Analyzing Federated Learning through an Adversarial Lens
Arjun Nitin Bhagoji1, Supriyo Chakraborty2, Prateek Mittal1 and Seraphin Calo2
1Princeton University 2IBM Research
Analyzing Federated Learning through an Adversarial Lens Arjun Nitin - - PowerPoint PPT Presentation
Analyzing Federated Learning through an Adversarial Lens Arjun Nitin Bhagoji 1 , Supriyo Chakraborty 2 , Prateek Mittal 1 and Seraphin Calo 2 1 Princeton University 2 IBM Research ICML 2019 Federated learning (with a malicious agent) Federated
1Princeton University 2IBM Research
McMahan et al., Communication- Efficient Learning of Deep Networks from Decentralized Data, AISTATS 2017
McMahan et al., Communication- Efficient Learning of Deep Networks from Decentralized Data, AISTATS 2017
Compute
1
<latexit sha1_base64="D3aW/8S9R5G7eFMRvexSRdDWfV4=">ACSnicdVBNSxBEO3ZmETN1xqPOaTJEgElhkJxKMYDx4NZFXY2SzVPTXa2N0zdNe4LM38lyT/5I/kL/hTbykZ10haixo+vFeFa/qiVorT2n6J+k9Wn85Onq2vqz5y9evupvD70VeMkjmSlK3cswKNWFkekSONx7RCM0Hgkzr50+tE5Oq8q+43mNU4MnFhVKgkUqWl/Mxcm5AVqgnafQ/0MWun/UE63E674vdBNlz86YAt62C6kbzNi0o2Bi1JDd6Ps7SmSQBHSmps1/PGYw3yDE5wHKEFg34SFtu3/H1kCl5WLj5LfMH+OxHAeD83InYaoFN/V+vI/2njhsrtSVC2bgitvDYqG82p4l0UvFAOJel5BCdirtyeQoOJMXAbrkIE2+wOJOVMWCLkIty1oa8sxRlmLV3VCP3lqoEHfaiHCO9yY0/DA63hlk6zL5+GuzsLsNdZW/YO/aBZewz2H7ICNmGRz9oP9ZL+S38lFcplcXbf2kuXMJrtVvZW/VwizlA=</latexit><latexit sha1_base64="D3aW/8S9R5G7eFMRvexSRdDWfV4=">ACSnicdVBNSxBEO3ZmETN1xqPOaTJEgElhkJxKMYDx4NZFXY2SzVPTXa2N0zdNe4LM38lyT/5I/kL/hTbykZ10haixo+vFeFa/qiVorT2n6J+k9Wn85Onq2vqz5y9evupvD70VeMkjmSlK3cswKNWFkekSONx7RCM0Hgkzr50+tE5Oq8q+43mNU4MnFhVKgkUqWl/Mxcm5AVqgnafQ/0MWun/UE63E674vdBNlz86YAt62C6kbzNi0o2Bi1JDd6Ps7SmSQBHSmps1/PGYw3yDE5wHKEFg34SFtu3/H1kCl5WLj5LfMH+OxHAeD83InYaoFN/V+vI/2njhsrtSVC2bgitvDYqG82p4l0UvFAOJel5BCdirtyeQoOJMXAbrkIE2+wOJOVMWCLkIty1oa8sxRlmLV3VCP3lqoEHfaiHCO9yY0/DA63hlk6zL5+GuzsLsNdZW/YO/aBZewz2H7ICNmGRz9oP9ZL+S38lFcplcXbf2kuXMJrtVvZW/VwizlA=</latexit><latexit sha1_base64="D3aW/8S9R5G7eFMRvexSRdDWfV4=">ACSnicdVBNSxBEO3ZmETN1xqPOaTJEgElhkJxKMYDx4NZFXY2SzVPTXa2N0zdNe4LM38lyT/5I/kL/hTbykZ10haixo+vFeFa/qiVorT2n6J+k9Wn85Onq2vqz5y9evupvD70VeMkjmSlK3cswKNWFkekSONx7RCM0Hgkzr50+tE5Oq8q+43mNU4MnFhVKgkUqWl/Mxcm5AVqgnafQ/0MWun/UE63E674vdBNlz86YAt62C6kbzNi0o2Bi1JDd6Ps7SmSQBHSmps1/PGYw3yDE5wHKEFg34SFtu3/H1kCl5WLj5LfMH+OxHAeD83InYaoFN/V+vI/2njhsrtSVC2bgitvDYqG82p4l0UvFAOJel5BCdirtyeQoOJMXAbrkIE2+wOJOVMWCLkIty1oa8sxRlmLV3VCP3lqoEHfaiHCO9yY0/DA63hlk6zL5+GuzsLsNdZW/YO/aBZewz2H7ICNmGRz9oP9ZL+S38lFcplcXbf2kuXMJrtVvZW/VwizlA=</latexit><latexit sha1_base64="D3aW/8S9R5G7eFMRvexSRdDWfV4=">ACSnicdVBNSxBEO3ZmETN1xqPOaTJEgElhkJxKMYDx4NZFXY2SzVPTXa2N0zdNe4LM38lyT/5I/kL/hTbykZ10haixo+vFeFa/qiVorT2n6J+k9Wn85Onq2vqz5y9evupvD70VeMkjmSlK3cswKNWFkekSONx7RCM0Hgkzr50+tE5Oq8q+43mNU4MnFhVKgkUqWl/Mxcm5AVqgnafQ/0MWun/UE63E674vdBNlz86YAt62C6kbzNi0o2Bi1JDd6Ps7SmSQBHSmps1/PGYw3yDE5wHKEFg34SFtu3/H1kCl5WLj5LfMH+OxHAeD83InYaoFN/V+vI/2njhsrtSVC2bgitvDYqG82p4l0UvFAOJel5BCdirtyeQoOJMXAbrkIE2+wOJOVMWCLkIty1oa8sxRlmLV3VCP3lqoEHfaiHCO9yY0/DA63hlk6zL5+GuzsLsNdZW/YO/aBZewz2H7ICNmGRz9oP9ZL+S38lFcplcXbf2kuXMJrtVvZW/VwizlA=</latexit>Compute
2
<latexit sha1_base64="wDksDghZJzr8BfzalpPBZhXvt8=">ACSnicdVBNSxBEO3ZmGjM1xqPOaTJEgElhkJ6FGMhxwVsirsbJbqnhpt7O4ZumtclmZ+S67Jf8kfyN/ITbzYs24gaixo+vFeFa/qiVorT2n6O+k9Wn8ZHXt6fqz5y9evupvD7yVeMkjmSlK3ciwKNWFkekSONJ7RCM0Hgszj93+vEFOq8q+5XmNU4MnFpVKgkUqWl/Mxcm5AVqgna69S3Qx6yd9gfpcCftit8H2XDxpwO2rIPpRvI2LyrZGLQkNXg/ztKaJgEcKamxXc8bjzXIczjFcYQWDPpJWGzf8veRKXhZufgs8QX70QA4/3ciNhpgM78Xa0j/6eNGyp3JkHZuiG08saobDSnindR8EI5lKTnEYB0Ku7K5Rk4kBQDu+UiTLzB4kxWxoAtQi7KWRvyzlKUYdbeUY3cX6oSdNiPcoz0b278YXC0NczSYXb4abC7twx3jb1h79gHlrFtsu+sAM2YpLN2Xf2g/1MfiV/ksvk6qa1lyxnNtmt6q1cA1jgs5U=</latexit><latexit sha1_base64="wDksDghZJzr8BfzalpPBZhXvt8=">ACSnicdVBNSxBEO3ZmGjM1xqPOaTJEgElhkJ6FGMhxwVsirsbJbqnhpt7O4ZumtclmZ+S67Jf8kfyN/ITbzYs24gaixo+vFeFa/qiVorT2n6O+k9Wn8ZHXt6fqz5y9evupvD7yVeMkjmSlK3ciwKNWFkekSONJ7RCM0Hgszj93+vEFOq8q+5XmNU4MnFpVKgkUqWl/Mxcm5AVqgna69S3Qx6yd9gfpcCftit8H2XDxpwO2rIPpRvI2LyrZGLQkNXg/ztKaJgEcKamxXc8bjzXIczjFcYQWDPpJWGzf8veRKXhZufgs8QX70QA4/3ciNhpgM78Xa0j/6eNGyp3JkHZuiG08saobDSnindR8EI5lKTnEYB0Ku7K5Rk4kBQDu+UiTLzB4kxWxoAtQi7KWRvyzlKUYdbeUY3cX6oSdNiPcoz0b278YXC0NczSYXb4abC7twx3jb1h79gHlrFtsu+sAM2YpLN2Xf2g/1MfiV/ksvk6qa1lyxnNtmt6q1cA1jgs5U=</latexit><latexit sha1_base64="wDksDghZJzr8BfzalpPBZhXvt8=">ACSnicdVBNSxBEO3ZmGjM1xqPOaTJEgElhkJ6FGMhxwVsirsbJbqnhpt7O4ZumtclmZ+S67Jf8kfyN/ITbzYs24gaixo+vFeFa/qiVorT2n6O+k9Wn8ZHXt6fqz5y9evupvD7yVeMkjmSlK3ciwKNWFkekSONJ7RCM0Hgszj93+vEFOq8q+5XmNU4MnFpVKgkUqWl/Mxcm5AVqgna69S3Qx6yd9gfpcCftit8H2XDxpwO2rIPpRvI2LyrZGLQkNXg/ztKaJgEcKamxXc8bjzXIczjFcYQWDPpJWGzf8veRKXhZufgs8QX70QA4/3ciNhpgM78Xa0j/6eNGyp3JkHZuiG08saobDSnindR8EI5lKTnEYB0Ku7K5Rk4kBQDu+UiTLzB4kxWxoAtQi7KWRvyzlKUYdbeUY3cX6oSdNiPcoz0b278YXC0NczSYXb4abC7twx3jb1h79gHlrFtsu+sAM2YpLN2Xf2g/1MfiV/ksvk6qa1lyxnNtmt6q1cA1jgs5U=</latexit><latexit sha1_base64="wDksDghZJzr8BfzalpPBZhXvt8=">ACSnicdVBNSxBEO3ZmGjM1xqPOaTJEgElhkJ6FGMhxwVsirsbJbqnhpt7O4ZumtclmZ+S67Jf8kfyN/ITbzYs24gaixo+vFeFa/qiVorT2n6O+k9Wn8ZHXt6fqz5y9evupvD7yVeMkjmSlK3ciwKNWFkekSONJ7RCM0Hgszj93+vEFOq8q+5XmNU4MnFpVKgkUqWl/Mxcm5AVqgna69S3Qx6yd9gfpcCftit8H2XDxpwO2rIPpRvI2LyrZGLQkNXg/ztKaJgEcKamxXc8bjzXIczjFcYQWDPpJWGzf8veRKXhZufgs8QX70QA4/3ciNhpgM78Xa0j/6eNGyp3JkHZuiG08saobDSnindR8EI5lKTnEYB0Ku7K5Rk4kBQDu+UiTLzB4kxWxoAtQi7KWRvyzlKUYdbeUY3cX6oSdNiPcoz0b278YXC0NczSYXb4abC7twx3jb1h79gHlrFtsu+sAM2YpLN2Xf2g/1MfiV/ksvk6qa1lyxnNtmt6q1cA1jgs5U=</latexit>j
δ
j, yi j}nj i=1; wt G + δ
McMahan et al., Communication- Efficient Learning of Deep Networks from Decentralized Data, AISTATS 2017
Compute
1
<latexit sha1_base64="D3aW/8S9R5G7eFMRvexSRdDWfV4=">ACSnicdVBNSxBEO3ZmETN1xqPOaTJEgElhkJxKMYDx4NZFXY2SzVPTXa2N0zdNe4LM38lyT/5I/kL/hTbykZ10haixo+vFeFa/qiVorT2n6J+k9Wn85Onq2vqz5y9evupvD70VeMkjmSlK3cswKNWFkekSONx7RCM0Hgkzr50+tE5Oq8q+43mNU4MnFhVKgkUqWl/Mxcm5AVqgnafQ/0MWun/UE63E674vdBNlz86YAt62C6kbzNi0o2Bi1JDd6Ps7SmSQBHSmps1/PGYw3yDE5wHKEFg34SFtu3/H1kCl5WLj5LfMH+OxHAeD83InYaoFN/V+vI/2njhsrtSVC2bgitvDYqG82p4l0UvFAOJel5BCdirtyeQoOJMXAbrkIE2+wOJOVMWCLkIty1oa8sxRlmLV3VCP3lqoEHfaiHCO9yY0/DA63hlk6zL5+GuzsLsNdZW/YO/aBZewz2H7ICNmGRz9oP9ZL+S38lFcplcXbf2kuXMJrtVvZW/VwizlA=</latexit><latexit sha1_base64="D3aW/8S9R5G7eFMRvexSRdDWfV4=">ACSnicdVBNSxBEO3ZmETN1xqPOaTJEgElhkJxKMYDx4NZFXY2SzVPTXa2N0zdNe4LM38lyT/5I/kL/hTbykZ10haixo+vFeFa/qiVorT2n6J+k9Wn85Onq2vqz5y9evupvD70VeMkjmSlK3cswKNWFkekSONx7RCM0Hgkzr50+tE5Oq8q+43mNU4MnFhVKgkUqWl/Mxcm5AVqgnafQ/0MWun/UE63E674vdBNlz86YAt62C6kbzNi0o2Bi1JDd6Ps7SmSQBHSmps1/PGYw3yDE5wHKEFg34SFtu3/H1kCl5WLj5LfMH+OxHAeD83InYaoFN/V+vI/2njhsrtSVC2bgitvDYqG82p4l0UvFAOJel5BCdirtyeQoOJMXAbrkIE2+wOJOVMWCLkIty1oa8sxRlmLV3VCP3lqoEHfaiHCO9yY0/DA63hlk6zL5+GuzsLsNdZW/YO/aBZewz2H7ICNmGRz9oP9ZL+S38lFcplcXbf2kuXMJrtVvZW/VwizlA=</latexit><latexit sha1_base64="D3aW/8S9R5G7eFMRvexSRdDWfV4=">ACSnicdVBNSxBEO3ZmETN1xqPOaTJEgElhkJxKMYDx4NZFXY2SzVPTXa2N0zdNe4LM38lyT/5I/kL/hTbykZ10haixo+vFeFa/qiVorT2n6J+k9Wn85Onq2vqz5y9evupvD70VeMkjmSlK3cswKNWFkekSONx7RCM0Hgkzr50+tE5Oq8q+43mNU4MnFhVKgkUqWl/Mxcm5AVqgnafQ/0MWun/UE63E674vdBNlz86YAt62C6kbzNi0o2Bi1JDd6Ps7SmSQBHSmps1/PGYw3yDE5wHKEFg34SFtu3/H1kCl5WLj5LfMH+OxHAeD83InYaoFN/V+vI/2njhsrtSVC2bgitvDYqG82p4l0UvFAOJel5BCdirtyeQoOJMXAbrkIE2+wOJOVMWCLkIty1oa8sxRlmLV3VCP3lqoEHfaiHCO9yY0/DA63hlk6zL5+GuzsLsNdZW/YO/aBZewz2H7ICNmGRz9oP9ZL+S38lFcplcXbf2kuXMJrtVvZW/VwizlA=</latexit><latexit sha1_base64="D3aW/8S9R5G7eFMRvexSRdDWfV4=">ACSnicdVBNSxBEO3ZmETN1xqPOaTJEgElhkJxKMYDx4NZFXY2SzVPTXa2N0zdNe4LM38lyT/5I/kL/hTbykZ10haixo+vFeFa/qiVorT2n6J+k9Wn85Onq2vqz5y9evupvD70VeMkjmSlK3cswKNWFkekSONx7RCM0Hgkzr50+tE5Oq8q+43mNU4MnFhVKgkUqWl/Mxcm5AVqgnafQ/0MWun/UE63E674vdBNlz86YAt62C6kbzNi0o2Bi1JDd6Ps7SmSQBHSmps1/PGYw3yDE5wHKEFg34SFtu3/H1kCl5WLj5LfMH+OxHAeD83InYaoFN/V+vI/2njhsrtSVC2bgitvDYqG82p4l0UvFAOJel5BCdirtyeQoOJMXAbrkIE2+wOJOVMWCLkIty1oa8sxRlmLV3VCP3lqoEHfaiHCO9yY0/DA63hlk6zL5+GuzsLsNdZW/YO/aBZewz2H7ICNmGRz9oP9ZL+S38lFcplcXbf2kuXMJrtVvZW/VwizlA=</latexit>Compute
2
<latexit sha1_base64="wDksDghZJzr8BfzalpPBZhXvt8=">ACSnicdVBNSxBEO3ZmGjM1xqPOaTJEgElhkJ6FGMhxwVsirsbJbqnhpt7O4ZumtclmZ+S67Jf8kfyN/ITbzYs24gaixo+vFeFa/qiVorT2n6O+k9Wn8ZHXt6fqz5y9evupvD7yVeMkjmSlK3ciwKNWFkekSONJ7RCM0Hgszj93+vEFOq8q+5XmNU4MnFpVKgkUqWl/Mxcm5AVqgna69S3Qx6yd9gfpcCftit8H2XDxpwO2rIPpRvI2LyrZGLQkNXg/ztKaJgEcKamxXc8bjzXIczjFcYQWDPpJWGzf8veRKXhZufgs8QX70QA4/3ciNhpgM78Xa0j/6eNGyp3JkHZuiG08saobDSnindR8EI5lKTnEYB0Ku7K5Rk4kBQDu+UiTLzB4kxWxoAtQi7KWRvyzlKUYdbeUY3cX6oSdNiPcoz0b278YXC0NczSYXb4abC7twx3jb1h79gHlrFtsu+sAM2YpLN2Xf2g/1MfiV/ksvk6qa1lyxnNtmt6q1cA1jgs5U=</latexit><latexit sha1_base64="wDksDghZJzr8BfzalpPBZhXvt8=">ACSnicdVBNSxBEO3ZmGjM1xqPOaTJEgElhkJ6FGMhxwVsirsbJbqnhpt7O4ZumtclmZ+S67Jf8kfyN/ITbzYs24gaixo+vFeFa/qiVorT2n6O+k9Wn8ZHXt6fqz5y9evupvD7yVeMkjmSlK3ciwKNWFkekSONJ7RCM0Hgszj93+vEFOq8q+5XmNU4MnFpVKgkUqWl/Mxcm5AVqgna69S3Qx6yd9gfpcCftit8H2XDxpwO2rIPpRvI2LyrZGLQkNXg/ztKaJgEcKamxXc8bjzXIczjFcYQWDPpJWGzf8veRKXhZufgs8QX70QA4/3ciNhpgM78Xa0j/6eNGyp3JkHZuiG08saobDSnindR8EI5lKTnEYB0Ku7K5Rk4kBQDu+UiTLzB4kxWxoAtQi7KWRvyzlKUYdbeUY3cX6oSdNiPcoz0b278YXC0NczSYXb4abC7twx3jb1h79gHlrFtsu+sAM2YpLN2Xf2g/1MfiV/ksvk6qa1lyxnNtmt6q1cA1jgs5U=</latexit><latexit sha1_base64="wDksDghZJzr8BfzalpPBZhXvt8=">ACSnicdVBNSxBEO3ZmGjM1xqPOaTJEgElhkJ6FGMhxwVsirsbJbqnhpt7O4ZumtclmZ+S67Jf8kfyN/ITbzYs24gaixo+vFeFa/qiVorT2n6O+k9Wn8ZHXt6fqz5y9evupvD7yVeMkjmSlK3ciwKNWFkekSONJ7RCM0Hgszj93+vEFOq8q+5XmNU4MnFpVKgkUqWl/Mxcm5AVqgna69S3Qx6yd9gfpcCftit8H2XDxpwO2rIPpRvI2LyrZGLQkNXg/ztKaJgEcKamxXc8bjzXIczjFcYQWDPpJWGzf8veRKXhZufgs8QX70QA4/3ciNhpgM78Xa0j/6eNGyp3JkHZuiG08saobDSnindR8EI5lKTnEYB0Ku7K5Rk4kBQDu+UiTLzB4kxWxoAtQi7KWRvyzlKUYdbeUY3cX6oSdNiPcoz0b278YXC0NczSYXb4abC7twx3jb1h79gHlrFtsu+sAM2YpLN2Xf2g/1MfiV/ksvk6qa1lyxnNtmt6q1cA1jgs5U=</latexit><latexit sha1_base64="wDksDghZJzr8BfzalpPBZhXvt8=">ACSnicdVBNSxBEO3ZmGjM1xqPOaTJEgElhkJ6FGMhxwVsirsbJbqnhpt7O4ZumtclmZ+S67Jf8kfyN/ITbzYs24gaixo+vFeFa/qiVorT2n6O+k9Wn8ZHXt6fqz5y9evupvD7yVeMkjmSlK3ciwKNWFkekSONJ7RCM0Hgszj93+vEFOq8q+5XmNU4MnFpVKgkUqWl/Mxcm5AVqgna69S3Qx6yd9gfpcCftit8H2XDxpwO2rIPpRvI2LyrZGLQkNXg/ztKaJgEcKamxXc8bjzXIczjFcYQWDPpJWGzf8veRKXhZufgs8QX70QA4/3ciNhpgM78Xa0j/6eNGyp3JkHZuiG08saobDSnindR8EI5lKTnEYB0Ku7K5Rk4kBQDu+UiTLzB4kxWxoAtQi7KWRvyzlKUYdbeUY3cX6oSdNiPcoz0b278YXC0NczSYXb4abC7twx3jb1h79gHlrFtsu+sAM2YpLN2Xf2g/1MfiV/ksvk6qa1lyxnNtmt6q1cA1jgs5U=</latexit>j
δ
j, yi j}nj i=1; wt G + δ
G
G + k
j=1
j
<latexit sha1_base64="OGBemspsUbiFWogaMpCReQJCYoM=">ACe3icdVBda9swFW8bu26j6b4x4qFgZjHcEeK+tLoWyB9rGFpi3EqbmW5UaJBvpeiEI/6H9mr12/2UwOXGh7bYLQkfnMvVPWkphcUwvOkEj9YeP1nfeLr57PmLl1vd7VfntqgM40NWyMJcpmC5FJoPUaDkl6XhoFLJL9LZt0a/+M6NFYU+w0XJxwqutcgFA/RU0h3EaT5Pjq4c7kb1AW1fSHdpbCuVuOlBVF+5WU1jkOUEkqm3KBdnXCLUyXTVl3R7YX8/bIr+DaL+8g57pK2TZLuzE2cFqxTXyCRYO4rCEscODAomeb0ZV5aXwGZwzUcealDcjt1y3Zq+80xG8L4o5Eu2bsdDpS1C5V6pwKc2IdaQ/5LG1WY74+d0GWFXLPVoLySFAvaZEczYThDufAmBH+r5RNwABDn/C9KanyO2g+Z4VSoDPX5Fq7uBmZ5m5eP1AVG7QqA+kGXvaR3uZG/w/OP/WjsB+dfu4dfm3D3SBvyFvynkTkCzkx+SEDAkjP8hPckN+dX4HveBD8HFlDTptz2tyr4K9P/QexAg=</latexit><latexit sha1_base64="OGBemspsUbiFWogaMpCReQJCYoM=">ACe3icdVBda9swFW8bu26j6b4x4qFgZjHcEeK+tLoWyB9rGFpi3EqbmW5UaJBvpeiEI/6H9mr12/2UwOXGh7bYLQkfnMvVPWkphcUwvOkEj9YeP1nfeLr57PmLl1vd7VfntqgM40NWyMJcpmC5FJoPUaDkl6XhoFLJL9LZt0a/+M6NFYU+w0XJxwqutcgFA/RU0h3EaT5Pjq4c7kb1AW1fSHdpbCuVuOlBVF+5WU1jkOUEkqm3KBdnXCLUyXTVl3R7YX8/bIr+DaL+8g57pK2TZLuzE2cFqxTXyCRYO4rCEscODAomeb0ZV5aXwGZwzUcealDcjt1y3Zq+80xG8L4o5Eu2bsdDpS1C5V6pwKc2IdaQ/5LG1WY74+d0GWFXLPVoLySFAvaZEczYThDufAmBH+r5RNwABDn/C9KanyO2g+Z4VSoDPX5Fq7uBmZ5m5eP1AVG7QqA+kGXvaR3uZG/w/OP/WjsB+dfu4dfm3D3SBvyFvynkTkCzkx+SEDAkjP8hPckN+dX4HveBD8HFlDTptz2tyr4K9P/QexAg=</latexit><latexit sha1_base64="OGBemspsUbiFWogaMpCReQJCYoM=">ACe3icdVBda9swFW8bu26j6b4x4qFgZjHcEeK+tLoWyB9rGFpi3EqbmW5UaJBvpeiEI/6H9mr12/2UwOXGh7bYLQkfnMvVPWkphcUwvOkEj9YeP1nfeLr57PmLl1vd7VfntqgM40NWyMJcpmC5FJoPUaDkl6XhoFLJL9LZt0a/+M6NFYU+w0XJxwqutcgFA/RU0h3EaT5Pjq4c7kb1AW1fSHdpbCuVuOlBVF+5WU1jkOUEkqm3KBdnXCLUyXTVl3R7YX8/bIr+DaL+8g57pK2TZLuzE2cFqxTXyCRYO4rCEscODAomeb0ZV5aXwGZwzUcealDcjt1y3Zq+80xG8L4o5Eu2bsdDpS1C5V6pwKc2IdaQ/5LG1WY74+d0GWFXLPVoLySFAvaZEczYThDufAmBH+r5RNwABDn/C9KanyO2g+Z4VSoDPX5Fq7uBmZ5m5eP1AVG7QqA+kGXvaR3uZG/w/OP/WjsB+dfu4dfm3D3SBvyFvynkTkCzkx+SEDAkjP8hPckN+dX4HveBD8HFlDTptz2tyr4K9P/QexAg=</latexit><latexit sha1_base64="OGBemspsUbiFWogaMpCReQJCYoM=">ACe3icdVBda9swFW8bu26j6b4x4qFgZjHcEeK+tLoWyB9rGFpi3EqbmW5UaJBvpeiEI/6H9mr12/2UwOXGh7bYLQkfnMvVPWkphcUwvOkEj9YeP1nfeLr57PmLl1vd7VfntqgM40NWyMJcpmC5FJoPUaDkl6XhoFLJL9LZt0a/+M6NFYU+w0XJxwqutcgFA/RU0h3EaT5Pjq4c7kb1AW1fSHdpbCuVuOlBVF+5WU1jkOUEkqm3KBdnXCLUyXTVl3R7YX8/bIr+DaL+8g57pK2TZLuzE2cFqxTXyCRYO4rCEscODAomeb0ZV5aXwGZwzUcealDcjt1y3Zq+80xG8L4o5Eu2bsdDpS1C5V6pwKc2IdaQ/5LG1WY74+d0GWFXLPVoLySFAvaZEczYThDufAmBH+r5RNwABDn/C9KanyO2g+Z4VSoDPX5Fq7uBmZ5m5eP1AVG7QqA+kGXvaR3uZG/w/OP/WjsB+dfu4dfm3D3SBvyFvynkTkCzkx+SEDAkjP8hPckN+dX4HveBD8HFlDTptz2tyr4K9P/QexAg=</latexit>McMahan et al., Communication- Efficient Learning of Deep Networks from Decentralized Data, AISTATS 2017
Compute
1
<latexit sha1_base64="D3aW/8S9R5G7eFMRvexSRdDWfV4=">ACSnicdVBNSxBEO3ZmETN1xqPOaTJEgElhkJxKMYDx4NZFXY2SzVPTXa2N0zdNe4LM38lyT/5I/kL/hTbykZ10haixo+vFeFa/qiVorT2n6J+k9Wn85Onq2vqz5y9evupvD70VeMkjmSlK3cswKNWFkekSONx7RCM0Hgkzr50+tE5Oq8q+43mNU4MnFhVKgkUqWl/Mxcm5AVqgnafQ/0MWun/UE63E674vdBNlz86YAt62C6kbzNi0o2Bi1JDd6Ps7SmSQBHSmps1/PGYw3yDE5wHKEFg34SFtu3/H1kCl5WLj5LfMH+OxHAeD83InYaoFN/V+vI/2njhsrtSVC2bgitvDYqG82p4l0UvFAOJel5BCdirtyeQoOJMXAbrkIE2+wOJOVMWCLkIty1oa8sxRlmLV3VCP3lqoEHfaiHCO9yY0/DA63hlk6zL5+GuzsLsNdZW/YO/aBZewz2H7ICNmGRz9oP9ZL+S38lFcplcXbf2kuXMJrtVvZW/VwizlA=</latexit><latexit sha1_base64="D3aW/8S9R5G7eFMRvexSRdDWfV4=">ACSnicdVBNSxBEO3ZmETN1xqPOaTJEgElhkJxKMYDx4NZFXY2SzVPTXa2N0zdNe4LM38lyT/5I/kL/hTbykZ10haixo+vFeFa/qiVorT2n6J+k9Wn85Onq2vqz5y9evupvD70VeMkjmSlK3cswKNWFkekSONx7RCM0Hgkzr50+tE5Oq8q+43mNU4MnFhVKgkUqWl/Mxcm5AVqgnafQ/0MWun/UE63E674vdBNlz86YAt62C6kbzNi0o2Bi1JDd6Ps7SmSQBHSmps1/PGYw3yDE5wHKEFg34SFtu3/H1kCl5WLj5LfMH+OxHAeD83InYaoFN/V+vI/2njhsrtSVC2bgitvDYqG82p4l0UvFAOJel5BCdirtyeQoOJMXAbrkIE2+wOJOVMWCLkIty1oa8sxRlmLV3VCP3lqoEHfaiHCO9yY0/DA63hlk6zL5+GuzsLsNdZW/YO/aBZewz2H7ICNmGRz9oP9ZL+S38lFcplcXbf2kuXMJrtVvZW/VwizlA=</latexit><latexit sha1_base64="D3aW/8S9R5G7eFMRvexSRdDWfV4=">ACSnicdVBNSxBEO3ZmETN1xqPOaTJEgElhkJxKMYDx4NZFXY2SzVPTXa2N0zdNe4LM38lyT/5I/kL/hTbykZ10haixo+vFeFa/qiVorT2n6J+k9Wn85Onq2vqz5y9evupvD70VeMkjmSlK3cswKNWFkekSONx7RCM0Hgkzr50+tE5Oq8q+43mNU4MnFhVKgkUqWl/Mxcm5AVqgnafQ/0MWun/UE63E674vdBNlz86YAt62C6kbzNi0o2Bi1JDd6Ps7SmSQBHSmps1/PGYw3yDE5wHKEFg34SFtu3/H1kCl5WLj5LfMH+OxHAeD83InYaoFN/V+vI/2njhsrtSVC2bgitvDYqG82p4l0UvFAOJel5BCdirtyeQoOJMXAbrkIE2+wOJOVMWCLkIty1oa8sxRlmLV3VCP3lqoEHfaiHCO9yY0/DA63hlk6zL5+GuzsLsNdZW/YO/aBZewz2H7ICNmGRz9oP9ZL+S38lFcplcXbf2kuXMJrtVvZW/VwizlA=</latexit><latexit sha1_base64="D3aW/8S9R5G7eFMRvexSRdDWfV4=">ACSnicdVBNSxBEO3ZmETN1xqPOaTJEgElhkJxKMYDx4NZFXY2SzVPTXa2N0zdNe4LM38lyT/5I/kL/hTbykZ10haixo+vFeFa/qiVorT2n6J+k9Wn85Onq2vqz5y9evupvD70VeMkjmSlK3cswKNWFkekSONx7RCM0Hgkzr50+tE5Oq8q+43mNU4MnFhVKgkUqWl/Mxcm5AVqgnafQ/0MWun/UE63E674vdBNlz86YAt62C6kbzNi0o2Bi1JDd6Ps7SmSQBHSmps1/PGYw3yDE5wHKEFg34SFtu3/H1kCl5WLj5LfMH+OxHAeD83InYaoFN/V+vI/2njhsrtSVC2bgitvDYqG82p4l0UvFAOJel5BCdirtyeQoOJMXAbrkIE2+wOJOVMWCLkIty1oa8sxRlmLV3VCP3lqoEHfaiHCO9yY0/DA63hlk6zL5+GuzsLsNdZW/YO/aBZewz2H7ICNmGRz9oP9ZL+S38lFcplcXbf2kuXMJrtVvZW/VwizlA=</latexit>Compute
2
<latexit sha1_base64="wDksDghZJzr8BfzalpPBZhXvt8=">ACSnicdVBNSxBEO3ZmGjM1xqPOaTJEgElhkJ6FGMhxwVsirsbJbqnhpt7O4ZumtclmZ+S67Jf8kfyN/ITbzYs24gaixo+vFeFa/qiVorT2n6O+k9Wn8ZHXt6fqz5y9evupvD7yVeMkjmSlK3ciwKNWFkekSONJ7RCM0Hgszj93+vEFOq8q+5XmNU4MnFpVKgkUqWl/Mxcm5AVqgna69S3Qx6yd9gfpcCftit8H2XDxpwO2rIPpRvI2LyrZGLQkNXg/ztKaJgEcKamxXc8bjzXIczjFcYQWDPpJWGzf8veRKXhZufgs8QX70QA4/3ciNhpgM78Xa0j/6eNGyp3JkHZuiG08saobDSnindR8EI5lKTnEYB0Ku7K5Rk4kBQDu+UiTLzB4kxWxoAtQi7KWRvyzlKUYdbeUY3cX6oSdNiPcoz0b278YXC0NczSYXb4abC7twx3jb1h79gHlrFtsu+sAM2YpLN2Xf2g/1MfiV/ksvk6qa1lyxnNtmt6q1cA1jgs5U=</latexit><latexit sha1_base64="wDksDghZJzr8BfzalpPBZhXvt8=">ACSnicdVBNSxBEO3ZmGjM1xqPOaTJEgElhkJ6FGMhxwVsirsbJbqnhpt7O4ZumtclmZ+S67Jf8kfyN/ITbzYs24gaixo+vFeFa/qiVorT2n6O+k9Wn8ZHXt6fqz5y9evupvD7yVeMkjmSlK3ciwKNWFkekSONJ7RCM0Hgszj93+vEFOq8q+5XmNU4MnFpVKgkUqWl/Mxcm5AVqgna69S3Qx6yd9gfpcCftit8H2XDxpwO2rIPpRvI2LyrZGLQkNXg/ztKaJgEcKamxXc8bjzXIczjFcYQWDPpJWGzf8veRKXhZufgs8QX70QA4/3ciNhpgM78Xa0j/6eNGyp3JkHZuiG08saobDSnindR8EI5lKTnEYB0Ku7K5Rk4kBQDu+UiTLzB4kxWxoAtQi7KWRvyzlKUYdbeUY3cX6oSdNiPcoz0b278YXC0NczSYXb4abC7twx3jb1h79gHlrFtsu+sAM2YpLN2Xf2g/1MfiV/ksvk6qa1lyxnNtmt6q1cA1jgs5U=</latexit><latexit sha1_base64="wDksDghZJzr8BfzalpPBZhXvt8=">ACSnicdVBNSxBEO3ZmGjM1xqPOaTJEgElhkJ6FGMhxwVsirsbJbqnhpt7O4ZumtclmZ+S67Jf8kfyN/ITbzYs24gaixo+vFeFa/qiVorT2n6O+k9Wn8ZHXt6fqz5y9evupvD7yVeMkjmSlK3ciwKNWFkekSONJ7RCM0Hgszj93+vEFOq8q+5XmNU4MnFpVKgkUqWl/Mxcm5AVqgna69S3Qx6yd9gfpcCftit8H2XDxpwO2rIPpRvI2LyrZGLQkNXg/ztKaJgEcKamxXc8bjzXIczjFcYQWDPpJWGzf8veRKXhZufgs8QX70QA4/3ciNhpgM78Xa0j/6eNGyp3JkHZuiG08saobDSnindR8EI5lKTnEYB0Ku7K5Rk4kBQDu+UiTLzB4kxWxoAtQi7KWRvyzlKUYdbeUY3cX6oSdNiPcoz0b278YXC0NczSYXb4abC7twx3jb1h79gHlrFtsu+sAM2YpLN2Xf2g/1MfiV/ksvk6qa1lyxnNtmt6q1cA1jgs5U=</latexit><latexit sha1_base64="wDksDghZJzr8BfzalpPBZhXvt8=">ACSnicdVBNSxBEO3ZmGjM1xqPOaTJEgElhkJ6FGMhxwVsirsbJbqnhpt7O4ZumtclmZ+S67Jf8kfyN/ITbzYs24gaixo+vFeFa/qiVorT2n6O+k9Wn8ZHXt6fqz5y9evupvD7yVeMkjmSlK3ciwKNWFkekSONJ7RCM0Hgszj93+vEFOq8q+5XmNU4MnFpVKgkUqWl/Mxcm5AVqgna69S3Qx6yd9gfpcCftit8H2XDxpwO2rIPpRvI2LyrZGLQkNXg/ztKaJgEcKamxXc8bjzXIczjFcYQWDPpJWGzf8veRKXhZufgs8QX70QA4/3ciNhpgM78Xa0j/6eNGyp3JkHZuiG08saobDSnindR8EI5lKTnEYB0Ku7K5Rk4kBQDu+UiTLzB4kxWxoAtQi7KWRvyzlKUYdbeUY3cX6oSdNiPcoz0b278YXC0NczSYXb4abC7twx3jb1h79gHlrFtsu+sAM2YpLN2Xf2g/1MfiV/ksvk6qa1lyxnNtmt6q1cA1jgs5U=</latexit>j
δ
j, yi j}nj i=1; wt G + δ
