Adversarial interference and its mitigations in privacy-preserving collaborative machine learning
File(s)nature_mi_attacks_survey.pdf (1.91 MB)
Accepted version
Author(s)
Type
Journal Article
Abstract
Despite the rapid increase of data available to train machine-learning algorithms in many domains, several applications suffer from a paucity of representative and diverse data. The medical and financial sectors are, for example, constrained by legal, ethical, regulatory and privacy concerns preventing data sharing between institutions. Collaborative learning systems, such as federated learning, are designed to circumvent such restrictions and provide a privacy-preserving alternative by eschewing data sharing and relying instead on the distributed remote execution of algorithms. However, such systems are susceptible to malicious adversarial interference attempting to undermine their utility or divulge confidential information. Here we present an overview and analysis of current adversarial attacks and their mitigations in the context of collaborative machine learning. We discuss the applicability of attack vectors to specific learning contexts and attempt to formulate a generic foundation for adversarial influence and mitigation mechanisms. We moreover show that a number of context-specific learning conditions are exploited in similar fashion across all settings. Lastly, we provide a focused perspective on open challenges and promising areas of future research in the field.
Date Issued
2021-09
Date Acceptance
2021-08-11
Citation
Nature Machine Intelligence, 2021, 3 (9), pp.749-758
ISSN
2522-5839
Publisher
Nature Research
Start Page
749
End Page
758
Journal / Book Title
Nature Machine Intelligence
Volume
3
Issue
9
Copyright Statement
Copyright © 2021 Springer-Verlag. This version of the article has been accepted for publication, after peer review (when applicable) and is subject to Springer Nature’s AM terms of use, but is not the Version of Record and does not reflect post-acceptance improvements, or any corrections. The Version of Record is available online at: http://dx.doi.org/10.1038/s42256-021-00390-3
Identifier
https://www.webofscience.com/api/gateway?GWVersion=2&SrcApp=PARTNER_APP&SrcAuth=LinksAMR&KeyUT=WOS:000696824400004&DestLinkType=FullRecord&DestApp=ALL_WOS&UsrCustomerID=a2bf6146997ec60c407a63945d4e92bb
Subjects
ATTACKS
Computer Science
Computer Science, Artificial Intelligence
Computer Science, Interdisciplinary Applications
Science & Technology
Technology
Publication Status
Published
Date Publish Online
2021-09-17