ThisData poisoningData leakage chapter discusses two attacks that target weaknesses of federated learningFederated learning systems: (1) data leakageData leakage, inferring raw data used to train an AIArtificial intelligence (AI) model by unauthorized parties and (2) data poisoningData poisoning, a cyberattack that compromises data used to train an AIArtificial intelligence (AI) model to manipulate its output. A major source of data leakageData leakage is gradient sharingGradientGradient sharing during training of federated learningFederated learning systems. A dishonest party with access to local gradientsGradient from participants during AIArtificial intelligence (AI) model training can carry out a gradient inversion attackGradientInversion attackGradient inversion attack to reconstruct the raw data of individual participants. As data leakageData leakage from gradient sharingGradientGradient sharing came to be recognized as a problem with no easy solution, the practice has been curtailed in commercial deployments. Another threat to federated learningFederated learning systems is data poisoningData poisoning. Modifying an AIArtificial intelligence (AI) model during training using poison data to generate incorrect predictions can be harmful and is particularly problematic when the contaminated global AIArtificial intelligence (AI) model confidently outputs incorrect results that look credible, at a cursory glance. These two attacks demonstrate the difficulty in developing new frameworks for real-world deployments. Since it is beyond the scope of this work to review cryptography, security, and privacy attacks, we refer readers to some survey works.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Data Leakage and Data Poisoning

  • Mei Kobayashi

摘要

ThisData poisoningData leakage chapter discusses two attacks that target weaknesses of federated learningFederated learning systems: (1) data leakageData leakage, inferring raw data used to train an AIArtificial intelligence (AI) model by unauthorized parties and (2) data poisoningData poisoning, a cyberattack that compromises data used to train an AIArtificial intelligence (AI) model to manipulate its output. A major source of data leakageData leakage is gradient sharingGradientGradient sharing during training of federated learningFederated learning systems. A dishonest party with access to local gradientsGradient from participants during AIArtificial intelligence (AI) model training can carry out a gradient inversion attackGradientInversion attackGradient inversion attack to reconstruct the raw data of individual participants. As data leakageData leakage from gradient sharingGradientGradient sharing came to be recognized as a problem with no easy solution, the practice has been curtailed in commercial deployments. Another threat to federated learningFederated learning systems is data poisoningData poisoning. Modifying an AIArtificial intelligence (AI) model during training using poison data to generate incorrect predictions can be harmful and is particularly problematic when the contaminated global AIArtificial intelligence (AI) model confidently outputs incorrect results that look credible, at a cursory glance. These two attacks demonstrate the difficulty in developing new frameworks for real-world deployments. Since it is beyond the scope of this work to review cryptography, security, and privacy attacks, we refer readers to some survey works.