G
G + k
j=1
j
<latexit sha1_base64="OGBemspsUbiFWogaMpCReQJCYoM=">ACe3icdVBda9swFW8bu26j6b4x4qFgZjHcEeK+tLoWyB9rGFpi3EqbmW5UaJBvpeiEI/6H9mr12/2UwOXGh7bYLQkfnMvVPWkphcUwvOkEj9YeP1nfeLr57PmLl1vd7VfntqgM40NWyMJcpmC5FJoPUaDkl6XhoFLJL9LZt0a/+M6NFYU+w0XJxwqutcgFA/RU0h3EaT5Pjq4c7kb1AW1fSHdpbCuVuOlBVF+5WU1jkOUEkqm3KBdnXCLUyXTVl3R7YX8/bIr+DaL+8g57pK2TZLuzE2cFqxTXyCRYO4rCEscODAomeb0ZV5aXwGZwzUcealDcjt1y3Zq+80xG8L4o5Eu2bsdDpS1C5V6pwKc2IdaQ/5LG1WY74+d0GWFXLPVoLySFAvaZEczYThDufAmBH+r5RNwABDn/C9KanyO2g+Z4VSoDPX5Fq7uBmZ5m5eP1AVG7QqA+kGXvaR3uZG/w/OP/WjsB+dfu4dfm3D3SBvyFvynkTkCzkx+SEDAkjP8hPckN+dX4HveBD8HFlDTptz2tyr4K9P/QexAg=</latexit><latexit sha1_base64="OGBemspsUbiFWogaMpCReQJCYoM=">ACe3icdVBda9swFW8bu26j6b4x4qFgZjHcEeK+tLoWyB9rGFpi3EqbmW5UaJBvpeiEI/6H9mr12/2UwOXGh7bYLQkfnMvVPWkphcUwvOkEj9YeP1nfeLr57PmLl1vd7VfntqgM40NWyMJcpmC5FJoPUaDkl6XhoFLJL9LZt0a/+M6NFYU+w0XJxwqutcgFA/RU0h3EaT5Pjq4c7kb1AW1fSHdpbCuVuOlBVF+5WU1jkOUEkqm3KBdnXCLUyXTVl3R7YX8/bIr+DaL+8g57pK2TZLuzE2cFqxTXyCRYO4rCEscODAomeb0ZV5aXwGZwzUcealDcjt1y3Zq+80xG8L4o5Eu2bsdDpS1C5V6pwKc2IdaQ/5LG1WY74+d0GWFXLPVoLySFAvaZEczYThDufAmBH+r5RNwABDn/C9KanyO2g+Z4VSoDPX5Fq7uBmZ5m5eP1AVG7QqA+kGXvaR3uZG/w/OP/WjsB+dfu4dfm3D3SBvyFvynkTkCzkx+SEDAkjP8hPckN+dX4HveBD8HFlDTptz2tyr4K9P/QexAg=</latexit><latexit sha1_base64="OGBemspsUbiFWogaMpCReQJCYoM=">ACe3icdVBda9swFW8bu26j6b4x4qFgZjHcEeK+tLoWyB9rGFpi3EqbmW5UaJBvpeiEI/6H9mr12/2UwOXGh7bYLQkfnMvVPWkphcUwvOkEj9YeP1nfeLr57PmLl1vd7VfntqgM40NWyMJcpmC5FJoPUaDkl6XhoFLJL9LZt0a/+M6NFYU+w0XJxwqutcgFA/RU0h3EaT5Pjq4c7kb1AW1fSHdpbCuVuOlBVF+5WU1jkOUEkqm3KBdnXCLUyXTVl3R7YX8/bIr+DaL+8g57pK2TZLuzE2cFqxTXyCRYO4rCEscODAomeb0ZV5aXwGZwzUcealDcjt1y3Zq+80xG8L4o5Eu2bsdDpS1C5V6pwKc2IdaQ/5LG1WY74+d0GWFXLPVoLySFAvaZEczYThDufAmBH+r5RNwABDn/C9KanyO2g+Z4VSoDPX5Fq7uBmZ5m5eP1AVG7QqA+kGXvaR3uZG/w/OP/WjsB+dfu4dfm3D3SBvyFvynkTkCzkx+SEDAkjP8hPckN+dX4HveBD8HFlDTptz2tyr4K9P/QexAg=</latexit><latexit sha1_base64="OGBemspsUbiFWogaMpCReQJCYoM=">ACe3icdVBda9swFW8bu26j6b4x4qFgZjHcEeK+tLoWyB9rGFpi3EqbmW5UaJBvpeiEI/6H9mr12/2UwOXGh7bYLQkfnMvVPWkphcUwvOkEj9YeP1nfeLr57PmLl1vd7VfntqgM40NWyMJcpmC5FJoPUaDkl6XhoFLJL9LZt0a/+M6NFYU+w0XJxwqutcgFA/RU0h3EaT5Pjq4c7kb1AW1fSHdpbCuVuOlBVF+5WU1jkOUEkqm3KBdnXCLUyXTVl3R7YX8/bIr+DaL+8g57pK2TZLuzE2cFqxTXyCRYO4rCEscODAomeb0ZV5aXwGZwzUcealDcjt1y3Zq+80xG8L4o5Eu2bsdDpS1C5V6pwKc2IdaQ/5LG1WY74+d0GWFXLPVoLySFAvaZEczYThDufAmBH+r5RNwABDn/C9KanyO2g+Z4VSoDPX5Fq7uBmZ5m5eP1AVG7QqA+kGXvaR3uZG/w/OP/WjsB+dfu4dfm3D3SBvyFvynkTkCzkx+SEDAkjP8hPckN+dX4HveBD8HFlDTptz2tyr4K9P/QexAg=</latexit>Threat model
Information available:
from other agents
global state
Compute
1
<latexit sha1_base64="D3aW/8S9R5G7eFMRvexSRdDWfV4=">ACSnicdVBNSxBEO3ZmETN1xqPOaTJEgElhkJxKMYDx4NZFXY2SzVPTXa2N0zdNe4LM38lyT/5I/kL/hTbykZ10haixo+vFeFa/qiVorT2n6J+k9Wn85Onq2vqz5y9evupvD70VeMkjmSlK3cswKNWFkekSONx7RCM0Hgkzr50+tE5Oq8q+43mNU4MnFhVKgkUqWl/Mxcm5AVqgnafQ/0MWun/UE63E674vdBNlz86YAt62C6kbzNi0o2Bi1JDd6Ps7SmSQBHSmps1/PGYw3yDE5wHKEFg34SFtu3/H1kCl5WLj5LfMH+OxHAeD83InYaoFN/V+vI/2njhsrtSVC2bgitvDYqG82p4l0UvFAOJel5BCdirtyeQoOJMXAbrkIE2+wOJOVMWCLkIty1oa8sxRlmLV3VCP3lqoEHfaiHCO9yY0/DA63hlk6zL5+GuzsLsNdZW/YO/aBZewz2H7ICNmGRz9oP9ZL+S38lFcplcXbf2kuXMJrtVvZW/VwizlA=</latexit><latexit sha1_base64="D3aW/8S9R5G7eFMRvexSRdDWfV4=">ACSnicdVBNSxBEO3ZmETN1xqPOaTJEgElhkJxKMYDx4NZFXY2SzVPTXa2N0zdNe4LM38lyT/5I/kL/hTbykZ10haixo+vFeFa/qiVorT2n6J+k9Wn85Onq2vqz5y9evupvD70VeMkjmSlK3cswKNWFkekSONx7RCM0Hgkzr50+tE5Oq8q+43mNU4MnFhVKgkUqWl/Mxcm5AVqgnafQ/0MWun/UE63E674vdBNlz86YAt62C6kbzNi0o2Bi1JDd6Ps7SmSQBHSmps1/PGYw3yDE5wHKEFg34SFtu3/H1kCl5WLj5LfMH+OxHAeD83InYaoFN/V+vI/2njhsrtSVC2bgitvDYqG82p4l0UvFAOJel5BCdirtyeQoOJMXAbrkIE2+wOJOVMWCLkIty1oa8sxRlmLV3VCP3lqoEHfaiHCO9yY0/DA63hlk6zL5+GuzsLsNdZW/YO/aBZewz2H7ICNmGRz9oP9ZL+S38lFcplcXbf2kuXMJrtVvZW/VwizlA=</latexit><latexit sha1_base64="D3aW/8S9R5G7eFMRvexSRdDWfV4=">ACSnicdVBNSxBEO3ZmETN1xqPOaTJEgElhkJxKMYDx4NZFXY2SzVPTXa2N0zdNe4LM38lyT/5I/kL/hTbykZ10haixo+vFeFa/qiVorT2n6J+k9Wn85Onq2vqz5y9evupvD70VeMkjmSlK3cswKNWFkekSONx7RCM0Hgkzr50+tE5Oq8q+43mNU4MnFhVKgkUqWl/Mxcm5AVqgnafQ/0MWun/UE63E674vdBNlz86YAt62C6kbzNi0o2Bi1JDd6Ps7SmSQBHSmps1/PGYw3yDE5wHKEFg34SFtu3/H1kCl5WLj5LfMH+OxHAeD83InYaoFN/V+vI/2njhsrtSVC2bgitvDYqG82p4l0UvFAOJel5BCdirtyeQoOJMXAbrkIE2+wOJOVMWCLkIty1oa8sxRlmLV3VCP3lqoEHfaiHCO9yY0/DA63hlk6zL5+GuzsLsNdZW/YO/aBZewz2H7ICNmGRz9oP9ZL+S38lFcplcXbf2kuXMJrtVvZW/VwizlA=</latexit><latexit sha1_base64="D3aW/8S9R5G7eFMRvexSRdDWfV4=">ACSnicdVBNSxBEO3ZmETN1xqPOaTJEgElhkJxKMYDx4NZFXY2SzVPTXa2N0zdNe4LM38lyT/5I/kL/hTbykZ10haixo+vFeFa/qiVorT2n6J+k9Wn85Onq2vqz5y9evupvD70VeMkjmSlK3cswKNWFkekSONx7RCM0Hgkzr50+tE5Oq8q+43mNU4MnFhVKgkUqWl/Mxcm5AVqgnafQ/0MWun/UE63E674vdBNlz86YAt62C6kbzNi0o2Bi1JDd6Ps7SmSQBHSmps1/PGYw3yDE5wHKEFg34SFtu3/H1kCl5WLj5LfMH+OxHAeD83InYaoFN/V+vI/2njhsrtSVC2bgitvDYqG82p4l0UvFAOJel5BCdirtyeQoOJMXAbrkIE2+wOJOVMWCLkIty1oa8sxRlmLV3VCP3lqoEHfaiHCO9yY0/DA63hlk6zL5+GuzsLsNdZW/YO/aBZewz2H7ICNmGRz9oP9ZL+S38lFcplcXbf2kuXMJrtVvZW/VwizlA=</latexit>Compute
2
<latexit sha1_base64="wDksDghZJzr8BfzalpPBZhXvt8=">ACSnicdVBNSxBEO3ZmGjM1xqPOaTJEgElhkJ6FGMhxwVsirsbJbqnhpt7O4ZumtclmZ+S67Jf8kfyN/ITbzYs24gaixo+vFeFa/qiVorT2n6O+k9Wn8ZHXt6fqz5y9evupvD7yVeMkjmSlK3ciwKNWFkekSONJ7RCM0Hgszj93+vEFOq8q+5XmNU4MnFpVKgkUqWl/Mxcm5AVqgna69S3Qx6yd9gfpcCftit8H2XDxpwO2rIPpRvI2LyrZGLQkNXg/ztKaJgEcKamxXc8bjzXIczjFcYQWDPpJWGzf8veRKXhZufgs8QX70QA4/3ciNhpgM78Xa0j/6eNGyp3JkHZuiG08saobDSnindR8EI5lKTnEYB0Ku7K5Rk4kBQDu+UiTLzB4kxWxoAtQi7KWRvyzlKUYdbeUY3cX6oSdNiPcoz0b278YXC0NczSYXb4abC7twx3jb1h79gHlrFtsu+sAM2YpLN2Xf2g/1MfiV/ksvk6qa1lyxnNtmt6q1cA1jgs5U=</latexit><latexit sha1_base64="wDksDghZJzr8BfzalpPBZhXvt8=">ACSnicdVBNSxBEO3ZmGjM1xqPOaTJEgElhkJ6FGMhxwVsirsbJbqnhpt7O4ZumtclmZ+S67Jf8kfyN/ITbzYs24gaixo+vFeFa/qiVorT2n6O+k9Wn8ZHXt6fqz5y9evupvD7yVeMkjmSlK3ciwKNWFkekSONJ7RCM0Hgszj93+vEFOq8q+5XmNU4MnFpVKgkUqWl/Mxcm5AVqgna69S3Qx6yd9gfpcCftit8H2XDxpwO2rIPpRvI2LyrZGLQkNXg/ztKaJgEcKamxXc8bjzXIczjFcYQWDPpJWGzf8veRKXhZufgs8QX70QA4/3ciNhpgM78Xa0j/6eNGyp3JkHZuiG08saobDSnindR8EI5lKTnEYB0Ku7K5Rk4kBQDu+UiTLzB4kxWxoAtQi7KWRvyzlKUYdbeUY3cX6oSdNiPcoz0b278YXC0NczSYXb4abC7twx3jb1h79gHlrFtsu+sAM2YpLN2Xf2g/1MfiV/ksvk6qa1lyxnNtmt6q1cA1jgs5U=</latexit><latexit sha1_base64="wDksDghZJzr8BfzalpPBZhXvt8=">ACSnicdVBNSxBEO3ZmGjM1xqPOaTJEgElhkJ6FGMhxwVsirsbJbqnhpt7O4ZumtclmZ+S67Jf8kfyN/ITbzYs24gaixo+vFeFa/qiVorT2n6O+k9Wn8ZHXt6fqz5y9evupvD7yVeMkjmSlK3ciwKNWFkekSONJ7RCM0Hgszj93+vEFOq8q+5XmNU4MnFpVKgkUqWl/Mxcm5AVqgna69S3Qx6yd9gfpcCftit8H2XDxpwO2rIPpRvI2LyrZGLQkNXg/ztKaJgEcKamxXc8bjzXIczjFcYQWDPpJWGzf8veRKXhZufgs8QX70QA4/3ciNhpgM78Xa0j/6eNGyp3JkHZuiG08saobDSnindR8EI5lKTnEYB0Ku7K5Rk4kBQDu+UiTLzB4kxWxoAtQi7KWRvyzlKUYdbeUY3cX6oSdNiPcoz0b278YXC0NczSYXb4abC7twx3jb1h79gHlrFtsu+sAM2YpLN2Xf2g/1MfiV/ksvk6qa1lyxnNtmt6q1cA1jgs5U=</latexit><latexit sha1_base64="wDksDghZJzr8BfzalpPBZhXvt8=">ACSnicdVBNSxBEO3ZmGjM1xqPOaTJEgElhkJ6FGMhxwVsirsbJbqnhpt7O4ZumtclmZ+S67Jf8kfyN/ITbzYs24gaixo+vFeFa/qiVorT2n6O+k9Wn8ZHXt6fqz5y9evupvD7yVeMkjmSlK3ciwKNWFkekSONJ7RCM0Hgszj93+vEFOq8q+5XmNU4MnFpVKgkUqWl/Mxcm5AVqgna69S3Qx6yd9gfpcCftit8H2XDxpwO2rIPpRvI2LyrZGLQkNXg/ztKaJgEcKamxXc8bjzXIczjFcYQWDPpJWGzf8veRKXhZufgs8QX70QA4/3ciNhpgM78Xa0j/6eNGyp3JkHZuiG08saobDSnindR8EI5lKTnEYB0Ku7K5Rk4kBQDu+UiTLzB4kxWxoAtQi7KWRvyzlKUYdbeUY3cX6oSdNiPcoz0b278YXC0NczSYXb4abC7twx3jb1h79gHlrFtsu+sAM2YpLN2Xf2g/1MfiV/ksvk6qa1lyxnNtmt6q1cA1jgs5U=</latexit>j
δ
j, yi j}nj i=1; wt G + δ
G
G + k
j=1
j
<latexit sha1_base64="OGBemspsUbiFWogaMpCReQJCYoM=">ACe3icdVBda9swFW8bu26j6b4x4qFgZjHcEeK+tLoWyB9rGFpi3EqbmW5UaJBvpeiEI/6H9mr12/2UwOXGh7bYLQkfnMvVPWkphcUwvOkEj9YeP1nfeLr57PmLl1vd7VfntqgM40NWyMJcpmC5FJoPUaDkl6XhoFLJL9LZt0a/+M6NFYU+w0XJxwqutcgFA/RU0h3EaT5Pjq4c7kb1AW1fSHdpbCuVuOlBVF+5WU1jkOUEkqm3KBdnXCLUyXTVl3R7YX8/bIr+DaL+8g57pK2TZLuzE2cFqxTXyCRYO4rCEscODAomeb0ZV5aXwGZwzUcealDcjt1y3Zq+80xG8L4o5Eu2bsdDpS1C5V6pwKc2IdaQ/5LG1WY74+d0GWFXLPVoLySFAvaZEczYThDufAmBH+r5RNwABDn/C9KanyO2g+Z4VSoDPX5Fq7uBmZ5m5eP1AVG7QqA+kGXvaR3uZG/w/OP/WjsB+dfu4dfm3D3SBvyFvynkTkCzkx+SEDAkjP8hPckN+dX4HveBD8HFlDTptz2tyr4K9P/QexAg=</latexit><latexit sha1_base64="OGBemspsUbiFWogaMpCReQJCYoM=">ACe3icdVBda9swFW8bu26j6b4x4qFgZjHcEeK+tLoWyB9rGFpi3EqbmW5UaJBvpeiEI/6H9mr12/2UwOXGh7bYLQkfnMvVPWkphcUwvOkEj9YeP1nfeLr57PmLl1vd7VfntqgM40NWyMJcpmC5FJoPUaDkl6XhoFLJL9LZt0a/+M6NFYU+w0XJxwqutcgFA/RU0h3EaT5Pjq4c7kb1AW1fSHdpbCuVuOlBVF+5WU1jkOUEkqm3KBdnXCLUyXTVl3R7YX8/bIr+DaL+8g57pK2TZLuzE2cFqxTXyCRYO4rCEscODAomeb0ZV5aXwGZwzUcealDcjt1y3Zq+80xG8L4o5Eu2bsdDpS1C5V6pwKc2IdaQ/5LG1WY74+d0GWFXLPVoLySFAvaZEczYThDufAmBH+r5RNwABDn/C9KanyO2g+Z4VSoDPX5Fq7uBmZ5m5eP1AVG7QqA+kGXvaR3uZG/w/OP/WjsB+dfu4dfm3D3SBvyFvynkTkCzkx+SEDAkjP8hPckN+dX4HveBD8HFlDTptz2tyr4K9P/QexAg=</latexit><latexit sha1_base64="OGBemspsUbiFWogaMpCReQJCYoM=">ACe3icdVBda9swFW8bu26j6b4x4qFgZjHcEeK+tLoWyB9rGFpi3EqbmW5UaJBvpeiEI/6H9mr12/2UwOXGh7bYLQkfnMvVPWkphcUwvOkEj9YeP1nfeLr57PmLl1vd7VfntqgM40NWyMJcpmC5FJoPUaDkl6XhoFLJL9LZt0a/+M6NFYU+w0XJxwqutcgFA/RU0h3EaT5Pjq4c7kb1AW1fSHdpbCuVuOlBVF+5WU1jkOUEkqm3KBdnXCLUyXTVl3R7YX8/bIr+DaL+8g57pK2TZLuzE2cFqxTXyCRYO4rCEscODAomeb0ZV5aXwGZwzUcealDcjt1y3Zq+80xG8L4o5Eu2bsdDpS1C5V6pwKc2IdaQ/5LG1WY74+d0GWFXLPVoLySFAvaZEczYThDufAmBH+r5RNwABDn/C9KanyO2g+Z4VSoDPX5Fq7uBmZ5m5eP1AVG7QqA+kGXvaR3uZG/w/OP/WjsB+dfu4dfm3D3SBvyFvynkTkCzkx+SEDAkjP8hPckN+dX4HveBD8HFlDTptz2tyr4K9P/QexAg=</latexit><latexit sha1_base64="OGBemspsUbiFWogaMpCReQJCYoM=">ACe3icdVBda9swFW8bu26j6b4x4qFgZjHcEeK+tLoWyB9rGFpi3EqbmW5UaJBvpeiEI/6H9mr12/2UwOXGh7bYLQkfnMvVPWkphcUwvOkEj9YeP1nfeLr57PmLl1vd7VfntqgM40NWyMJcpmC5FJoPUaDkl6XhoFLJL9LZt0a/+M6NFYU+w0XJxwqutcgFA/RU0h3EaT5Pjq4c7kb1AW1fSHdpbCuVuOlBVF+5WU1jkOUEkqm3KBdnXCLUyXTVl3R7YX8/bIr+DaL+8g57pK2TZLuzE2cFqxTXyCRYO4rCEscODAomeb0ZV5aXwGZwzUcealDcjt1y3Zq+80xG8L4o5Eu2bsdDpS1C5V6pwKc2IdaQ/5LG1WY74+d0GWFXLPVoLySFAvaZEczYThDufAmBH+r5RNwABDn/C9KanyO2g+Z4VSoDPX5Fq7uBmZ5m5eP1AVG7QqA+kGXvaR3uZG/w/OP/WjsB+dfu4dfm3D3SBvyFvynkTkCzkx+SEDAkjP8hPckN+dX4HveBD8HFlDTptz2tyr4K9P/QexAg=</latexit>Threat model
Information available:
from other agents
global state
Compute
1
<latexit sha1_base64="D3aW/8S9R5G7eFMRvexSRdDWfV4=">ACSnicdVBNSxBEO3ZmETN1xqPOaTJEgElhkJxKMYDx4NZFXY2SzVPTXa2N0zdNe4LM38lyT/5I/kL/hTbykZ10haixo+vFeFa/qiVorT2n6J+k9Wn85Onq2vqz5y9evupvD70VeMkjmSlK3cswKNWFkekSONx7RCM0Hgkzr50+tE5Oq8q+43mNU4MnFhVKgkUqWl/Mxcm5AVqgnafQ/0MWun/UE63E674vdBNlz86YAt62C6kbzNi0o2Bi1JDd6Ps7SmSQBHSmps1/PGYw3yDE5wHKEFg34SFtu3/H1kCl5WLj5LfMH+OxHAeD83InYaoFN/V+vI/2njhsrtSVC2bgitvDYqG82p4l0UvFAOJel5BCdirtyeQoOJMXAbrkIE2+wOJOVMWCLkIty1oa8sxRlmLV3VCP3lqoEHfaiHCO9yY0/DA63hlk6zL5+GuzsLsNdZW/YO/aBZewz2H7ICNmGRz9oP9ZL+S38lFcplcXbf2kuXMJrtVvZW/VwizlA=</latexit><latexit sha1_base64="D3aW/8S9R5G7eFMRvexSRdDWfV4=">ACSnicdVBNSxBEO3ZmETN1xqPOaTJEgElhkJxKMYDx4NZFXY2SzVPTXa2N0zdNe4LM38lyT/5I/kL/hTbykZ10haixo+vFeFa/qiVorT2n6J+k9Wn85Onq2vqz5y9evupvD70VeMkjmSlK3cswKNWFkekSONx7RCM0Hgkzr50+tE5Oq8q+43mNU4MnFhVKgkUqWl/Mxcm5AVqgnafQ/0MWun/UE63E674vdBNlz86YAt62C6kbzNi0o2Bi1JDd6Ps7SmSQBHSmps1/PGYw3yDE5wHKEFg34SFtu3/H1kCl5WLj5LfMH+OxHAeD83InYaoFN/V+vI/2njhsrtSVC2bgitvDYqG82p4l0UvFAOJel5BCdirtyeQoOJMXAbrkIE2+wOJOVMWCLkIty1oa8sxRlmLV3VCP3lqoEHfaiHCO9yY0/DA63hlk6zL5+GuzsLsNdZW/YO/aBZewz2H7ICNmGRz9oP9ZL+S38lFcplcXbf2kuXMJrtVvZW/VwizlA=</latexit><latexit sha1_base64="D3aW/8S9R5G7eFMRvexSRdDWfV4=">ACSnicdVBNSxBEO3ZmETN1xqPOaTJEgElhkJxKMYDx4NZFXY2SzVPTXa2N0zdNe4LM38lyT/5I/kL/hTbykZ10haixo+vFeFa/qiVorT2n6J+k9Wn85Onq2vqz5y9evupvD70VeMkjmSlK3cswKNWFkekSONx7RCM0Hgkzr50+tE5Oq8q+43mNU4MnFhVKgkUqWl/Mxcm5AVqgnafQ/0MWun/UE63E674vdBNlz86YAt62C6kbzNi0o2Bi1JDd6Ps7SmSQBHSmps1/PGYw3yDE5wHKEFg34SFtu3/H1kCl5WLj5LfMH+OxHAeD83InYaoFN/V+vI/2njhsrtSVC2bgitvDYqG82p4l0UvFAOJel5BCdirtyeQoOJMXAbrkIE2+wOJOVMWCLkIty1oa8sxRlmLV3VCP3lqoEHfaiHCO9yY0/DA63hlk6zL5+GuzsLsNdZW/YO/aBZewz2H7ICNmGRz9oP9ZL+S38lFcplcXbf2kuXMJrtVvZW/VwizlA=</latexit><latexit sha1_base64="D3aW/8S9R5G7eFMRvexSRdDWfV4=">ACSnicdVBNSxBEO3ZmETN1xqPOaTJEgElhkJxKMYDx4NZFXY2SzVPTXa2N0zdNe4LM38lyT/5I/kL/hTbykZ10haixo+vFeFa/qiVorT2n6J+k9Wn85Onq2vqz5y9evupvD70VeMkjmSlK3cswKNWFkekSONx7RCM0Hgkzr50+tE5Oq8q+43mNU4MnFhVKgkUqWl/Mxcm5AVqgnafQ/0MWun/UE63E674vdBNlz86YAt62C6kbzNi0o2Bi1JDd6Ps7SmSQBHSmps1/PGYw3yDE5wHKEFg34SFtu3/H1kCl5WLj5LfMH+OxHAeD83InYaoFN/V+vI/2njhsrtSVC2bgitvDYqG82p4l0UvFAOJel5BCdirtyeQoOJMXAbrkIE2+wOJOVMWCLkIty1oa8sxRlmLV3VCP3lqoEHfaiHCO9yY0/DA63hlk6zL5+GuzsLsNdZW/YO/aBZewz2H7ICNmGRz9oP9ZL+S38lFcplcXbf2kuXMJrtVvZW/VwizlA=</latexit>Compute
2
<latexit sha1_base64="wDksDghZJzr8BfzalpPBZhXvt8=">ACSnicdVBNSxBEO3ZmGjM1xqPOaTJEgElhkJ6FGMhxwVsirsbJbqnhpt7O4ZumtclmZ+S67Jf8kfyN/ITbzYs24gaixo+vFeFa/qiVorT2n6O+k9Wn8ZHXt6fqz5y9evupvD7yVeMkjmSlK3ciwKNWFkekSONJ7RCM0Hgszj93+vEFOq8q+5XmNU4MnFpVKgkUqWl/Mxcm5AVqgna69S3Qx6yd9gfpcCftit8H2XDxpwO2rIPpRvI2LyrZGLQkNXg/ztKaJgEcKamxXc8bjzXIczjFcYQWDPpJWGzf8veRKXhZufgs8QX70QA4/3ciNhpgM78Xa0j/6eNGyp3JkHZuiG08saobDSnindR8EI5lKTnEYB0Ku7K5Rk4kBQDu+UiTLzB4kxWxoAtQi7KWRvyzlKUYdbeUY3cX6oSdNiPcoz0b278YXC0NczSYXb4abC7twx3jb1h79gHlrFtsu+sAM2YpLN2Xf2g/1MfiV/ksvk6qa1lyxnNtmt6q1cA1jgs5U=</latexit><latexit sha1_base64="wDksDghZJzr8BfzalpPBZhXvt8=">ACSnicdVBNSxBEO3ZmGjM1xqPOaTJEgElhkJ6FGMhxwVsirsbJbqnhpt7O4ZumtclmZ+S67Jf8kfyN/ITbzYs24gaixo+vFeFa/qiVorT2n6O+k9Wn8ZHXt6fqz5y9evupvD7yVeMkjmSlK3ciwKNWFkekSONJ7RCM0Hgszj93+vEFOq8q+5XmNU4MnFpVKgkUqWl/Mxcm5AVqgna69S3Qx6yd9gfpcCftit8H2XDxpwO2rIPpRvI2LyrZGLQkNXg/ztKaJgEcKamxXc8bjzXIczjFcYQWDPpJWGzf8veRKXhZufgs8QX70QA4/3ciNhpgM78Xa0j/6eNGyp3JkHZuiG08saobDSnindR8EI5lKTnEYB0Ku7K5Rk4kBQDu+UiTLzB4kxWxoAtQi7KWRvyzlKUYdbeUY3cX6oSdNiPcoz0b278YXC0NczSYXb4abC7twx3jb1h79gHlrFtsu+sAM2YpLN2Xf2g/1MfiV/ksvk6qa1lyxnNtmt6q1cA1jgs5U=</latexit><latexit sha1_base64="wDksDghZJzr8BfzalpPBZhXvt8=">ACSnicdVBNSxBEO3ZmGjM1xqPOaTJEgElhkJ6FGMhxwVsirsbJbqnhpt7O4ZumtclmZ+S67Jf8kfyN/ITbzYs24gaixo+vFeFa/qiVorT2n6O+k9Wn8ZHXt6fqz5y9evupvD7yVeMkjmSlK3ciwKNWFkekSONJ7RCM0Hgszj93+vEFOq8q+5XmNU4MnFpVKgkUqWl/Mxcm5AVqgna69S3Qx6yd9gfpcCftit8H2XDxpwO2rIPpRvI2LyrZGLQkNXg/ztKaJgEcKamxXc8bjzXIczjFcYQWDPpJWGzf8veRKXhZufgs8QX70QA4/3ciNhpgM78Xa0j/6eNGyp3JkHZuiG08saobDSnindR8EI5lKTnEYB0Ku7K5Rk4kBQDu+UiTLzB4kxWxoAtQi7KWRvyzlKUYdbeUY3cX6oSdNiPcoz0b278YXC0NczSYXb4abC7twx3jb1h79gHlrFtsu+sAM2YpLN2Xf2g/1MfiV/ksvk6qa1lyxnNtmt6q1cA1jgs5U=</latexit><latexit sha1_base64="wDksDghZJzr8BfzalpPBZhXvt8=">ACSnicdVBNSxBEO3ZmGjM1xqPOaTJEgElhkJ6FGMhxwVsirsbJbqnhpt7O4ZumtclmZ+S67Jf8kfyN/ITbzYs24gaixo+vFeFa/qiVorT2n6O+k9Wn8ZHXt6fqz5y9evupvD7yVeMkjmSlK3ciwKNWFkekSONJ7RCM0Hgszj93+vEFOq8q+5XmNU4MnFpVKgkUqWl/Mxcm5AVqgna69S3Qx6yd9gfpcCftit8H2XDxpwO2rIPpRvI2LyrZGLQkNXg/ztKaJgEcKamxXc8bjzXIczjFcYQWDPpJWGzf8veRKXhZufgs8QX70QA4/3ciNhpgM78Xa0j/6eNGyp3JkHZuiG08saobDSnindR8EI5lKTnEYB0Ku7K5Rk4kBQDu+UiTLzB4kxWxoAtQi7KWRvyzlKUYdbeUY3cX6oSdNiPcoz0b278YXC0NczSYXb4abC7twx3jb1h79gHlrFtsu+sAM2YpLN2Xf2g/1MfiV/ksvk6qa1lyxnNtmt6q1cA1jgs5U=</latexit>j
δ
j, yi j}nj i=1; wt G + δ
Compute
m
<latexit sha1_base64="Gzxzi/3mpo1xAgKqA2ZEeTIBX9s=">ACSnicbVDLShxBFK2emPjIw1GXLmwcBCEwdIuQLCVxkaWBjArTk+FW9W0trKpuqm47DEV/S7bxX/ID+Q134sasRc6eqDgcM69nFuHV0o6SpL/UefN0t3yura+8/fPy03t3YPHVlbQUORKlKe87BoZIGByRJ4XlETRXeMavs/8s2u0TpbmF0rHGm4MLKQAihI4+5WxrXPclQEzVj/9vQ5bcbdXtJP5ohfkrQlPdbiZLwR7WR5KWqNhoQC54ZpUtHIgyUpFDZrWe2wAnEFzgM1IBGN/Lz65t4Lyh5XJQ2PEPxXH264UE7N9U8TGqgS7fozcTXvGFNxdeRl6aqCY14DCpqFVMZz6qIc2lRkJoGAsLKcGsLsGCoFDYsxSuwx8MTkSpNZjcZ7yYND6bRfLCT5oFV4vj1hWg/HGwQ6XpYoEvyelBP036c/D3tG3twVts12T5L2Rd2xH6wEzZgk3ZH/aX3UT/otvoLrp/HO1E7c4We4bO0gObYLO4</latexit><latexit sha1_base64="Gzxzi/3mpo1xAgKqA2ZEeTIBX9s=">ACSnicbVDLShxBFK2emPjIw1GXLmwcBCEwdIuQLCVxkaWBjArTk+FW9W0trKpuqm47DEV/S7bxX/ID+Q134sasRc6eqDgcM69nFuHV0o6SpL/UefN0t3yura+8/fPy03t3YPHVlbQUORKlKe87BoZIGByRJ4XlETRXeMavs/8s2u0TpbmF0rHGm4MLKQAihI4+5WxrXPclQEzVj/9vQ5bcbdXtJP5ohfkrQlPdbiZLwR7WR5KWqNhoQC54ZpUtHIgyUpFDZrWe2wAnEFzgM1IBGN/Lz65t4Lyh5XJQ2PEPxXH264UE7N9U8TGqgS7fozcTXvGFNxdeRl6aqCY14DCpqFVMZz6qIc2lRkJoGAsLKcGsLsGCoFDYsxSuwx8MTkSpNZjcZ7yYND6bRfLCT5oFV4vj1hWg/HGwQ6XpYoEvyelBP036c/D3tG3twVts12T5L2Rd2xH6wEzZgk3ZH/aX3UT/otvoLrp/HO1E7c4We4bO0gObYLO4</latexit><latexit sha1_base64="Gzxzi/3mpo1xAgKqA2ZEeTIBX9s=">ACSnicbVDLShxBFK2emPjIw1GXLmwcBCEwdIuQLCVxkaWBjArTk+FW9W0trKpuqm47DEV/S7bxX/ID+Q134sasRc6eqDgcM69nFuHV0o6SpL/UefN0t3yura+8/fPy03t3YPHVlbQUORKlKe87BoZIGByRJ4XlETRXeMavs/8s2u0TpbmF0rHGm4MLKQAihI4+5WxrXPclQEzVj/9vQ5bcbdXtJP5ohfkrQlPdbiZLwR7WR5KWqNhoQC54ZpUtHIgyUpFDZrWe2wAnEFzgM1IBGN/Lz65t4Lyh5XJQ2PEPxXH264UE7N9U8TGqgS7fozcTXvGFNxdeRl6aqCY14DCpqFVMZz6qIc2lRkJoGAsLKcGsLsGCoFDYsxSuwx8MTkSpNZjcZ7yYND6bRfLCT5oFV4vj1hWg/HGwQ6XpYoEvyelBP036c/D3tG3twVts12T5L2Rd2xH6wEzZgk3ZH/aX3UT/otvoLrp/HO1E7c4We4bO0gObYLO4</latexit><latexit sha1_base64="Gzxzi/3mpo1xAgKqA2ZEeTIBX9s=">ACSnicbVDLShxBFK2emPjIw1GXLmwcBCEwdIuQLCVxkaWBjArTk+FW9W0trKpuqm47DEV/S7bxX/ID+Q134sasRc6eqDgcM69nFuHV0o6SpL/UefN0t3yura+8/fPy03t3YPHVlbQUORKlKe87BoZIGByRJ4XlETRXeMavs/8s2u0TpbmF0rHGm4MLKQAihI4+5WxrXPclQEzVj/9vQ5bcbdXtJP5ohfkrQlPdbiZLwR7WR5KWqNhoQC54ZpUtHIgyUpFDZrWe2wAnEFzgM1IBGN/Lz65t4Lyh5XJQ2PEPxXH264UE7N9U8TGqgS7fozcTXvGFNxdeRl6aqCY14DCpqFVMZz6qIc2lRkJoGAsLKcGsLsGCoFDYsxSuwx8MTkSpNZjcZ7yYND6bRfLCT5oFV4vj1hWg/HGwQ6XpYoEvyelBP036c/D3tG3twVts12T5L2Rd2xH6wEzZgk3ZH/aX3UT/otvoLrp/HO1E7c4We4bO0gObYLO4</latexit>m
m, yi m}nm i=1, {xl, T l}nmal l=1 ; wt G + δ
Aim Cause targeted misclassification of an auxiliary set of examples for the global model and ensure global model has good performance
G
G + k
j=1
j
