and Q. Yang, “A survey on transfer learning,” IEEE Transactions on knowledge and data engineering , vol. 22, no. 10, pp. 1345–1359, 2009
2009
Earlier work this paper cites.
C. Gentry, “Fully homomorphic encryption using ideal lattices,” in STOC , 2009, pp. 169–178
2009
Earlier work this paper cites.
B. I. P. Rubinstein, B. Nelson, L. Huang, A. D. Joseph, S. Lau, S. Rao, N. Taft, and J. D. Tygar, “ANTIDOTE: understanding and defending against poisoning of anomaly detectors,” in Proceedings of the 9th ACM SIGCOMM Internet Measurement Conference . ACM, 2009, pp. 1–14
2009
Earlier work this paper cites.
V. Rastogi and S. Nath, “Differentially private aggregation of distributed time-series with transformation and encryption,” in Proceedings of the 2010 ACM SIGMOD International Conference on Management of data , 2010, pp. 735–746
2010
Earlier work this paper cites.
M. Barreno, B. Nelson, A. D. Joseph, and J. D. Tygar, “The security of machine learning,” Machine Learning , vol. 81, no. 2, pp. 121–148, 2010
2010
Earlier work this paper cites.
B. Biggio, B. Nelson, and P. Laskov, “Support vector machines under adversarial label noise,” in ACML , 2011, pp. 97–112
2011
Earlier work this paper cites.
E. Shi, H. Chan, E. Rieffel, R. Chow, and D. Song, “Privacy-preserving aggregation of time-series data,” in Annual Network & Distributed System Security Symposium (NDSS) , 2011
2011
Earlier work this paper cites.
G. Ács and C. Castelluccia, “I have a dream!(differentially private smart metering).” in Information hiding , vol. 6958, 2011, pp. 118–132
2011
Earlier work this paper cites.
K. Chaudhuri, C. Monteleoni, and A. D. Sarwate, “Differentially private empirical risk minimization,” Journal of Machine Learning Research , vol. 12, no. Mar, pp. 1069–1109, 2011
2011
Earlier work this paper cites.
L. Huang, A. D. Joseph, B. Nelson, B. I. Rubinstein, and J. D. Tygar, “Adversarial machine learning,” in Proceedings of the 4th ACM workshop on Security and Artificial Intelligence , 2011, pp. 43–58
2011
Earlier work this paper cites.
I. Damgård, V. Pastro, N. Smart, and S. Zakarias, “Multiparty computation from somewhat homomorphic encryption,” in Annual Cryptology Conference , 2012, pp. 643–662
2012
Earlier work this paper cites.
T. H. Chan, E. Shi, and D. Song, “Optimal lower bound for differentially private multi-party aggregation,” in European Symposium on Algorithms , 2012, pp. 277–288
2012
Earlier work this paper cites.
2012
Earlier work this paper cites.
X. He, L. Lyu, L. Sun, and Q. Xu, “Model extraction and adversarial transferability, your bert is vulnerable!” in Proceedings of the 2021 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies , 2021, pp. 2006–2012
2012
Earlier work this paper cites.
J. C. Duchi, M. I. Jordan, and M. J. Wainwright, “Local privacy and statistical minimax rates,” in Proceedings of the 54th IEEE Annual Symposium on Foundations of Computer Science , 2013, pp. 429–438
2013
Earlier work this paper cites.
C. Dwork and A. Roth, “The algorithmic foundations of differential privacy,” Foundations and Trends® in Theoretical Computer Science , vol. 9, no. 3–4, pp. 211–407, 2014
2014
Earlier work this paper cites.
Ú. Erlingsson, V. Pihur, and A. Korolova, “Rappor: Randomized aggregatable privacy-preserving ordinal response,” in CCS , 2014, pp. 1054–1067
2014
Earlier work this paper cites.
M. Fredrikson, S. Jha, and T. Ristenpart, “Model inversion attacks that exploit confidence information and basic countermeasures,” in CCS , 2015, pp. 1322–1333
2015
Earlier work this paper cites.
