Fetching the paper…
Reading the bibliography…
While recent works have indicated that federated learning (FL) may be vulnerable to poisoning attacks by compromised clients, their real impact on production FL systems is not fully understood.
Y. LeCun, L. Bottou, Y. Bengio et al. , “Gradient-based learning applied to document recognition,” Proceedings of the IEEE , 1998
1998
Earlier work this paper cites.
T. Minka, “Estimating a Dirichlet distribution,” 2000
2000
Earlier work this paper cites.
A. Krizhevsky, “Learning multiple layers of features from tiny images,” University of Toronto, Tech. Rep., 2009
2009
Earlier work this paper cites.
M. Barreno, B. Nelson, and A. D. Joseph, “The security of machine learning,” Machine Learning , 2010
2010
Earlier work this paper cites.
L. Huang, A. D. Joseph, B. Nelson, B. I. Rubinstein, and J. D. Tygar, “Adversarial machine learning,” in AISec , 2011
2011
Earlier work this paper cites.
B. Biggio, B. Nelson, and P. Laskov, “Poisoning attacks against support vector machines,” in ICML , 2012
2012
Earlier work this paper cites.
H. Xiao, H. Xiao, and C. Eckert, “Adversarial label flips attack on support vector machines,” in ECAI , 2012
2012
Earlier work this paper cites.
A. Newell, R. Potharaju, L. Xiang, and C. Nita-Rotaru, “On the practicality of integrity attacks on document-level sentiment analysis,” in AISec , 2014
2014
Earlier work this paper cites.
“Billion Passwords Stolen: Change All of Yours, Now!” https://www.nbcnews.com/tech/security/billion-passwords-stolen-change-all-yours-now-n174321 , 2014
2014
Earlier work this paper cites.
“Hackers Expose 8.4 Billion Passwords Post them Online in Possibly Largest Dump of Passwords Ever,” https://www.thegatewaypundit.com/2021/06/hackers-expose-8-4-billion-passwords-post-online-possibly-largest-dump-passwords-ever/ , 2014
2014
Earlier work this paper cites.
K. Simonyan and A. Zisserman, “Very deep convolutional networks for large-scale image recognition,” in ICLR , 2015
2015
Earlier work this paper cites.
H. Xiao, B. Biggio, B. Nelson, H. Xiao, C. Eckert, and F. Roli, “Support vector machines under adversarial label contamination,” Neurocomputing , 2015
2015
Earlier work this paper cites.
J. Konečnỳ, H. B. McMahan, F. X. Yu, P. Richtárik, A. T. Suresh, and D. Bacon, “Federated learning: Strategies for improving communication efficiency,” NIPS Workshop on Private Multi-Party ML , 2016
2016
Earlier work this paper cites.
“Federated learning: Collaborative machine learning without centralized training data,” https://ai.googleblog.com/2017/04/federated-learning-collaborative.html , 2017
2017
Earlier work this paper cites.
P. Blanchard, R. Guerraoui, J. Stainer et al. , “Machine learning with adversaries: Byzantine tolerant gradient descent,” in NeurIPS , 2017
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
G. Cohen, S. Afshar, J. Tapson, and A. Van Schaik, “EMNIST: Extending MNIST to handwritten letters,” in IJCNN , 2017
2017
Earlier work this paper cites.
H. B. McMahan, E. Moore, D. Ramage, S. Hampson, and B. A. y. Arcas, “Communication-efficient learning of deep networks from decentralized data,” in AISTATS , 2017
2017
Earlier work this paper cites.
L. Muñoz-González, B. Biggio, A. Demontis, A. Paudice, V. Wongrassamee, E. C. Lupu, and F. Roli, “Towards poisoning of deep learning algorithms with back-gradient optimization,” in AISec , 2017
2017
Earlier work this paper cites.
2017
Earlier work this paper cites.
D. Alistarh, Z. Allen-Zhu, and J. Li, “Byzantine stochastic gradient descent,” in NeurIPS , 2018
2018
Earlier work this paper cites.
J. Bernstein, J. Zhao, K. Azizzadenesheli, and A. Anandkumar, “signSGD with Majority Vote is Communication Efficient and Fault Tolerant,” in ICLR , 2018
2018
Earlier work this paper cites.
B. Biggio and F. Roli, “Wild patterns: Ten years after the rise of adversarial machine learning,” Pattern Recognition , 2018
2018
Earlier work this paper cites.
M. H. Brendan, D. Ramage, K. Talwar, and L. Zhang, “Learning differentially private recurrent language models,” in ICLR , 2018
2018
Earlier work this paper cites.
2018
Cited alongside, same era.
L. Chen, H. Wang, Z. Charles, and D. Papailiopoulos, “Draco: Byzantine-resilient distributed training via redundant gradients,” in ICML , 2018
2018
Cited alongside, same era.
M. Jagielski, A. Oprea, B. Biggio, C. Liu, C. Nita-Rotaru, and B. Li, “Manipulating machine learning: Poisoning attacks and countermeasures against regression learning,” 39th IEEE Symposium on S&P , 2018
2018
Cited alongside, same era.
