Goto

Collaborating Authors

 poisoning attack







Unveiling

Neural Information Processing Systems

Earlier research highlighted DMs' vulnerability todatapoisoning attacks, butthese studies placed stricter requirements than conventional methods like'BadNets' inimage classification.


DualDefense: EnhancingPrivacyandMitigating PoisoningAttacksinFederatedLearning

Neural Information Processing Systems

DDFedsimultaneously boosts privacyprotection andmitigatespoisoning attacks, without introducing new participant roles or disrupting the existing FL topology.DDFedinitially leveragescutting-edge fullyhomomorphic encryption (FHE)tosecurely aggregatemodelupdates, without theimpractical requirement for non-colluding two-server setups and ensures strong privacy protection.