D. Demmler, T. Schneider, and M. Zohner, “Aby-a framework for efficient mixed-protocol secure two-party computation.” in NDSS , 2015
2015
Earlier work this paper cites.
S. Goryczka and L. Xiong, “A comprehensive comparison of multiparty secure additions with differential privacy,” IEEE transactions on dependable and secure computing , vol. 14, no. 5, pp. 463–477, 2015
2015
Earlier work this paper cites.
R. Shokri and V. Shmatikov, “Privacy-preserving deep learning,” in CCS , 2015, pp. 1310–1321
2015
Earlier work this paper cites.
M. Abadi, A. Chu, I. Goodfellow, H. B. McMahan, I. Mironov, K. Talwar, and L. Zhang, “Deep learning with differential privacy,” in CCS , 2016, pp. 308–318
2016
Earlier work this paper cites.
2016
Earlier work this paper cites.
Y. Aono, T. Hayashi, L. Trieu Phong, and L. Wang, “Scalable and secure logistic regression via homomorphic encryption,” in Proceedings of the Sixth ACM Conference on Data and Application Security and Privacy , 2016, pp. 142–144
2016
Earlier work this paper cites.
2016
Earlier work this paper cites.
J. Hamm, Y. Cao, and M. Belkin, “Learning privately from multiparty data,” in International Conference on Machine Learning , 2016, pp. 555–563
2016
Earlier work this paper cites.
S. Shen, S. Tople, and P. Saxena, “Auror: defending against poisoning attacks in collaborative deep learning systems,” in Proceedings of the 32nd Annual Conference on Computer Security Applications . ACM, 2016, pp. 508–519
2016
Earlier work this paper cites.
B. Han, I. W. Tsang, and L. Chen, “On the convergence of a family of robust losses for stochastic gradient descent,” in Machine Learning and Knowledge Discovery in Databases - European Conference, ECML PKDD , 2016, pp. 665–680
2016
Earlier work this paper cites.
F. Tramèr, F. Zhang, A. Juels, M. K. Reiter, and T. Ristenpart, “Stealing machine learning models via prediction apis.” in USENIX Security Symposium , 2016, pp. 601–618
2016
Earlier work this paper cites.
K. Bonawitz, V. Ivanov, B. Kreuter, A. Marcedone, H. B. McMahan, S. Patel, D. Ramage, A. Segal, and K. Seth, “Practical secure aggregation for privacy-preserving machine learning,” in CCS , 2017, pp. 1175–1191
2017
Earlier work this paper cites.
B. McMahan, E. Moore, D. Ramage, S. Hampson, and B. A. y Arcas, “Communication-efficient learning of deep networks from decentralized data,” in Artificial Intelligence and Statistics , 2017, pp. 1273–1282
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
P. Blanchard, R. Guerraoui, J. Stainer et al. , “Machine learning with adversaries: Byzantine tolerant gradient descent,” in NeurIPS , 2017, pp. 119–129
2017
Earlier work this paper cites.
Y. Liu, Y. Xie, and A. Srivastava, “Neural trojans,” in ICCD , 2017, pp. 45–48
2017
Earlier work this paper cites.
Y. Chen, L. Su, and J. Xu, “Distributed statistical machine learning in adversarial settings: Byzantine gradient descent,” Proceedings of the ACM on Measurement and Analysis of Computing Systems , vol. 1, no. 2, p. 44, 2017
2017
Earlier work this paper cites.
C. Zhang, S. Bengio, M. Hardt, B. Recht, and O. Vinyals, “Understanding deep learning requires rethinking generalization,” in ICLR , 2017
2017
Earlier work this paper cites.
B. Hitaj, G. Ateniese, and F. Pérez-Cruz, “Deep models under the gan: information leakage from collaborative deep learning,” in CSS , 2017, pp. 603–618
2017
Earlier work this paper cites.
R. Shokri, M. Stronati, C. Song, and V. Shmatikov, “Membership inference attacks against machine learning models,” in SP , 2017, pp. 3–18
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
P. Mohassel and Y. Zhang, “Secureml: A system for scalable privacy-preserving machine learning,” in SP , 2017, pp. 19–38
2017
Earlier work this paper cites.