E. M. E. Mhamdi, R. Guerraoui, and S. Rouault, “The Hidden Vulnerability of Distributed Learning in Byzantium,” in ICML , 2018
2018
Cited alongside, same era.
A. Shafahi, W. R. Huang, M. Najibi, O. Suciu, C. Studer, T. Dumitras, and T. Goldstein, “Poison frogs! targeted clean-label poisoning attacks on neural networks,” in NeurIPS , 2018
2020
Later among the works it cites.
M. Fang, X. Cao, J. Jia, and N. Z. Gong, “Local Model Poisoning Attacks to Byzantine-Robust Federated Learning,” in USENIX , 2020
2020
Later among the works it cites.
“Google Workshop on Federated Learning and Analytics,” https://docs.google.com/document/d/1dWzVeFLrPinonQMauxIo0oI-Vbvqup5cZzgdPXvu97Y/edit#heading=h.7dsxad3c3nf7 , 2020
2020
Later among the works it cites.
C. Fung, C. J. Yoon, and I. Beschastnikh, “The limitations of federated learning in sybil settings,” in RAID , 2020
2020
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2018
Cited alongside, same era.
C. Xie, O. Koyejo, and I. Gupta, “Generalized byzantine-tolerant sgd,” arXiv:1802.10116 , 2018
2018
Cited alongside, same era.
D. Yin, Y. Chen, K. Ramchandran, and P. Bartlett, “Byzantine-robust distributed learning: Towards optimal statistical rates,” in ICML , 2018
2018
Cited alongside, same era.
M. Baruch, B. Gilad, and Y. Goldberg, “A Little Is Enough: Circumventing Defenses For Distributed Learning,” in NeurIPS , 2019
2019
Cited alongside, same era.
A. N. Bhagoji, S. Chakraborty, P. Mittal, and S. Calo, “Analyzing federated learning through an adversarial lens,” in ICML , 2019
2019
Cited alongside, same era.
K. Bonawitz, H. Eichner, W. Grieskamp, D. Huba, A. Ingerman, V. Ivanov, C. Kiddon, J. Konecný, S. Mazzocchi, B. McMahan, T. V. Overveldt, D. Petrou, D. Ramage, and J. Roselander, “Towards federated learning at scale: System design,” in MLSys , 2019
2019
Cited alongside, same era.
2019
Cited alongside, same era.
2019
Cited alongside, same era.
2020
Later among the works it cites.
M. S. Jere, T. Farnan, and F. Koushanfar, “A taxonomy of attacks on federated learning,” IEEE Security & Privacy , 2020
2020
Later among the works it cites.
T. Lin, L. Kong, S. U. Stich, and M. Jaggi, “Ensemble distillation for robust model fusion in federated learning,” in NeurIPS , 2020
2020
Later among the works it cites.
2020
Later among the works it cites.
S. J. Reddi, Z. Charles, M. Zaheer, Z. Garrett, K. Rush, J. Konečnỳ, S. Kumar, and H. B. McMahan, “Adaptive Federated Optimization,” in ICLR , 2020
2020
Later among the works it cites.
V. Tolpegin, S. Truex, M. E. Gursoy, and L. Liu, “Data poisoning attacks against federated learning systems,” in ESORICS , 2020
2020
Later among the works it cites.
H. Wang, K. Sreenivasan, S. Rajput, H. Vishwakarma, S. Agarwal, J.-y. Sohn, K. Lee, and D. Papailiopoulos, “Attack of the tails: Yes, you really can backdoor federated learning,” in NeurIPS , 2020
2020
Later among the works it cites.
2020
Later among the works it cites.
2020
Later among the works it cites.
X. Cao, J. Jia, and N. Z. Gong, “Provably Secure Federated Learning against Malicious Clients,” in AAAI , 2021
2021
Closest in time.
“CS231n: Convolutional Neural Networks for Visual Recognition,” https://cs231n.github.io/optimization-2/#grad , 2021
2021
Closest in time.
“Google Play Protect,” https://developers.google.com/android/play-protect , 2021
2021
Closest in time.
T. Li, S. Hu, A. Beirami, and V. Smith, “Ditto: Fair and robust federated learning through personalization,” in ICML , 2021
2021
Closest in time.
“26 million stolen passwords found online — see if you’re affected,” https://www.tomsguide.com/news/mystery-malware-info-stealer , 2021
2021
Closest in time.
2021
Closest in time.
“SafetyNet Attestation API,” https://developer.android.com/training/safetynet/attestation , 2021
2021
Closest in time.
V. Shejwalkar and A. Houmansadr, “Manipulating the Byzantine: Optimizing Model Poisoning Attacks and Defenses for Federated Learning,” in NDSS , 2021
2021
Closest in time.
G. Sun, Y. Cong, J. Dong, Q. Wang, L. Lyu, and J. Liu, “Data poisoning attacks on federated machine learning,” IEEE IoT Journal , 2021
2021
Closest in time.
C. Xie, M. Chen, P.-Y. Chen, and B. Li, “CRFL: Certifiably Robust Federated Learning against Backdoor Attacks,” in ICML , 2021
2021
Closest in time.