<latexit sha1_base64="OGBemspsUbiFWogaMpCReQJCYoM=">ACe3icdVBda9swFW8bu26j6b4x4qFgZjHcEeK+tLoWyB9rGFpi3EqbmW5UaJBvpeiEI/6H9mr12/2UwOXGh7bYLQkfnMvVPWkphcUwvOkEj9YeP1nfeLr57PmLl1vd7VfntqgM40NWyMJcpmC5FJoPUaDkl6XhoFLJL9LZt0a/+M6NFYU+w0XJxwqutcgFA/RU0h3EaT5Pjq4c7kb1AW1fSHdpbCuVuOlBVF+5WU1jkOUEkqm3KBdnXCLUyXTVl3R7YX8/bIr+DaL+8g57pK2TZLuzE2cFqxTXyCRYO4rCEscODAomeb0ZV5aXwGZwzUcealDcjt1y3Zq+80xG8L4o5Eu2bsdDpS1C5V6pwKc2IdaQ/5LG1WY74+d0GWFXLPVoLySFAvaZEczYThDufAmBH+r5RNwABDn/C9KanyO2g+Z4VSoDPX5Fq7uBmZ5m5eP1AVG7QqA+kGXvaR3uZG/w/OP/WjsB+dfu4dfm3D3SBvyFvynkTkCzkx+SEDAkjP8hPckN+dX4HveBD8HFlDTptz2tyr4K9P/QexAg=</latexit><latexit sha1_base64="OGBemspsUbiFWogaMpCReQJCYoM=">ACe3icdVBda9swFW8bu26j6b4x4qFgZjHcEeK+tLoWyB9rGFpi3EqbmW5UaJBvpeiEI/6H9mr12/2UwOXGh7bYLQkfnMvVPWkphcUwvOkEj9YeP1nfeLr57PmLl1vd7VfntqgM40NWyMJcpmC5FJoPUaDkl6XhoFLJL9LZt0a/+M6NFYU+w0XJxwqutcgFA/RU0h3EaT5Pjq4c7kb1AW1fSHdpbCuVuOlBVF+5WU1jkOUEkqm3KBdnXCLUyXTVl3R7YX8/bIr+DaL+8g57pK2TZLuzE2cFqxTXyCRYO4rCEscODAomeb0ZV5aXwGZwzUcealDcjt1y3Zq+80xG8L4o5Eu2bsdDpS1C5V6pwKc2IdaQ/5LG1WY74+d0GWFXLPVoLySFAvaZEczYThDufAmBH+r5RNwABDn/C9KanyO2g+Z4VSoDPX5Fq7uBmZ5m5eP1AVG7QqA+kGXvaR3uZG/w/OP/WjsB+dfu4dfm3D3SBvyFvynkTkCzkx+SEDAkjP8hPckN+dX4HveBD8HFlDTptz2tyr4K9P/QexAg=</latexit><latexit sha1_base64="OGBemspsUbiFWogaMpCReQJCYoM=">ACe3icdVBda9swFW8bu26j6b4x4qFgZjHcEeK+tLoWyB9rGFpi3EqbmW5UaJBvpeiEI/6H9mr12/2UwOXGh7bYLQkfnMvVPWkphcUwvOkEj9YeP1nfeLr57PmLl1vd7VfntqgM40NWyMJcpmC5FJoPUaDkl6XhoFLJL9LZt0a/+M6NFYU+w0XJxwqutcgFA/RU0h3EaT5Pjq4c7kb1AW1fSHdpbCuVuOlBVF+5WU1jkOUEkqm3KBdnXCLUyXTVl3R7YX8/bIr+DaL+8g57pK2TZLuzE2cFqxTXyCRYO4rCEscODAomeb0ZV5aXwGZwzUcealDcjt1y3Zq+80xG8L4o5Eu2bsdDpS1C5V6pwKc2IdaQ/5LG1WY74+d0GWFXLPVoLySFAvaZEczYThDufAmBH+r5RNwABDn/C9KanyO2g+Z4VSoDPX5Fq7uBmZ5m5eP1AVG7QqA+kGXvaR3uZG/w/OP/WjsB+dfu4dfm3D3SBvyFvynkTkCzkx+SEDAkjP8hPckN+dX4HveBD8HFlDTptz2tyr4K9P/QexAg=</latexit><latexit sha1_base64="OGBemspsUbiFWogaMpCReQJCYoM=">ACe3icdVBda9swFW8bu26j6b4x4qFgZjHcEeK+tLoWyB9rGFpi3EqbmW5UaJBvpeiEI/6H9mr12/2UwOXGh7bYLQkfnMvVPWkphcUwvOkEj9YeP1nfeLr57PmLl1vd7VfntqgM40NWyMJcpmC5FJoPUaDkl6XhoFLJL9LZt0a/+M6NFYU+w0XJxwqutcgFA/RU0h3EaT5Pjq4c7kb1AW1fSHdpbCuVuOlBVF+5WU1jkOUEkqm3KBdnXCLUyXTVl3R7YX8/bIr+DaL+8g57pK2TZLuzE2cFqxTXyCRYO4rCEscODAomeb0ZV5aXwGZwzUcealDcjt1y3Zq+80xG8L4o5Eu2bsdDpS1C5V6pwKc2IdaQ/5LG1WY74+d0GWFXLPVoLySFAvaZEczYThDufAmBH+r5RNwABDn/C9KanyO2g+Z4VSoDPX5Fq7uBmZ5m5eP1AVG7QqA+kGXvaR3uZG/w/OP/WjsB+dfu4dfm3D3SBvyFvynkTkCzkx+SEDAkjP8hPckN+dX4HveBD8HFlDTptz2tyr4K9P/QexAg=</latexit>Strategy
Malicious agent’s update computation
Boosting malicious update, no local training
δmal = argminδCross-entropy({xl
m, T l m}nmal l=1 ; wG + δ)
<latexit sha1_base64="J/M0Ent6MdJ4NKeZ70D9owiBcn4=">ACyHicdVFtb9MwEHYyXsZ46+AjQlhUwBAQOVU7VqFJkzYJxKchrdukposcx+ms2U5kO3SR5S/8A34ev4SvOG2BdYKTbD2+585391xWcaYNQj+CcO3GzVu31+9s3L13/8HDzuajY13WitARKXmpTjOsKWeSjgwznJ5WimKRcXqSXey3/MlXqjQr5ZFpKjoReCpZwQg23pV2vieZsElOucEutYmhl8YKzJ2Du3DxwmoqmGzJv5Fuye2rUut3VBpVo3bSmwisDnPCnvpUnHG3x61d+Jz+W7szqxcqeA+JFkxSz/CN/DK16/ThdFqLcz6PcginoDNIyHgxQPNzuwzhCc+uCpR2m8GzJC9JLXwfhGOtxzGqzMQ3bhjh1G0ktaYVJhd4SsceSiyonti5dg6+8J4cFqXyRxo4917NsFho3YjMR7az6etc6/wXN65NsTOxTFa1oZIsChU1h6aE7SJgzhQlhjceYKY7xWSc6wMX5dK1Uy4WeQdEZKIbDMbSub+yP1zF1jBTlYsgRze+BpL+lv3eD/wXEvilEUf+l39BS3HXwBDwHWyAG78Ee+AQOwQgQ8DN4GrwMXoWfwyqchc0iNAyWOY/BioXfgE4TuQI</latexit><latexit sha1_base64="J/M0Ent6MdJ4NKeZ70D9owiBcn4=">ACyHicdVFtb9MwEHYyXsZ46+AjQlhUwBAQOVU7VqFJkzYJxKchrdukposcx+ms2U5kO3SR5S/8A34ev4SvOG2BdYKTbD2+585391xWcaYNQj+CcO3GzVu31+9s3L13/8HDzuajY13WitARKXmpTjOsKWeSjgwznJ5WimKRcXqSXey3/MlXqjQr5ZFpKjoReCpZwQg23pV2vieZsElOucEutYmhl8YKzJ2Du3DxwmoqmGzJv5Fuye2rUut3VBpVo3bSmwisDnPCnvpUnHG3x61d+Jz+W7szqxcqeA+JFkxSz/CN/DK16/ThdFqLcz6PcginoDNIyHgxQPNzuwzhCc+uCpR2m8GzJC9JLXwfhGOtxzGqzMQ3bhjh1G0ktaYVJhd4SsceSiyonti5dg6+8J4cFqXyRxo4917NsFho3YjMR7az6etc6/wXN65NsTOxTFa1oZIsChU1h6aE7SJgzhQlhjceYKY7xWSc6wMX5dK1Uy4WeQdEZKIbDMbSub+yP1zF1jBTlYsgRze+BpL+lv3eD/wXEvilEUf+l39BS3HXwBDwHWyAG78Ee+AQOwQgQ8DN4GrwMXoWfwyqchc0iNAyWOY/BioXfgE4TuQI</latexit><latexit sha1_base64="J/M0Ent6MdJ4NKeZ70D9owiBcn4=">ACyHicdVFtb9MwEHYyXsZ46+AjQlhUwBAQOVU7VqFJkzYJxKchrdukposcx+ms2U5kO3SR5S/8A34ev4SvOG2BdYKTbD2+585391xWcaYNQj+CcO3GzVu31+9s3L13/8HDzuajY13WitARKXmpTjOsKWeSjgwznJ5WimKRcXqSXey3/MlXqjQr5ZFpKjoReCpZwQg23pV2vieZsElOucEutYmhl8YKzJ2Du3DxwmoqmGzJv5Fuye2rUut3VBpVo3bSmwisDnPCnvpUnHG3x61d+Jz+W7szqxcqeA+JFkxSz/CN/DK16/ThdFqLcz6PcginoDNIyHgxQPNzuwzhCc+uCpR2m8GzJC9JLXwfhGOtxzGqzMQ3bhjh1G0ktaYVJhd4SsceSiyonti5dg6+8J4cFqXyRxo4917NsFho3YjMR7az6etc6/wXN65NsTOxTFa1oZIsChU1h6aE7SJgzhQlhjceYKY7xWSc6wMX5dK1Uy4WeQdEZKIbDMbSub+yP1zF1jBTlYsgRze+BpL+lv3eD/wXEvilEUf+l39BS3HXwBDwHWyAG78Ee+AQOwQgQ8DN4GrwMXoWfwyqchc0iNAyWOY/BioXfgE4TuQI</latexit><latexit sha1_base64="J/M0Ent6MdJ4NKeZ70D9owiBcn4=">ACyHicdVFtb9MwEHYyXsZ46+AjQlhUwBAQOVU7VqFJkzYJxKchrdukposcx+ms2U5kO3SR5S/8A34ev4SvOG2BdYKTbD2+585391xWcaYNQj+CcO3GzVu31+9s3L13/8HDzuajY13WitARKXmpTjOsKWeSjgwznJ5WimKRcXqSXey3/MlXqjQr5ZFpKjoReCpZwQg23pV2vieZsElOucEutYmhl8YKzJ2Du3DxwmoqmGzJv5Fuye2rUut3VBpVo3bSmwisDnPCnvpUnHG3x61d+Jz+W7szqxcqeA+JFkxSz/CN/DK16/ThdFqLcz6PcginoDNIyHgxQPNzuwzhCc+uCpR2m8GzJC9JLXwfhGOtxzGqzMQ3bhjh1G0ktaYVJhd4SsceSiyonti5dg6+8J4cFqXyRxo4917NsFho3YjMR7az6etc6/wXN65NsTOxTFa1oZIsChU1h6aE7SJgzhQlhjceYKY7xWSc6wMX5dK1Uy4WeQdEZKIbDMbSub+yP1zF1jBTlYsgRze+BpL+lv3eD/wXEvilEUf+l39BS3HXwBDwHWyAG78Ee+AQOwQgQ8DN4GrwMXoWfwyqchc0iNAyWOY/BioXfgE4TuQI</latexit>δmal → βδmal
<latexit sha1_base64="SVLAfWw+ZsQa7W5GOoVDFtpN2Y=">ACenicdVBNaxsxFJS3X2n65bTHipiCi2FRWvsJr4FkOPKdRJwGvMk1Zri0jaRXpbx4j9Qf01vTb/pYfKjgtNaAYEw8x7jN7wWiuPjF13kgcPHz1+svN09nzFy9fdfden/mqcUKORaUrd8HBS62sHKNCLS9qJ8FwLc/5fHaP/8unVeV/YarWk4NzK0qlQCM0qx7nHMT8kJqhHYWcpRXGAzots2dmi8QnKuWNOcSgd43SWfdHktZ/3A46FOW9odslI0iGbJs9HlAs5Rt0CNbnM72Ou/yohKNkRaFBu8nGatxGsChElq2u3njZQ3iEuZyEqkFI/0bK5t6fuoFLSsXHwW6Ub9dyOA8X5leJw0gAt/1uL/MmDZaH06Bs3aC04iaobDTFiq6ro4VyUqBeRQLCqfhXKhbgQGAs+FYKN/EGK5eiMgZsEXJeLtuQryN5GZbtHdeIk60rQIeTaMdK/ZG7ydn/TRjafZ10Dti23J3yFuyTz6QjByQI/KFnJIxEeQH+Ul+kevO72Q/+Zh8uhlNOtudN+QWksEfQjGuQ=</latexit><latexit sha1_base64="SVLAfWw+ZsQa7W5GOoVDFtpN2Y=">ACenicdVBNaxsxFJS3X2n65bTHipiCi2FRWvsJr4FkOPKdRJwGvMk1Zri0jaRXpbx4j9Qf01vTb/pYfKjgtNaAYEw8x7jN7wWiuPjF13kgcPHz1+svN09nzFy9fdfden/mqcUKORaUrd8HBS62sHKNCLS9qJ8FwLc/5fHaP/8unVeV/YarWk4NzK0qlQCM0qx7nHMT8kJqhHYWcpRXGAzots2dmi8QnKuWNOcSgd43SWfdHktZ/3A46FOW9odslI0iGbJs9HlAs5Rt0CNbnM72Ou/yohKNkRaFBu8nGatxGsChElq2u3njZQ3iEuZyEqkFI/0bK5t6fuoFLSsXHwW6Ub9dyOA8X5leJw0gAt/1uL/MmDZaH06Bs3aC04iaobDTFiq6ro4VyUqBeRQLCqfhXKhbgQGAs+FYKN/EGK5eiMgZsEXJeLtuQryN5GZbtHdeIk60rQIeTaMdK/ZG7ydn/TRjafZ10Dti23J3yFuyTz6QjByQI/KFnJIxEeQH+Ul+kevO72Q/+Zh8uhlNOtudN+QWksEfQjGuQ=</latexit><latexit sha1_base64="SVLAfWw+ZsQa7W5GOoVDFtpN2Y=">ACenicdVBNaxsxFJS3X2n65bTHipiCi2FRWvsJr4FkOPKdRJwGvMk1Zri0jaRXpbx4j9Qf01vTb/pYfKjgtNaAYEw8x7jN7wWiuPjF13kgcPHz1+svN09nzFy9fdfden/mqcUKORaUrd8HBS62sHKNCLS9qJ8FwLc/5fHaP/8unVeV/YarWk4NzK0qlQCM0qx7nHMT8kJqhHYWcpRXGAzots2dmi8QnKuWNOcSgd43SWfdHktZ/3A46FOW9odslI0iGbJs9HlAs5Rt0CNbnM72Ou/yohKNkRaFBu8nGatxGsChElq2u3njZQ3iEuZyEqkFI/0bK5t6fuoFLSsXHwW6Ub9dyOA8X5leJw0gAt/1uL/MmDZaH06Bs3aC04iaobDTFiq6ro4VyUqBeRQLCqfhXKhbgQGAs+FYKN/EGK5eiMgZsEXJeLtuQryN5GZbtHdeIk60rQIeTaMdK/ZG7ydn/TRjafZ10Dti23J3yFuyTz6QjByQI/KFnJIxEeQH+Ul+kevO72Q/+Zh8uhlNOtudN+QWksEfQjGuQ=</latexit><latexit sha1_base64="SVLAfWw+ZsQa7W5GOoVDFtpN2Y=">ACenicdVBNaxsxFJS3X2n65bTHipiCi2FRWvsJr4FkOPKdRJwGvMk1Zri0jaRXpbx4j9Qf01vTb/pYfKjgtNaAYEw8x7jN7wWiuPjF13kgcPHz1+svN09nzFy9fdfden/mqcUKORaUrd8HBS62sHKNCLS9qJ8FwLc/5fHaP/8unVeV/YarWk4NzK0qlQCM0qx7nHMT8kJqhHYWcpRXGAzots2dmi8QnKuWNOcSgd43SWfdHktZ/3A46FOW9odslI0iGbJs9HlAs5Rt0CNbnM72Ou/yohKNkRaFBu8nGatxGsChElq2u3njZQ3iEuZyEqkFI/0bK5t6fuoFLSsXHwW6Ub9dyOA8X5leJw0gAt/1uL/MmDZaH06Bs3aC04iaobDTFiq6ro4VyUqBeRQLCqfhXKhbgQGAs+FYKN/EGK5eiMgZsEXJeLtuQryN5GZbtHdeIk60rQIeTaMdK/ZG7ydn/TRjafZ10Dti23J3yFuyTz6QjByQI/KFnJIxEeQH+Ul+kevO72Q/+Zh8uhlNOtudN+QWksEfQjGuQ=</latexit>✦ Fashion MNIST data [2] ✦ CNN achieving 91.5% accuracy on test data ✦ Total of 10 agents, all called every time step ✦ Training is stopped when global model achieves above 91% validation accuracy ✦ Adversarial objective: Classify (‘sandal’, class 5) as a ‘sneaker’, class 7
Strategy
Malicious agent’s update computation
Boosting malicious update, no local training
δmal = argminδCross-entropy({xl
m, T l m}nmal l=1 ; wG + δ)
<latexit sha1_base64="J/M0Ent6MdJ4NKeZ70D9owiBcn4=">ACyHicdVFtb9MwEHYyXsZ46+AjQlhUwBAQOVU7VqFJkzYJxKchrdukposcx+ms2U5kO3SR5S/8A34ev4SvOG2BdYKTbD2+585391xWcaYNQj+CcO3GzVu31+9s3L13/8HDzuajY13WitARKXmpTjOsKWeSjgwznJ5WimKRcXqSXey3/MlXqjQr5ZFpKjoReCpZwQg23pV2vieZsElOucEutYmhl8YKzJ2Du3DxwmoqmGzJv5Fuye2rUut3VBpVo3bSmwisDnPCnvpUnHG3x61d+Jz+W7szqxcqeA+JFkxSz/CN/DK16/ThdFqLcz6PcginoDNIyHgxQPNzuwzhCc+uCpR2m8GzJC9JLXwfhGOtxzGqzMQ3bhjh1G0ktaYVJhd4SsceSiyonti5dg6+8J4cFqXyRxo4917NsFho3YjMR7az6etc6/wXN65NsTOxTFa1oZIsChU1h6aE7SJgzhQlhjceYKY7xWSc6wMX5dK1Uy4WeQdEZKIbDMbSub+yP1zF1jBTlYsgRze+BpL+lv3eD/wXEvilEUf+l39BS3HXwBDwHWyAG78Ee+AQOwQgQ8DN4GrwMXoWfwyqchc0iNAyWOY/BioXfgE4TuQI</latexit><latexit sha1_base64="J/M0Ent6MdJ4NKeZ70D9owiBcn4=">ACyHicdVFtb9MwEHYyXsZ46+AjQlhUwBAQOVU7VqFJkzYJxKchrdukposcx+ms2U5kO3SR5S/8A34ev4SvOG2BdYKTbD2+585391xWcaYNQj+CcO3GzVu31+9s3L13/8HDzuajY13WitARKXmpTjOsKWeSjgwznJ5WimKRcXqSXey3/MlXqjQr5ZFpKjoReCpZwQg23pV2vieZsElOucEutYmhl8YKzJ2Du3DxwmoqmGzJv5Fuye2rUut3VBpVo3bSmwisDnPCnvpUnHG3x61d+Jz+W7szqxcqeA+JFkxSz/CN/DK16/ThdFqLcz6PcginoDNIyHgxQPNzuwzhCc+uCpR2m8GzJC9JLXwfhGOtxzGqzMQ3bhjh1G0ktaYVJhd4SsceSiyonti5dg6+8J4cFqXyRxo4917NsFho3YjMR7az6etc6/wXN65NsTOxTFa1oZIsChU1h6aE7SJgzhQlhjceYKY7xWSc6wMX5dK1Uy4WeQdEZKIbDMbSub+yP1zF1jBTlYsgRze+BpL+lv3eD/wXEvilEUf+l39BS3HXwBDwHWyAG78Ee+AQOwQgQ8DN4GrwMXoWfwyqchc0iNAyWOY/BioXfgE4TuQI</latexit><latexit sha1_base64="J/M0Ent6MdJ4NKeZ70D9owiBcn4=">ACyHicdVFtb9MwEHYyXsZ46+AjQlhUwBAQOVU7VqFJkzYJxKchrdukposcx+ms2U5kO3SR5S/8A34ev4SvOG2BdYKTbD2+585391xWcaYNQj+CcO3GzVu31+9s3L13/8HDzuajY13WitARKXmpTjOsKWeSjgwznJ5WimKRcXqSXey3/MlXqjQr5ZFpKjoReCpZwQg23pV2vieZsElOucEutYmhl8YKzJ2Du3DxwmoqmGzJv5Fuye2rUut3VBpVo3bSmwisDnPCnvpUnHG3x61d+Jz+W7szqxcqeA+JFkxSz/CN/DK16/ThdFqLcz6PcginoDNIyHgxQPNzuwzhCc+uCpR2m8GzJC9JLXwfhGOtxzGqzMQ3bhjh1G0ktaYVJhd4SsceSiyonti5dg6+8J4cFqXyRxo4917NsFho3YjMR7az6etc6/wXN65NsTOxTFa1oZIsChU1h6aE7SJgzhQlhjceYKY7xWSc6wMX5dK1Uy4WeQdEZKIbDMbSub+yP1zF1jBTlYsgRze+BpL+lv3eD/wXEvilEUf+l39BS3HXwBDwHWyAG78Ee+AQOwQgQ8DN4GrwMXoWfwyqchc0iNAyWOY/BioXfgE4TuQI</latexit><latexit sha1_base64="J/M0Ent6MdJ4NKeZ70D9owiBcn4=">ACyHicdVFtb9MwEHYyXsZ46+AjQlhUwBAQOVU7VqFJkzYJxKchrdukposcx+ms2U5kO3SR5S/8A34ev4SvOG2BdYKTbD2+585391xWcaYNQj+CcO3GzVu31+9s3L13/8HDzuajY13WitARKXmpTjOsKWeSjgwznJ5WimKRcXqSXey3/MlXqjQr5ZFpKjoReCpZwQg23pV2vieZsElOucEutYmhl8YKzJ2Du3DxwmoqmGzJv5Fuye2rUut3VBpVo3bSmwisDnPCnvpUnHG3x61d+Jz+W7szqxcqeA+JFkxSz/CN/DK16/ThdFqLcz6PcginoDNIyHgxQPNzuwzhCc+uCpR2m8GzJC9JLXwfhGOtxzGqzMQ3bhjh1G0ktaYVJhd4SsceSiyonti5dg6+8J4cFqXyRxo4917NsFho3YjMR7az6etc6/wXN65NsTOxTFa1oZIsChU1h6aE7SJgzhQlhjceYKY7xWSc6wMX5dK1Uy4WeQdEZKIbDMbSub+yP1zF1jBTlYsgRze+BpL+lv3eD/wXEvilEUf+l39BS3HXwBDwHWyAG78Ee+AQOwQgQ8DN4GrwMXoWfwyqchc0iNAyWOY/BioXfgE4TuQI</latexit>δmal → βδmal
<latexit sha1_base64="SVLAfWw+ZsQa7W5GOoVDFtpN2Y=">ACenicdVBNaxsxFJS3X2n65bTHipiCi2FRWvsJr4FkOPKdRJwGvMk1Zri0jaRXpbx4j9Qf01vTb/pYfKjgtNaAYEw8x7jN7wWiuPjF13kgcPHz1+svN09nzFy9fdfden/mqcUKORaUrd8HBS62sHKNCLS9qJ8FwLc/5fHaP/8unVeV/YarWk4NzK0qlQCM0qx7nHMT8kJqhHYWcpRXGAzots2dmi8QnKuWNOcSgd43SWfdHktZ/3A46FOW9odslI0iGbJs9HlAs5Rt0CNbnM72Ou/yohKNkRaFBu8nGatxGsChElq2u3njZQ3iEuZyEqkFI/0bK5t6fuoFLSsXHwW6Ub9dyOA8X5leJw0gAt/1uL/MmDZaH06Bs3aC04iaobDTFiq6ro4VyUqBeRQLCqfhXKhbgQGAs+FYKN/EGK5eiMgZsEXJeLtuQryN5GZbtHdeIk60rQIeTaMdK/ZG7ydn/TRjafZ10Dti23J3yFuyTz6QjByQI/KFnJIxEeQH+Ul+kevO72Q/+Zh8uhlNOtudN+QWksEfQjGuQ=</latexit><latexit sha1_base64="SVLAfWw+ZsQa7W5GOoVDFtpN2Y=">ACenicdVBNaxsxFJS3X2n65bTHipiCi2FRWvsJr4FkOPKdRJwGvMk1Zri0jaRXpbx4j9Qf01vTb/pYfKjgtNaAYEw8x7jN7wWiuPjF13kgcPHz1+svN09nzFy9fdfden/mqcUKORaUrd8HBS62sHKNCLS9qJ8FwLc/5fHaP/8unVeV/YarWk4NzK0qlQCM0qx7nHMT8kJqhHYWcpRXGAzots2dmi8QnKuWNOcSgd43SWfdHktZ/3A46FOW9odslI0iGbJs9HlAs5Rt0CNbnM72Ou/yohKNkRaFBu8nGatxGsChElq2u3njZQ3iEuZyEqkFI/0bK5t6fuoFLSsXHwW6Ub9dyOA8X5leJw0gAt/1uL/MmDZaH06Bs3aC04iaobDTFiq6ro4VyUqBeRQLCqfhXKhbgQGAs+FYKN/EGK5eiMgZsEXJeLtuQryN5GZbtHdeIk60rQIeTaMdK/ZG7ydn/TRjafZ10Dti23J3yFuyTz6QjByQI/KFnJIxEeQH+Ul+kevO72Q/+Zh8uhlNOtudN+QWksEfQjGuQ=</latexit><latexit sha1_base64="SVLAfWw+ZsQa7W5GOoVDFtpN2Y=">ACenicdVBNaxsxFJS3X2n65bTHipiCi2FRWvsJr4FkOPKdRJwGvMk1Zri0jaRXpbx4j9Qf01vTb/pYfKjgtNaAYEw8x7jN7wWiuPjF13kgcPHz1+svN09nzFy9fdfden/mqcUKORaUrd8HBS62sHKNCLS9qJ8FwLc/5fHaP/8unVeV/YarWk4NzK0qlQCM0qx7nHMT8kJqhHYWcpRXGAzots2dmi8QnKuWNOcSgd43SWfdHktZ/3A46FOW9odslI0iGbJs9HlAs5Rt0CNbnM72Ou/yohKNkRaFBu8nGatxGsChElq2u3njZQ3iEuZyEqkFI/0bK5t6fuoFLSsXHwW6Ub9dyOA8X5leJw0gAt/1uL/MmDZaH06Bs3aC04iaobDTFiq6ro4VyUqBeRQLCqfhXKhbgQGAs+FYKN/EGK5eiMgZsEXJeLtuQryN5GZbtHdeIk60rQIeTaMdK/ZG7ydn/TRjafZ10Dti23J3yFuyTz6QjByQI/KFnJIxEeQH+Ul+kevO72Q/+Zh8uhlNOtudN+QWksEfQjGuQ=</latexit><latexit sha1_base64="SVLAfWw+ZsQa7W5GOoVDFtpN2Y=">ACenicdVBNaxsxFJS3X2n65bTHipiCi2FRWvsJr4FkOPKdRJwGvMk1Zri0jaRXpbx4j9Qf01vTb/pYfKjgtNaAYEw8x7jN7wWiuPjF13kgcPHz1+svN09nzFy9fdfden/mqcUKORaUrd8HBS62sHKNCLS9qJ8FwLc/5fHaP/8unVeV/YarWk4NzK0qlQCM0qx7nHMT8kJqhHYWcpRXGAzots2dmi8QnKuWNOcSgd43SWfdHktZ/3A46FOW9odslI0iGbJs9HlAs5Rt0CNbnM72Ou/yohKNkRaFBu8nGatxGsChElq2u3njZQ3iEuZyEqkFI/0bK5t6fuoFLSsXHwW6Ub9dyOA8X5leJw0gAt/1uL/MmDZaH06Bs3aC04iaobDTFiq6ro4VyUqBeRQLCqfhXKhbgQGAs+FYKN/EGK5eiMgZsEXJeLtuQryN5GZbtHdeIk60rQIeTaMdK/ZG7ydn/TRjafZ10Dti23J3yFuyTz6QjByQI/KFnJIxEeQH+Ul+kevO72Q/+Zh8uhlNOtudN+QWksEfQjGuQ=</latexit>✦ Fashion MNIST data [2] ✦ CNN achieving 91.5% accuracy on test data ✦ Total of 10 agents, all called every time step ✦ Training is stopped when global model achieves above 91% validation accuracy ✦ Adversarial objective: Classify (‘sandal’, class 5) as a ‘sneaker’, class 7
Strategy
Malicious agent’s update computation
Boosting malicious update, no local training
δmal = argminδCross-entropy({xl
m, T l m}nmal l=1 ; wG + δ)
<latexit sha1_base64="J/M0Ent6MdJ4NKeZ70D9owiBcn4=">ACyHicdVFtb9MwEHYyXsZ46+AjQlhUwBAQOVU7VqFJkzYJxKchrdukposcx+ms2U5kO3SR5S/8A34ev4SvOG2BdYKTbD2+585391xWcaYNQj+CcO3GzVu31+9s3L13/8HDzuajY13WitARKXmpTjOsKWeSjgwznJ5WimKRcXqSXey3/MlXqjQr5ZFpKjoReCpZwQg23pV2vieZsElOucEutYmhl8YKzJ2Du3DxwmoqmGzJv5Fuye2rUut3VBpVo3bSmwisDnPCnvpUnHG3x61d+Jz+W7szqxcqeA+JFkxSz/CN/DK16/ThdFqLcz6PcginoDNIyHgxQPNzuwzhCc+uCpR2m8GzJC9JLXwfhGOtxzGqzMQ3bhjh1G0ktaYVJhd4SsceSiyonti5dg6+8J4cFqXyRxo4917NsFho3YjMR7az6etc6/wXN65NsTOxTFa1oZIsChU1h6aE7SJgzhQlhjceYKY7xWSc6wMX5dK1Uy4WeQdEZKIbDMbSub+yP1zF1jBTlYsgRze+BpL+lv3eD/wXEvilEUf+l39BS3HXwBDwHWyAG78Ee+AQOwQgQ8DN4GrwMXoWfwyqchc0iNAyWOY/BioXfgE4TuQI</latexit><latexit sha1_base64="J/M0Ent6MdJ4NKeZ70D9owiBcn4=">ACyHicdVFtb9MwEHYyXsZ46+AjQlhUwBAQOVU7VqFJkzYJxKchrdukposcx+ms2U5kO3SR5S/8A34ev4SvOG2BdYKTbD2+585391xWcaYNQj+CcO3GzVu31+9s3L13/8HDzuajY13WitARKXmpTjOsKWeSjgwznJ5WimKRcXqSXey3/MlXqjQr5ZFpKjoReCpZwQg23pV2vieZsElOucEutYmhl8YKzJ2Du3DxwmoqmGzJv5Fuye2rUut3VBpVo3bSmwisDnPCnvpUnHG3x61d+Jz+W7szqxcqeA+JFkxSz/CN/DK16/ThdFqLcz6PcginoDNIyHgxQPNzuwzhCc+uCpR2m8GzJC9JLXwfhGOtxzGqzMQ3bhjh1G0ktaYVJhd4SsceSiyonti5dg6+8J4cFqXyRxo4917NsFho3YjMR7az6etc6/wXN65NsTOxTFa1oZIsChU1h6aE7SJgzhQlhjceYKY7xWSc6wMX5dK1Uy4WeQdEZKIbDMbSub+yP1zF1jBTlYsgRze+BpL+lv3eD/wXEvilEUf+l39BS3HXwBDwHWyAG78Ee+AQOwQgQ8DN4GrwMXoWfwyqchc0iNAyWOY/BioXfgE4TuQI</latexit><latexit sha1_base64="J/M0Ent6MdJ4NKeZ70D9owiBcn4=">ACyHicdVFtb9MwEHYyXsZ46+AjQlhUwBAQOVU7VqFJkzYJxKchrdukposcx+ms2U5kO3SR5S/8A34ev4SvOG2BdYKTbD2+585391xWcaYNQj+CcO3GzVu31+9s3L13/8HDzuajY13WitARKXmpTjOsKWeSjgwznJ5WimKRcXqSXey3/MlXqjQr5ZFpKjoReCpZwQg23pV2vieZsElOucEutYmhl8YKzJ2Du3DxwmoqmGzJv5Fuye2rUut3VBpVo3bSmwisDnPCnvpUnHG3x61d+Jz+W7szqxcqeA+JFkxSz/CN/DK16/ThdFqLcz6PcginoDNIyHgxQPNzuwzhCc+uCpR2m8GzJC9JLXwfhGOtxzGqzMQ3bhjh1G0ktaYVJhd4SsceSiyonti5dg6+8J4cFqXyRxo4917NsFho3YjMR7az6etc6/wXN65NsTOxTFa1oZIsChU1h6aE7SJgzhQlhjceYKY7xWSc6wMX5dK1Uy4WeQdEZKIbDMbSub+yP1zF1jBTlYsgRze+BpL+lv3eD/wXEvilEUf+l39BS3HXwBDwHWyAG78Ee+AQOwQgQ8DN4GrwMXoWfwyqchc0iNAyWOY/BioXfgE4TuQI</latexit><latexit sha1_base64="J/M0Ent6MdJ4NKeZ70D9owiBcn4=">ACyHicdVFtb9MwEHYyXsZ46+AjQlhUwBAQOVU7VqFJkzYJxKchrdukposcx+ms2U5kO3SR5S/8A34ev4SvOG2BdYKTbD2+585391xWcaYNQj+CcO3GzVu31+9s3L13/8HDzuajY13WitARKXmpTjOsKWeSjgwznJ5WimKRcXqSXey3/MlXqjQr5ZFpKjoReCpZwQg23pV2vieZsElOucEutYmhl8YKzJ2Du3DxwmoqmGzJv5Fuye2rUut3VBpVo3bSmwisDnPCnvpUnHG3x61d+Jz+W7szqxcqeA+JFkxSz/CN/DK16/ThdFqLcz6PcginoDNIyHgxQPNzuwzhCc+uCpR2m8GzJC9JLXwfhGOtxzGqzMQ3bhjh1G0ktaYVJhd4SsceSiyonti5dg6+8J4cFqXyRxo4917NsFho3YjMR7az6etc6/wXN65NsTOxTFa1oZIsChU1h6aE7SJgzhQlhjceYKY7xWSc6wMX5dK1Uy4WeQdEZKIbDMbSub+yP1zF1jBTlYsgRze+BpL+lv3eD/wXEvilEUf+l39BS3HXwBDwHWyAG78Ee+AQOwQgQ8DN4GrwMXoWfwyqchc0iNAyWOY/BioXfgE4TuQI</latexit>δmal → βδmal
<latexit sha1_base64="SVLAfWw+ZsQa7W5GOoVDFtpN2Y=">ACenicdVBNaxsxFJS3X2n65bTHipiCi2FRWvsJr4FkOPKdRJwGvMk1Zri0jaRXpbx4j9Qf01vTb/pYfKjgtNaAYEw8x7jN7wWiuPjF13kgcPHz1+svN09nzFy9fdfden/mqcUKORaUrd8HBS62sHKNCLS9qJ8FwLc/5fHaP/8unVeV/YarWk4NzK0qlQCM0qx7nHMT8kJqhHYWcpRXGAzots2dmi8QnKuWNOcSgd43SWfdHktZ/3A46FOW9odslI0iGbJs9HlAs5Rt0CNbnM72Ou/yohKNkRaFBu8nGatxGsChElq2u3njZQ3iEuZyEqkFI/0bK5t6fuoFLSsXHwW6Ub9dyOA8X5leJw0gAt/1uL/MmDZaH06Bs3aC04iaobDTFiq6ro4VyUqBeRQLCqfhXKhbgQGAs+FYKN/EGK5eiMgZsEXJeLtuQryN5GZbtHdeIk60rQIeTaMdK/ZG7ydn/TRjafZ10Dti23J3yFuyTz6QjByQI/KFnJIxEeQH+Ul+kevO72Q/+Zh8uhlNOtudN+QWksEfQjGuQ=</latexit><latexit sha1_base64="SVLAfWw+ZsQa7W5GOoVDFtpN2Y=">ACenicdVBNaxsxFJS3X2n65bTHipiCi2FRWvsJr4FkOPKdRJwGvMk1Zri0jaRXpbx4j9Qf01vTb/pYfKjgtNaAYEw8x7jN7wWiuPjF13kgcPHz1+svN09nzFy9fdfden/mqcUKORaUrd8HBS62sHKNCLS9qJ8FwLc/5fHaP/8unVeV/YarWk4NzK0qlQCM0qx7nHMT8kJqhHYWcpRXGAzots2dmi8QnKuWNOcSgd43SWfdHktZ/3A46FOW9odslI0iGbJs9HlAs5Rt0CNbnM72Ou/yohKNkRaFBu8nGatxGsChElq2u3njZQ3iEuZyEqkFI/0bK5t6fuoFLSsXHwW6Ub9dyOA8X5leJw0gAt/1uL/MmDZaH06Bs3aC04iaobDTFiq6ro4VyUqBeRQLCqfhXKhbgQGAs+FYKN/EGK5eiMgZsEXJeLtuQryN5GZbtHdeIk60rQIeTaMdK/ZG7ydn/TRjafZ10Dti23J3yFuyTz6QjByQI/KFnJIxEeQH+Ul+kevO72Q/+Zh8uhlNOtudN+QWksEfQjGuQ=</latexit><latexit sha1_base64="SVLAfWw+ZsQa7W5GOoVDFtpN2Y=">ACenicdVBNaxsxFJS3X2n65bTHipiCi2FRWvsJr4FkOPKdRJwGvMk1Zri0jaRXpbx4j9Qf01vTb/pYfKjgtNaAYEw8x7jN7wWiuPjF13kgcPHz1+svN09nzFy9fdfden/mqcUKORaUrd8HBS62sHKNCLS9qJ8FwLc/5fHaP/8unVeV/YarWk4NzK0qlQCM0qx7nHMT8kJqhHYWcpRXGAzots2dmi8QnKuWNOcSgd43SWfdHktZ/3A46FOW9odslI0iGbJs9HlAs5Rt0CNbnM72Ou/yohKNkRaFBu8nGatxGsChElq2u3njZQ3iEuZyEqkFI/0bK5t6fuoFLSsXHwW6Ub9dyOA8X5leJw0gAt/1uL/MmDZaH06Bs3aC04iaobDTFiq6ro4VyUqBeRQLCqfhXKhbgQGAs+FYKN/EGK5eiMgZsEXJeLtuQryN5GZbtHdeIk60rQIeTaMdK/ZG7ydn/TRjafZ10Dti23J3yFuyTz6QjByQI/KFnJIxEeQH+Ul+kevO72Q/+Zh8uhlNOtudN+QWksEfQjGuQ=</latexit><latexit sha1_base64="SVLAfWw+ZsQa7W5GOoVDFtpN2Y=">ACenicdVBNaxsxFJS3X2n65bTHipiCi2FRWvsJr4FkOPKdRJwGvMk1Zri0jaRXpbx4j9Qf01vTb/pYfKjgtNaAYEw8x7jN7wWiuPjF13kgcPHz1+svN09nzFy9fdfden/mqcUKORaUrd8HBS62sHKNCLS9qJ8FwLc/5fHaP/8unVeV/YarWk4NzK0qlQCM0qx7nHMT8kJqhHYWcpRXGAzots2dmi8QnKuWNOcSgd43SWfdHktZ/3A46FOW9odslI0iGbJs9HlAs5Rt0CNbnM72Ou/yohKNkRaFBu8nGatxGsChElq2u3njZQ3iEuZyEqkFI/0bK5t6fuoFLSsXHwW6Ub9dyOA8X5leJw0gAt/1uL/MmDZaH06Bs3aC04iaobDTFiq6ro4VyUqBeRQLCqfhXKhbgQGAs+FYKN/EGK5eiMgZsEXJeLtuQryN5GZbtHdeIk60rQIeTaMdK/ZG7ydn/TRjafZ10Dti23J3yFuyTz6QjByQI/KFnJIxEeQH+Ul+kevO72Q/+Zh8uhlNOtudN+QWksEfQjGuQ=</latexit>5 epochs
