Matches in SemOpenAlex for { <https://semopenalex.org/work/W4229455429> ?p ?o ?g. }
Showing items 1 to 59 of
59
with 100 items per page.
- W4229455429 abstract "Existing model poisoning attacks to federated learning assume that an attacker has access to a large fraction of compromised genuine clients. However, such assumption is not realistic in production federated learning systems that involve millions of clients. In this work, we propose the first Model Poisoning Attack based on Fake clients called MPAF. Specifically, we assume the attacker injects fake clients to a federated learning system and sends carefully crafted fake local model updates to the cloud server during training, such that the learnt global model has low accuracy for many indiscriminate test inputs. Towards this goal, our attack drags the global model towards an attacker-chosen base model that has low accuracy. Specifically, in each round of federated learning, the fake clients craft fake local model updates that point to the base model and scale them up to amplify their impact before sending them to the cloud server. Our experiments show that MPAF can significantly decrease the test accuracy of the global model, even if classical defenses and norm clipping are adopted, highlighting the need for more advanced defenses." @default.
- W4229455429 created "2022-05-11" @default.
- W4229455429 creator A5009102659 @default.
- W4229455429 creator A5032504910 @default.
- W4229455429 date "2022-06-01" @default.
- W4229455429 modified "2023-10-16" @default.
- W4229455429 title "MPAF: Model Poisoning Attacks to Federated Learning based on Fake Clients" @default.
- W4229455429 cites W2559840118 @default.
- W4229455429 cites W3087391814 @default.
- W4229455429 cites W3138597937 @default.
- W4229455429 cites W4252654521 @default.
- W4229455429 cites W4288057793 @default.
- W4229455429 doi "https://doi.org/10.1109/cvprw56347.2022.00383" @default.
- W4229455429 hasPublicationYear "2022" @default.
- W4229455429 type Work @default.
- W4229455429 citedByCount "13" @default.
- W4229455429 countsByYear W42294554292022 @default.
- W4229455429 countsByYear W42294554292023 @default.
- W4229455429 crossrefType "proceedings-article" @default.
- W4229455429 hasAuthorship W4229455429A5009102659 @default.
- W4229455429 hasAuthorship W4229455429A5032504910 @default.
- W4229455429 hasBestOaLocation W42294554292 @default.
- W4229455429 hasConcept C111919701 @default.
- W4229455429 hasConcept C136764020 @default.
- W4229455429 hasConcept C154945302 @default.
- W4229455429 hasConcept C2987335383 @default.
- W4229455429 hasConcept C2992525071 @default.
- W4229455429 hasConcept C38652104 @default.
- W4229455429 hasConcept C41008148 @default.
- W4229455429 hasConcept C79974875 @default.
- W4229455429 hasConcept C93996380 @default.
- W4229455429 hasConceptScore W4229455429C111919701 @default.
- W4229455429 hasConceptScore W4229455429C136764020 @default.
- W4229455429 hasConceptScore W4229455429C154945302 @default.
- W4229455429 hasConceptScore W4229455429C2987335383 @default.
- W4229455429 hasConceptScore W4229455429C2992525071 @default.
- W4229455429 hasConceptScore W4229455429C38652104 @default.
- W4229455429 hasConceptScore W4229455429C41008148 @default.
- W4229455429 hasConceptScore W4229455429C79974875 @default.
- W4229455429 hasConceptScore W4229455429C93996380 @default.
- W4229455429 hasFunder F4320306076 @default.
- W4229455429 hasFunder F4320316514 @default.
- W4229455429 hasLocation W42294554291 @default.
- W4229455429 hasLocation W42294554292 @default.
- W4229455429 hasOpenAccess W4229455429 @default.
- W4229455429 hasPrimaryLocation W42294554291 @default.
- W4229455429 hasRelatedWork W1850392543 @default.
- W4229455429 hasRelatedWork W2077950080 @default.
- W4229455429 hasRelatedWork W2118985335 @default.
- W4229455429 hasRelatedWork W2290069055 @default.
- W4229455429 hasRelatedWork W2476611981 @default.
- W4229455429 hasRelatedWork W2911113383 @default.
- W4229455429 hasRelatedWork W3108329480 @default.
- W4229455429 hasRelatedWork W4220807133 @default.
- W4229455429 hasRelatedWork W4285611274 @default.
- W4229455429 hasRelatedWork W4290996980 @default.
- W4229455429 isParatext "false" @default.
- W4229455429 isRetracted "false" @default.
- W4229455429 workType "article" @default.