N. Papernot, M. Abadi, U. Erlingsson, I. Goodfellow, and K. Talwar, “Semi-supervised knowledge transfer for deep learning from private training data,” in ICLR , 2017
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
L. Muñoz-González, B. Biggio, A. Demontis, A. Paudice, V. Wongrassamee, E. C. Lupu, and F. Roli, “Towards poisoning of deep learning algorithms with back-gradient optimization,” in Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security , 2017, pp. 27–38
2017
Earlier work this paper cites.
P. W. Koh and P. Liang, “Understanding black-box predictions via influence functions,” in ICML , 2017, pp. 1885–1894
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
J. Steinhardt, P. W. W. Koh, and P. S. Liang, “Certified defenses for data poisoning attacks,” in NeurIPS , 2017, pp. 3517–3529
2017
Earlier work this paper cites.
H. Li, K. Ota, and M. Dong, “Learning iot in edge: Deep learning for the internet of things with edge computing,” IEEE Network , vol. 32, no. 1, pp. 96–101, 2018
2018
Earlier work this paper cites.
H. B. McMahan, D. Ramage, K. Talwar, and L. Zhang, “Learning differentially private recurrent language models,” in ICLR , 2018
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
2018
Earlier work this paper cites.
N. Agarwal, A. T. Suresh, F. X. X. Yu, S. Kumar, and B. McMahan, “cpsgd: Communication-efficient and differentially-private distributed sgd,” in NeurIPS , 2018, pp. 7564–7575
2018
Cited alongside, same era.
Y. Aono, T. Hayashi, L. Wang, S. Moriai et al. , “Privacy-preserving deep learning via additively homomorphic encryption,” IEEE Transactions on Information Forensics and Security , vol. 13, no. 5, pp. 1333–1345, 2018
2018
Cited alongside, same era.
2018
Cited alongside, same era.
2018
Cited alongside, same era.
H. Wang, K. Sreenivasan, S. Rajput, H. Vishwakarma, S. Agarwal, J.-y. Sohn, K. Lee, and D. Papailiopoulos, “Attack of the tails: Yes, you really can backdoor federated learning,” NeurIPS , 2020
2020
Closest in time.
C. Xie, K. Huang, P. Chen, and B. Li, “DBA: distributed backdoor attacks against federated learning,” in 8th International Conference on Learning Representations , 2020
2020
Closest in time.
C. Fung, C. J. Yoon, and I. Beschastnikh, “The limitations of federated learning in sybil settings,” in 23rd International Symposium on Research in Attacks, Intrusions and Defenses ( { \{ RAID } \} 2020) , 2020, pp. 301–316
2020
Closest in time.
L. Lyu, Y. W. Law, K. S. Ng, S. Xue, J. Zhao, M. Yang, and L. Liu, “Distributed privacy-preserving prediction,” in International Conference on Systems, Man, and Cybernetics , 2020
2020
Closest in time.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2018
Cited alongside, same era.
B. Tran, J. Li, and A. Madry, “Spectral signatures in backdoor attacks,” in NeurIPS , 2018, pp. 8000–8010
2018
Cited alongside, same era.
2018
Cited alongside, same era.
C. Miao, Q. Li, H. Xiao, W. Jiang, M. Huai, and L. Su, “Towards data poisoning attacks in crowd sensing systems,” in Proceedings of the Eighteenth ACM International Symposium on Mobile Ad Hoc Networking and Computing , 2018, pp. 111–120
2018
Cited alongside, same era.
C. Miao, Q. Li, L. Su, M. Huai, W. Jiang, and J. Gao, “Attack under disguise: An intelligent data poisoning attack mechanism in crowdsourcing,” in Proceedings of the 2018 World Wide Web Conference , 2018, pp. 13–22
2018
Cited alongside, same era.
