paper-with-me

홈 › Papers

UTrace: Poisoning Forensics for Private Collaborative Learning

2024-09-23 · Evan Rose, Hidde Lycklama, Harsh Chaudhari, Anwar Hithnawi, Alina Oprea

Privacy-preserving machine learning (PPML) enables multiple data owners to contribute their data privately to a set of servers that run a secure multi-party computation (MPC) protocol to train a joint ML model. In these protocols, the input data remains private throughout the training process, and only the resulting model is made available. While this approach benefits privacy, it also exacerbates the risks of data poisoning, where compromised data owners induce undesirable model behavior by contributing malicious datasets. Existing MPC mechanisms can mitigate certain poisoning attacks, but these measures are not exhaustive. To complement existing poisoning defenses, we introduce UTrace: a framework for User-level Traceback of poisoning attacks in PPML. Utrace computes user responsibility scores using gradient similarity metrics aggregated across the most relevant samples in an owner's dataset. UTrace is effective at low poisoning rates and is resilient to poisoning attacks distributed across multiple data owners, unlike existing unlearning-based methods. We introduce methods for checkpointing gradients with low storage overhead, enabling traceback in the absence of data owners at deployment time. We also design several optimizations that reduce traceback time and communication in MPC. We provide a comprehensive evaluation of UTrace across four datasets from three data modalities (vision, text, and malware) and show its effectiveness against 10 poisoning attacks.

📄 PDF Abstract BibTeX arXiv:2409.15126

Code (0)

등록된 구현이 없습니다.

Tasks

Data PoisoningPrivacy Preserving

Methods 이 논문이 사용한 방법론

SET Dynamic Sparse Training method where weight mask is updated randomly periodically

Similar Papers 제목 키워드 기반

Tracing Back the Malicious Clients in Poisoning Attacks to Federated Learning

2024-07-09 · Yuqi Jia, Minghong Fang, Hongbin Liu, Jinghuai Zhang 외

Poisoning attacks compromise the training phase of federated learning (FL) such that the learned global model misclassifies attacker-chosen inputs called target inputs. Existing defenses mainly focus on protecting the tr…

Federated Learning

Traceback of Poisoning Attacks to Retrieval-Augmented Generation

2025-04-30 · Baolei Zhang, Haoran Xin, Minghong Fang, Zhuqing Liu 외

Large language models (LLMs) integrated with retrieval-augmented generation (RAG) systems improve accuracy by leveraging external knowledge sources. However, recent research has revealed RAG's susceptibility to poisoning…

RAGRetrievalRetrieval-augmented Generation

Literature Mining System for Nutraceutical Biosynthesis: From AI Framework to Biological Insight

2025-12-23 · Xinyang Sun, Nipon Sarmah, Miao Guo arxiv

The extraction of structured knowledge from scientific literature remains a major bottleneck in nutraceutical research, particularly when identifying microbial strains involved in compound biosynthesis. This study presen…

Prompt Engineering

Dietary Supplements and Nutraceuticals Under Investigation for COVID-19 Prevention and Treatment

2021-02-03 · Ronan Lordan, Halie M. Rando, COVID-19 Review Consortium, Casey S. Greene

Coronavirus disease 2019 (COVID-19) has caused global disruption and a significant loss of life. Existing treatments that can be repurposed as prophylactic and therapeutic agents could reduce the pandemic's devastation. …

Client Clustering Meets Knowledge Sharing: Enhancing Privacy and Robustness in Personalized Peer-to-Peer Learning

2025-06-25 · Mohammad Mahdi Maheri, Denys Herasymuk, Hamed Haddadi

The growing adoption of Artificial Intelligence (AI) in Internet of Things (IoT) ecosystems has intensified the need for personalized learning methods that can operate efficiently and privately across heterogeneous, reso…

Knowledge DistillationTransfer Learning