CoPur: Certifiably Robust Collaborative Inference via Feature Purification

Neural Information Processing Systems 

In this setting, we consider inference phase attacks when a small fraction of agents is compromised. The compromised agent either does not send embedded features to the FC or sends arbitrary embedded features.