Goto

Collaborating Authors

 lockdown



Lockdown: Backdoor Defense for Federated Learning with Isolated Subspace Training

Neural Information Processing Systems

Federated learning (FL) is vulnerable to backdoor attacks due to its distributed computing nature. Existing defense solution usually requires larger amount of computation in either the training or testing phase, which limits their practicality in the resource-constrain scenarios. A more practical defense, i.e., neural network (NN) pruning based defense has been proposed in centralized backdoor setting. However, our empirical study shows that traditional pruning-based solution suffers \textit{poison-coupling} effect in FL, which significantly degrades the defense performance.This paper presents Lockdown, an isolated subspace training method to mitigate the poison-coupling effect. Lockdown follows three key procedures.



Appendix A: Related Literature

Neural Information Processing Systems

Appendix for "When and How to Lift the Lockdown? A tabulated comparison between our model and existing ones is laid out in Table A1.Approach Training Approach Modeling Scope Policy Effects Model Uncertainty Compartmental models Exhaustive parameter search Individual countries Not incorporated None Machine learning-based compartmental models Gradient descent optimization Individual countries Not incorporated Ad-hoc bootstrap estimates Bayesian mechanistic hierarchical model Posterior inference via MCMC methods Individual countries Incorporated Bayesian credible intervals Curve fitting Exhaustive parameter search Individual countries Not incorporated None Dynamic control modeling Model parameters based on expert knowledge Individual countries Incorporated None Recurrent neural networks for fatality curve modeling [49] Gradient descent optimization Individual countries Not incorporated None Compartmental Gaussian processes Stochastic gradient-based variational inference Global ...




A Supplementary Material 463 A.1 Implementation Details

Neural Information Processing Systems

We use Erd os-Rényi Kernel (ERK) (Evci et al., 2020), an empirical (l 1) In the mask searching process, we use parameter's magnitude to guide the Following (Evci et al., 2020), we use Labels of poison samples are manipulated to the target label (e.g., a horse). " corresponds to be applicable while " " corresponds to be not applicable. BadNet is the earliest, and also the simplest backdoor attack first proposed in (Gu et al., DBA. DBA (Xie et al., 2019) is a backdoor attack specifically targeted on FL. Sinusoidal attack (Barni et al., 2019) shares a similar perspective with BadNet, The basic idea of Scaling (Bagdasaryan et al., 2020) is to enlarge the gradient update FixMask is an adaptive attack method specifically targeting Lockdown.




The pandemic may have aged our brains even before we caught covid-19

New Scientist

The covid-19 pandemic may have accelerated the ageing of our brains even before we caught the infection. Research suggests that even relatively early on in the outbreak, brains aged by 5.5 months, possibly due to stress or lifestyle changes. We know that many people with long covid experience brain fog, but years after the arrival of covid-19, the pandemic's broader neurological impact is far from fully understood. To get a grasp on this, Ali-Reza Mohammadi-Nejad at Nottingham University, UK, and his colleagues trained a machine learning model on 15,000 brain scans to identify how its structure changes with age. They then fed the model pairs of brain scans from 996 volunteers from the UK Biobank study.