L. T. Phong, Y. Aono, T. Hayashi, L. Wang, and S. Moriai, “Privacy-preserving deep learning via additively homomorphic encryption,” IEEE Transactions on Information Forensics and Security , vol. 13, no. 5, pp. 1333–1345, 2018
2018
Cited alongside, same era.
2018
Cited alongside, same era.
L. Lyu, “Privacy-preserving machine learning and data aggregation for internet of things,” Ph.D. dissertation, The University of Melbourne, 2018
2018
Cited alongside, same era.
2020
Closest in time.
2020
Closest in time.
2020
Closest in time.
E. Chou, F. Tramer, and G. Pellegrino, “Sentinet: Detecting localized universal attack against deep learning systems,” IEEE SPW , 2020
2020
Closest in time.
Y. Liu, X. Ma, J. Bailey, and F. Lu, “Reflection backdoor: A natural backdoor attack on deep neural networks,” in ECCV . Springer, 2020, pp. 182–199
2020
Closest in time.
2020
Closest in time.
M. Fang, X. Cao, J. Jia, and N. Gong, “Local model poisoning attacks to byzantine-robust federated learning,” in 29th { \{ USENIX } \} Security Symposium ( { \{ USENIX } \} Security 20) , 2020, pp. 1605–1622
2020
Closest in time.
C. Xie, O. Koyejo, and I. Gupta, “Fall of empires: Breaking byzantine-tolerant sgd by inner product manipulation,” in UAI . PMLR, 2020, pp. 261–270
2020
Closest in time.
2020
Closest in time.
2020
Closest in time.
S. Truex, L. Liu, K.-H. Chow, M. E. Gursoy, and W. Wei, “Ldp-fed: federated learning with local differential privacy,” in Proceedings of the Third ACM International Workshop on Edge Systems, Analytics and Networking , 2020, pp. 61–66
2020
Closest in time.
2020
Closest in time.
L. Lyu, “Lightweight crypto-assisted distributed differential privacy for privacy-preserving distributed learning,” in 2020 International Joint Conference on Neural Networks (IJCNN) . IEEE, 2020, pp. 1–8
2020
Closest in time.
2020
Closest in time.
2020
Closest in time.
2020
Closest in time.
L. Lyu and C.-H. Chen, “Differentially private knowledge distillation for mobile analytics,” in Proceedings of the 43rd International ACM SIGIR Conference on Research and Development in Information Retrieval , 2020, pp. 1809–1812
2020
Closest in time.
2020
Closest in time.
T. A. Nguyen and A. Tran, “Input-aware dynamic backdoor attack,” Advances in Neural Information Processing Systems , vol. 33, pp. 3454–3464, 2020
2020
Closest in time.
S. Zhao, X. Ma, X. Zheng, J. Bailey, J. Chen, and Y.-G. Jiang, “Clean-label backdoor attacks on video recognition models,” in CVPR , 2020, pp. 14 443–14 452
2020
Closest in time.
2020
Closest in time.
2020
Closest in time.
2020
Closest in time.
2020
Closest in time.
L. Lyu, J. Yu, K. Nandakumar, Y. Li, X. Ma, J. Jin, H. Yu, and K. S. Ng, “Towards fair and privacy-preserving federated deep models,” IEEE Transactions on Parallel and Distributed Systems , vol. 31, no. 11, pp. 2524–2541, 2020
2020
Closest in time.
L. Lyu, Y. Li, K. Nandakumar, J. Yu, and X. Ma, “How to democratise and protect ai: Fair and differentially private decentralised deep learning,” IEEE Transactions on Dependable and Secure Computing , 2020
2020
Closest in time.
L. Lyu, J. C. Bezdek, J. Jin, and Y. Yang, “Foreseen: Towards differentially private deep inference for intelligent internet of things,” IEEE Journal on Selected Areas in Communications , 2020
2020
Closest in time.
X. Pan, M. Zhang, S. Ji, and M. Yang, “Privacy risks of general-purpose language models,” in 2020 IEEE Symposium on Security and Privacy (SP) . IEEE, 2020, pp. 1314–1331
2020
Closest in time.
2020
Closest in time.
2020
Closest in time.