Takeaways
global model
0.2 0.4 0.6 0.8 1 2 4 6 8 10 12 20 40 60 80 100
Confidence Classification accuracy Time
Validation Accuracy Global Malicious objective confidence (5→7) Global Validation Accuracy Malicious (Stealth)
Takeaways
malicious agents are very different
benign one Takeaways
global model
0.2 0.4 0.6 0.8 1 2 4 6 8 10 12 20 40 60 80 100
Confidence Classification accuracy Time
Validation Accuracy Global Malicious objective confidence (5→7) Global Validation Accuracy Malicious (Stealth)
Strategy Malicious agent’s update computation Alternating minimization of benign and malicious
constraints
Strategy Malicious agent’s update computation Alternating minimization of benign and malicious
constraints
δ0
mal = argminδCross-entropy({xl m, T l m}nmal l=1 ; wG + δ)
<latexit sha1_base64="+1V7VtyagHXve5ilOYiCbnVH9U=">ACyXicdVFtb9MwEHbC2xhvHXxEAosKrQiInKqFVWjSpE0CiS9DWrdJTRc5rtNZs51gO7TF8if+Af+Of8JHnDbAOsFJth7fc+e7ey4rOdMGoR9BeO36jZu3Nm5v3rl7/6D1tbDY1UitAhKXihTjOsKWeSDg0znJ6WimKRcXqSXezX/MkXqjQr5JFZlHQs8FSynBFsvCtfU8yYZMJ5Qa7dQmhs6NFZg7B3fh6oXVDpPk31DXcviq0fk2lUW5cJ3EJgKb8y3c5eKM/7qL4Tn8t3Y3dm5VoF9y7J8ln6Hr6El75+kbaKELdnX6vC1HU7aNBPCgj+LBmx6MI7S0NmjsMN0KniaTglTC90E41noUo9KMfeOGEU7dZlJpWmJygad05KHEguqxXYrn4HPvmcC8UP5IA5feyxkWC60XIvOR9Wz6Klc7/8WNKpPvjC2TZWoJKtCecWhKWC9CThihLDFx5gopjvFZJzrDAxfl9rVTLhZ5B0RgohsJzYWjb3R+qZu8IKctCwBHN74Gkv6W/d4P/BcTeKUR/6rX3UCPuBngMnoEOiMFbsAc+gEMwBAT8DJ4E20En/Bh+Dufh1VoGDQ5j8Cahd9+Ab6w5Dk=</latexit><latexit sha1_base64="+1V7VtyagHXve5ilOYiCbnVH9U=">ACyXicdVFtb9MwEHbC2xhvHXxEAosKrQiInKqFVWjSpE0CiS9DWrdJTRc5rtNZs51gO7TF8if+Af+Of8JHnDbAOsFJth7fc+e7ey4rOdMGoR9BeO36jZu3Nm5v3rl7/6D1tbDY1UitAhKXihTjOsKWeSDg0znJ6WimKRcXqSXezX/MkXqjQr5JFZlHQs8FSynBFsvCtfU8yYZMJ5Qa7dQmhs6NFZg7B3fh6oXVDpPk31DXcviq0fk2lUW5cJ3EJgKb8y3c5eKM/7qL4Tn8t3Y3dm5VoF9y7J8ln6Hr6El75+kbaKELdnX6vC1HU7aNBPCgj+LBmx6MI7S0NmjsMN0KniaTglTC90E41noUo9KMfeOGEU7dZlJpWmJygad05KHEguqxXYrn4HPvmcC8UP5IA5feyxkWC60XIvOR9Wz6Klc7/8WNKpPvjC2TZWoJKtCecWhKWC9CThihLDFx5gopjvFZJzrDAxfl9rVTLhZ5B0RgohsJzYWjb3R+qZu8IKctCwBHN74Gkv6W/d4P/BcTeKUR/6rX3UCPuBngMnoEOiMFbsAc+gEMwBAT8DJ4E20En/Bh+Dufh1VoGDQ5j8Cahd9+Ab6w5Dk=</latexit><latexit sha1_base64="+1V7VtyagHXve5ilOYiCbnVH9U=">ACyXicdVFtb9MwEHbC2xhvHXxEAosKrQiInKqFVWjSpE0CiS9DWrdJTRc5rtNZs51gO7TF8if+Af+Of8JHnDbAOsFJth7fc+e7ey4rOdMGoR9BeO36jZu3Nm5v3rl7/6D1tbDY1UitAhKXihTjOsKWeSDg0znJ6WimKRcXqSXezX/MkXqjQr5JFZlHQs8FSynBFsvCtfU8yYZMJ5Qa7dQmhs6NFZg7B3fh6oXVDpPk31DXcviq0fk2lUW5cJ3EJgKb8y3c5eKM/7qL4Tn8t3Y3dm5VoF9y7J8ln6Hr6El75+kbaKELdnX6vC1HU7aNBPCgj+LBmx6MI7S0NmjsMN0KniaTglTC90E41noUo9KMfeOGEU7dZlJpWmJygad05KHEguqxXYrn4HPvmcC8UP5IA5feyxkWC60XIvOR9Wz6Klc7/8WNKpPvjC2TZWoJKtCecWhKWC9CThihLDFx5gopjvFZJzrDAxfl9rVTLhZ5B0RgohsJzYWjb3R+qZu8IKctCwBHN74Gkv6W/d4P/BcTeKUR/6rX3UCPuBngMnoEOiMFbsAc+gEMwBAT8DJ4E20En/Bh+Dufh1VoGDQ5j8Cahd9+Ab6w5Dk=</latexit><latexit sha1_base64="+1V7VtyagHXve5ilOYiCbnVH9U=">ACyXicdVFtb9MwEHbC2xhvHXxEAosKrQiInKqFVWjSpE0CiS9DWrdJTRc5rtNZs51gO7TF8if+Af+Of8JHnDbAOsFJth7fc+e7ey4rOdMGoR9BeO36jZu3Nm5v3rl7/6D1tbDY1UitAhKXihTjOsKWeSDg0znJ6WimKRcXqSXezX/MkXqjQr5JFZlHQs8FSynBFsvCtfU8yYZMJ5Qa7dQmhs6NFZg7B3fh6oXVDpPk31DXcviq0fk2lUW5cJ3EJgKb8y3c5eKM/7qL4Tn8t3Y3dm5VoF9y7J8ln6Hr6El75+kbaKELdnX6vC1HU7aNBPCgj+LBmx6MI7S0NmjsMN0KniaTglTC90E41noUo9KMfeOGEU7dZlJpWmJygad05KHEguqxXYrn4HPvmcC8UP5IA5feyxkWC60XIvOR9Wz6Klc7/8WNKpPvjC2TZWoJKtCecWhKWC9CThihLDFx5gopjvFZJzrDAxfl9rVTLhZ5B0RgohsJzYWjb3R+qZu8IKctCwBHN74Gkv6W/d4P/BcTeKUR/6rX3UCPuBngMnoEOiMFbsAc+gEMwBAT8DJ4E20En/Bh+Dufh1VoGDQ5j8Cahd9+Ab6w5Dk=</latexit>Malicious Objective
Strategy Malicious agent’s update computation Alternating minimization of benign and malicious
constraints
δ0
mal → βδ0 mal
<latexit sha1_base64="zVk37AnjomAR2N02F+4MmPeucUs=">ACfHicdVBdixMxFE3Hr3X96uqjDwarKIhDprTr9m3BFXxcwe4udEq5yWTasElmSO5YS5hf5K/xUf0vYtqt4C7ugcDhnHs5uYfXWnlk7EcnuXHz1u07O3d3791/8PBRd+/xia8aJ+RYVLpyZxy81MrKMSrU8qx2EgzX8pSfv1/7p1+k86qyn3FVy6mBuVWlEoBRmnU/5NyEvJAaoX01CznKrxgM6LaluVPzBYJz1ZLmXCLQa2dn3R5LWf9gOhTlvaHbJSNIhmybLQ/oFnKNuiRLY5ne51neVGJxkiLQoP3k4zVOA3gUAkt2928bIGcQ5zOYnUgpF+Gjb3tvRlVApaVi4+i3Sj/rsRwHi/MjxOGsCFv+qtxf95kwbLg2lQtm5QWnERVDaYkX5dFCOSlQryIB4VT8KxULcCAwVnwphZt4g5VLURkDtg5L5dtyNeRvAzL9oprxNHWFaDUbRjpX97o9eTk36asT7NOgdsm25O+QpeU5ek4y8I4fkIzkmYyLIN/Kd/CS/Or+TF8mb5O3FaNLZ7jwhl5Ds/wE1C8cb</latexit><latexit sha1_base64="zVk37AnjomAR2N02F+4MmPeucUs=">ACfHicdVBdixMxFE3Hr3X96uqjDwarKIhDprTr9m3BFXxcwe4udEq5yWTasElmSO5YS5hf5K/xUf0vYtqt4C7ugcDhnHs5uYfXWnlk7EcnuXHz1u07O3d3791/8PBRd+/xia8aJ+RYVLpyZxy81MrKMSrU8qx2EgzX8pSfv1/7p1+k86qyn3FVy6mBuVWlEoBRmnU/5NyEvJAaoX01CznKrxgM6LaluVPzBYJz1ZLmXCLQa2dn3R5LWf9gOhTlvaHbJSNIhmybLQ/oFnKNuiRLY5ne51neVGJxkiLQoP3k4zVOA3gUAkt2928bIGcQ5zOYnUgpF+Gjb3tvRlVApaVi4+i3Sj/rsRwHi/MjxOGsCFv+qtxf95kwbLg2lQtm5QWnERVDaYkX5dFCOSlQryIB4VT8KxULcCAwVnwphZt4g5VLURkDtg5L5dtyNeRvAzL9oprxNHWFaDUbRjpX97o9eTk36asT7NOgdsm25O+QpeU5ek4y8I4fkIzkmYyLIN/Kd/CS/Or+TF8mb5O3FaNLZ7jwhl5Ds/wE1C8cb</latexit><latexit sha1_base64="zVk37AnjomAR2N02F+4MmPeucUs=">ACfHicdVBdixMxFE3Hr3X96uqjDwarKIhDprTr9m3BFXxcwe4udEq5yWTasElmSO5YS5hf5K/xUf0vYtqt4C7ugcDhnHs5uYfXWnlk7EcnuXHz1u07O3d3791/8PBRd+/xia8aJ+RYVLpyZxy81MrKMSrU8qx2EgzX8pSfv1/7p1+k86qyn3FVy6mBuVWlEoBRmnU/5NyEvJAaoX01CznKrxgM6LaluVPzBYJz1ZLmXCLQa2dn3R5LWf9gOhTlvaHbJSNIhmybLQ/oFnKNuiRLY5ne51neVGJxkiLQoP3k4zVOA3gUAkt2928bIGcQ5zOYnUgpF+Gjb3tvRlVApaVi4+i3Sj/rsRwHi/MjxOGsCFv+qtxf95kwbLg2lQtm5QWnERVDaYkX5dFCOSlQryIB4VT8KxULcCAwVnwphZt4g5VLURkDtg5L5dtyNeRvAzL9oprxNHWFaDUbRjpX97o9eTk36asT7NOgdsm25O+QpeU5ek4y8I4fkIzkmYyLIN/Kd/CS/Or+TF8mb5O3FaNLZ7jwhl5Ds/wE1C8cb</latexit><latexit sha1_base64="zVk37AnjomAR2N02F+4MmPeucUs=">ACfHicdVBdixMxFE3Hr3X96uqjDwarKIhDprTr9m3BFXxcwe4udEq5yWTasElmSO5YS5hf5K/xUf0vYtqt4C7ugcDhnHs5uYfXWnlk7EcnuXHz1u07O3d3791/8PBRd+/xia8aJ+RYVLpyZxy81MrKMSrU8qx2EgzX8pSfv1/7p1+k86qyn3FVy6mBuVWlEoBRmnU/5NyEvJAaoX01CznKrxgM6LaluVPzBYJz1ZLmXCLQa2dn3R5LWf9gOhTlvaHbJSNIhmybLQ/oFnKNuiRLY5ne51neVGJxkiLQoP3k4zVOA3gUAkt2928bIGcQ5zOYnUgpF+Gjb3tvRlVApaVi4+i3Sj/rsRwHi/MjxOGsCFv+qtxf95kwbLg2lQtm5QWnERVDaYkX5dFCOSlQryIB4VT8KxULcCAwVnwphZt4g5VLURkDtg5L5dtyNeRvAzL9oprxNHWFaDUbRjpX97o9eTk36asT7NOgdsm25O+QpeU5ek4y8I4fkIzkmYyLIN/Kd/CS/Or+TF8mb5O3FaNLZ7jwhl5Ds/wE1C8cb</latexit>δ0
mal = argminδCross-entropy({xl m, T l m}nmal l=1 ; wG + δ)
<latexit sha1_base64="+1V7VtyagHXve5ilOYiCbnVH9U=">ACyXicdVFtb9MwEHbC2xhvHXxEAosKrQiInKqFVWjSpE0CiS9DWrdJTRc5rtNZs51gO7TF8if+Af+Of8JHnDbAOsFJth7fc+e7ey4rOdMGoR9BeO36jZu3Nm5v3rl7/6D1tbDY1UitAhKXihTjOsKWeSDg0znJ6WimKRcXqSXezX/MkXqjQr5JFZlHQs8FSynBFsvCtfU8yYZMJ5Qa7dQmhs6NFZg7B3fh6oXVDpPk31DXcviq0fk2lUW5cJ3EJgKb8y3c5eKM/7qL4Tn8t3Y3dm5VoF9y7J8ln6Hr6El75+kbaKELdnX6vC1HU7aNBPCgj+LBmx6MI7S0NmjsMN0KniaTglTC90E41noUo9KMfeOGEU7dZlJpWmJygad05KHEguqxXYrn4HPvmcC8UP5IA5feyxkWC60XIvOR9Wz6Klc7/8WNKpPvjC2TZWoJKtCecWhKWC9CThihLDFx5gopjvFZJzrDAxfl9rVTLhZ5B0RgohsJzYWjb3R+qZu8IKctCwBHN74Gkv6W/d4P/BcTeKUR/6rX3UCPuBngMnoEOiMFbsAc+gEMwBAT8DJ4E20En/Bh+Dufh1VoGDQ5j8Cahd9+Ab6w5Dk=</latexit><latexit sha1_base64="+1V7VtyagHXve5ilOYiCbnVH9U=">ACyXicdVFtb9MwEHbC2xhvHXxEAosKrQiInKqFVWjSpE0CiS9DWrdJTRc5rtNZs51gO7TF8if+Af+Of8JHnDbAOsFJth7fc+e7ey4rOdMGoR9BeO36jZu3Nm5v3rl7/6D1tbDY1UitAhKXihTjOsKWeSDg0znJ6WimKRcXqSXezX/MkXqjQr5JFZlHQs8FSynBFsvCtfU8yYZMJ5Qa7dQmhs6NFZg7B3fh6oXVDpPk31DXcviq0fk2lUW5cJ3EJgKb8y3c5eKM/7qL4Tn8t3Y3dm5VoF9y7J8ln6Hr6El75+kbaKELdnX6vC1HU7aNBPCgj+LBmx6MI7S0NmjsMN0KniaTglTC90E41noUo9KMfeOGEU7dZlJpWmJygad05KHEguqxXYrn4HPvmcC8UP5IA5feyxkWC60XIvOR9Wz6Klc7/8WNKpPvjC2TZWoJKtCecWhKWC9CThihLDFx5gopjvFZJzrDAxfl9rVTLhZ5B0RgohsJzYWjb3R+qZu8IKctCwBHN74Gkv6W/d4P/BcTeKUR/6rX3UCPuBngMnoEOiMFbsAc+gEMwBAT8DJ4E20En/Bh+Dufh1VoGDQ5j8Cahd9+Ab6w5Dk=</latexit><latexit sha1_base64="+1V7VtyagHXve5ilOYiCbnVH9U=">ACyXicdVFtb9MwEHbC2xhvHXxEAosKrQiInKqFVWjSpE0CiS9DWrdJTRc5rtNZs51gO7TF8if+Af+Of8JHnDbAOsFJth7fc+e7ey4rOdMGoR9BeO36jZu3Nm5v3rl7/6D1tbDY1UitAhKXihTjOsKWeSDg0znJ6WimKRcXqSXezX/MkXqjQr5JFZlHQs8FSynBFsvCtfU8yYZMJ5Qa7dQmhs6NFZg7B3fh6oXVDpPk31DXcviq0fk2lUW5cJ3EJgKb8y3c5eKM/7qL4Tn8t3Y3dm5VoF9y7J8ln6Hr6El75+kbaKELdnX6vC1HU7aNBPCgj+LBmx6MI7S0NmjsMN0KniaTglTC90E41noUo9KMfeOGEU7dZlJpWmJygad05KHEguqxXYrn4HPvmcC8UP5IA5feyxkWC60XIvOR9Wz6Klc7/8WNKpPvjC2TZWoJKtCecWhKWC9CThihLDFx5gopjvFZJzrDAxfl9rVTLhZ5B0RgohsJzYWjb3R+qZu8IKctCwBHN74Gkv6W/d4P/BcTeKUR/6rX3UCPuBngMnoEOiMFbsAc+gEMwBAT8DJ4E20En/Bh+Dufh1VoGDQ5j8Cahd9+Ab6w5Dk=</latexit><latexit sha1_base64="+1V7VtyagHXve5ilOYiCbnVH9U=">ACyXicdVFtb9MwEHbC2xhvHXxEAosKrQiInKqFVWjSpE0CiS9DWrdJTRc5rtNZs51gO7TF8if+Af+Of8JHnDbAOsFJth7fc+e7ey4rOdMGoR9BeO36jZu3Nm5v3rl7/6D1tbDY1UitAhKXihTjOsKWeSDg0znJ6WimKRcXqSXezX/MkXqjQr5JFZlHQs8FSynBFsvCtfU8yYZMJ5Qa7dQmhs6NFZg7B3fh6oXVDpPk31DXcviq0fk2lUW5cJ3EJgKb8y3c5eKM/7qL4Tn8t3Y3dm5VoF9y7J8ln6Hr6El75+kbaKELdnX6vC1HU7aNBPCgj+LBmx6MI7S0NmjsMN0KniaTglTC90E41noUo9KMfeOGEU7dZlJpWmJygad05KHEguqxXYrn4HPvmcC8UP5IA5feyxkWC60XIvOR9Wz6Klc7/8WNKpPvjC2TZWoJKtCecWhKWC9CThihLDFx5gopjvFZJzrDAxfl9rVTLhZ5B0RgohsJzYWjb3R+qZu8IKctCwBHN74Gkv6W/d4P/BcTeKUR/6rX3UCPuBngMnoEOiMFbsAc+gEMwBAT8DJ4E20En/Bh+Dufh1VoGDQ5j8Cahd9+Ab6w5Dk=</latexit>Malicious Objective
Strategy Malicious agent’s update computation Alternating minimization of benign and malicious
constraints
δ0
mal → βδ0 mal
<latexit sha1_base64="zVk37AnjomAR2N02F+4MmPeucUs=">ACfHicdVBdixMxFE3Hr3X96uqjDwarKIhDprTr9m3BFXxcwe4udEq5yWTasElmSO5YS5hf5K/xUf0vYtqt4C7ugcDhnHs5uYfXWnlk7EcnuXHz1u07O3d3791/8PBRd+/xia8aJ+RYVLpyZxy81MrKMSrU8qx2EgzX8pSfv1/7p1+k86qyn3FVy6mBuVWlEoBRmnU/5NyEvJAaoX01CznKrxgM6LaluVPzBYJz1ZLmXCLQa2dn3R5LWf9gOhTlvaHbJSNIhmybLQ/oFnKNuiRLY5ne51neVGJxkiLQoP3k4zVOA3gUAkt2928bIGcQ5zOYnUgpF+Gjb3tvRlVApaVi4+i3Sj/rsRwHi/MjxOGsCFv+qtxf95kwbLg2lQtm5QWnERVDaYkX5dFCOSlQryIB4VT8KxULcCAwVnwphZt4g5VLURkDtg5L5dtyNeRvAzL9oprxNHWFaDUbRjpX97o9eTk36asT7NOgdsm25O+QpeU5ek4y8I4fkIzkmYyLIN/Kd/CS/Or+TF8mb5O3FaNLZ7jwhl5Ds/wE1C8cb</latexit><latexit sha1_base64="zVk37AnjomAR2N02F+4MmPeucUs=">ACfHicdVBdixMxFE3Hr3X96uqjDwarKIhDprTr9m3BFXxcwe4udEq5yWTasElmSO5YS5hf5K/xUf0vYtqt4C7ugcDhnHs5uYfXWnlk7EcnuXHz1u07O3d3791/8PBRd+/xia8aJ+RYVLpyZxy81MrKMSrU8qx2EgzX8pSfv1/7p1+k86qyn3FVy6mBuVWlEoBRmnU/5NyEvJAaoX01CznKrxgM6LaluVPzBYJz1ZLmXCLQa2dn3R5LWf9gOhTlvaHbJSNIhmybLQ/oFnKNuiRLY5ne51neVGJxkiLQoP3k4zVOA3gUAkt2928bIGcQ5zOYnUgpF+Gjb3tvRlVApaVi4+i3Sj/rsRwHi/MjxOGsCFv+qtxf95kwbLg2lQtm5QWnERVDaYkX5dFCOSlQryIB4VT8KxULcCAwVnwphZt4g5VLURkDtg5L5dtyNeRvAzL9oprxNHWFaDUbRjpX97o9eTk36asT7NOgdsm25O+QpeU5ek4y8I4fkIzkmYyLIN/Kd/CS/Or+TF8mb5O3FaNLZ7jwhl5Ds/wE1C8cb</latexit><latexit sha1_base64="zVk37AnjomAR2N02F+4MmPeucUs=">ACfHicdVBdixMxFE3Hr3X96uqjDwarKIhDprTr9m3BFXxcwe4udEq5yWTasElmSO5YS5hf5K/xUf0vYtqt4C7ugcDhnHs5uYfXWnlk7EcnuXHz1u07O3d3791/8PBRd+/xia8aJ+RYVLpyZxy81MrKMSrU8qx2EgzX8pSfv1/7p1+k86qyn3FVy6mBuVWlEoBRmnU/5NyEvJAaoX01CznKrxgM6LaluVPzBYJz1ZLmXCLQa2dn3R5LWf9gOhTlvaHbJSNIhmybLQ/oFnKNuiRLY5ne51neVGJxkiLQoP3k4zVOA3gUAkt2928bIGcQ5zOYnUgpF+Gjb3tvRlVApaVi4+i3Sj/rsRwHi/MjxOGsCFv+qtxf95kwbLg2lQtm5QWnERVDaYkX5dFCOSlQryIB4VT8KxULcCAwVnwphZt4g5VLURkDtg5L5dtyNeRvAzL9oprxNHWFaDUbRjpX97o9eTk36asT7NOgdsm25O+QpeU5ek4y8I4fkIzkmYyLIN/Kd/CS/Or+TF8mb5O3FaNLZ7jwhl5Ds/wE1C8cb</latexit><latexit sha1_base64="zVk37AnjomAR2N02F+4MmPeucUs=">ACfHicdVBdixMxFE3Hr3X96uqjDwarKIhDprTr9m3BFXxcwe4udEq5yWTasElmSO5YS5hf5K/xUf0vYtqt4C7ugcDhnHs5uYfXWnlk7EcnuXHz1u07O3d3791/8PBRd+/xia8aJ+RYVLpyZxy81MrKMSrU8qx2EgzX8pSfv1/7p1+k86qyn3FVy6mBuVWlEoBRmnU/5NyEvJAaoX01CznKrxgM6LaluVPzBYJz1ZLmXCLQa2dn3R5LWf9gOhTlvaHbJSNIhmybLQ/oFnKNuiRLY5ne51neVGJxkiLQoP3k4zVOA3gUAkt2928bIGcQ5zOYnUgpF+Gjb3tvRlVApaVi4+i3Sj/rsRwHi/MjxOGsCFv+qtxf95kwbLg2lQtm5QWnERVDaYkX5dFCOSlQryIB4VT8KxULcCAwVnwphZt4g5VLURkDtg5L5dtyNeRvAzL9oprxNHWFaDUbRjpX97o9eTk36asT7NOgdsm25O+QpeU5ek4y8I4fkIzkmYyLIN/Kd/CS/Or+TF8mb5O3FaNLZ7jwhl5Ds/wE1C8cb</latexit>δ00
mal = argminδ Cross-entropy
m, yi m}n i=1; wG + βδ0 mal + δ
2
<latexit sha1_base64="bpGqatx5D7OXRuiowl4CsCBvZi8=">ADfnicfVJb9MwGHVWLqPcNnjkxaKCbCVpNpgFZpUGBK8IZEu0l1GxzXa3FdrBd2uL5F/DA70P8GZx2Ky23T3J8dM6xP8fHSZ4xbcLwe7BSunT5ytXVa+XrN27eur2fqel5VAR2iQyk+okwZpmTNCmYSajJ7mimCcZPU5ODwv9+DNVmknxwUxy2uG4L1jKCDaeitd+oIRb1KOZwW5jI0aGjo3lOHPwACKs+pyJ2C543MxqKTWO1QYJfOJgyijqdlE3piOY95l25Pi1xs2UHkula4514axa/hY4gSajBcbOsbzNu6qWOuQaRYf2C2ClYNJERnC+LOAr7Yg0ih/SHP4lq3Fq9VwmpY29/brcGwWtsL61Hdg70wqj/dhVE1nFalsfXty0cAwFG8HnxFPUmG3P8YybDW7SjMTcdiZRjJqCujoaY5Jqe4T9seCsyp7thpCg4+8EwPplL5IQycsosrLOZaT3jinRybgf5dK8i/ae2hSfc7lol8aKgs0bpMINGwiJS2GOKEpNPMBEMX9WSAZYWJ8GUk6IhIzrHoWdRy7ahjUdEjSW0lcm5Z9yG5uTz6Ux3/UseF+or6e1L0rafe5VRhI9UjO3032FvP5/ZmJjZ/Lx0Hwl3Pr6LjOC/QatWjTx+H1UaL8GsVsE9cB9sg8Aw3wBhyBJiDBi6Af5MGnEig9LO2UnsysK8H5mrtgqUr7PwG5wCqW</latexit><latexit sha1_base64="o3NR/rwYsUwyoLX4pYQ6qUzsbFs=">ADfnicfVLdbtMwGHUWfsb42+CSG4sKtgErSbXBJjRpMCS4QyJdpPqNnJcp7UW28F2WIvnJ+CW56Ad0K8DE67lZa/T3J8dM6xP8fHaZEzbaLoe7AQXrh46fLilaWr167fuLm8cqulZakIbRKZS3WUYk1zJmjTMJPTo0JRzNOcHqbH+5V+JEqzaR4b0YF7XDcFyxjBtPJcs/UMot6tHcYLe6miBDh8ZynDu4CxFWfc5EYmc8buLYV1LrDSqMksXIQZTzKwhb8yGCe+yR6Pqi1xi2W7sula4Z146SV7BhxCl1GA429Y3mLZ1Y8dUg0ix/sCsV6waSIhOZ8SNGXy+B5FC+0OeJo1uI1muRfWosb212YBRvbEV7cQ7HmxF8c6TRjXo3HV9ta/fCoWv309SFaCz6gnScn9j5Eca92Oo8J0LFaGkZy6JVRqWmByjPu07aHAnOqOHafg4D3P9GAmlR/CwDE7u8JirvWIp97JsRno37WK/JvWLk23bFMFKWhgkwaZWUOjYRVpLDHFCUmH3mAiWL+rJAMsMLE+OCXkKAnRHKORc+ilmvHYuqHmlma7Fz87oPyU3lkz/V4S91WKkvqb8nRd946m1BFTZSPbDjd4O9Wz+n42Jic3Pc/eRcufjO8I/hu0GvXY43dxbe8FmNQiuAPugjUQg6dgD7wGB6AJSPA86AdF8CE4f1wI3w8sS4EZ2tug7kKt38Cet0r7A=</latexit><latexit sha1_base64="o3NR/rwYsUwyoLX4pYQ6qUzsbFs=">ADfnicfVLdbtMwGHUWfsb42+CSG4sKtgErSbXBJjRpMCS4QyJdpPqNnJcp7UW28F2WIvnJ+CW56Ad0K8DE67lZa/T3J8dM6xP8fHaZEzbaLoe7AQXrh46fLilaWr167fuLm8cqulZakIbRKZS3WUYk1zJmjTMJPTo0JRzNOcHqbH+5V+JEqzaR4b0YF7XDcFyxjBtPJcs/UMot6tHcYLe6miBDh8ZynDu4CxFWfc5EYmc8buLYV1LrDSqMksXIQZTzKwhb8yGCe+yR6Pqi1xi2W7sula4Z146SV7BhxCl1GA429Y3mLZ1Y8dUg0ix/sCsV6waSIhOZ8SNGXy+B5FC+0OeJo1uI1muRfWosb212YBRvbEV7cQ7HmxF8c6TRjXo3HV9ta/fCoWv309SFaCz6gnScn9j5Eca92Oo8J0LFaGkZy6JVRqWmByjPu07aHAnOqOHafg4D3P9GAmlR/CwDE7u8JirvWIp97JsRno37WK/JvWLk23bFMFKWhgkwaZWUOjYRVpLDHFCUmH3mAiWL+rJAMsMLE+OCXkKAnRHKORc+ilmvHYuqHmlma7Fz87oPyU3lkz/V4S91WKkvqb8nRd946m1BFTZSPbDjd4O9Wz+n42Jic3Pc/eRcufjO8I/hu0GvXY43dxbe8FmNQiuAPugjUQg6dgD7wGB6AJSPA86AdF8CE4f1wI3w8sS4EZ2tug7kKt38Cet0r7A=</latexit><latexit sha1_base64="xa40SpmTZi3T5MqG/LGuh2EwYQ=">ADfnicfVJb9MwGHUWLmPcOnjkxaKCDdhKEq2wCk0aDAleENiF6nuIsd1WmuxHWyHtfL8C/iFiD+D03aj5fZJjo/Ofbn+DgrC6ZNFH0PlsIrV69dX76xcvPW7Tt3G6v3DrWsFKEHRBZSHWdY04IJemCYKehxqSjmWUGPstO9Wj/6SpVmUnw245L2OB4IljOCjafSxg+UcYv6tDYra2lyNCRsRwXDu5AhNWAM5HaOY+bOvaU1HqTCqNkOXYQFTQ368gb81HKT9jGuP4il1q2E7sTK9wrL52l7+AziDJqMJxv6xtctnUTx6UGkWKDoXlSs2oITqfEzfn8MUeRArtD3meJidJ2mhGrSjZbm8lMGol7agTdzxoR3HnxRaMW9GkmBW+lq8A31Jam4/zFSYK27cVSansXKMFJQt4IqTUtMTvGAdj0UmFPds5MUHzkmT7MpfJDGDh51dYzLUe8w7OTZD/btWk3/TupXJt3uWibIyVJBpo7wqoJGwjhT2maLEFGMPMFHMnxWSIVaYGB/8ChL0jEjOsehbdOi6c+iukeW2bs3KLuQ3KX8tmf6uiXOqrVt9Tfk6IfPWxpAobqZ7aybvB3jqb/2djYmrz8J9ZNz5+C4ygv8Gh0kr9vhT3Nx9MwtyGTwAD8E6iMFLsAveg31wAEjwOhgEZfAlBOHjcDN8PrUuBbM198FChds/AfGtKMQ=</latexit>Benign Objective Distance Constraint
δ0
mal = argminδCross-entropy({xl m, T l m}nmal l=1 ; wG + δ)
<latexit sha1_base64="+1V7VtyagHXve5ilOYiCbnVH9U=">ACyXicdVFtb9MwEHbC2xhvHXxEAosKrQiInKqFVWjSpE0CiS9DWrdJTRc5rtNZs51gO7TF8if+Af+Of8JHnDbAOsFJth7fc+e7ey4rOdMGoR9BeO36jZu3Nm5v3rl7/6D1tbDY1UitAhKXihTjOsKWeSDg0znJ6WimKRcXqSXezX/MkXqjQr5JFZlHQs8FSynBFsvCtfU8yYZMJ5Qa7dQmhs6NFZg7B3fh6oXVDpPk31DXcviq0fk2lUW5cJ3EJgKb8y3c5eKM/7qL4Tn8t3Y3dm5VoF9y7J8ln6Hr6El75+kbaKELdnX6vC1HU7aNBPCgj+LBmx6MI7S0NmjsMN0KniaTglTC90E41noUo9KMfeOGEU7dZlJpWmJygad05KHEguqxXYrn4HPvmcC8UP5IA5feyxkWC60XIvOR9Wz6Klc7/8WNKpPvjC2TZWoJKtCecWhKWC9CThihLDFx5gopjvFZJzrDAxfl9rVTLhZ5B0RgohsJzYWjb3R+qZu8IKctCwBHN74Gkv6W/d4P/BcTeKUR/6rX3UCPuBngMnoEOiMFbsAc+gEMwBAT8DJ4E20En/Bh+Dufh1VoGDQ5j8Cahd9+Ab6w5Dk=</latexit><latexit sha1_base64="+1V7VtyagHXve5ilOYiCbnVH9U=">ACyXicdVFtb9MwEHbC2xhvHXxEAosKrQiInKqFVWjSpE0CiS9DWrdJTRc5rtNZs51gO7TF8if+Af+Of8JHnDbAOsFJth7fc+e7ey4rOdMGoR9BeO36jZu3Nm5v3rl7/6D1tbDY1UitAhKXihTjOsKWeSDg0znJ6WimKRcXqSXezX/MkXqjQr5JFZlHQs8FSynBFsvCtfU8yYZMJ5Qa7dQmhs6NFZg7B3fh6oXVDpPk31DXcviq0fk2lUW5cJ3EJgKb8y3c5eKM/7qL4Tn8t3Y3dm5VoF9y7J8ln6Hr6El75+kbaKELdnX6vC1HU7aNBPCgj+LBmx6MI7S0NmjsMN0KniaTglTC90E41noUo9KMfeOGEU7dZlJpWmJygad05KHEguqxXYrn4HPvmcC8UP5IA5feyxkWC60XIvOR9Wz6Klc7/8WNKpPvjC2TZWoJKtCecWhKWC9CThihLDFx5gopjvFZJzrDAxfl9rVTLhZ5B0RgohsJzYWjb3R+qZu8IKctCwBHN74Gkv6W/d4P/BcTeKUR/6rX3UCPuBngMnoEOiMFbsAc+gEMwBAT8DJ4E20En/Bh+Dufh1VoGDQ5j8Cahd9+Ab6w5Dk=</latexit><latexit sha1_base64="+1V7VtyagHXve5ilOYiCbnVH9U=">ACyXicdVFtb9MwEHbC2xhvHXxEAosKrQiInKqFVWjSpE0CiS9DWrdJTRc5rtNZs51gO7TF8if+Af+Of8JHnDbAOsFJth7fc+e7ey4rOdMGoR9BeO36jZu3Nm5v3rl7/6D1tbDY1UitAhKXihTjOsKWeSDg0znJ6WimKRcXqSXezX/MkXqjQr5JFZlHQs8FSynBFsvCtfU8yYZMJ5Qa7dQmhs6NFZg7B3fh6oXVDpPk31DXcviq0fk2lUW5cJ3EJgKb8y3c5eKM/7qL4Tn8t3Y3dm5VoF9y7J8ln6Hr6El75+kbaKELdnX6vC1HU7aNBPCgj+LBmx6MI7S0NmjsMN0KniaTglTC90E41noUo9KMfeOGEU7dZlJpWmJygad05KHEguqxXYrn4HPvmcC8UP5IA5feyxkWC60XIvOR9Wz6Klc7/8WNKpPvjC2TZWoJKtCecWhKWC9CThihLDFx5gopjvFZJzrDAxfl9rVTLhZ5B0RgohsJzYWjb3R+qZu8IKctCwBHN74Gkv6W/d4P/BcTeKUR/6rX3UCPuBngMnoEOiMFbsAc+gEMwBAT8DJ4E20En/Bh+Dufh1VoGDQ5j8Cahd9+Ab6w5Dk=</latexit><latexit sha1_base64="+1V7VtyagHXve5ilOYiCbnVH9U=">ACyXicdVFtb9MwEHbC2xhvHXxEAosKrQiInKqFVWjSpE0CiS9DWrdJTRc5rtNZs51gO7TF8if+Af+Of8JHnDbAOsFJth7fc+e7ey4rOdMGoR9BeO36jZu3Nm5v3rl7/6D1tbDY1UitAhKXihTjOsKWeSDg0znJ6WimKRcXqSXezX/MkXqjQr5JFZlHQs8FSynBFsvCtfU8yYZMJ5Qa7dQmhs6NFZg7B3fh6oXVDpPk31DXcviq0fk2lUW5cJ3EJgKb8y3c5eKM/7qL4Tn8t3Y3dm5VoF9y7J8ln6Hr6El75+kbaKELdnX6vC1HU7aNBPCgj+LBmx6MI7S0NmjsMN0KniaTglTC90E41noUo9KMfeOGEU7dZlJpWmJygad05KHEguqxXYrn4HPvmcC8UP5IA5feyxkWC60XIvOR9Wz6Klc7/8WNKpPvjC2TZWoJKtCecWhKWC9CThihLDFx5gopjvFZJzrDAxfl9rVTLhZ5B0RgohsJzYWjb3R+qZu8IKctCwBHN74Gkv6W/d4P/BcTeKUR/6rX3UCPuBngMnoEOiMFbsAc+gEMwBAT8DJ4E20En/Bh+Dufh1VoGDQ5j8Cahd9+Ab6w5Dk=</latexit>Malicious Objective
