5 papers
Color Matters: Trigger Color Affects Success in Federated Backdoor Attacks
Kavindu Herath, Joshua C. Zhao, Saurabh Bagchi
Federated learning is vulnerable to backdoor attacks in which malicious clients inject poisoned updates while preserving benign-task performance. In this paper, we study a semantic…
Beyond Corner Patches: Semantics-Aware Backdoor Attack in Federated Learning
Kavindu Herath, Joshua Zhao, Saurabh Bagchi
Backdoor attacks on federated learning (FL) are most often evaluated with synthetic corner patches or out-of-distribution (OOD) patterns that are unlikely to arise in practice. In…
Are Fast Methods Stable in Adversarially Robust Transfer Learning?
Joshua C. Zhao, Saurabh Bagchi
Transfer learning is often used to decrease the computational cost of model training, as fine-tuning a model allows a downstream task to leverage the features learned from the pre-…
TESSERACT: Gradient Flip Score to Secure Federated Learning Against Model Poisoning Attacks
Atul Sharma, Wei Chen, Joshua Zhao +3
Federated learning---multi-party, distributed learning in a decentralized environment---is vulnerable to model poisoning attacks, even more so than centralized learning approaches.…
An End-to-End Solution for Effectively Demoting Watermarked Images in Image Search
Ning Ma, Xin Zhao, Mark Bolin
We propose an end-to-end solution, from watermark feature generation to metric design, for effectively demoting watermarked images surfed by a real world image search engine. We us…