A new research paper explores the potential harm of gradient attacks in distributed machine learning systems, specifically focusing on label flipping. The study proposes a formalization of these attacks as a constrained optimization problem and derives a greedy label-selection rule that is provably optimal for attackers under mean aggregation. Empirically, the research demonstrates that optimized label flipping can significantly degrade model accuracy and even transfer to other aggregation methods like median and trimmed mean, posing a substantial availability threat. AI
IMPACT Highlights a significant security vulnerability in distributed machine learning systems, potentially impacting the robustness of federated learning deployments.
RANK_REASON Academic paper on machine learning security. [lever_c_demoted from research: ic=1 ai=1.0]
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →