REVIEW 1 cited by
Fall of Empires: Breaking Byzantine-tolerant SGD by Inner Product Manipulation
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
read the original abstract
Recently, new defense techniques have been developed to tolerate Byzantine failures for distributed machine learning. The Byzantine model captures workers that behave arbitrarily, including malicious and compromised workers. In this paper, we break two prevailing Byzantine-tolerant techniques. Specifically we show robust aggregation methods for synchronous SGD -- coordinate-wise median and Krum -- can be broken using new attack strategies based on inner product manipulation. We prove our results theoretically, as well as show empirical validation.
Forward citations
Cited by 1 Pith paper
-
Decoding FL Defenses: Systemization, Pitfalls, and Remedies
Many FL defenses are evaluated on overly easy datasets and attacks, and this paper demonstrates with case studies that those easy settings can make weak defenses look strong.
Discussion (0). Continue with ORCID to comment.