Strategy Malicious agent’s update computation Alternating minimization of benign and malicious
constraints
δ0
mal → βδ0 mal
<latexit sha1_base64="zVk37AnjomAR2N02F+4MmPeucUs=">ACfHicdVBdixMxFE3Hr3X96uqjDwarKIhDprTr9m3BFXxcwe4udEq5yWTasElmSO5YS5hf5K/xUf0vYtqt4C7ugcDhnHs5uYfXWnlk7EcnuXHz1u07O3d3791/8PBRd+/xia8aJ+RYVLpyZxy81MrKMSrU8qx2EgzX8pSfv1/7p1+k86qyn3FVy6mBuVWlEoBRmnU/5NyEvJAaoX01CznKrxgM6LaluVPzBYJz1ZLmXCLQa2dn3R5LWf9gOhTlvaHbJSNIhmybLQ/oFnKNuiRLY5ne51neVGJxkiLQoP3k4zVOA3gUAkt2928bIGcQ5zOYnUgpF+Gjb3tvRlVApaVi4+i3Sj/rsRwHi/MjxOGsCFv+qtxf95kwbLg2lQtm5QWnERVDaYkX5dFCOSlQryIB4VT8KxULcCAwVnwphZt4g5VLURkDtg5L5dtyNeRvAzL9oprxNHWFaDUbRjpX97o9eTk36asT7NOgdsm25O+QpeU5ek4y8I4fkIzkmYyLIN/Kd/CS/Or+TF8mb5O3FaNLZ7jwhl5Ds/wE1C8cb</latexit><latexit sha1_base64="zVk37AnjomAR2N02F+4MmPeucUs=">ACfHicdVBdixMxFE3Hr3X96uqjDwarKIhDprTr9m3BFXxcwe4udEq5yWTasElmSO5YS5hf5K/xUf0vYtqt4C7ugcDhnHs5uYfXWnlk7EcnuXHz1u07O3d3791/8PBRd+/xia8aJ+RYVLpyZxy81MrKMSrU8qx2EgzX8pSfv1/7p1+k86qyn3FVy6mBuVWlEoBRmnU/5NyEvJAaoX01CznKrxgM6LaluVPzBYJz1ZLmXCLQa2dn3R5LWf9gOhTlvaHbJSNIhmybLQ/oFnKNuiRLY5ne51neVGJxkiLQoP3k4zVOA3gUAkt2928bIGcQ5zOYnUgpF+Gjb3tvRlVApaVi4+i3Sj/rsRwHi/MjxOGsCFv+qtxf95kwbLg2lQtm5QWnERVDaYkX5dFCOSlQryIB4VT8KxULcCAwVnwphZt4g5VLURkDtg5L5dtyNeRvAzL9oprxNHWFaDUbRjpX97o9eTk36asT7NOgdsm25O+QpeU5ek4y8I4fkIzkmYyLIN/Kd/CS/Or+TF8mb5O3FaNLZ7jwhl5Ds/wE1C8cb</latexit><latexit sha1_base64="zVk37AnjomAR2N02F+4MmPeucUs=">ACfHicdVBdixMxFE3Hr3X96uqjDwarKIhDprTr9m3BFXxcwe4udEq5yWTasElmSO5YS5hf5K/xUf0vYtqt4C7ugcDhnHs5uYfXWnlk7EcnuXHz1u07O3d3791/8PBRd+/xia8aJ+RYVLpyZxy81MrKMSrU8qx2EgzX8pSfv1/7p1+k86qyn3FVy6mBuVWlEoBRmnU/5NyEvJAaoX01CznKrxgM6LaluVPzBYJz1ZLmXCLQa2dn3R5LWf9gOhTlvaHbJSNIhmybLQ/oFnKNuiRLY5ne51neVGJxkiLQoP3k4zVOA3gUAkt2928bIGcQ5zOYnUgpF+Gjb3tvRlVApaVi4+i3Sj/rsRwHi/MjxOGsCFv+qtxf95kwbLg2lQtm5QWnERVDaYkX5dFCOSlQryIB4VT8KxULcCAwVnwphZt4g5VLURkDtg5L5dtyNeRvAzL9oprxNHWFaDUbRjpX97o9eTk36asT7NOgdsm25O+QpeU5ek4y8I4fkIzkmYyLIN/Kd/CS/Or+TF8mb5O3FaNLZ7jwhl5Ds/wE1C8cb</latexit><latexit sha1_base64="zVk37AnjomAR2N02F+4MmPeucUs=">ACfHicdVBdixMxFE3Hr3X96uqjDwarKIhDprTr9m3BFXxcwe4udEq5yWTasElmSO5YS5hf5K/xUf0vYtqt4C7ugcDhnHs5uYfXWnlk7EcnuXHz1u07O3d3791/8PBRd+/xia8aJ+RYVLpyZxy81MrKMSrU8qx2EgzX8pSfv1/7p1+k86qyn3FVy6mBuVWlEoBRmnU/5NyEvJAaoX01CznKrxgM6LaluVPzBYJz1ZLmXCLQa2dn3R5LWf9gOhTlvaHbJSNIhmybLQ/oFnKNuiRLY5ne51neVGJxkiLQoP3k4zVOA3gUAkt2928bIGcQ5zOYnUgpF+Gjb3tvRlVApaVi4+i3Sj/rsRwHi/MjxOGsCFv+qtxf95kwbLg2lQtm5QWnERVDaYkX5dFCOSlQryIB4VT8KxULcCAwVnwphZt4g5VLURkDtg5L5dtyNeRvAzL9oprxNHWFaDUbRjpX97o9eTk36asT7NOgdsm25O+QpeU5ek4y8I4fkIzkmYyLIN/Kd/CS/Or+TF8mb5O3FaNLZ7jwhl5Ds/wE1C8cb</latexit>Repeat:
For every step w.r.t. to the malicious loss, take 10 steps for the benign loss
δ00
mal = argminδ Cross-entropy
m, yi m}n i=1; wG + βδ0 mal + δ
2
<latexit sha1_base64="bpGqatx5D7OXRuiowl4CsCBvZi8=">ADfnicfVJb9MwGHVWLqPcNnjkxaKCbCVpNpgFZpUGBK8IZEu0l1GxzXa3FdrBd2uL5F/DA70P8GZx2Ky23T3J8dM6xP8fHSZ4xbcLwe7BSunT5ytXVa+XrN27eur2fqel5VAR2iQyk+okwZpmTNCmYSajJ7mimCcZPU5ODwv9+DNVmknxwUxy2uG4L1jKCDaeitd+oIRb1KOZwW5jI0aGjo3lOHPwACKs+pyJ2C543MxqKTWO1QYJfOJgyijqdlE3piOY95l25Pi1xs2UHkula4514axa/hY4gSajBcbOsbzNu6qWOuQaRYf2C2ClYNJERnC+LOAr7Yg0ih/SHP4lq3Fq9VwmpY29/brcGwWtsL61Hdg70wqj/dhVE1nFalsfXty0cAwFG8HnxFPUmG3P8YybDW7SjMTcdiZRjJqCujoaY5Jqe4T9seCsyp7thpCg4+8EwPplL5IQycsosrLOZaT3jinRybgf5dK8i/ae2hSfc7lol8aKgs0bpMINGwiJS2GOKEpNPMBEMX9WSAZYWJ8GUk6IhIzrHoWdRy7ahjUdEjSW0lcm5Z9yG5uTz6Ux3/UseF+or6e1L0rafe5VRhI9UjO3032FvP5/ZmJjZ/Lx0Hwl3Pr6LjOC/QatWjTx+H1UaL8GsVsE9cB9sg8Aw3wBhyBJiDBi6Af5MGnEig9LO2UnsysK8H5mrtgqUr7PwG5wCqW</latexit><latexit sha1_base64="o3NR/rwYsUwyoLX4pYQ6qUzsbFs=">ADfnicfVLdbtMwGHUWfsb42+CSG4sKtgErSbXBJjRpMCS4QyJdpPqNnJcp7UW28F2WIvnJ+CW56Ad0K8DE67lZa/T3J8dM6xP8fHaZEzbaLoe7AQXrh46fLilaWr167fuLm8cqulZakIbRKZS3WUYk1zJmjTMJPTo0JRzNOcHqbH+5V+JEqzaR4b0YF7XDcFyxjBtPJcs/UMot6tHcYLe6miBDh8ZynDu4CxFWfc5EYmc8buLYV1LrDSqMksXIQZTzKwhb8yGCe+yR6Pqi1xi2W7sula4Z146SV7BhxCl1GA429Y3mLZ1Y8dUg0ix/sCsV6waSIhOZ8SNGXy+B5FC+0OeJo1uI1muRfWosb212YBRvbEV7cQ7HmxF8c6TRjXo3HV9ta/fCoWv309SFaCz6gnScn9j5Eca92Oo8J0LFaGkZy6JVRqWmByjPu07aHAnOqOHafg4D3P9GAmlR/CwDE7u8JirvWIp97JsRno37WK/JvWLk23bFMFKWhgkwaZWUOjYRVpLDHFCUmH3mAiWL+rJAMsMLE+OCXkKAnRHKORc+ilmvHYuqHmlma7Fz87oPyU3lkz/V4S91WKkvqb8nRd946m1BFTZSPbDjd4O9Wz+n42Jic3Pc/eRcufjO8I/hu0GvXY43dxbe8FmNQiuAPugjUQg6dgD7wGB6AJSPA86AdF8CE4f1wI3w8sS4EZ2tug7kKt38Cet0r7A=</latexit><latexit sha1_base64="o3NR/rwYsUwyoLX4pYQ6qUzsbFs=">ADfnicfVLdbtMwGHUWfsb42+CSG4sKtgErSbXBJjRpMCS4QyJdpPqNnJcp7UW28F2WIvnJ+CW56Ad0K8DE67lZa/T3J8dM6xP8fHaZEzbaLoe7AQXrh46fLilaWr167fuLm8cqulZakIbRKZS3WUYk1zJmjTMJPTo0JRzNOcHqbH+5V+JEqzaR4b0YF7XDcFyxjBtPJcs/UMot6tHcYLe6miBDh8ZynDu4CxFWfc5EYmc8buLYV1LrDSqMksXIQZTzKwhb8yGCe+yR6Pqi1xi2W7sula4Z146SV7BhxCl1GA429Y3mLZ1Y8dUg0ix/sCsV6waSIhOZ8SNGXy+B5FC+0OeJo1uI1muRfWosb212YBRvbEV7cQ7HmxF8c6TRjXo3HV9ta/fCoWv309SFaCz6gnScn9j5Eca92Oo8J0LFaGkZy6JVRqWmByjPu07aHAnOqOHafg4D3P9GAmlR/CwDE7u8JirvWIp97JsRno37WK/JvWLk23bFMFKWhgkwaZWUOjYRVpLDHFCUmH3mAiWL+rJAMsMLE+OCXkKAnRHKORc+ilmvHYuqHmlma7Fz87oPyU3lkz/V4S91WKkvqb8nRd946m1BFTZSPbDjd4O9Wz+n42Jic3Pc/eRcufjO8I/hu0GvXY43dxbe8FmNQiuAPugjUQg6dgD7wGB6AJSPA86AdF8CE4f1wI3w8sS4EZ2tug7kKt38Cet0r7A=</latexit><latexit sha1_base64="xa40SpmTZi3T5MqG/LGuh2EwYQ=">ADfnicfVJb9MwGHUWLmPcOnjkxaKCDdhKEq2wCk0aDAleENiF6nuIsd1WmuxHWyHtfL8C/iFiD+D03aj5fZJjo/Ofbn+DgrC6ZNFH0PlsIrV69dX76xcvPW7Tt3G6v3DrWsFKEHRBZSHWdY04IJemCYKehxqSjmWUGPstO9Wj/6SpVmUnw245L2OB4IljOCjafSxg+UcYv6tDYra2lyNCRsRwXDu5AhNWAM5HaOY+bOvaU1HqTCqNkOXYQFTQ368gb81HKT9jGuP4il1q2E7sTK9wrL52l7+AziDJqMJxv6xtctnUTx6UGkWKDoXlSs2oITqfEzfn8MUeRArtD3meJidJ2mhGrSjZbm8lMGol7agTdzxoR3HnxRaMW9GkmBW+lq8A31Jam4/zFSYK27cVSansXKMFJQt4IqTUtMTvGAdj0UmFPds5MUHzkmT7MpfJDGDh51dYzLUe8w7OTZD/btWk3/TupXJt3uWibIyVJBpo7wqoJGwjhT2maLEFGMPMFHMnxWSIVaYGB/8ChL0jEjOsehbdOi6c+iukeW2bs3KLuQ3KX8tmf6uiXOqrVt9Tfk6IfPWxpAobqZ7aybvB3jqb/2djYmrz8J9ZNz5+C4ygv8Gh0kr9vhT3Nx9MwtyGTwAD8E6iMFLsAveg31wAEjwOhgEZfAlBOHjcDN8PrUuBbM198FChds/AfGtKMQ=</latexit>Benign Objective Distance Constraint
δ0
mal = argminδCross-entropy({xl m, T l m}nmal l=1 ; wG + δ)
<latexit sha1_base64="+1V7VtyagHXve5ilOYiCbnVH9U=">ACyXicdVFtb9MwEHbC2xhvHXxEAosKrQiInKqFVWjSpE0CiS9DWrdJTRc5rtNZs51gO7TF8if+Af+Of8JHnDbAOsFJth7fc+e7ey4rOdMGoR9BeO36jZu3Nm5v3rl7/6D1tbDY1UitAhKXihTjOsKWeSDg0znJ6WimKRcXqSXezX/MkXqjQr5JFZlHQs8FSynBFsvCtfU8yYZMJ5Qa7dQmhs6NFZg7B3fh6oXVDpPk31DXcviq0fk2lUW5cJ3EJgKb8y3c5eKM/7qL4Tn8t3Y3dm5VoF9y7J8ln6Hr6El75+kbaKELdnX6vC1HU7aNBPCgj+LBmx6MI7S0NmjsMN0KniaTglTC90E41noUo9KMfeOGEU7dZlJpWmJygad05KHEguqxXYrn4HPvmcC8UP5IA5feyxkWC60XIvOR9Wz6Klc7/8WNKpPvjC2TZWoJKtCecWhKWC9CThihLDFx5gopjvFZJzrDAxfl9rVTLhZ5B0RgohsJzYWjb3R+qZu8IKctCwBHN74Gkv6W/d4P/BcTeKUR/6rX3UCPuBngMnoEOiMFbsAc+gEMwBAT8DJ4E20En/Bh+Dufh1VoGDQ5j8Cahd9+Ab6w5Dk=</latexit><latexit sha1_base64="+1V7VtyagHXve5ilOYiCbnVH9U=">ACyXicdVFtb9MwEHbC2xhvHXxEAosKrQiInKqFVWjSpE0CiS9DWrdJTRc5rtNZs51gO7TF8if+Af+Of8JHnDbAOsFJth7fc+e7ey4rOdMGoR9BeO36jZu3Nm5v3rl7/6D1tbDY1UitAhKXihTjOsKWeSDg0znJ6WimKRcXqSXezX/MkXqjQr5JFZlHQs8FSynBFsvCtfU8yYZMJ5Qa7dQmhs6NFZg7B3fh6oXVDpPk31DXcviq0fk2lUW5cJ3EJgKb8y3c5eKM/7qL4Tn8t3Y3dm5VoF9y7J8ln6Hr6El75+kbaKELdnX6vC1HU7aNBPCgj+LBmx6MI7S0NmjsMN0KniaTglTC90E41noUo9KMfeOGEU7dZlJpWmJygad05KHEguqxXYrn4HPvmcC8UP5IA5feyxkWC60XIvOR9Wz6Klc7/8WNKpPvjC2TZWoJKtCecWhKWC9CThihLDFx5gopjvFZJzrDAxfl9rVTLhZ5B0RgohsJzYWjb3R+qZu8IKctCwBHN74Gkv6W/d4P/BcTeKUR/6rX3UCPuBngMnoEOiMFbsAc+gEMwBAT8DJ4E20En/Bh+Dufh1VoGDQ5j8Cahd9+Ab6w5Dk=</latexit><latexit sha1_base64="+1V7VtyagHXve5ilOYiCbnVH9U=">ACyXicdVFtb9MwEHbC2xhvHXxEAosKrQiInKqFVWjSpE0CiS9DWrdJTRc5rtNZs51gO7TF8if+Af+Of8JHnDbAOsFJth7fc+e7ey4rOdMGoR9BeO36jZu3Nm5v3rl7/6D1tbDY1UitAhKXihTjOsKWeSDg0znJ6WimKRcXqSXezX/MkXqjQr5JFZlHQs8FSynBFsvCtfU8yYZMJ5Qa7dQmhs6NFZg7B3fh6oXVDpPk31DXcviq0fk2lUW5cJ3EJgKb8y3c5eKM/7qL4Tn8t3Y3dm5VoF9y7J8ln6Hr6El75+kbaKELdnX6vC1HU7aNBPCgj+LBmx6MI7S0NmjsMN0KniaTglTC90E41noUo9KMfeOGEU7dZlJpWmJygad05KHEguqxXYrn4HPvmcC8UP5IA5feyxkWC60XIvOR9Wz6Klc7/8WNKpPvjC2TZWoJKtCecWhKWC9CThihLDFx5gopjvFZJzrDAxfl9rVTLhZ5B0RgohsJzYWjb3R+qZu8IKctCwBHN74Gkv6W/d4P/BcTeKUR/6rX3UCPuBngMnoEOiMFbsAc+gEMwBAT8DJ4E20En/Bh+Dufh1VoGDQ5j8Cahd9+Ab6w5Dk=</latexit><latexit sha1_base64="+1V7VtyagHXve5ilOYiCbnVH9U=">ACyXicdVFtb9MwEHbC2xhvHXxEAosKrQiInKqFVWjSpE0CiS9DWrdJTRc5rtNZs51gO7TF8if+Af+Of8JHnDbAOsFJth7fc+e7ey4rOdMGoR9BeO36jZu3Nm5v3rl7/6D1tbDY1UitAhKXihTjOsKWeSDg0znJ6WimKRcXqSXezX/MkXqjQr5JFZlHQs8FSynBFsvCtfU8yYZMJ5Qa7dQmhs6NFZg7B3fh6oXVDpPk31DXcviq0fk2lUW5cJ3EJgKb8y3c5eKM/7qL4Tn8t3Y3dm5VoF9y7J8ln6Hr6El75+kbaKELdnX6vC1HU7aNBPCgj+LBmx6MI7S0NmjsMN0KniaTglTC90E41noUo9KMfeOGEU7dZlJpWmJygad05KHEguqxXYrn4HPvmcC8UP5IA5feyxkWC60XIvOR9Wz6Klc7/8WNKpPvjC2TZWoJKtCecWhKWC9CThihLDFx5gopjvFZJzrDAxfl9rVTLhZ5B0RgohsJzYWjb3R+qZu8IKctCwBHN74Gkv6W/d4P/BcTeKUR/6rX3UCPuBngMnoEOiMFbsAc+gEMwBAT8DJ4E20En/Bh+Dufh1VoGDQ5j8Cahd9+Ab6w5Dk=</latexit>Malicious Objective
Takeaway Malicious objective is met while maintaining high validation accuracy for malicious model
0.2 0.4 0.6 0.8 1 2 4 6 8 10 12 20 40 60 80 100
Confidence Classification accuracy Time
Strategy Malicious agent’s update computation Alternating minimization of benign and malicious
constraints
δ0
mal → βδ0 mal
<latexit sha1_base64="zVk37AnjomAR2N02F+4MmPeucUs=">ACfHicdVBdixMxFE3Hr3X96uqjDwarKIhDprTr9m3BFXxcwe4udEq5yWTasElmSO5YS5hf5K/xUf0vYtqt4C7ugcDhnHs5uYfXWnlk7EcnuXHz1u07O3d3791/8PBRd+/xia8aJ+RYVLpyZxy81MrKMSrU8qx2EgzX8pSfv1/7p1+k86qyn3FVy6mBuVWlEoBRmnU/5NyEvJAaoX01CznKrxgM6LaluVPzBYJz1ZLmXCLQa2dn3R5LWf9gOhTlvaHbJSNIhmybLQ/oFnKNuiRLY5ne51neVGJxkiLQoP3k4zVOA3gUAkt2928bIGcQ5zOYnUgpF+Gjb3tvRlVApaVi4+i3Sj/rsRwHi/MjxOGsCFv+qtxf95kwbLg2lQtm5QWnERVDaYkX5dFCOSlQryIB4VT8KxULcCAwVnwphZt4g5VLURkDtg5L5dtyNeRvAzL9oprxNHWFaDUbRjpX97o9eTk36asT7NOgdsm25O+QpeU5ek4y8I4fkIzkmYyLIN/Kd/CS/Or+TF8mb5O3FaNLZ7jwhl5Ds/wE1C8cb</latexit><latexit sha1_base64="zVk37AnjomAR2N02F+4MmPeucUs=">ACfHicdVBdixMxFE3Hr3X96uqjDwarKIhDprTr9m3BFXxcwe4udEq5yWTasElmSO5YS5hf5K/xUf0vYtqt4C7ugcDhnHs5uYfXWnlk7EcnuXHz1u07O3d3791/8PBRd+/xia8aJ+RYVLpyZxy81MrKMSrU8qx2EgzX8pSfv1/7p1+k86qyn3FVy6mBuVWlEoBRmnU/5NyEvJAaoX01CznKrxgM6LaluVPzBYJz1ZLmXCLQa2dn3R5LWf9gOhTlvaHbJSNIhmybLQ/oFnKNuiRLY5ne51neVGJxkiLQoP3k4zVOA3gUAkt2928bIGcQ5zOYnUgpF+Gjb3tvRlVApaVi4+i3Sj/rsRwHi/MjxOGsCFv+qtxf95kwbLg2lQtm5QWnERVDaYkX5dFCOSlQryIB4VT8KxULcCAwVnwphZt4g5VLURkDtg5L5dtyNeRvAzL9oprxNHWFaDUbRjpX97o9eTk36asT7NOgdsm25O+QpeU5ek4y8I4fkIzkmYyLIN/Kd/CS/Or+TF8mb5O3FaNLZ7jwhl5Ds/wE1C8cb</latexit><latexit sha1_base64="zVk37AnjomAR2N02F+4MmPeucUs=">ACfHicdVBdixMxFE3Hr3X96uqjDwarKIhDprTr9m3BFXxcwe4udEq5yWTasElmSO5YS5hf5K/xUf0vYtqt4C7ugcDhnHs5uYfXWnlk7EcnuXHz1u07O3d3791/8PBRd+/xia8aJ+RYVLpyZxy81MrKMSrU8qx2EgzX8pSfv1/7p1+k86qyn3FVy6mBuVWlEoBRmnU/5NyEvJAaoX01CznKrxgM6LaluVPzBYJz1ZLmXCLQa2dn3R5LWf9gOhTlvaHbJSNIhmybLQ/oFnKNuiRLY5ne51neVGJxkiLQoP3k4zVOA3gUAkt2928bIGcQ5zOYnUgpF+Gjb3tvRlVApaVi4+i3Sj/rsRwHi/MjxOGsCFv+qtxf95kwbLg2lQtm5QWnERVDaYkX5dFCOSlQryIB4VT8KxULcCAwVnwphZt4g5VLURkDtg5L5dtyNeRvAzL9oprxNHWFaDUbRjpX97o9eTk36asT7NOgdsm25O+QpeU5ek4y8I4fkIzkmYyLIN/Kd/CS/Or+TF8mb5O3FaNLZ7jwhl5Ds/wE1C8cb</latexit><latexit sha1_base64="zVk37AnjomAR2N02F+4MmPeucUs=">ACfHicdVBdixMxFE3Hr3X96uqjDwarKIhDprTr9m3BFXxcwe4udEq5yWTasElmSO5YS5hf5K/xUf0vYtqt4C7ugcDhnHs5uYfXWnlk7EcnuXHz1u07O3d3791/8PBRd+/xia8aJ+RYVLpyZxy81MrKMSrU8qx2EgzX8pSfv1/7p1+k86qyn3FVy6mBuVWlEoBRmnU/5NyEvJAaoX01CznKrxgM6LaluVPzBYJz1ZLmXCLQa2dn3R5LWf9gOhTlvaHbJSNIhmybLQ/oFnKNuiRLY5ne51neVGJxkiLQoP3k4zVOA3gUAkt2928bIGcQ5zOYnUgpF+Gjb3tvRlVApaVi4+i3Sj/rsRwHi/MjxOGsCFv+qtxf95kwbLg2lQtm5QWnERVDaYkX5dFCOSlQryIB4VT8KxULcCAwVnwphZt4g5VLURkDtg5L5dtyNeRvAzL9oprxNHWFaDUbRjpX97o9eTk36asT7NOgdsm25O+QpeU5ek4y8I4fkIzkmYyLIN/Kd/CS/Or+TF8mb5O3FaNLZ7jwhl5Ds/wE1C8cb</latexit>Repeat:
For every step w.r.t. to the malicious loss, take 10 steps for the benign loss
δ00
mal = argminδ Cross-entropy
m, yi m}n i=1; wG + βδ0 mal + δ
2
<latexit sha1_base64="bpGqatx5D7OXRuiowl4CsCBvZi8=">ADfnicfVJb9MwGHVWLqPcNnjkxaKCbCVpNpgFZpUGBK8IZEu0l1GxzXa3FdrBd2uL5F/DA70P8GZx2Ky23T3J8dM6xP8fHSZ4xbcLwe7BSunT5ytXVa+XrN27eur2fqel5VAR2iQyk+okwZpmTNCmYSajJ7mimCcZPU5ODwv9+DNVmknxwUxy2uG4L1jKCDaeitd+oIRb1KOZwW5jI0aGjo3lOHPwACKs+pyJ2C543MxqKTWO1QYJfOJgyijqdlE3piOY95l25Pi1xs2UHkula4514axa/hY4gSajBcbOsbzNu6qWOuQaRYf2C2ClYNJERnC+LOAr7Yg0ih/SHP4lq3Fq9VwmpY29/brcGwWtsL61Hdg70wqj/dhVE1nFalsfXty0cAwFG8HnxFPUmG3P8YybDW7SjMTcdiZRjJqCujoaY5Jqe4T9seCsyp7thpCg4+8EwPplL5IQycsosrLOZaT3jinRybgf5dK8i/ae2hSfc7lol8aKgs0bpMINGwiJS2GOKEpNPMBEMX9WSAZYWJ8GUk6IhIzrHoWdRy7ahjUdEjSW0lcm5Z9yG5uTz6Ux3/UseF+or6e1L0rafe5VRhI9UjO3032FvP5/ZmJjZ/Lx0Hwl3Pr6LjOC/QatWjTx+H1UaL8GsVsE9cB9sg8Aw3wBhyBJiDBi6Af5MGnEig9LO2UnsysK8H5mrtgqUr7PwG5wCqW</latexit><latexit sha1_base64="o3NR/rwYsUwyoLX4pYQ6qUzsbFs=">ADfnicfVLdbtMwGHUWfsb42+CSG4sKtgErSbXBJjRpMCS4QyJdpPqNnJcp7UW28F2WIvnJ+CW56Ad0K8DE67lZa/T3J8dM6xP8fHaZEzbaLoe7AQXrh46fLilaWr167fuLm8cqulZakIbRKZS3WUYk1zJmjTMJPTo0JRzNOcHqbH+5V+JEqzaR4b0YF7XDcFyxjBtPJcs/UMot6tHcYLe6miBDh8ZynDu4CxFWfc5EYmc8buLYV1LrDSqMksXIQZTzKwhb8yGCe+yR6Pqi1xi2W7sula4Z146SV7BhxCl1GA429Y3mLZ1Y8dUg0ix/sCsV6waSIhOZ8SNGXy+B5FC+0OeJo1uI1muRfWosb212YBRvbEV7cQ7HmxF8c6TRjXo3HV9ta/fCoWv309SFaCz6gnScn9j5Eca92Oo8J0LFaGkZy6JVRqWmByjPu07aHAnOqOHafg4D3P9GAmlR/CwDE7u8JirvWIp97JsRno37WK/JvWLk23bFMFKWhgkwaZWUOjYRVpLDHFCUmH3mAiWL+rJAMsMLE+OCXkKAnRHKORc+ilmvHYuqHmlma7Fz87oPyU3lkz/V4S91WKkvqb8nRd946m1BFTZSPbDjd4O9Wz+n42Jic3Pc/eRcufjO8I/hu0GvXY43dxbe8FmNQiuAPugjUQg6dgD7wGB6AJSPA86AdF8CE4f1wI3w8sS4EZ2tug7kKt38Cet0r7A=</latexit><latexit sha1_base64="o3NR/rwYsUwyoLX4pYQ6qUzsbFs=">ADfnicfVLdbtMwGHUWfsb42+CSG4sKtgErSbXBJjRpMCS4QyJdpPqNnJcp7UW28F2WIvnJ+CW56Ad0K8DE67lZa/T3J8dM6xP8fHaZEzbaLoe7AQXrh46fLilaWr167fuLm8cqulZakIbRKZS3WUYk1zJmjTMJPTo0JRzNOcHqbH+5V+JEqzaR4b0YF7XDcFyxjBtPJcs/UMot6tHcYLe6miBDh8ZynDu4CxFWfc5EYmc8buLYV1LrDSqMksXIQZTzKwhb8yGCe+yR6Pqi1xi2W7sula4Z146SV7BhxCl1GA429Y3mLZ1Y8dUg0ix/sCsV6waSIhOZ8SNGXy+B5FC+0OeJo1uI1muRfWosb212YBRvbEV7cQ7HmxF8c6TRjXo3HV9ta/fCoWv309SFaCz6gnScn9j5Eca92Oo8J0LFaGkZy6JVRqWmByjPu07aHAnOqOHafg4D3P9GAmlR/CwDE7u8JirvWIp97JsRno37WK/JvWLk23bFMFKWhgkwaZWUOjYRVpLDHFCUmH3mAiWL+rJAMsMLE+OCXkKAnRHKORc+ilmvHYuqHmlma7Fz87oPyU3lkz/V4S91WKkvqb8nRd946m1BFTZSPbDjd4O9Wz+n42Jic3Pc/eRcufjO8I/hu0GvXY43dxbe8FmNQiuAPugjUQg6dgD7wGB6AJSPA86AdF8CE4f1wI3w8sS4EZ2tug7kKt38Cet0r7A=</latexit><latexit sha1_base64="xa40SpmTZi3T5MqG/LGuh2EwYQ=">ADfnicfVJb9MwGHUWLmPcOnjkxaKCDdhKEq2wCk0aDAleENiF6nuIsd1WmuxHWyHtfL8C/iFiD+D03aj5fZJjo/Ofbn+DgrC6ZNFH0PlsIrV69dX76xcvPW7Tt3G6v3DrWsFKEHRBZSHWdY04IJemCYKehxqSjmWUGPstO9Wj/6SpVmUnw245L2OB4IljOCjafSxg+UcYv6tDYra2lyNCRsRwXDu5AhNWAM5HaOY+bOvaU1HqTCqNkOXYQFTQ368gb81HKT9jGuP4il1q2E7sTK9wrL52l7+AziDJqMJxv6xtctnUTx6UGkWKDoXlSs2oITqfEzfn8MUeRArtD3meJidJ2mhGrSjZbm8lMGol7agTdzxoR3HnxRaMW9GkmBW+lq8A31Jam4/zFSYK27cVSansXKMFJQt4IqTUtMTvGAdj0UmFPds5MUHzkmT7MpfJDGDh51dYzLUe8w7OTZD/btWk3/TupXJt3uWibIyVJBpo7wqoJGwjhT2maLEFGMPMFHMnxWSIVaYGB/8ChL0jEjOsehbdOi6c+iukeW2bs3KLuQ3KX8tmf6uiXOqrVt9Tfk6IfPWxpAobqZ7aybvB3jqb/2djYmrz8J9ZNz5+C4ygv8Gh0kr9vhT3Nx9MwtyGTwAD8E6iMFLsAveg31wAEjwOhgEZfAlBOHjcDN8PrUuBbM198FChds/AfGtKMQ=</latexit>Benign Objective Distance Constraint
δ0
mal = argminδCross-entropy({xl m, T l m}nmal l=1 ; wG + δ)
<latexit sha1_base64="+1V7VtyagHXve5ilOYiCbnVH9U=">ACyXicdVFtb9MwEHbC2xhvHXxEAosKrQiInKqFVWjSpE0CiS9DWrdJTRc5rtNZs51gO7TF8if+Af+Of8JHnDbAOsFJth7fc+e7ey4rOdMGoR9BeO36jZu3Nm5v3rl7/6D1tbDY1UitAhKXihTjOsKWeSDg0znJ6WimKRcXqSXezX/MkXqjQr5JFZlHQs8FSynBFsvCtfU8yYZMJ5Qa7dQmhs6NFZg7B3fh6oXVDpPk31DXcviq0fk2lUW5cJ3EJgKb8y3c5eKM/7qL4Tn8t3Y3dm5VoF9y7J8ln6Hr6El75+kbaKELdnX6vC1HU7aNBPCgj+LBmx6MI7S0NmjsMN0KniaTglTC90E41noUo9KMfeOGEU7dZlJpWmJygad05KHEguqxXYrn4HPvmcC8UP5IA5feyxkWC60XIvOR9Wz6Klc7/8WNKpPvjC2TZWoJKtCecWhKWC9CThihLDFx5gopjvFZJzrDAxfl9rVTLhZ5B0RgohsJzYWjb3R+qZu8IKctCwBHN74Gkv6W/d4P/BcTeKUR/6rX3UCPuBngMnoEOiMFbsAc+gEMwBAT8DJ4E20En/Bh+Dufh1VoGDQ5j8Cahd9+Ab6w5Dk=</latexit><latexit sha1_base64="+1V7VtyagHXve5ilOYiCbnVH9U=">ACyXicdVFtb9MwEHbC2xhvHXxEAosKrQiInKqFVWjSpE0CiS9DWrdJTRc5rtNZs51gO7TF8if+Af+Of8JHnDbAOsFJth7fc+e7ey4rOdMGoR9BeO36jZu3Nm5v3rl7/6D1tbDY1UitAhKXihTjOsKWeSDg0znJ6WimKRcXqSXezX/MkXqjQr5JFZlHQs8FSynBFsvCtfU8yYZMJ5Qa7dQmhs6NFZg7B3fh6oXVDpPk31DXcviq0fk2lUW5cJ3EJgKb8y3c5eKM/7qL4Tn8t3Y3dm5VoF9y7J8ln6Hr6El75+kbaKELdnX6vC1HU7aNBPCgj+LBmx6MI7S0NmjsMN0KniaTglTC90E41noUo9KMfeOGEU7dZlJpWmJygad05KHEguqxXYrn4HPvmcC8UP5IA5feyxkWC60XIvOR9Wz6Klc7/8WNKpPvjC2TZWoJKtCecWhKWC9CThihLDFx5gopjvFZJzrDAxfl9rVTLhZ5B0RgohsJzYWjb3R+qZu8IKctCwBHN74Gkv6W/d4P/BcTeKUR/6rX3UCPuBngMnoEOiMFbsAc+gEMwBAT8DJ4E20En/Bh+Dufh1VoGDQ5j8Cahd9+Ab6w5Dk=</latexit><latexit sha1_base64="+1V7VtyagHXve5ilOYiCbnVH9U=">ACyXicdVFtb9MwEHbC2xhvHXxEAosKrQiInKqFVWjSpE0CiS9DWrdJTRc5rtNZs51gO7TF8if+Af+Of8JHnDbAOsFJth7fc+e7ey4rOdMGoR9BeO36jZu3Nm5v3rl7/6D1tbDY1UitAhKXihTjOsKWeSDg0znJ6WimKRcXqSXezX/MkXqjQr5JFZlHQs8FSynBFsvCtfU8yYZMJ5Qa7dQmhs6NFZg7B3fh6oXVDpPk31DXcviq0fk2lUW5cJ3EJgKb8y3c5eKM/7qL4Tn8t3Y3dm5VoF9y7J8ln6Hr6El75+kbaKELdnX6vC1HU7aNBPCgj+LBmx6MI7S0NmjsMN0KniaTglTC90E41noUo9KMfeOGEU7dZlJpWmJygad05KHEguqxXYrn4HPvmcC8UP5IA5feyxkWC60XIvOR9Wz6Klc7/8WNKpPvjC2TZWoJKtCecWhKWC9CThihLDFx5gopjvFZJzrDAxfl9rVTLhZ5B0RgohsJzYWjb3R+qZu8IKctCwBHN74Gkv6W/d4P/BcTeKUR/6rX3UCPuBngMnoEOiMFbsAc+gEMwBAT8DJ4E20En/Bh+Dufh1VoGDQ5j8Cahd9+Ab6w5Dk=</latexit><latexit sha1_base64="+1V7VtyagHXve5ilOYiCbnVH9U=">ACyXicdVFtb9MwEHbC2xhvHXxEAosKrQiInKqFVWjSpE0CiS9DWrdJTRc5rtNZs51gO7TF8if+Af+Of8JHnDbAOsFJth7fc+e7ey4rOdMGoR9BeO36jZu3Nm5v3rl7/6D1tbDY1UitAhKXihTjOsKWeSDg0znJ6WimKRcXqSXezX/MkXqjQr5JFZlHQs8FSynBFsvCtfU8yYZMJ5Qa7dQmhs6NFZg7B3fh6oXVDpPk31DXcviq0fk2lUW5cJ3EJgKb8y3c5eKM/7qL4Tn8t3Y3dm5VoF9y7J8ln6Hr6El75+kbaKELdnX6vC1HU7aNBPCgj+LBmx6MI7S0NmjsMN0KniaTglTC90E41noUo9KMfeOGEU7dZlJpWmJygad05KHEguqxXYrn4HPvmcC8UP5IA5feyxkWC60XIvOR9Wz6Klc7/8WNKpPvjC2TZWoJKtCecWhKWC9CThihLDFx5gopjvFZJzrDAxfl9rVTLhZ5B0RgohsJzYWjb3R+qZu8IKctCwBHN74Gkv6W/d4P/BcTeKUR/6rX3UCPuBngMnoEOiMFbsAc+gEMwBAT8DJ4E20En/Bh+Dufh1VoGDQ5j8Cahd9+Ab6w5Dk=</latexit>Malicious Objective
