← Search

I Shumailov

1 accepted papers

2021

Manipulating SGD with Data Ordering Attacks

NeurIPS 2021poster

Machine learning is vulnerable to a wide variety of attacks. It is now well understood that by changing the underlying data distribution, an adversary can poison the model trained with it or introduce backdoors. In this paper we present a novel class of training-time attacks that require no changes…

Cited by 102SourcePDFScholar