← Search

Eugene Bagdasaryan

2 accepted papers

2020

How To Backdoor Federated Learning

AISTATS 2020poster

Federated models are created by aggregating model updates submittedby participants. To protect confidentiality of the training data,the aggregator by design has no visibility into how these updates aregenerated. We show that this makes federated learning vulnerable to amodel-poisoning attack that…

2019

Differential Privacy Has Disparate Impact on Model Accuracy

NeurIPS 2019poster

Differential privacy (DP) is a popular mechanism for training machine learning models with bounded leakage about the presence of specific points in the training data. The cost of differential privacy is a reduction in the model's accuracy. We demonstrate that in the neural networks trained using d…