Takeaway Shape and range match closely due to distance constraint Takeaway Malicious objective is met while maintaining high validation accuracy for malicious model
0.2 0.4 0.6 0.8 1 2 4 6 8 10 12 20 40 60 80 100
Confidence Classification accuracy Time
Strategy Malicious agent’s update computation Alternating minimization of benign and malicious
constraints
δ0
mal → βδ0 mal
<latexit sha1_base64="zVk37AnjomAR2N02F+4MmPeucUs=">ACfHicdVBdixMxFE3Hr3X96uqjDwarKIhDprTr9m3BFXxcwe4udEq5yWTasElmSO5YS5hf5K/xUf0vYtqt4C7ugcDhnHs5uYfXWnlk7EcnuXHz1u07O3d3791/8PBRd+/xia8aJ+RYVLpyZxy81MrKMSrU8qx2EgzX8pSfv1/7p1+k86qyn3FVy6mBuVWlEoBRmnU/5NyEvJAaoX01CznKrxgM6LaluVPzBYJz1ZLmXCLQa2dn3R5LWf9gOhTlvaHbJSNIhmybLQ/oFnKNuiRLY5ne51neVGJxkiLQoP3k4zVOA3gUAkt2928bIGcQ5zOYnUgpF+Gjb3tvRlVApaVi4+i3Sj/rsRwHi/MjxOGsCFv+qtxf95kwbLg2lQtm5QWnERVDaYkX5dFCOSlQryIB4VT8KxULcCAwVnwphZt4g5VLURkDtg5L5dtyNeRvAzL9oprxNHWFaDUbRjpX97o9eTk36asT7NOgdsm25O+QpeU5ek4y8I4fkIzkmYyLIN/Kd/CS/Or+TF8mb5O3FaNLZ7jwhl5Ds/wE1C8cb</latexit><latexit sha1_base64="zVk37AnjomAR2N02F+4MmPeucUs=">ACfHicdVBdixMxFE3Hr3X96uqjDwarKIhDprTr9m3BFXxcwe4udEq5yWTasElmSO5YS5hf5K/xUf0vYtqt4C7ugcDhnHs5uYfXWnlk7EcnuXHz1u07O3d3791/8PBRd+/xia8aJ+RYVLpyZxy81MrKMSrU8qx2EgzX8pSfv1/7p1+k86qyn3FVy6mBuVWlEoBRmnU/5NyEvJAaoX01CznKrxgM6LaluVPzBYJz1ZLmXCLQa2dn3R5LWf9gOhTlvaHbJSNIhmybLQ/oFnKNuiRLY5ne51neVGJxkiLQoP3k4zVOA3gUAkt2928bIGcQ5zOYnUgpF+Gjb3tvRlVApaVi4+i3Sj/rsRwHi/MjxOGsCFv+qtxf95kwbLg2lQtm5QWnERVDaYkX5dFCOSlQryIB4VT8KxULcCAwVnwphZt4g5VLURkDtg5L5dtyNeRvAzL9oprxNHWFaDUbRjpX97o9eTk36asT7NOgdsm25O+QpeU5ek4y8I4fkIzkmYyLIN/Kd/CS/Or+TF8mb5O3FaNLZ7jwhl5Ds/wE1C8cb</latexit><latexit sha1_base64="zVk37AnjomAR2N02F+4MmPeucUs=">ACfHicdVBdixMxFE3Hr3X96uqjDwarKIhDprTr9m3BFXxcwe4udEq5yWTasElmSO5YS5hf5K/xUf0vYtqt4C7ugcDhnHs5uYfXWnlk7EcnuXHz1u07O3d3791/8PBRd+/xia8aJ+RYVLpyZxy81MrKMSrU8qx2EgzX8pSfv1/7p1+k86qyn3FVy6mBuVWlEoBRmnU/5NyEvJAaoX01CznKrxgM6LaluVPzBYJz1ZLmXCLQa2dn3R5LWf9gOhTlvaHbJSNIhmybLQ/oFnKNuiRLY5ne51neVGJxkiLQoP3k4zVOA3gUAkt2928bIGcQ5zOYnUgpF+Gjb3tvRlVApaVi4+i3Sj/rsRwHi/MjxOGsCFv+qtxf95kwbLg2lQtm5QWnERVDaYkX5dFCOSlQryIB4VT8KxULcCAwVnwphZt4g5VLURkDtg5L5dtyNeRvAzL9oprxNHWFaDUbRjpX97o9eTk36asT7NOgdsm25O+QpeU5ek4y8I4fkIzkmYyLIN/Kd/CS/Or+TF8mb5O3FaNLZ7jwhl5Ds/wE1C8cb</latexit><latexit sha1_base64="zVk37AnjomAR2N02F+4MmPeucUs=">ACfHicdVBdixMxFE3Hr3X96uqjDwarKIhDprTr9m3BFXxcwe4udEq5yWTasElmSO5YS5hf5K/xUf0vYtqt4C7ugcDhnHs5uYfXWnlk7EcnuXHz1u07O3d3791/8PBRd+/xia8aJ+RYVLpyZxy81MrKMSrU8qx2EgzX8pSfv1/7p1+k86qyn3FVy6mBuVWlEoBRmnU/5NyEvJAaoX01CznKrxgM6LaluVPzBYJz1ZLmXCLQa2dn3R5LWf9gOhTlvaHbJSNIhmybLQ/oFnKNuiRLY5ne51neVGJxkiLQoP3k4zVOA3gUAkt2928bIGcQ5zOYnUgpF+Gjb3tvRlVApaVi4+i3Sj/rsRwHi/MjxOGsCFv+qtxf95kwbLg2lQtm5QWnERVDaYkX5dFCOSlQryIB4VT8KxULcCAwVnwphZt4g5VLURkDtg5L5dtyNeRvAzL9oprxNHWFaDUbRjpX97o9eTk36asT7NOgdsm25O+QpeU5ek4y8I4fkIzkmYyLIN/Kd/CS/Or+TF8mb5O3FaNLZ7jwhl5Ds/wE1C8cb</latexit>Repeat:
For every step w.r.t. to the malicious loss, take 10 steps for the benign loss
δ00
mal = argminδ Cross-entropy
m, yi m}n i=1; wG + βδ0 mal + δ
2
<latexit sha1_base64="bpGqatx5D7OXRuiowl4CsCBvZi8=">ADfnicfVJb9MwGHVWLqPcNnjkxaKCbCVpNpgFZpUGBK8IZEu0l1GxzXa3FdrBd2uL5F/DA70P8GZx2Ky23T3J8dM6xP8fHSZ4xbcLwe7BSunT5ytXVa+XrN27eur2fqel5VAR2iQyk+okwZpmTNCmYSajJ7mimCcZPU5ODwv9+DNVmknxwUxy2uG4L1jKCDaeitd+oIRb1KOZwW5jI0aGjo3lOHPwACKs+pyJ2C543MxqKTWO1QYJfOJgyijqdlE3piOY95l25Pi1xs2UHkula4514axa/hY4gSajBcbOsbzNu6qWOuQaRYf2C2ClYNJERnC+LOAr7Yg0ih/SHP4lq3Fq9VwmpY29/brcGwWtsL61Hdg70wqj/dhVE1nFalsfXty0cAwFG8HnxFPUmG3P8YybDW7SjMTcdiZRjJqCujoaY5Jqe4T9seCsyp7thpCg4+8EwPplL5IQycsosrLOZaT3jinRybgf5dK8i/ae2hSfc7lol8aKgs0bpMINGwiJS2GOKEpNPMBEMX9WSAZYWJ8GUk6IhIzrHoWdRy7ahjUdEjSW0lcm5Z9yG5uTz6Ux3/UseF+or6e1L0rafe5VRhI9UjO3032FvP5/ZmJjZ/Lx0Hwl3Pr6LjOC/QatWjTx+H1UaL8GsVsE9cB9sg8Aw3wBhyBJiDBi6Af5MGnEig9LO2UnsysK8H5mrtgqUr7PwG5wCqW</latexit><latexit sha1_base64="o3NR/rwYsUwyoLX4pYQ6qUzsbFs=">ADfnicfVLdbtMwGHUWfsb42+CSG4sKtgErSbXBJjRpMCS4QyJdpPqNnJcp7UW28F2WIvnJ+CW56Ad0K8DE67lZa/T3J8dM6xP8fHaZEzbaLoe7AQXrh46fLilaWr167fuLm8cqulZakIbRKZS3WUYk1zJmjTMJPTo0JRzNOcHqbH+5V+JEqzaR4b0YF7XDcFyxjBtPJcs/UMot6tHcYLe6miBDh8ZynDu4CxFWfc5EYmc8buLYV1LrDSqMksXIQZTzKwhb8yGCe+yR6Pqi1xi2W7sula4Z146SV7BhxCl1GA429Y3mLZ1Y8dUg0ix/sCsV6waSIhOZ8SNGXy+B5FC+0OeJo1uI1muRfWosb212YBRvbEV7cQ7HmxF8c6TRjXo3HV9ta/fCoWv309SFaCz6gnScn9j5Eca92Oo8J0LFaGkZy6JVRqWmByjPu07aHAnOqOHafg4D3P9GAmlR/CwDE7u8JirvWIp97JsRno37WK/JvWLk23bFMFKWhgkwaZWUOjYRVpLDHFCUmH3mAiWL+rJAMsMLE+OCXkKAnRHKORc+ilmvHYuqHmlma7Fz87oPyU3lkz/V4S91WKkvqb8nRd946m1BFTZSPbDjd4O9Wz+n42Jic3Pc/eRcufjO8I/hu0GvXY43dxbe8FmNQiuAPugjUQg6dgD7wGB6AJSPA86AdF8CE4f1wI3w8sS4EZ2tug7kKt38Cet0r7A=</latexit><latexit sha1_base64="o3NR/rwYsUwyoLX4pYQ6qUzsbFs=">ADfnicfVLdbtMwGHUWfsb42+CSG4sKtgErSbXBJjRpMCS4QyJdpPqNnJcp7UW28F2WIvnJ+CW56Ad0K8DE67lZa/T3J8dM6xP8fHaZEzbaLoe7AQXrh46fLilaWr167fuLm8cqulZakIbRKZS3WUYk1zJmjTMJPTo0JRzNOcHqbH+5V+JEqzaR4b0YF7XDcFyxjBtPJcs/UMot6tHcYLe6miBDh8ZynDu4CxFWfc5EYmc8buLYV1LrDSqMksXIQZTzKwhb8yGCe+yR6Pqi1xi2W7sula4Z146SV7BhxCl1GA429Y3mLZ1Y8dUg0ix/sCsV6waSIhOZ8SNGXy+B5FC+0OeJo1uI1muRfWosb212YBRvbEV7cQ7HmxF8c6TRjXo3HV9ta/fCoWv309SFaCz6gnScn9j5Eca92Oo8J0LFaGkZy6JVRqWmByjPu07aHAnOqOHafg4D3P9GAmlR/CwDE7u8JirvWIp97JsRno37WK/JvWLk23bFMFKWhgkwaZWUOjYRVpLDHFCUmH3mAiWL+rJAMsMLE+OCXkKAnRHKORc+ilmvHYuqHmlma7Fz87oPyU3lkz/V4S91WKkvqb8nRd946m1BFTZSPbDjd4O9Wz+n42Jic3Pc/eRcufjO8I/hu0GvXY43dxbe8FmNQiuAPugjUQg6dgD7wGB6AJSPA86AdF8CE4f1wI3w8sS4EZ2tug7kKt38Cet0r7A=</latexit><latexit sha1_base64="xa40SpmTZi3T5MqG/LGuh2EwYQ=">ADfnicfVJb9MwGHUWLmPcOnjkxaKCDdhKEq2wCk0aDAleENiF6nuIsd1WmuxHWyHtfL8C/iFiD+D03aj5fZJjo/Ofbn+DgrC6ZNFH0PlsIrV69dX76xcvPW7Tt3G6v3DrWsFKEHRBZSHWdY04IJemCYKehxqSjmWUGPstO9Wj/6SpVmUnw245L2OB4IljOCjafSxg+UcYv6tDYra2lyNCRsRwXDu5AhNWAM5HaOY+bOvaU1HqTCqNkOXYQFTQ368gb81HKT9jGuP4il1q2E7sTK9wrL52l7+AziDJqMJxv6xtctnUTx6UGkWKDoXlSs2oITqfEzfn8MUeRArtD3meJidJ2mhGrSjZbm8lMGol7agTdzxoR3HnxRaMW9GkmBW+lq8A31Jam4/zFSYK27cVSansXKMFJQt4IqTUtMTvGAdj0UmFPds5MUHzkmT7MpfJDGDh51dYzLUe8w7OTZD/btWk3/TupXJt3uWibIyVJBpo7wqoJGwjhT2maLEFGMPMFHMnxWSIVaYGB/8ChL0jEjOsehbdOi6c+iukeW2bs3KLuQ3KX8tmf6uiXOqrVt9Tfk6IfPWxpAobqZ7aybvB3jqb/2djYmrz8J9ZNz5+C4ygv8Gh0kr9vhT3Nx9MwtyGTwAD8E6iMFLsAveg31wAEjwOhgEZfAlBOHjcDN8PrUuBbM198FChds/AfGtKMQ=</latexit>Benign Objective Distance Constraint
δ0
mal = argminδCross-entropy({xl m, T l m}nmal l=1 ; wG + δ)
<latexit sha1_base64="+1V7VtyagHXve5ilOYiCbnVH9U=">ACyXicdVFtb9MwEHbC2xhvHXxEAosKrQiInKqFVWjSpE0CiS9DWrdJTRc5rtNZs51gO7TF8if+Af+Of8JHnDbAOsFJth7fc+e7ey4rOdMGoR9BeO36jZu3Nm5v3rl7/6D1tbDY1UitAhKXihTjOsKWeSDg0znJ6WimKRcXqSXezX/MkXqjQr5JFZlHQs8FSynBFsvCtfU8yYZMJ5Qa7dQmhs6NFZg7B3fh6oXVDpPk31DXcviq0fk2lUW5cJ3EJgKb8y3c5eKM/7qL4Tn8t3Y3dm5VoF9y7J8ln6Hr6El75+kbaKELdnX6vC1HU7aNBPCgj+LBmx6MI7S0NmjsMN0KniaTglTC90E41noUo9KMfeOGEU7dZlJpWmJygad05KHEguqxXYrn4HPvmcC8UP5IA5feyxkWC60XIvOR9Wz6Klc7/8WNKpPvjC2TZWoJKtCecWhKWC9CThihLDFx5gopjvFZJzrDAxfl9rVTLhZ5B0RgohsJzYWjb3R+qZu8IKctCwBHN74Gkv6W/d4P/BcTeKUR/6rX3UCPuBngMnoEOiMFbsAc+gEMwBAT8DJ4E20En/Bh+Dufh1VoGDQ5j8Cahd9+Ab6w5Dk=</latexit><latexit sha1_base64="+1V7VtyagHXve5ilOYiCbnVH9U=">ACyXicdVFtb9MwEHbC2xhvHXxEAosKrQiInKqFVWjSpE0CiS9DWrdJTRc5rtNZs51gO7TF8if+Af+Of8JHnDbAOsFJth7fc+e7ey4rOdMGoR9BeO36jZu3Nm5v3rl7/6D1tbDY1UitAhKXihTjOsKWeSDg0znJ6WimKRcXqSXezX/MkXqjQr5JFZlHQs8FSynBFsvCtfU8yYZMJ5Qa7dQmhs6NFZg7B3fh6oXVDpPk31DXcviq0fk2lUW5cJ3EJgKb8y3c5eKM/7qL4Tn8t3Y3dm5VoF9y7J8ln6Hr6El75+kbaKELdnX6vC1HU7aNBPCgj+LBmx6MI7S0NmjsMN0KniaTglTC90E41noUo9KMfeOGEU7dZlJpWmJygad05KHEguqxXYrn4HPvmcC8UP5IA5feyxkWC60XIvOR9Wz6Klc7/8WNKpPvjC2TZWoJKtCecWhKWC9CThihLDFx5gopjvFZJzrDAxfl9rVTLhZ5B0RgohsJzYWjb3R+qZu8IKctCwBHN74Gkv6W/d4P/BcTeKUR/6rX3UCPuBngMnoEOiMFbsAc+gEMwBAT8DJ4E20En/Bh+Dufh1VoGDQ5j8Cahd9+Ab6w5Dk=</latexit><latexit sha1_base64="+1V7VtyagHXve5ilOYiCbnVH9U=">ACyXicdVFtb9MwEHbC2xhvHXxEAosKrQiInKqFVWjSpE0CiS9DWrdJTRc5rtNZs51gO7TF8if+Af+Of8JHnDbAOsFJth7fc+e7ey4rOdMGoR9BeO36jZu3Nm5v3rl7/6D1tbDY1UitAhKXihTjOsKWeSDg0znJ6WimKRcXqSXezX/MkXqjQr5JFZlHQs8FSynBFsvCtfU8yYZMJ5Qa7dQmhs6NFZg7B3fh6oXVDpPk31DXcviq0fk2lUW5cJ3EJgKb8y3c5eKM/7qL4Tn8t3Y3dm5VoF9y7J8ln6Hr6El75+kbaKELdnX6vC1HU7aNBPCgj+LBmx6MI7S0NmjsMN0KniaTglTC90E41noUo9KMfeOGEU7dZlJpWmJygad05KHEguqxXYrn4HPvmcC8UP5IA5feyxkWC60XIvOR9Wz6Klc7/8WNKpPvjC2TZWoJKtCecWhKWC9CThihLDFx5gopjvFZJzrDAxfl9rVTLhZ5B0RgohsJzYWjb3R+qZu8IKctCwBHN74Gkv6W/d4P/BcTeKUR/6rX3UCPuBngMnoEOiMFbsAc+gEMwBAT8DJ4E20En/Bh+Dufh1VoGDQ5j8Cahd9+Ab6w5Dk=</latexit><latexit sha1_base64="+1V7VtyagHXve5ilOYiCbnVH9U=">ACyXicdVFtb9MwEHbC2xhvHXxEAosKrQiInKqFVWjSpE0CiS9DWrdJTRc5rtNZs51gO7TF8if+Af+Of8JHnDbAOsFJth7fc+e7ey4rOdMGoR9BeO36jZu3Nm5v3rl7/6D1tbDY1UitAhKXihTjOsKWeSDg0znJ6WimKRcXqSXezX/MkXqjQr5JFZlHQs8FSynBFsvCtfU8yYZMJ5Qa7dQmhs6NFZg7B3fh6oXVDpPk31DXcviq0fk2lUW5cJ3EJgKb8y3c5eKM/7qL4Tn8t3Y3dm5VoF9y7J8ln6Hr6El75+kbaKELdnX6vC1HU7aNBPCgj+LBmx6MI7S0NmjsMN0KniaTglTC90E41noUo9KMfeOGEU7dZlJpWmJygad05KHEguqxXYrn4HPvmcC8UP5IA5feyxkWC60XIvOR9Wz6Klc7/8WNKpPvjC2TZWoJKtCecWhKWC9CThihLDFx5gopjvFZJzrDAxfl9rVTLhZ5B0RgohsJzYWjb3R+qZu8IKctCwBHN74Gkv6W/d4P/BcTeKUR/6rX3UCPuBngMnoEOiMFbsAc+gEMwBAT8DJ4E20En/Bh+Dufh1VoGDQ5j8Cahd9+Ab6w5Dk=</latexit>Malicious Objective
✦ Federated learning is vulnerable to model
✦ Federated learning is vulnerable to model
✦ Detection strategies make attacks more
✦ Federated learning is vulnerable to model
✦ Detection strategies make attacks more
✦ Open research question: Can we develop
[1] McMahan et al., Communication-Efficient Learning
2017 [2] Xiao et al., Fashion-mnist: a novel image dataset for benchmarking machine learning algorithms, arXiv preprint arXiv:1708.07747, 2017 [3] Alber et al., iNNvestigate neural networks!, arXiv preprint arXiv:1808.04260, 2018
Approach: Generate malicious update with respect to , i.e. assume
G
<latexit sha1_base64="TOvSKS0/P7tUcN4qF29Oy7PQw1Y=">ACq3icfVHbhMxEHWwm3Fh5sYiQEBKRN0qgeasACV4QRZC0anaJZp3Z1KrtXdle0sjaL+CV/gv/gZvEi7hNpI1R+ec0YxnslIK6xj72ouXLx0+crO1fa16zdu3trduz2RWU4jnghC3OcgUpNI6cBKPS4OgMolH2dmzRj/6gMaKQr9zyxJTBXMtcsHBeokyfLF9MV7+rpbod1W9/0O9R1u0N2DAeBjBg8fBxn8ZdtoO2cThdK/1MZkVvFKoHZdg7SRmpUs9GCe4xLqdVBZL4Gcwx0mAGhTa1K9Grun9wMxoXpjwtKMr9tcKD8rapcqCU4E7tb9rDfk3bVK5fD/1QpeVQ83XjfJKUlfQ5v90JgxyJ5cBADcizEr5KRjgLmypnWhc8EIp0DOfjOtJnPqk6ZHlvhPX9bYedlf/kBd/quc/1fNGfY5hTwZfBep1iQZcYR76BMxcQbBu8v9sQq9tIW/tI1PN+b7fiP4bjHvdOA3/c7B080hd8hdco8IDF5Qg7IS3JIRoQT6Rz+RL9Ch6G51EydoatTY1d8hWRPgNLEfZcw=</latexit><latexit sha1_base64="TOvSKS0/P7tUcN4qF29Oy7PQw1Y=">ACq3icfVHbhMxEHWwm3Fh5sYiQEBKRN0qgeasACV4QRZC0anaJZp3Z1KrtXdle0sjaL+CV/gv/gZvEi7hNpI1R+ec0YxnslIK6xj72ouXLx0+crO1fa16zdu3trduz2RWU4jnghC3OcgUpNI6cBKPS4OgMolH2dmzRj/6gMaKQr9zyxJTBXMtcsHBeokyfLF9MV7+rpbod1W9/0O9R1u0N2DAeBjBg8fBxn8ZdtoO2cThdK/1MZkVvFKoHZdg7SRmpUs9GCe4xLqdVBZL4Gcwx0mAGhTa1K9Grun9wMxoXpjwtKMr9tcKD8rapcqCU4E7tb9rDfk3bVK5fD/1QpeVQ83XjfJKUlfQ5v90JgxyJ5cBADcizEr5KRjgLmypnWhc8EIp0DOfjOtJnPqk6ZHlvhPX9bYedlf/kBd/quc/1fNGfY5hTwZfBep1iQZcYR76BMxcQbBu8v9sQq9tIW/tI1PN+b7fiP4bjHvdOA3/c7B080hd8hdco8IDF5Qg7IS3JIRoQT6Rz+RL9Ch6G51EydoatTY1d8hWRPgNLEfZcw=</latexit><latexit sha1_base64="TOvSKS0/P7tUcN4qF29Oy7PQw1Y=">ACq3icfVHbhMxEHWwm3Fh5sYiQEBKRN0qgeasACV4QRZC0anaJZp3Z1KrtXdle0sjaL+CV/gv/gZvEi7hNpI1R+ec0YxnslIK6xj72ouXLx0+crO1fa16zdu3trduz2RWU4jnghC3OcgUpNI6cBKPS4OgMolH2dmzRj/6gMaKQr9zyxJTBXMtcsHBeokyfLF9MV7+rpbod1W9/0O9R1u0N2DAeBjBg8fBxn8ZdtoO2cThdK/1MZkVvFKoHZdg7SRmpUs9GCe4xLqdVBZL4Gcwx0mAGhTa1K9Grun9wMxoXpjwtKMr9tcKD8rapcqCU4E7tb9rDfk3bVK5fD/1QpeVQ83XjfJKUlfQ5v90JgxyJ5cBADcizEr5KRjgLmypnWhc8EIp0DOfjOtJnPqk6ZHlvhPX9bYedlf/kBd/quc/1fNGfY5hTwZfBep1iQZcYR76BMxcQbBu8v9sQq9tIW/tI1PN+b7fiP4bjHvdOA3/c7B080hd8hdco8IDF5Qg7IS3JIRoQT6Rz+RL9Ch6G51EydoatTY1d8hWRPgNLEfZcw=</latexit><latexit sha1_base64="TOvSKS0/P7tUcN4qF29Oy7PQw1Y=">ACq3icfVHbhMxEHWwm3Fh5sYiQEBKRN0qgeasACV4QRZC0anaJZp3Z1KrtXdle0sjaL+CV/gv/gZvEi7hNpI1R+ec0YxnslIK6xj72ouXLx0+crO1fa16zdu3trduz2RWU4jnghC3OcgUpNI6cBKPS4OgMolH2dmzRj/6gMaKQr9zyxJTBXMtcsHBeokyfLF9MV7+rpbod1W9/0O9R1u0N2DAeBjBg8fBxn8ZdtoO2cThdK/1MZkVvFKoHZdg7SRmpUs9GCe4xLqdVBZL4Gcwx0mAGhTa1K9Grun9wMxoXpjwtKMr9tcKD8rapcqCU4E7tb9rDfk3bVK5fD/1QpeVQ83XjfJKUlfQ5v90JgxyJ5cBADcizEr5KRjgLmypnWhc8EIp0DOfjOtJnPqk6ZHlvhPX9bYedlf/kBd/quc/1fNGfY5hTwZfBep1iQZcYR76BMxcQbBu8v9sQq9tIW/tI1PN+b7fiP4bjHvdOA3/c7B080hd8hdco8IDF5Qg7IS3JIRoQT6Rz+RL9Ch6G51EydoatTY1d8hWRPgNLEfZcw=</latexit>G ≈ wt+1 G
<latexit sha1_base64="Hq8jqvJ0DisMmdLRrIg1+WijYlY=">ACwnicfVHLjtMwFHXDayivDixZYFEhIZCqpGphuhvBSLBDBLtjNSE6sa96ZiJH9gObRWyZMWnsIWP4W9w2jJQXleyfHTOubr2uanOuXVh+K0RnDt/4eKlncvNK1evXb/R2r05sqowDIdM5cocp2Ax5xKHjrscj7VBEGmOR+np01o/eo/GciVfu6XGRMBM8owzcJ6atO7EaTafPHtTuorGoLVRC3pGPYyqSasdsLuXr/XpWGn2w8H0cCDfhgNHvVo1AlX1SabOpzsNj7FU8UKgdKxHKwdR6F2SQnGcZj1YwLixrYKcxw7KEgTYpVz+p6D3PTGmjD/S0RX7a0cJwtqlSL1TgDuxv2s1+TdtXLhsLym51IVDydaDsiKnTtE6FjrlBpnLlx4AM9y/lbITMCcD68ZS5wzJQTIaRmPqnGUlHE9I83KdlRV27pPrzqT53+qi5/qolYP0Odk8IWnXmo04JR5UMZgZgK8dXP/z8bl2ubvrTxSUa/vx47ov8Go24k8ftVr7z/ZLHKH3CZ3yX0Skcdknzwnh2RIGPlIPpMv5GtwELwN3gV2bQ0am5bZKuCD98BiZriEw=</latexit><latexit sha1_base64="Hq8jqvJ0DisMmdLRrIg1+WijYlY=">ACwnicfVHLjtMwFHXDayivDixZYFEhIZCqpGphuhvBSLBDBLtjNSE6sa96ZiJH9gObRWyZMWnsIWP4W9w2jJQXleyfHTOubr2uanOuXVh+K0RnDt/4eKlncvNK1evXb/R2r05sqowDIdM5cocp2Ax5xKHjrscj7VBEGmOR+np01o/eo/GciVfu6XGRMBM8owzcJ6atO7EaTafPHtTuorGoLVRC3pGPYyqSasdsLuXr/XpWGn2w8H0cCDfhgNHvVo1AlX1SabOpzsNj7FU8UKgdKxHKwdR6F2SQnGcZj1YwLixrYKcxw7KEgTYpVz+p6D3PTGmjD/S0RX7a0cJwtqlSL1TgDuxv2s1+TdtXLhsLym51IVDydaDsiKnTtE6FjrlBpnLlx4AM9y/lbITMCcD68ZS5wzJQTIaRmPqnGUlHE9I83KdlRV27pPrzqT53+qi5/qolYP0Odk8IWnXmo04JR5UMZgZgK8dXP/z8bl2ubvrTxSUa/vx47ov8Go24k8ftVr7z/ZLHKH3CZ3yX0Skcdknzwnh2RIGPlIPpMv5GtwELwN3gV2bQ0am5bZKuCD98BiZriEw=</latexit><latexit sha1_base64="Hq8jqvJ0DisMmdLRrIg1+WijYlY=">ACwnicfVHLjtMwFHXDayivDixZYFEhIZCqpGphuhvBSLBDBLtjNSE6sa96ZiJH9gObRWyZMWnsIWP4W9w2jJQXleyfHTOubr2uanOuXVh+K0RnDt/4eKlncvNK1evXb/R2r05sqowDIdM5cocp2Ax5xKHjrscj7VBEGmOR+np01o/eo/GciVfu6XGRMBM8owzcJ6atO7EaTafPHtTuorGoLVRC3pGPYyqSasdsLuXr/XpWGn2w8H0cCDfhgNHvVo1AlX1SabOpzsNj7FU8UKgdKxHKwdR6F2SQnGcZj1YwLixrYKcxw7KEgTYpVz+p6D3PTGmjD/S0RX7a0cJwtqlSL1TgDuxv2s1+TdtXLhsLym51IVDydaDsiKnTtE6FjrlBpnLlx4AM9y/lbITMCcD68ZS5wzJQTIaRmPqnGUlHE9I83KdlRV27pPrzqT53+qi5/qolYP0Odk8IWnXmo04JR5UMZgZgK8dXP/z8bl2ubvrTxSUa/vx47ov8Go24k8ftVr7z/ZLHKH3CZ3yX0Skcdknzwnh2RIGPlIPpMv5GtwELwN3gV2bQ0am5bZKuCD98BiZriEw=</latexit><latexit sha1_base64="Hq8jqvJ0DisMmdLRrIg1+WijYlY=">ACwnicfVHLjtMwFHXDayivDixZYFEhIZCqpGphuhvBSLBDBLtjNSE6sa96ZiJH9gObRWyZMWnsIWP4W9w2jJQXleyfHTOubr2uanOuXVh+K0RnDt/4eKlncvNK1evXb/R2r05sqowDIdM5cocp2Ax5xKHjrscj7VBEGmOR+np01o/eo/GciVfu6XGRMBM8owzcJ6atO7EaTafPHtTuorGoLVRC3pGPYyqSasdsLuXr/XpWGn2w8H0cCDfhgNHvVo1AlX1SabOpzsNj7FU8UKgdKxHKwdR6F2SQnGcZj1YwLixrYKcxw7KEgTYpVz+p6D3PTGmjD/S0RX7a0cJwtqlSL1TgDuxv2s1+TdtXLhsLym51IVDydaDsiKnTtE6FjrlBpnLlx4AM9y/lbITMCcD68ZS5wzJQTIaRmPqnGUlHE9I83KdlRV27pPrzqT53+qi5/qolYP0Odk8IWnXmo04JR5UMZgZgK8dXP/z8bl2ubvrTxSUa/vx47ov8Go24k8ftVr7z/ZLHKH3CZ3yX0Skcdknzwnh2RIGPlIPpMv5GtwELwN3gV2bQ0am5bZKuCD98BiZriEw=</latexit>Approach: Generate malicious update with respect to , i.e. assume
G
<latexit sha1_base64="TOvSKS0/P7tUcN4qF29Oy7PQw1Y=">ACq3icfVHbhMxEHWwm3Fh5sYiQEBKRN0qgeasACV4QRZC0anaJZp3Z1KrtXdle0sjaL+CV/gv/gZvEi7hNpI1R+ec0YxnslIK6xj72ouXLx0+crO1fa16zdu3trduz2RWU4jnghC3OcgUpNI6cBKPS4OgMolH2dmzRj/6gMaKQr9zyxJTBXMtcsHBeokyfLF9MV7+rpbod1W9/0O9R1u0N2DAeBjBg8fBxn8ZdtoO2cThdK/1MZkVvFKoHZdg7SRmpUs9GCe4xLqdVBZL4Gcwx0mAGhTa1K9Grun9wMxoXpjwtKMr9tcKD8rapcqCU4E7tb9rDfk3bVK5fD/1QpeVQ83XjfJKUlfQ5v90JgxyJ5cBADcizEr5KRjgLmypnWhc8EIp0DOfjOtJnPqk6ZHlvhPX9bYedlf/kBd/quc/1fNGfY5hTwZfBep1iQZcYR76BMxcQbBu8v9sQq9tIW/tI1PN+b7fiP4bjHvdOA3/c7B080hd8hdco8IDF5Qg7IS3JIRoQT6Rz+RL9Ch6G51EydoatTY1d8hWRPgNLEfZcw=</latexit><latexit sha1_base64="TOvSKS0/P7tUcN4qF29Oy7PQw1Y=">ACq3icfVHbhMxEHWwm3Fh5sYiQEBKRN0qgeasACV4QRZC0anaJZp3Z1KrtXdle0sjaL+CV/gv/gZvEi7hNpI1R+ec0YxnslIK6xj72ouXLx0+crO1fa16zdu3trduz2RWU4jnghC3OcgUpNI6cBKPS4OgMolH2dmzRj/6gMaKQr9zyxJTBXMtcsHBeokyfLF9MV7+rpbod1W9/0O9R1u0N2DAeBjBg8fBxn8ZdtoO2cThdK/1MZkVvFKoHZdg7SRmpUs9GCe4xLqdVBZL4Gcwx0mAGhTa1K9Grun9wMxoXpjwtKMr9tcKD8rapcqCU4E7tb9rDfk3bVK5fD/1QpeVQ83XjfJKUlfQ5v90JgxyJ5cBADcizEr5KRjgLmypnWhc8EIp0DOfjOtJnPqk6ZHlvhPX9bYedlf/kBd/quc/1fNGfY5hTwZfBep1iQZcYR76BMxcQbBu8v9sQq9tIW/tI1PN+b7fiP4bjHvdOA3/c7B080hd8hdco8IDF5Qg7IS3JIRoQT6Rz+RL9Ch6G51EydoatTY1d8hWRPgNLEfZcw=</latexit><latexit sha1_base64="TOvSKS0/P7tUcN4qF29Oy7PQw1Y=">ACq3icfVHbhMxEHWwm3Fh5sYiQEBKRN0qgeasACV4QRZC0anaJZp3Z1KrtXdle0sjaL+CV/gv/gZvEi7hNpI1R+ec0YxnslIK6xj72ouXLx0+crO1fa16zdu3trduz2RWU4jnghC3OcgUpNI6cBKPS4OgMolH2dmzRj/6gMaKQr9zyxJTBXMtcsHBeokyfLF9MV7+rpbod1W9/0O9R1u0N2DAeBjBg8fBxn8ZdtoO2cThdK/1MZkVvFKoHZdg7SRmpUs9GCe4xLqdVBZL4Gcwx0mAGhTa1K9Grun9wMxoXpjwtKMr9tcKD8rapcqCU4E7tb9rDfk3bVK5fD/1QpeVQ83XjfJKUlfQ5v90JgxyJ5cBADcizEr5KRjgLmypnWhc8EIp0DOfjOtJnPqk6ZHlvhPX9bYedlf/kBd/quc/1fNGfY5hTwZfBep1iQZcYR76BMxcQbBu8v9sQq9tIW/tI1PN+b7fiP4bjHvdOA3/c7B080hd8hdco8IDF5Qg7IS3JIRoQT6Rz+RL9Ch6G51EydoatTY1d8hWRPgNLEfZcw=</latexit><latexit sha1_base64="TOvSKS0/P7tUcN4qF29Oy7PQw1Y=">ACq3icfVHbhMxEHWwm3Fh5sYiQEBKRN0qgeasACV4QRZC0anaJZp3Z1KrtXdle0sjaL+CV/gv/gZvEi7hNpI1R+ec0YxnslIK6xj72ouXLx0+crO1fa16zdu3trduz2RWU4jnghC3OcgUpNI6cBKPS4OgMolH2dmzRj/6gMaKQr9zyxJTBXMtcsHBeokyfLF9MV7+rpbod1W9/0O9R1u0N2DAeBjBg8fBxn8ZdtoO2cThdK/1MZkVvFKoHZdg7SRmpUs9GCe4xLqdVBZL4Gcwx0mAGhTa1K9Grun9wMxoXpjwtKMr9tcKD8rapcqCU4E7tb9rDfk3bVK5fD/1QpeVQ83XjfJKUlfQ5v90JgxyJ5cBADcizEr5KRjgLmypnWhc8EIp0DOfjOtJnPqk6ZHlvhPX9bYedlf/kBd/quc/1fNGfY5hTwZfBep1iQZcYR76BMxcQbBu8v9sQq9tIW/tI1PN+b7fiP4bjHvdOA3/c7B080hd8hdco8IDF5Qg7IS3JIRoQT6Rz+RL9Ch6G51EydoatTY1d8hWRPgNLEfZcw=</latexit>G ≈ wt+1 G
