כתבה
arXiv cs.LG ·
התקרבות לנזק של התקפות גרדיאנטים תוך שינוי תוויות
Approaching the Harm of Gradient Attacks While Only Flipping Labels
במאמר זה, נחקור את ההשפעה של התקפות גרדיאנטים תוך שינוי תוויות על רכיבי למידה מופצים. נבחן את היכולת של התקפות כאלו לגרום לירידה בדיוק, ואת האפשרות להגן על רכיבי למידה אלה.
תקציר מקורי באנגליתarXiv:2503.00140v3 Announce Type: replace-cross Abstract: Machine learning systems deployed in distributed or federated environments are highly susceptible to adversarial manipulations, particularly availability attacks -- rendering the trained model unavailable. Prior research in distributed ML has demonstrated such adversarial effects through the injection of gradients or data poisoning. In this work, we ask whether comparable degradation is still possible under a substantially more constrained action space: the adversary may only flip a limited number of labels of existing training examples, without modifying features, injecting samples, or directly controlling gradients. We analyze the extent of damage caused by constrained label flipping attacks against distributed learning under mean
קרא במקור המקורי
arxiv.org
פתח כתבה מקורית