2020
Closest in time.
Q. Yang, L. Fan, and H. Yu, Eds., Federated Learning: Privacy and Incentive . Springer International Publishing, 2020
2020
Closest in time.
2020
Closest in time.
2021
Closest in time.
J. Cui, C. Chen, L. Lyu, C. Yang, and W. Li, “Exploiting data sparsity in secure cross-platform social recommendation,” Advances in Neural Information Processing Systems , vol. 34, 2021
2021
Closest in time.
J. Li, L. Lyu, X. Liu, X. Zhang, and X. Lv, “Fleam: A federated learning empowered architecture to mitigate ddos in industrial iot,” IEEE Transactions on Industrial Informatics , 2021
2021
Closest in time.
2021
Closest in time.
2021
Closest in time.
D. Tang, X. Wang, H. Tang, and K. Zhang, “Demon in the variant: Statistical analysis of dnns for robust backdoor contamination detection,” USENIX , 2021
2021
Closest in time.
2021
Closest in time.
——, “Anti-backdoor learning: Training clean models on poisoned data,” Advances in Neural Information Processing Systems , vol. 34, 2021
2021
Closest in time.
G. Sun, Y. Cong, J. Dong, Q. Wang, L. Lyu, and J. Liu, “Data poisoning attacks on federated machine learning,” IEEE Internet of Things Journal , 2021
2021
Closest in time.
2021
Closest in time.
2021
Closest in time.
S. Andreina, G. A. Marson, H. Möllering, and G. Karame, “Baffle: Backdoor detection via feedback-based federated learning,” in 2021 IEEE 41st International Conference on Distributed Computing Systems (ICDCS) . IEEE, 2021, pp. 852–863
2021
Closest in time.
2021
Closest in time.
2021
Closest in time.
2021
Closest in time.
2021
Closest in time.
2021
Closest in time.
N. Truong, K. Sun, S. Wang, F. Guitton, and Y. Guo, “Privacy preservation in federated learning: An insightful survey from the gdpr perspective,” Computers & Security , vol. 110, p. 102402, 2021
2021
Closest in time.
K. Cheng, T. Fan, Y. Jin, Y. Liu, T. Chen, D. Papadopoulos, and Q. Yang, “Secureboost: A lossless federated learning framework,” IEEE Intelligent Systems , 2021
2021
Closest in time.
X. Jin, P.-Y. Chen, C.-Y. Hsu, C.-M. Yu, and T. Chen, “Catastrophic data leakage in vertical federated learning,” Advances in Neural Information Processing Systems , vol. 34, 2021
2021
Closest in time.
X. Xinyi, L. Lyu, X. Ma, C. Miao, C.-S. Foo, and B. K. H. Low, “Gradient driven rewards to guarantee fairness in collaborative machine learning,” in Thirty-Fifth Conference on Neural Information Processing Systems , 2021
2021
Closest in time.
S. Warnat-Herresthal, H. Schultze, K. L. Shastry, S. Manamohan, S. Mukherjee, V. Garg, R. Sarveswara, K. Händler, P. Pickkers, N. A. Aziz et al. , “Swarm learning for decentralized and confidential clinical machine learning,” Nature , vol. 594, no. 7862, pp. 265–270, 2021
2021
Closest in time.
D. K. Dennis, T. Li, and V. Smith, “Heterogeneity for the win: One-shot federated clustering,” 2021
2021
Closest in time.
2021
Closest in time.
X. Xu and L. Lyu, “A reputation mechanism is all you need: Collaborative fairness and adversarial robustness in federated learning,” in Proc. ICML Workshop on Federated Learning for User Privacy and Data Confidentiality , 2021
2021
Closest in time.
X. He, Q. Xu, L. Lyu, F. Wu, and C. Wang, “Protecting intellectual property of language generation apis with lexical watermark,” in AAAI , 2022
2022
Closest in time.
Y. Yao, H. Li, H. Zheng, and B. Y. Zhao, “Latent backdoor attacks on deep neural networks,” in Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security , 2019, pp. 2041–2055
2055
Closest in time.