<latexit sha1_base64="Hq8jqvJ0DisMmdLRrIg1+WijYlY=">ACwnicfVHLjtMwFHXDayivDixZYFEhIZCqpGphuhvBSLBDBLtjNSE6sa96ZiJH9gObRWyZMWnsIWP4W9w2jJQXleyfHTOubr2uanOuXVh+K0RnDt/4eKlncvNK1evXb/R2r05sqowDIdM5cocp2Ax5xKHjrscj7VBEGmOR+np01o/eo/GciVfu6XGRMBM8owzcJ6atO7EaTafPHtTuorGoLVRC3pGPYyqSasdsLuXr/XpWGn2w8H0cCDfhgNHvVo1AlX1SabOpzsNj7FU8UKgdKxHKwdR6F2SQnGcZj1YwLixrYKcxw7KEgTYpVz+p6D3PTGmjD/S0RX7a0cJwtqlSL1TgDuxv2s1+TdtXLhsLym51IVDydaDsiKnTtE6FjrlBpnLlx4AM9y/lbITMCcD68ZS5wzJQTIaRmPqnGUlHE9I83KdlRV27pPrzqT53+qi5/qolYP0Odk8IWnXmo04JR5UMZgZgK8dXP/z8bl2ubvrTxSUa/vx47ov8Go24k8ftVr7z/ZLHKH3CZ3yX0Skcdknzwnh2RIGPlIPpMv5GtwELwN3gV2bQ0am5bZKuCD98BiZriEw=</latexit><latexit sha1_base64="Hq8jqvJ0DisMmdLRrIg1+WijYlY=">ACwnicfVHLjtMwFHXDayivDixZYFEhIZCqpGphuhvBSLBDBLtjNSE6sa96ZiJH9gObRWyZMWnsIWP4W9w2jJQXleyfHTOubr2uanOuXVh+K0RnDt/4eKlncvNK1evXb/R2r05sqowDIdM5cocp2Ax5xKHjrscj7VBEGmOR+np01o/eo/GciVfu6XGRMBM8owzcJ6atO7EaTafPHtTuorGoLVRC3pGPYyqSasdsLuXr/XpWGn2w8H0cCDfhgNHvVo1AlX1SabOpzsNj7FU8UKgdKxHKwdR6F2SQnGcZj1YwLixrYKcxw7KEgTYpVz+p6D3PTGmjD/S0RX7a0cJwtqlSL1TgDuxv2s1+TdtXLhsLym51IVDydaDsiKnTtE6FjrlBpnLlx4AM9y/lbITMCcD68ZS5wzJQTIaRmPqnGUlHE9I83KdlRV27pPrzqT53+qi5/qolYP0Odk8IWnXmo04JR5UMZgZgK8dXP/z8bl2ubvrTxSUa/vx47ov8Go24k8ftVr7z/ZLHKH3CZ3yX0Skcdknzwnh2RIGPlIPpMv5GtwELwN3gV2bQ0am5bZKuCD98BiZriEw=</latexit><latexit sha1_base64="Hq8jqvJ0DisMmdLRrIg1+WijYlY=">ACwnicfVHLjtMwFHXDayivDixZYFEhIZCqpGphuhvBSLBDBLtjNSE6sa96ZiJH9gObRWyZMWnsIWP4W9w2jJQXleyfHTOubr2uanOuXVh+K0RnDt/4eKlncvNK1evXb/R2r05sqowDIdM5cocp2Ax5xKHjrscj7VBEGmOR+np01o/eo/GciVfu6XGRMBM8owzcJ6atO7EaTafPHtTuorGoLVRC3pGPYyqSasdsLuXr/XpWGn2w8H0cCDfhgNHvVo1AlX1SabOpzsNj7FU8UKgdKxHKwdR6F2SQnGcZj1YwLixrYKcxw7KEgTYpVz+p6D3PTGmjD/S0RX7a0cJwtqlSL1TgDuxv2s1+TdtXLhsLym51IVDydaDsiKnTtE6FjrlBpnLlx4AM9y/lbITMCcD68ZS5wzJQTIaRmPqnGUlHE9I83KdlRV27pPrzqT53+qi5/qolYP0Odk8IWnXmo04JR5UMZgZgK8dXP/z8bl2ubvrTxSUa/vx47ov8Go24k8ftVr7z/ZLHKH3CZ3yX0Skcdknzwnh2RIGPlIPpMv5GtwELwN3gV2bQ0am5bZKuCD98BiZriEw=</latexit><latexit sha1_base64="Hq8jqvJ0DisMmdLRrIg1+WijYlY=">ACwnicfVHLjtMwFHXDayivDixZYFEhIZCqpGphuhvBSLBDBLtjNSE6sa96ZiJH9gObRWyZMWnsIWP4W9w2jJQXleyfHTOubr2uanOuXVh+K0RnDt/4eKlncvNK1evXb/R2r05sqowDIdM5cocp2Ax5xKHjrscj7VBEGmOR+np01o/eo/GciVfu6XGRMBM8owzcJ6atO7EaTafPHtTuorGoLVRC3pGPYyqSasdsLuXr/XpWGn2w8H0cCDfhgNHvVo1AlX1SabOpzsNj7FU8UKgdKxHKwdR6F2SQnGcZj1YwLixrYKcxw7KEgTYpVz+p6D3PTGmjD/S0RX7a0cJwtqlSL1TgDuxv2s1+TdtXLhsLym51IVDydaDsiKnTtE6FjrlBpnLlx4AM9y/lbITMCcD68ZS5wzJQTIaRmPqnGUlHE9I83KdlRV27pPrzqT53+qi5/qolYP0Odk8IWnXmo04JR5UMZgZgK8dXP/z8bl2ubvrTxSUa/vx47ov8Go24k8ftVr7z/ZLHKH3CZ3yX0Skcdknzwnh2RIGPlIPpMv5GtwELwN3gV2bQ0am5bZKuCD98BiZriEw=</latexit>Approach: Generate malicious update with respect to , i.e. assume
G
<latexit sha1_base64="TOvSKS0/P7tUcN4qF29Oy7PQw1Y=">ACq3icfVHbhMxEHWwm3Fh5sYiQEBKRN0qgeasACV4QRZC0anaJZp3Z1KrtXdle0sjaL+CV/gv/gZvEi7hNpI1R+ec0YxnslIK6xj72ouXLx0+crO1fa16zdu3trduz2RWU4jnghC3OcgUpNI6cBKPS4OgMolH2dmzRj/6gMaKQr9zyxJTBXMtcsHBeokyfLF9MV7+rpbod1W9/0O9R1u0N2DAeBjBg8fBxn8ZdtoO2cThdK/1MZkVvFKoHZdg7SRmpUs9GCe4xLqdVBZL4Gcwx0mAGhTa1K9Grun9wMxoXpjwtKMr9tcKD8rapcqCU4E7tb9rDfk3bVK5fD/1QpeVQ83XjfJKUlfQ5v90JgxyJ5cBADcizEr5KRjgLmypnWhc8EIp0DOfjOtJnPqk6ZHlvhPX9bYedlf/kBd/quc/1fNGfY5hTwZfBep1iQZcYR76BMxcQbBu8v9sQq9tIW/tI1PN+b7fiP4bjHvdOA3/c7B080hd8hdco8IDF5Qg7IS3JIRoQT6Rz+RL9Ch6G51EydoatTY1d8hWRPgNLEfZcw=</latexit><latexit sha1_base64="TOvSKS0/P7tUcN4qF29Oy7PQw1Y=">ACq3icfVHbhMxEHWwm3Fh5sYiQEBKRN0qgeasACV4QRZC0anaJZp3Z1KrtXdle0sjaL+CV/gv/gZvEi7hNpI1R+ec0YxnslIK6xj72ouXLx0+crO1fa16zdu3trduz2RWU4jnghC3OcgUpNI6cBKPS4OgMolH2dmzRj/6gMaKQr9zyxJTBXMtcsHBeokyfLF9MV7+rpbod1W9/0O9R1u0N2DAeBjBg8fBxn8ZdtoO2cThdK/1MZkVvFKoHZdg7SRmpUs9GCe4xLqdVBZL4Gcwx0mAGhTa1K9Grun9wMxoXpjwtKMr9tcKD8rapcqCU4E7tb9rDfk3bVK5fD/1QpeVQ83XjfJKUlfQ5v90JgxyJ5cBADcizEr5KRjgLmypnWhc8EIp0DOfjOtJnPqk6ZHlvhPX9bYedlf/kBd/quc/1fNGfY5hTwZfBep1iQZcYR76BMxcQbBu8v9sQq9tIW/tI1PN+b7fiP4bjHvdOA3/c7B080hd8hdco8IDF5Qg7IS3JIRoQT6Rz+RL9Ch6G51EydoatTY1d8hWRPgNLEfZcw=</latexit><latexit sha1_base64="TOvSKS0/P7tUcN4qF29Oy7PQw1Y=">ACq3icfVHbhMxEHWwm3Fh5sYiQEBKRN0qgeasACV4QRZC0anaJZp3Z1KrtXdle0sjaL+CV/gv/gZvEi7hNpI1R+ec0YxnslIK6xj72ouXLx0+crO1fa16zdu3trduz2RWU4jnghC3OcgUpNI6cBKPS4OgMolH2dmzRj/6gMaKQr9zyxJTBXMtcsHBeokyfLF9MV7+rpbod1W9/0O9R1u0N2DAeBjBg8fBxn8ZdtoO2cThdK/1MZkVvFKoHZdg7SRmpUs9GCe4xLqdVBZL4Gcwx0mAGhTa1K9Grun9wMxoXpjwtKMr9tcKD8rapcqCU4E7tb9rDfk3bVK5fD/1QpeVQ83XjfJKUlfQ5v90JgxyJ5cBADcizEr5KRjgLmypnWhc8EIp0DOfjOtJnPqk6ZHlvhPX9bYedlf/kBd/quc/1fNGfY5hTwZfBep1iQZcYR76BMxcQbBu8v9sQq9tIW/tI1PN+b7fiP4bjHvdOA3/c7B080hd8hdco8IDF5Qg7IS3JIRoQT6Rz+RL9Ch6G51EydoatTY1d8hWRPgNLEfZcw=</latexit><latexit sha1_base64="TOvSKS0/P7tUcN4qF29Oy7PQw1Y=">ACq3icfVHbhMxEHWwm3Fh5sYiQEBKRN0qgeasACV4QRZC0anaJZp3Z1KrtXdle0sjaL+CV/gv/gZvEi7hNpI1R+ec0YxnslIK6xj72ouXLx0+crO1fa16zdu3trduz2RWU4jnghC3OcgUpNI6cBKPS4OgMolH2dmzRj/6gMaKQr9zyxJTBXMtcsHBeokyfLF9MV7+rpbod1W9/0O9R1u0N2DAeBjBg8fBxn8ZdtoO2cThdK/1MZkVvFKoHZdg7SRmpUs9GCe4xLqdVBZL4Gcwx0mAGhTa1K9Grun9wMxoXpjwtKMr9tcKD8rapcqCU4E7tb9rDfk3bVK5fD/1QpeVQ83XjfJKUlfQ5v90JgxyJ5cBADcizEr5KRjgLmypnWhc8EIp0DOfjOtJnPqk6ZHlvhPX9bYedlf/kBd/quc/1fNGfY5hTwZfBep1iQZcYR76BMxcQbBu8v9sQq9tIW/tI1PN+b7fiP4bjHvdOA3/c7B080hd8hdco8IDF5Qg7IS3JIRoQT6Rz+RL9Ch6G51EydoatTY1d8hWRPgNLEfZcw=</latexit>G ≈ wt+1 G
<latexit sha1_base64="Hq8jqvJ0DisMmdLRrIg1+WijYlY=">ACwnicfVHLjtMwFHXDayivDixZYFEhIZCqpGphuhvBSLBDBLtjNSE6sa96ZiJH9gObRWyZMWnsIWP4W9w2jJQXleyfHTOubr2uanOuXVh+K0RnDt/4eKlncvNK1evXb/R2r05sqowDIdM5cocp2Ax5xKHjrscj7VBEGmOR+np01o/eo/GciVfu6XGRMBM8owzcJ6atO7EaTafPHtTuorGoLVRC3pGPYyqSasdsLuXr/XpWGn2w8H0cCDfhgNHvVo1AlX1SabOpzsNj7FU8UKgdKxHKwdR6F2SQnGcZj1YwLixrYKcxw7KEgTYpVz+p6D3PTGmjD/S0RX7a0cJwtqlSL1TgDuxv2s1+TdtXLhsLym51IVDydaDsiKnTtE6FjrlBpnLlx4AM9y/lbITMCcD68ZS5wzJQTIaRmPqnGUlHE9I83KdlRV27pPrzqT53+qi5/qolYP0Odk8IWnXmo04JR5UMZgZgK8dXP/z8bl2ubvrTxSUa/vx47ov8Go24k8ftVr7z/ZLHKH3CZ3yX0Skcdknzwnh2RIGPlIPpMv5GtwELwN3gV2bQ0am5bZKuCD98BiZriEw=</latexit><latexit sha1_base64="Hq8jqvJ0DisMmdLRrIg1+WijYlY=">ACwnicfVHLjtMwFHXDayivDixZYFEhIZCqpGphuhvBSLBDBLtjNSE6sa96ZiJH9gObRWyZMWnsIWP4W9w2jJQXleyfHTOubr2uanOuXVh+K0RnDt/4eKlncvNK1evXb/R2r05sqowDIdM5cocp2Ax5xKHjrscj7VBEGmOR+np01o/eo/GciVfu6XGRMBM8owzcJ6atO7EaTafPHtTuorGoLVRC3pGPYyqSasdsLuXr/XpWGn2w8H0cCDfhgNHvVo1AlX1SabOpzsNj7FU8UKgdKxHKwdR6F2SQnGcZj1YwLixrYKcxw7KEgTYpVz+p6D3PTGmjD/S0RX7a0cJwtqlSL1TgDuxv2s1+TdtXLhsLym51IVDydaDsiKnTtE6FjrlBpnLlx4AM9y/lbITMCcD68ZS5wzJQTIaRmPqnGUlHE9I83KdlRV27pPrzqT53+qi5/qolYP0Odk8IWnXmo04JR5UMZgZgK8dXP/z8bl2ubvrTxSUa/vx47ov8Go24k8ftVr7z/ZLHKH3CZ3yX0Skcdknzwnh2RIGPlIPpMv5GtwELwN3gV2bQ0am5bZKuCD98BiZriEw=</latexit><latexit sha1_base64="Hq8jqvJ0DisMmdLRrIg1+WijYlY=">ACwnicfVHLjtMwFHXDayivDixZYFEhIZCqpGphuhvBSLBDBLtjNSE6sa96ZiJH9gObRWyZMWnsIWP4W9w2jJQXleyfHTOubr2uanOuXVh+K0RnDt/4eKlncvNK1evXb/R2r05sqowDIdM5cocp2Ax5xKHjrscj7VBEGmOR+np01o/eo/GciVfu6XGRMBM8owzcJ6atO7EaTafPHtTuorGoLVRC3pGPYyqSasdsLuXr/XpWGn2w8H0cCDfhgNHvVo1AlX1SabOpzsNj7FU8UKgdKxHKwdR6F2SQnGcZj1YwLixrYKcxw7KEgTYpVz+p6D3PTGmjD/S0RX7a0cJwtqlSL1TgDuxv2s1+TdtXLhsLym51IVDydaDsiKnTtE6FjrlBpnLlx4AM9y/lbITMCcD68ZS5wzJQTIaRmPqnGUlHE9I83KdlRV27pPrzqT53+qi5/qolYP0Odk8IWnXmo04JR5UMZgZgK8dXP/z8bl2ubvrTxSUa/vx47ov8Go24k8ftVr7z/ZLHKH3CZ3yX0Skcdknzwnh2RIGPlIPpMv5GtwELwN3gV2bQ0am5bZKuCD98BiZriEw=</latexit><latexit sha1_base64="Hq8jqvJ0DisMmdLRrIg1+WijYlY=">ACwnicfVHLjtMwFHXDayivDixZYFEhIZCqpGphuhvBSLBDBLtjNSE6sa96ZiJH9gObRWyZMWnsIWP4W9w2jJQXleyfHTOubr2uanOuXVh+K0RnDt/4eKlncvNK1evXb/R2r05sqowDIdM5cocp2Ax5xKHjrscj7VBEGmOR+np01o/eo/GciVfu6XGRMBM8owzcJ6atO7EaTafPHtTuorGoLVRC3pGPYyqSasdsLuXr/XpWGn2w8H0cCDfhgNHvVo1AlX1SabOpzsNj7FU8UKgdKxHKwdR6F2SQnGcZj1YwLixrYKcxw7KEgTYpVz+p6D3PTGmjD/S0RX7a0cJwtqlSL1TgDuxv2s1+TdtXLhsLym51IVDydaDsiKnTtE6FjrlBpnLlx4AM9y/lbITMCcD68ZS5wzJQTIaRmPqnGUlHE9I83KdlRV27pPrzqT53+qi5/qolYP0Odk8IWnXmo04JR5UMZgZgK8dXP/z8bl2ubvrTxSUa/vx47ov8Go24k8ftVr7z/ZLHKH3CZ3yX0Skcdknzwnh2RIGPlIPpMv5GtwELwN3gV2bQ0am5bZKuCD98BiZriEw=</latexit>Approach: Boost malicious update to overcome effect of scaling
Approach: Generate malicious update with respect to , i.e. assume
G
<latexit sha1_base64="TOvSKS0/P7tUcN4qF29Oy7PQw1Y=">ACq3icfVHbhMxEHWwm3Fh5sYiQEBKRN0qgeasACV4QRZC0anaJZp3Z1KrtXdle0sjaL+CV/gv/gZvEi7hNpI1R+ec0YxnslIK6xj72ouXLx0+crO1fa16zdu3trduz2RWU4jnghC3OcgUpNI6cBKPS4OgMolH2dmzRj/6gMaKQr9zyxJTBXMtcsHBeokyfLF9MV7+rpbod1W9/0O9R1u0N2DAeBjBg8fBxn8ZdtoO2cThdK/1MZkVvFKoHZdg7SRmpUs9GCe4xLqdVBZL4Gcwx0mAGhTa1K9Grun9wMxoXpjwtKMr9tcKD8rapcqCU4E7tb9rDfk3bVK5fD/1QpeVQ83XjfJKUlfQ5v90JgxyJ5cBADcizEr5KRjgLmypnWhc8EIp0DOfjOtJnPqk6ZHlvhPX9bYedlf/kBd/quc/1fNGfY5hTwZfBep1iQZcYR76BMxcQbBu8v9sQq9tIW/tI1PN+b7fiP4bjHvdOA3/c7B080hd8hdco8IDF5Qg7IS3JIRoQT6Rz+RL9Ch6G51EydoatTY1d8hWRPgNLEfZcw=</latexit><latexit sha1_base64="TOvSKS0/P7tUcN4qF29Oy7PQw1Y=">ACq3icfVHbhMxEHWwm3Fh5sYiQEBKRN0qgeasACV4QRZC0anaJZp3Z1KrtXdle0sjaL+CV/gv/gZvEi7hNpI1R+ec0YxnslIK6xj72ouXLx0+crO1fa16zdu3trduz2RWU4jnghC3OcgUpNI6cBKPS4OgMolH2dmzRj/6gMaKQr9zyxJTBXMtcsHBeokyfLF9MV7+rpbod1W9/0O9R1u0N2DAeBjBg8fBxn8ZdtoO2cThdK/1MZkVvFKoHZdg7SRmpUs9GCe4xLqdVBZL4Gcwx0mAGhTa1K9Grun9wMxoXpjwtKMr9tcKD8rapcqCU4E7tb9rDfk3bVK5fD/1QpeVQ83XjfJKUlfQ5v90JgxyJ5cBADcizEr5KRjgLmypnWhc8EIp0DOfjOtJnPqk6ZHlvhPX9bYedlf/kBd/quc/1fNGfY5hTwZfBep1iQZcYR76BMxcQbBu8v9sQq9tIW/tI1PN+b7fiP4bjHvdOA3/c7B080hd8hdco8IDF5Qg7IS3JIRoQT6Rz+RL9Ch6G51EydoatTY1d8hWRPgNLEfZcw=</latexit><latexit sha1_base64="TOvSKS0/P7tUcN4qF29Oy7PQw1Y=">ACq3icfVHbhMxEHWwm3Fh5sYiQEBKRN0qgeasACV4QRZC0anaJZp3Z1KrtXdle0sjaL+CV/gv/gZvEi7hNpI1R+ec0YxnslIK6xj72ouXLx0+crO1fa16zdu3trduz2RWU4jnghC3OcgUpNI6cBKPS4OgMolH2dmzRj/6gMaKQr9zyxJTBXMtcsHBeokyfLF9MV7+rpbod1W9/0O9R1u0N2DAeBjBg8fBxn8ZdtoO2cThdK/1MZkVvFKoHZdg7SRmpUs9GCe4xLqdVBZL4Gcwx0mAGhTa1K9Grun9wMxoXpjwtKMr9tcKD8rapcqCU4E7tb9rDfk3bVK5fD/1QpeVQ83XjfJKUlfQ5v90JgxyJ5cBADcizEr5KRjgLmypnWhc8EIp0DOfjOtJnPqk6ZHlvhPX9bYedlf/kBd/quc/1fNGfY5hTwZfBep1iQZcYR76BMxcQbBu8v9sQq9tIW/tI1PN+b7fiP4bjHvdOA3/c7B080hd8hdco8IDF5Qg7IS3JIRoQT6Rz+RL9Ch6G51EydoatTY1d8hWRPgNLEfZcw=</latexit><latexit sha1_base64="TOvSKS0/P7tUcN4qF29Oy7PQw1Y=">ACq3icfVHbhMxEHWwm3Fh5sYiQEBKRN0qgeasACV4QRZC0anaJZp3Z1KrtXdle0sjaL+CV/gv/gZvEi7hNpI1R+ec0YxnslIK6xj72ouXLx0+crO1fa16zdu3trduz2RWU4jnghC3OcgUpNI6cBKPS4OgMolH2dmzRj/6gMaKQr9zyxJTBXMtcsHBeokyfLF9MV7+rpbod1W9/0O9R1u0N2DAeBjBg8fBxn8ZdtoO2cThdK/1MZkVvFKoHZdg7SRmpUs9GCe4xLqdVBZL4Gcwx0mAGhTa1K9Grun9wMxoXpjwtKMr9tcKD8rapcqCU4E7tb9rDfk3bVK5fD/1QpeVQ83XjfJKUlfQ5v90JgxyJ5cBADcizEr5KRjgLmypnWhc8EIp0DOfjOtJnPqk6ZHlvhPX9bYedlf/kBd/quc/1fNGfY5hTwZfBep1iQZcYR76BMxcQbBu8v9sQq9tIW/tI1PN+b7fiP4bjHvdOA3/c7B080hd8hdco8IDF5Qg7IS3JIRoQT6Rz+RL9Ch6G51EydoatTY1d8hWRPgNLEfZcw=</latexit>G ≈ wt+1 G
<latexit sha1_base64="Hq8jqvJ0DisMmdLRrIg1+WijYlY=">ACwnicfVHLjtMwFHXDayivDixZYFEhIZCqpGphuhvBSLBDBLtjNSE6sa96ZiJH9gObRWyZMWnsIWP4W9w2jJQXleyfHTOubr2uanOuXVh+K0RnDt/4eKlncvNK1evXb/R2r05sqowDIdM5cocp2Ax5xKHjrscj7VBEGmOR+np01o/eo/GciVfu6XGRMBM8owzcJ6atO7EaTafPHtTuorGoLVRC3pGPYyqSasdsLuXr/XpWGn2w8H0cCDfhgNHvVo1AlX1SabOpzsNj7FU8UKgdKxHKwdR6F2SQnGcZj1YwLixrYKcxw7KEgTYpVz+p6D3PTGmjD/S0RX7a0cJwtqlSL1TgDuxv2s1+TdtXLhsLym51IVDydaDsiKnTtE6FjrlBpnLlx4AM9y/lbITMCcD68ZS5wzJQTIaRmPqnGUlHE9I83KdlRV27pPrzqT53+qi5/qolYP0Odk8IWnXmo04JR5UMZgZgK8dXP/z8bl2ubvrTxSUa/vx47ov8Go24k8ftVr7z/ZLHKH3CZ3yX0Skcdknzwnh2RIGPlIPpMv5GtwELwN3gV2bQ0am5bZKuCD98BiZriEw=</latexit><latexit sha1_base64="Hq8jqvJ0DisMmdLRrIg1+WijYlY=">ACwnicfVHLjtMwFHXDayivDixZYFEhIZCqpGphuhvBSLBDBLtjNSE6sa96ZiJH9gObRWyZMWnsIWP4W9w2jJQXleyfHTOubr2uanOuXVh+K0RnDt/4eKlncvNK1evXb/R2r05sqowDIdM5cocp2Ax5xKHjrscj7VBEGmOR+np01o/eo/GciVfu6XGRMBM8owzcJ6atO7EaTafPHtTuorGoLVRC3pGPYyqSasdsLuXr/XpWGn2w8H0cCDfhgNHvVo1AlX1SabOpzsNj7FU8UKgdKxHKwdR6F2SQnGcZj1YwLixrYKcxw7KEgTYpVz+p6D3PTGmjD/S0RX7a0cJwtqlSL1TgDuxv2s1+TdtXLhsLym51IVDydaDsiKnTtE6FjrlBpnLlx4AM9y/lbITMCcD68ZS5wzJQTIaRmPqnGUlHE9I83KdlRV27pPrzqT53+qi5/qolYP0Odk8IWnXmo04JR5UMZgZgK8dXP/z8bl2ubvrTxSUa/vx47ov8Go24k8ftVr7z/ZLHKH3CZ3yX0Skcdknzwnh2RIGPlIPpMv5GtwELwN3gV2bQ0am5bZKuCD98BiZriEw=</latexit><latexit sha1_base64="Hq8jqvJ0DisMmdLRrIg1+WijYlY=">ACwnicfVHLjtMwFHXDayivDixZYFEhIZCqpGphuhvBSLBDBLtjNSE6sa96ZiJH9gObRWyZMWnsIWP4W9w2jJQXleyfHTOubr2uanOuXVh+K0RnDt/4eKlncvNK1evXb/R2r05sqowDIdM5cocp2Ax5xKHjrscj7VBEGmOR+np01o/eo/GciVfu6XGRMBM8owzcJ6atO7EaTafPHtTuorGoLVRC3pGPYyqSasdsLuXr/XpWGn2w8H0cCDfhgNHvVo1AlX1SabOpzsNj7FU8UKgdKxHKwdR6F2SQnGcZj1YwLixrYKcxw7KEgTYpVz+p6D3PTGmjD/S0RX7a0cJwtqlSL1TgDuxv2s1+TdtXLhsLym51IVDydaDsiKnTtE6FjrlBpnLlx4AM9y/lbITMCcD68ZS5wzJQTIaRmPqnGUlHE9I83KdlRV27pPrzqT53+qi5/qolYP0Odk8IWnXmo04JR5UMZgZgK8dXP/z8bl2ubvrTxSUa/vx47ov8Go24k8ftVr7z/ZLHKH3CZ3yX0Skcdknzwnh2RIGPlIPpMv5GtwELwN3gV2bQ0am5bZKuCD98BiZriEw=</latexit><latexit sha1_base64="Hq8jqvJ0DisMmdLRrIg1+WijYlY=">ACwnicfVHLjtMwFHXDayivDixZYFEhIZCqpGphuhvBSLBDBLtjNSE6sa96ZiJH9gObRWyZMWnsIWP4W9w2jJQXleyfHTOubr2uanOuXVh+K0RnDt/4eKlncvNK1evXb/R2r05sqowDIdM5cocp2Ax5xKHjrscj7VBEGmOR+np01o/eo/GciVfu6XGRMBM8owzcJ6atO7EaTafPHtTuorGoLVRC3pGPYyqSasdsLuXr/XpWGn2w8H0cCDfhgNHvVo1AlX1SabOpzsNj7FU8UKgdKxHKwdR6F2SQnGcZj1YwLixrYKcxw7KEgTYpVz+p6D3PTGmjD/S0RX7a0cJwtqlSL1TgDuxv2s1+TdtXLhsLym51IVDydaDsiKnTtE6FjrlBpnLlx4AM9y/lbITMCcD68ZS5wzJQTIaRmPqnGUlHE9I83KdlRV27pPrzqT53+qi5/qolYP0Odk8IWnXmo04JR5UMZgZgK8dXP/z8bl2ubvrTxSUa/vx47ov8Go24k8ftVr7z/ZLHKH3CZ3yX0Skcdknzwnh2RIGPlIPpMv5GtwELwN3gV2bQ0am5bZKuCD98BiZriEw=</latexit>Approach: Boost malicious update to overcome effect of scaling
Approach: Generate malicious update with respect to , i.e. assume
G
<latexit sha1_base64="TOvSKS0/P7tUcN4qF29Oy7PQw1Y=">ACq3icfVHbhMxEHWwm3Fh5sYiQEBKRN0qgeasACV4QRZC0anaJZp3Z1KrtXdle0sjaL+CV/gv/gZvEi7hNpI1R+ec0YxnslIK6xj72ouXLx0+crO1fa16zdu3trduz2RWU4jnghC3OcgUpNI6cBKPS4OgMolH2dmzRj/6gMaKQr9zyxJTBXMtcsHBeokyfLF9MV7+rpbod1W9/0O9R1u0N2DAeBjBg8fBxn8ZdtoO2cThdK/1MZkVvFKoHZdg7SRmpUs9GCe4xLqdVBZL4Gcwx0mAGhTa1K9Grun9wMxoXpjwtKMr9tcKD8rapcqCU4E7tb9rDfk3bVK5fD/1QpeVQ83XjfJKUlfQ5v90JgxyJ5cBADcizEr5KRjgLmypnWhc8EIp0DOfjOtJnPqk6ZHlvhPX9bYedlf/kBd/quc/1fNGfY5hTwZfBep1iQZcYR76BMxcQbBu8v9sQq9tIW/tI1PN+b7fiP4bjHvdOA3/c7B080hd8hdco8IDF5Qg7IS3JIRoQT6Rz+RL9Ch6G51EydoatTY1d8hWRPgNLEfZcw=</latexit><latexit sha1_base64="TOvSKS0/P7tUcN4qF29Oy7PQw1Y=">ACq3icfVHbhMxEHWwm3Fh5sYiQEBKRN0qgeasACV4QRZC0anaJZp3Z1KrtXdle0sjaL+CV/gv/gZvEi7hNpI1R+ec0YxnslIK6xj72ouXLx0+crO1fa16zdu3trduz2RWU4jnghC3OcgUpNI6cBKPS4OgMolH2dmzRj/6gMaKQr9zyxJTBXMtcsHBeokyfLF9MV7+rpbod1W9/0O9R1u0N2DAeBjBg8fBxn8ZdtoO2cThdK/1MZkVvFKoHZdg7SRmpUs9GCe4xLqdVBZL4Gcwx0mAGhTa1K9Grun9wMxoXpjwtKMr9tcKD8rapcqCU4E7tb9rDfk3bVK5fD/1QpeVQ83XjfJKUlfQ5v90JgxyJ5cBADcizEr5KRjgLmypnWhc8EIp0DOfjOtJnPqk6ZHlvhPX9bYedlf/kBd/quc/1fNGfY5hTwZfBep1iQZcYR76BMxcQbBu8v9sQq9tIW/tI1PN+b7fiP4bjHvdOA3/c7B080hd8hdco8IDF5Qg7IS3JIRoQT6Rz+RL9Ch6G51EydoatTY1d8hWRPgNLEfZcw=</latexit><latexit sha1_base64="TOvSKS0/P7tUcN4qF29Oy7PQw1Y=">ACq3icfVHbhMxEHWwm3Fh5sYiQEBKRN0qgeasACV4QRZC0anaJZp3Z1KrtXdle0sjaL+CV/gv/gZvEi7hNpI1R+ec0YxnslIK6xj72ouXLx0+crO1fa16zdu3trduz2RWU4jnghC3OcgUpNI6cBKPS4OgMolH2dmzRj/6gMaKQr9zyxJTBXMtcsHBeokyfLF9MV7+rpbod1W9/0O9R1u0N2DAeBjBg8fBxn8ZdtoO2cThdK/1MZkVvFKoHZdg7SRmpUs9GCe4xLqdVBZL4Gcwx0mAGhTa1K9Grun9wMxoXpjwtKMr9tcKD8rapcqCU4E7tb9rDfk3bVK5fD/1QpeVQ83XjfJKUlfQ5v90JgxyJ5cBADcizEr5KRjgLmypnWhc8EIp0DOfjOtJnPqk6ZHlvhPX9bYedlf/kBd/quc/1fNGfY5hTwZfBep1iQZcYR76BMxcQbBu8v9sQq9tIW/tI1PN+b7fiP4bjHvdOA3/c7B080hd8hdco8IDF5Qg7IS3JIRoQT6Rz+RL9Ch6G51EydoatTY1d8hWRPgNLEfZcw=</latexit><latexit sha1_base64="TOvSKS0/P7tUcN4qF29Oy7PQw1Y=">ACq3icfVHbhMxEHWwm3Fh5sYiQEBKRN0qgeasACV4QRZC0anaJZp3Z1KrtXdle0sjaL+CV/gv/gZvEi7hNpI1R+ec0YxnslIK6xj72ouXLx0+crO1fa16zdu3trduz2RWU4jnghC3OcgUpNI6cBKPS4OgMolH2dmzRj/6gMaKQr9zyxJTBXMtcsHBeokyfLF9MV7+rpbod1W9/0O9R1u0N2DAeBjBg8fBxn8ZdtoO2cThdK/1MZkVvFKoHZdg7SRmpUs9GCe4xLqdVBZL4Gcwx0mAGhTa1K9Grun9wMxoXpjwtKMr9tcKD8rapcqCU4E7tb9rDfk3bVK5fD/1QpeVQ83XjfJKUlfQ5v90JgxyJ5cBADcizEr5KRjgLmypnWhc8EIp0DOfjOtJnPqk6ZHlvhPX9bYedlf/kBd/quc/1fNGfY5hTwZfBep1iQZcYR76BMxcQbBu8v9sQq9tIW/tI1PN+b7fiP4bjHvdOA3/c7B080hd8hdco8IDF5Qg7IS3JIRoQT6Rz+RL9Ch6G51EydoatTY1d8hWRPgNLEfZcw=</latexit>G ≈ wt+1 G
<latexit sha1_base64="Hq8jqvJ0DisMmdLRrIg1+WijYlY=">ACwnicfVHLjtMwFHXDayivDixZYFEhIZCqpGphuhvBSLBDBLtjNSE6sa96ZiJH9gObRWyZMWnsIWP4W9w2jJQXleyfHTOubr2uanOuXVh+K0RnDt/4eKlncvNK1evXb/R2r05sqowDIdM5cocp2Ax5xKHjrscj7VBEGmOR+np01o/eo/GciVfu6XGRMBM8owzcJ6atO7EaTafPHtTuorGoLVRC3pGPYyqSasdsLuXr/XpWGn2w8H0cCDfhgNHvVo1AlX1SabOpzsNj7FU8UKgdKxHKwdR6F2SQnGcZj1YwLixrYKcxw7KEgTYpVz+p6D3PTGmjD/S0RX7a0cJwtqlSL1TgDuxv2s1+TdtXLhsLym51IVDydaDsiKnTtE6FjrlBpnLlx4AM9y/lbITMCcD68ZS5wzJQTIaRmPqnGUlHE9I83KdlRV27pPrzqT53+qi5/qolYP0Odk8IWnXmo04JR5UMZgZgK8dXP/z8bl2ubvrTxSUa/vx47ov8Go24k8ftVr7z/ZLHKH3CZ3yX0Skcdknzwnh2RIGPlIPpMv5GtwELwN3gV2bQ0am5bZKuCD98BiZriEw=</latexit><latexit sha1_base64="Hq8jqvJ0DisMmdLRrIg1+WijYlY=">ACwnicfVHLjtMwFHXDayivDixZYFEhIZCqpGphuhvBSLBDBLtjNSE6sa96ZiJH9gObRWyZMWnsIWP4W9w2jJQXleyfHTOubr2uanOuXVh+K0RnDt/4eKlncvNK1evXb/R2r05sqowDIdM5cocp2Ax5xKHjrscj7VBEGmOR+np01o/eo/GciVfu6XGRMBM8owzcJ6atO7EaTafPHtTuorGoLVRC3pGPYyqSasdsLuXr/XpWGn2w8H0cCDfhgNHvVo1AlX1SabOpzsNj7FU8UKgdKxHKwdR6F2SQnGcZj1YwLixrYKcxw7KEgTYpVz+p6D3PTGmjD/S0RX7a0cJwtqlSL1TgDuxv2s1+TdtXLhsLym51IVDydaDsiKnTtE6FjrlBpnLlx4AM9y/lbITMCcD68ZS5wzJQTIaRmPqnGUlHE9I83KdlRV27pPrzqT53+qi5/qolYP0Odk8IWnXmo04JR5UMZgZgK8dXP/z8bl2ubvrTxSUa/vx47ov8Go24k8ftVr7z/ZLHKH3CZ3yX0Skcdknzwnh2RIGPlIPpMv5GtwELwN3gV2bQ0am5bZKuCD98BiZriEw=</latexit><latexit sha1_base64="Hq8jqvJ0DisMmdLRrIg1+WijYlY=">ACwnicfVHLjtMwFHXDayivDixZYFEhIZCqpGphuhvBSLBDBLtjNSE6sa96ZiJH9gObRWyZMWnsIWP4W9w2jJQXleyfHTOubr2uanOuXVh+K0RnDt/4eKlncvNK1evXb/R2r05sqowDIdM5cocp2Ax5xKHjrscj7VBEGmOR+np01o/eo/GciVfu6XGRMBM8owzcJ6atO7EaTafPHtTuorGoLVRC3pGPYyqSasdsLuXr/XpWGn2w8H0cCDfhgNHvVo1AlX1SabOpzsNj7FU8UKgdKxHKwdR6F2SQnGcZj1YwLixrYKcxw7KEgTYpVz+p6D3PTGmjD/S0RX7a0cJwtqlSL1TgDuxv2s1+TdtXLhsLym51IVDydaDsiKnTtE6FjrlBpnLlx4AM9y/lbITMCcD68ZS5wzJQTIaRmPqnGUlHE9I83KdlRV27pPrzqT53+qi5/qolYP0Odk8IWnXmo04JR5UMZgZgK8dXP/z8bl2ubvrTxSUa/vx47ov8Go24k8ftVr7z/ZLHKH3CZ3yX0Skcdknzwnh2RIGPlIPpMv5GtwELwN3gV2bQ0am5bZKuCD98BiZriEw=</latexit><latexit sha1_base64="Hq8jqvJ0DisMmdLRrIg1+WijYlY=">ACwnicfVHLjtMwFHXDayivDixZYFEhIZCqpGphuhvBSLBDBLtjNSE6sa96ZiJH9gObRWyZMWnsIWP4W9w2jJQXleyfHTOubr2uanOuXVh+K0RnDt/4eKlncvNK1evXb/R2r05sqowDIdM5cocp2Ax5xKHjrscj7VBEGmOR+np01o/eo/GciVfu6XGRMBM8owzcJ6atO7EaTafPHtTuorGoLVRC3pGPYyqSasdsLuXr/XpWGn2w8H0cCDfhgNHvVo1AlX1SabOpzsNj7FU8UKgdKxHKwdR6F2SQnGcZj1YwLixrYKcxw7KEgTYpVz+p6D3PTGmjD/S0RX7a0cJwtqlSL1TgDuxv2s1+TdtXLhsLym51IVDydaDsiKnTtE6FjrlBpnLlx4AM9y/lbITMCcD68ZS5wzJQTIaRmPqnGUlHE9I83KdlRV27pPrzqT53+qi5/qolYP0Odk8IWnXmo04JR5UMZgZgK8dXP/z8bl2ubvrTxSUa/vx47ov8Go24k8ftVr7z/ZLHKH3CZ3yX0Skcdknzwnh2RIGPlIPpMv5GtwELwN3gV2bQ0am5bZKuCD98BiZriEw=</latexit>Approach: Boost malicious update to overcome effect of scaling
Approach: Generate malicious update with respect to , i.e. assume
G
<latexit sha1_base64="TOvSKS0/P7tUcN4qF29Oy7PQw1Y=">ACq3icfVHbhMxEHWwm3Fh5sYiQEBKRN0qgeasACV4QRZC0anaJZp3Z1KrtXdle0sjaL+CV/gv/gZvEi7hNpI1R+ec0YxnslIK6xj72ouXLx0+crO1fa16zdu3trduz2RWU4jnghC3OcgUpNI6cBKPS4OgMolH2dmzRj/6gMaKQr9zyxJTBXMtcsHBeokyfLF9MV7+rpbod1W9/0O9R1u0N2DAeBjBg8fBxn8ZdtoO2cThdK/1MZkVvFKoHZdg7SRmpUs9GCe4xLqdVBZL4Gcwx0mAGhTa1K9Grun9wMxoXpjwtKMr9tcKD8rapcqCU4E7tb9rDfk3bVK5fD/1QpeVQ83XjfJKUlfQ5v90JgxyJ5cBADcizEr5KRjgLmypnWhc8EIp0DOfjOtJnPqk6ZHlvhPX9bYedlf/kBd/quc/1fNGfY5hTwZfBep1iQZcYR76BMxcQbBu8v9sQq9tIW/tI1PN+b7fiP4bjHvdOA3/c7B080hd8hdco8IDF5Qg7IS3JIRoQT6Rz+RL9Ch6G51EydoatTY1d8hWRPgNLEfZcw=</latexit><latexit sha1_base64="TOvSKS0/P7tUcN4qF29Oy7PQw1Y=">ACq3icfVHbhMxEHWwm3Fh5sYiQEBKRN0qgeasACV4QRZC0anaJZp3Z1KrtXdle0sjaL+CV/gv/gZvEi7hNpI1R+ec0YxnslIK6xj72ouXLx0+crO1fa16zdu3trduz2RWU4jnghC3OcgUpNI6cBKPS4OgMolH2dmzRj/6gMaKQr9zyxJTBXMtcsHBeokyfLF9MV7+rpbod1W9/0O9R1u0N2DAeBjBg8fBxn8ZdtoO2cThdK/1MZkVvFKoHZdg7SRmpUs9GCe4xLqdVBZL4Gcwx0mAGhTa1K9Grun9wMxoXpjwtKMr9tcKD8rapcqCU4E7tb9rDfk3bVK5fD/1QpeVQ83XjfJKUlfQ5v90JgxyJ5cBADcizEr5KRjgLmypnWhc8EIp0DOfjOtJnPqk6ZHlvhPX9bYedlf/kBd/quc/1fNGfY5hTwZfBep1iQZcYR76BMxcQbBu8v9sQq9tIW/tI1PN+b7fiP4bjHvdOA3/c7B080hd8hdco8IDF5Qg7IS3JIRoQT6Rz+RL9Ch6G51EydoatTY1d8hWRPgNLEfZcw=</latexit><latexit sha1_base64="TOvSKS0/P7tUcN4qF29Oy7PQw1Y=">ACq3icfVHbhMxEHWwm3Fh5sYiQEBKRN0qgeasACV4QRZC0anaJZp3Z1KrtXdle0sjaL+CV/gv/gZvEi7hNpI1R+ec0YxnslIK6xj72ouXLx0+crO1fa16zdu3trduz2RWU4jnghC3OcgUpNI6cBKPS4OgMolH2dmzRj/6gMaKQr9zyxJTBXMtcsHBeokyfLF9MV7+rpbod1W9/0O9R1u0N2DAeBjBg8fBxn8ZdtoO2cThdK/1MZkVvFKoHZdg7SRmpUs9GCe4xLqdVBZL4Gcwx0mAGhTa1K9Grun9wMxoXpjwtKMr9tcKD8rapcqCU4E7tb9rDfk3bVK5fD/1QpeVQ83XjfJKUlfQ5v90JgxyJ5cBADcizEr5KRjgLmypnWhc8EIp0DOfjOtJnPqk6ZHlvhPX9bYedlf/kBd/quc/1fNGfY5hTwZfBep1iQZcYR76BMxcQbBu8v9sQq9tIW/tI1PN+b7fiP4bjHvdOA3/c7B080hd8hdco8IDF5Qg7IS3JIRoQT6Rz+RL9Ch6G51EydoatTY1d8hWRPgNLEfZcw=</latexit><latexit sha1_base64="TOvSKS0/P7tUcN4qF29Oy7PQw1Y=">ACq3icfVHbhMxEHWwm3Fh5sYiQEBKRN0qgeasACV4QRZC0anaJZp3Z1KrtXdle0sjaL+CV/gv/gZvEi7hNpI1R+ec0YxnslIK6xj72ouXLx0+crO1fa16zdu3trduz2RWU4jnghC3OcgUpNI6cBKPS4OgMolH2dmzRj/6gMaKQr9zyxJTBXMtcsHBeokyfLF9MV7+rpbod1W9/0O9R1u0N2DAeBjBg8fBxn8ZdtoO2cThdK/1MZkVvFKoHZdg7SRmpUs9GCe4xLqdVBZL4Gcwx0mAGhTa1K9Grun9wMxoXpjwtKMr9tcKD8rapcqCU4E7tb9rDfk3bVK5fD/1QpeVQ83XjfJKUlfQ5v90JgxyJ5cBADcizEr5KRjgLmypnWhc8EIp0DOfjOtJnPqk6ZHlvhPX9bYedlf/kBd/quc/1fNGfY5hTwZfBep1iQZcYR76BMxcQbBu8v9sQq9tIW/tI1PN+b7fiP4bjHvdOA3/c7B080hd8hdco8IDF5Qg7IS3JIRoQT6Rz+RL9Ch6G51EydoatTY1d8hWRPgNLEfZcw=</latexit>G ≈ wt+1 G
<latexit sha1_base64="Hq8jqvJ0DisMmdLRrIg1+WijYlY=">ACwnicfVHLjtMwFHXDayivDixZYFEhIZCqpGphuhvBSLBDBLtjNSE6sa96ZiJH9gObRWyZMWnsIWP4W9w2jJQXleyfHTOubr2uanOuXVh+K0RnDt/4eKlncvNK1evXb/R2r05sqowDIdM5cocp2Ax5xKHjrscj7VBEGmOR+np01o/eo/GciVfu6XGRMBM8owzcJ6atO7EaTafPHtTuorGoLVRC3pGPYyqSasdsLuXr/XpWGn2w8H0cCDfhgNHvVo1AlX1SabOpzsNj7FU8UKgdKxHKwdR6F2SQnGcZj1YwLixrYKcxw7KEgTYpVz+p6D3PTGmjD/S0RX7a0cJwtqlSL1TgDuxv2s1+TdtXLhsLym51IVDydaDsiKnTtE6FjrlBpnLlx4AM9y/lbITMCcD68ZS5wzJQTIaRmPqnGUlHE9I83KdlRV27pPrzqT53+qi5/qolYP0Odk8IWnXmo04JR5UMZgZgK8dXP/z8bl2ubvrTxSUa/vx47ov8Go24k8ftVr7z/ZLHKH3CZ3yX0Skcdknzwnh2RIGPlIPpMv5GtwELwN3gV2bQ0am5bZKuCD98BiZriEw=</latexit><latexit sha1_base64="Hq8jqvJ0DisMmdLRrIg1+WijYlY=">ACwnicfVHLjtMwFHXDayivDixZYFEhIZCqpGphuhvBSLBDBLtjNSE6sa96ZiJH9gObRWyZMWnsIWP4W9w2jJQXleyfHTOubr2uanOuXVh+K0RnDt/4eKlncvNK1evXb/R2r05sqowDIdM5cocp2Ax5xKHjrscj7VBEGmOR+np01o/eo/GciVfu6XGRMBM8owzcJ6atO7EaTafPHtTuorGoLVRC3pGPYyqSasdsLuXr/XpWGn2w8H0cCDfhgNHvVo1AlX1SabOpzsNj7FU8UKgdKxHKwdR6F2SQnGcZj1YwLixrYKcxw7KEgTYpVz+p6D3PTGmjD/S0RX7a0cJwtqlSL1TgDuxv2s1+TdtXLhsLym51IVDydaDsiKnTtE6FjrlBpnLlx4AM9y/lbITMCcD68ZS5wzJQTIaRmPqnGUlHE9I83KdlRV27pPrzqT53+qi5/qolYP0Odk8IWnXmo04JR5UMZgZgK8dXP/z8bl2ubvrTxSUa/vx47ov8Go24k8ftVr7z/ZLHKH3CZ3yX0Skcdknzwnh2RIGPlIPpMv5GtwELwN3gV2bQ0am5bZKuCD98BiZriEw=</latexit><latexit sha1_base64="Hq8jqvJ0DisMmdLRrIg1+WijYlY=">ACwnicfVHLjtMwFHXDayivDixZYFEhIZCqpGphuhvBSLBDBLtjNSE6sa96ZiJH9gObRWyZMWnsIWP4W9w2jJQXleyfHTOubr2uanOuXVh+K0RnDt/4eKlncvNK1evXb/R2r05sqowDIdM5cocp2Ax5xKHjrscj7VBEGmOR+np01o/eo/GciVfu6XGRMBM8owzcJ6atO7EaTafPHtTuorGoLVRC3pGPYyqSasdsLuXr/XpWGn2w8H0cCDfhgNHvVo1AlX1SabOpzsNj7FU8UKgdKxHKwdR6F2SQnGcZj1YwLixrYKcxw7KEgTYpVz+p6D3PTGmjD/S0RX7a0cJwtqlSL1TgDuxv2s1+TdtXLhsLym51IVDydaDsiKnTtE6FjrlBpnLlx4AM9y/lbITMCcD68ZS5wzJQTIaRmPqnGUlHE9I83KdlRV27pPrzqT53+qi5/qolYP0Odk8IWnXmo04JR5UMZgZgK8dXP/z8bl2ubvrTxSUa/vx47ov8Go24k8ftVr7z/ZLHKH3CZ3yX0Skcdknzwnh2RIGPlIPpMv5GtwELwN3gV2bQ0am5bZKuCD98BiZriEw=</latexit><latexit sha1_base64="Hq8jqvJ0DisMmdLRrIg1+WijYlY=">ACwnicfVHLjtMwFHXDayivDixZYFEhIZCqpGphuhvBSLBDBLtjNSE6sa96ZiJH9gObRWyZMWnsIWP4W9w2jJQXleyfHTOubr2uanOuXVh+K0RnDt/4eKlncvNK1evXb/R2r05sqowDIdM5cocp2Ax5xKHjrscj7VBEGmOR+np01o/eo/GciVfu6XGRMBM8owzcJ6atO7EaTafPHtTuorGoLVRC3pGPYyqSasdsLuXr/XpWGn2w8H0cCDfhgNHvVo1AlX1SabOpzsNj7FU8UKgdKxHKwdR6F2SQnGcZj1YwLixrYKcxw7KEgTYpVz+p6D3PTGmjD/S0RX7a0cJwtqlSL1TgDuxv2s1+TdtXLhsLym51IVDydaDsiKnTtE6FjrlBpnLlx4AM9y/lbITMCcD68ZS5wzJQTIaRmPqnGUlHE9I83KdlRV27pPrzqT53+qi5/qolYP0Odk8IWnXmo04JR5UMZgZgK8dXP/z8bl2ubvrTxSUa/vx47ov8Go24k8ftVr7z/ZLHKH3CZ3yX0Skcdknzwnh2RIGPlIPpMv5GtwELwN3gV2bQ0am5bZKuCD98BiZriEw=</latexit>Approach: Boost malicious update to overcome effect of scaling Approach: Improve on baseline by adding benign training and distance constraints
Strategy Malicious agent’s update computation Joint minimization of benign and malicious
constraints
Benign Objective Malicious Objective Distance Constraint
δmal = argmin
δ
L
m, yi m}nm i=1; wG + δ
l=1 ; wG + δ
2
<latexit sha1_base64="2NkVr+zB9hbKe1ZjUdHZqjGafFg=">ADpXicfVJdb9MwFE1WPkb52uCRF4sKMWCrktDCKjRpAiR42MSQ2m5S3UaO67TWbCeyHdbK8y9A4hX+Gv8Gpy2shY0rJb4659xj+14nOaNKB8FPf61y7fqNm+u3qrfv3L13f2PzQVdlhcSkgzOWyZMEKcKoIB1NSMnuSIJ4wcJ6fvSv74C5GKZqKtpznpczQSNKUYaQfFm74PE27gkDCNbGygJhNtOGLWgj0AkRxKhx8obHgADKS6i0AHZxOYj6g29PyD1093QvtwIiY2zeOPIs/gBdgqRhASUdj/WyGEo3AZibzb0GbLs9YKUPW/gsH+gKy2VPOc4APF+hd8AlF8SZUO4m8DyOBlG8UQvqQbTbEQgqEfNoBW2XNIMwtarBgjrwSxq3iKOXNO+wmGC06Exgwp1QuDXPcNkpiRmwVForkCJ+iEem5VCBOVN/MhmXBE4cMQZpJ9wkNZuhyhUFcqSlPnJIjPVZ/cyV4GdcrdLrbN1TkhSYCzdKCwZ0BsrJgyGVBGs2dQnCkrqzAjxGEmHt3kcVCnKGM86RGBrYtb2wb2C5R5KaWmjtKu/mYP/QZ/+ykwt2UrLvieuTJIcO+pQTiXQmn5vZ60JOulj/J6NiLnPrSj8Sbt34fs8IXJ10o3r4sh59btT23y4Gue498h57W17ovfb2vY/ekdfxsD/2v/nf/R+Vp5XDSrvSnUvX/EXNQ28lKvEvJMg05g=</latexit>Strategy Malicious agent’s update computation Joint minimization of benign and malicious
constraints
Benign Objective Malicious Objective Distance Constraint
Experiment settings
cumulative update from other agents
β = 10
<latexit sha1_base64="h1yJ0xDNnoGJzAMiU5spdEXuvg=">ACq3icfVHbhMxEHWwm3lj7yYhEhISidYuAPiBVhQdeEWQtGp2VY2d2dSqLyvbSxqt9gt47Wv5L/4GbxIuocBI1hydc0YznuGlkj6k6bdOcuXqtes31m52b92+c/fe+sb9obeVEzgQVl3yMGjkgYHQaFh6VD0FzhAT93eoHn9F5ac2nMCsx1zAxspACQqSOMo4B6CvK0uP1XtrfSdnOc0YvA9ZP59Ejy9g/3uh8ycZWVBpNEAq8H7G0DHkNLkihsOlmlcSxClMcBShAY0+r+cjN/RZMa0sC4+E+ic/b2iBu39TPo1BO/J9aS/5NG1WheJnX0pRVQCMWjYpK0WBp+386lg5FULMIQDgZ6XiByIELfUzQxOhdUazLjOhs2I5XW9uBF3WNs6rzYtr8lKeX1bNf6lmrvsG4J4fvIvW+RAfBuid1Bm6iIVqX+X82aRa2mFf2wXUTz/fjRvTfYLjVZ9v9rQ/Pert7y0OukQfkIXlMGHlBdslbsk8GRBDzskF+Zo8T4mR0m2sCadZc0mWYkEvwOD7thI</latexit>δmal = argmin
δ
L
m, yi m}nm i=1; wG + δ
l=1 ; wG + δ
2
<latexit sha1_base64="2NkVr+zB9hbKe1ZjUdHZqjGafFg=">ADpXicfVJdb9MwFE1WPkb52uCRF4sKMWCrktDCKjRpAiR42MSQ2m5S3UaO67TWbCeyHdbK8y9A4hX+Gv8Gpy2shY0rJb4659xj+14nOaNKB8FPf61y7fqNm+u3qrfv3L13f2PzQVdlhcSkgzOWyZMEKcKoIB1NSMnuSIJ4wcJ6fvSv74C5GKZqKtpznpczQSNKUYaQfFm74PE27gkDCNbGygJhNtOGLWgj0AkRxKhx8obHgADKS6i0AHZxOYj6g29PyD1093QvtwIiY2zeOPIs/gBdgqRhASUdj/WyGEo3AZibzb0GbLs9YKUPW/gsH+gKy2VPOc4APF+hd8AlF8SZUO4m8DyOBlG8UQvqQbTbEQgqEfNoBW2XNIMwtarBgjrwSxq3iKOXNO+wmGC06Exgwp1QuDXPcNkpiRmwVForkCJ+iEem5VCBOVN/MhmXBE4cMQZpJ9wkNZuhyhUFcqSlPnJIjPVZ/cyV4GdcrdLrbN1TkhSYCzdKCwZ0BsrJgyGVBGs2dQnCkrqzAjxGEmHt3kcVCnKGM86RGBrYtb2wb2C5R5KaWmjtKu/mYP/QZ/+ykwt2UrLvieuTJIcO+pQTiXQmn5vZ60JOulj/J6NiLnPrSj8Sbt34fs8IXJ10o3r4sh59btT23y4Gue498h57W17ovfb2vY/ekdfxsD/2v/nf/R+Vp5XDSrvSnUvX/EXNQ28lKvEvJMg05g=</latexit>0.2 0.4 0.6 0.8 1 2 4 6 8 10 12 14 16 20 40 60 80 100 Confidence Classification accuracy Time
(a) Confidence on malicious objective and accuracy on valida- (b)
Takeaways
to Targeted Model Poisoning
0.2 0.4 0.6 0.8 1 2 4 6 8 10 12 14 16 20 40 60 80 100 Confidence Classification accuracy Time
(a) Confidence on malicious objective and accuracy on valida- (b)
Takeaways
to Targeted Model Poisoning Takeaway Closer match between weight updates for benign and malicious agents
Spread of distances between all the benign agents and between the malicious agent and the benign agents
30 40 50 60 70 80 90 100 110 2 4 6 8 10 12 14 16
Distance Time
Targeted Model Poisoning (Benign) Targeted Model Poisoning (Malicious) Stealthy Model Poisoning (Benign) Stealthy Model Poisoning (Malicious) Alternating Minimization (Benign) Alternating Minimization (Malicious)
Spread of distances between all the benign agents and between the malicious agent and the benign agents
Benign for all 3 attacks
30 40 50 60 70 80 90 100 110 2 4 6 8 10 12 14 16
Distance Time
Targeted Model Poisoning (Benign) Targeted Model Poisoning (Malicious) Stealthy Model Poisoning (Benign) Stealthy Model Poisoning (Malicious) Alternating Minimization (Benign) Alternating Minimization (Malicious)
Spread of distances between all the benign agents and between the malicious agent and the benign agents
Benign for all 3 attacks Targeted poison
30 40 50 60 70 80 90 100 110 2 4 6 8 10 12 14 16
Distance Time
Targeted Model Poisoning (Benign) Targeted Model Poisoning (Malicious) Stealthy Model Poisoning (Benign) Stealthy Model Poisoning (Malicious) Alternating Minimization (Benign) Alternating Minimization (Malicious)
Spread of distances between all the benign agents and between the malicious agent and the benign agents
Stealthy poison Benign for all 3 attacks Targeted poison
30 40 50 60 70 80 90 100 110 2 4 6 8 10 12 14 16
Distance Time
Targeted Model Poisoning (Benign) Targeted Model Poisoning (Malicious) Stealthy Model Poisoning (Benign) Stealthy Model Poisoning (Malicious) Alternating Minimization (Benign) Alternating Minimization (Malicious)
Spread of distances between all the benign agents and between the malicious agent and the benign agents
Stealthy poison Alt.min. Benign for all 3 attacks Targeted poison
30 40 50 60 70 80 90 100 110 2 4 6 8 10 12 14 16
Distance Time
Targeted Model Poisoning (Benign) Targeted Model Poisoning (Malicious) Stealthy Model Poisoning (Benign) Stealthy Model Poisoning (Malicious) Alternating Minimization (Benign) Alternating Minimization (Malicious)
Spread of distances between all the benign agents and between the malicious agent and the benign agents
Stealthy poison Alt.min. Benign for all 3 attacks Adding distance constraints reduces distinguishability of malicious update Takeaway Targeted poison
30 40 50 60 70 80 90 100 110 2 4 6 8 10 12 14 16
Distance Time
Targeted Model Poisoning (Benign) Targeted Model Poisoning (Malicious) Stealthy Model Poisoning (Benign) Stealthy Model Poisoning (Malicious) Alternating Minimization (Benign) Alternating Minimization (Malicious)
[k]\m
<latexit sha1_base64="D1nVs6RHQbU8adP5DTkzy5zubXQ=">AC7nicfVFdixMxFE3Hr7V+bFcfQkWQTLTGl1+yAs6oMg4gq2uzAZSya904YmSHJ2C1hfoHvomvprxDf9J2baqltdvRByOdcbnJuWghubBh+bQTnzl+4eGncvPK1WvXd1t7N0YmLzWDIctFro9TakBwBUPLrYDjQgOVqYCjdP6k1o/egjY8V6/tsoBE0qniGWfUemrceo7JjFpHUunIBISlVTV28TzBxICVXJUGywo/wviU42z96MzbONWO+yE3f1+r4vDTrcfDqKB/0wGjzo4agTrqNnU43mu8I5OclRKUZYIaE0dhYRNHteVMQNUkpYGCsjmdQuyhohJM4la/rvAdz0xwlmt/lMUr9nSHo9KYpUy9U1I7M39qNXmWFpc208cV0VpQbH1oKwU2Oa4jhBPuAZmxdIDyjT3b8VsRjVl1gfdJAoWLJeSqokjoyqOEkfqGWnm2lFVbetptqh+yYu/1ZPf6kmtPgWfk4YXnpZgKY21/coXoqbdu7v/ZuFrb/L2VR7pa38d4X+DUbcTefyq1z54vFnkDrqFbqO7KEIP0QF6hg7REDH0GX1B39D3oAjeBx+Cj2tr0Nj03ERbFXz6AUim9KE=</latexit><latexit sha1_base64="D1nVs6RHQbU8adP5DTkzy5zubXQ=">AC7nicfVFdixMxFE3Hr7V+bFcfQkWQTLTGl1+yAs6oMg4gq2uzAZSya904YmSHJ2C1hfoHvomvprxDf9J2baqltdvRByOdcbnJuWghubBh+bQTnzl+4eGncvPK1WvXd1t7N0YmLzWDIctFro9TakBwBUPLrYDjQgOVqYCjdP6k1o/egjY8V6/tsoBE0qniGWfUemrceo7JjFpHUunIBISlVTV28TzBxICVXJUGywo/wviU42z96MzbONWO+yE3f1+r4vDTrcfDqKB/0wGjzo4agTrqNnU43mu8I5OclRKUZYIaE0dhYRNHteVMQNUkpYGCsjmdQuyhohJM4la/rvAdz0xwlmt/lMUr9nSHo9KYpUy9U1I7M39qNXmWFpc208cV0VpQbH1oKwU2Oa4jhBPuAZmxdIDyjT3b8VsRjVl1gfdJAoWLJeSqokjoyqOEkfqGWnm2lFVbetptqh+yYu/1ZPf6kmtPgWfk4YXnpZgKY21/coXoqbdu7v/ZuFrb/L2VR7pa38d4X+DUbcTefyq1z54vFnkDrqFbqO7KEIP0QF6hg7REDH0GX1B39D3oAjeBx+Cj2tr0Nj03ERbFXz6AUim9KE=</latexit><latexit sha1_base64="D1nVs6RHQbU8adP5DTkzy5zubXQ=">AC7nicfVFdixMxFE3Hr7V+bFcfQkWQTLTGl1+yAs6oMg4gq2uzAZSya904YmSHJ2C1hfoHvomvprxDf9J2baqltdvRByOdcbnJuWghubBh+bQTnzl+4eGncvPK1WvXd1t7N0YmLzWDIctFro9TakBwBUPLrYDjQgOVqYCjdP6k1o/egjY8V6/tsoBE0qniGWfUemrceo7JjFpHUunIBISlVTV28TzBxICVXJUGywo/wviU42z96MzbONWO+yE3f1+r4vDTrcfDqKB/0wGjzo4agTrqNnU43mu8I5OclRKUZYIaE0dhYRNHteVMQNUkpYGCsjmdQuyhohJM4la/rvAdz0xwlmt/lMUr9nSHo9KYpUy9U1I7M39qNXmWFpc208cV0VpQbH1oKwU2Oa4jhBPuAZmxdIDyjT3b8VsRjVl1gfdJAoWLJeSqokjoyqOEkfqGWnm2lFVbetptqh+yYu/1ZPf6kmtPgWfk4YXnpZgKY21/coXoqbdu7v/ZuFrb/L2VR7pa38d4X+DUbcTefyq1z54vFnkDrqFbqO7KEIP0QF6hg7REDH0GX1B39D3oAjeBx+Cj2tr0Nj03ERbFXz6AUim9KE=</latexit><latexit sha1_base64="D1nVs6RHQbU8adP5DTkzy5zubXQ=">AC7nicfVFdixMxFE3Hr7V+bFcfQkWQTLTGl1+yAs6oMg4gq2uzAZSya904YmSHJ2C1hfoHvomvprxDf9J2baqltdvRByOdcbnJuWghubBh+bQTnzl+4eGncvPK1WvXd1t7N0YmLzWDIctFro9TakBwBUPLrYDjQgOVqYCjdP6k1o/egjY8V6/tsoBE0qniGWfUemrceo7JjFpHUunIBISlVTV28TzBxICVXJUGywo/wviU42z96MzbONWO+yE3f1+r4vDTrcfDqKB/0wGjzo4agTrqNnU43mu8I5OclRKUZYIaE0dhYRNHteVMQNUkpYGCsjmdQuyhohJM4la/rvAdz0xwlmt/lMUr9nSHo9KYpUy9U1I7M39qNXmWFpc208cV0VpQbH1oKwU2Oa4jhBPuAZmxdIDyjT3b8VsRjVl1gfdJAoWLJeSqokjoyqOEkfqGWnm2lFVbetptqh+yYu/1ZPf6kmtPgWfk4YXnpZgKY21/coXoqbdu7v/ZuFrb/L2VR7pa38d4X+DUbcTefyq1z54vFnkDrqFbqO7KEIP0QF6hg7REDH0GX1B39D3oAjeBx+Cj2tr0Nj03ERbFXz6AUim9KE=</latexit>Attack Targeted Model Poisoning Alternating Minimization Estimation None Previous step None Previous step t = 2 0.63 0.82 0.17 0.47 t = 3 0.93 0.98 0.34 0.89 t = 4 0.99 1.0 0.88 1.0
Estimating update from other agents Previous step estimation: Improvement in attack confidence (CNN on Fashion MNIST, 10 agents)
0.2 0.4 0.6 0.8 1 5 10 15 20 25 30 35 40 20 40 60 80 100 Confidence Classification accuracy Time
(a) Targeted model poisoning (b) Comparison of weight update distributions for targeted model poisoning
0.2 0.4 0.6 0.8 1 5 10 15 20 25 30 35 40 20 40 60 80 100 Confidence Classification accuracy Time
(c) Stealthy model poisoning with λ = 20 and ρ = 1e−4 (d) Comparison of weight update distributions for stealthy model poisoning
0.2 0.4 0.6 0.8 1 5 10 15 20 25 30 35 40 20 40 60 80 100 Confidence Classification accuracy Time
(e) Alternating minimization with λ = 20 and ρ = 1e−4 and 10 epochs for the malicious agent (f) Comparison of weight update distributions for alternating minimization
0.2 0.4 0.6 0.8 1 5 10 15 20 25 30 35 40 45 50 20 40 60 80 100 Confidence Classification accuracy Time
(a) Targeted model poisoning with λ = 100.
0.2 0.4 0.6 0.8 1 5 10 15 20 25 30 35 40 45 50 20 40 60 80 100 Confidence Classification accuracy Time
(b) Alternating minimization with λ = 100, 100 epochs for the malicious agent and 10 steps for the stealth objective for every step of the benign objective.
0.2 0.4 0.6 0.8 1 5 10 15 20 25 30 35 40 20 40 60 80 100 Confidence Classification accuracy Time
(a) Targeted model poisoning.
0.2 0.4 0.6 0.8 1 5 10 15 20 25 30 35 40 20 40 60 80 100 Confidence Classification accuracy Time
(b) Alternating minimization with 10 epochs for the malicious agent and 10 steps for the stealth objective for every step of the benign objective.
Using a suite of interpretability techniques [3] to compare global model decisions
Global model trained using only benign agents Using a suite of interpretability techniques [3] to compare global model decisions
Global model trained using only benign agents Global model trained with one malicious model and the rest benign Using a suite of interpretability techniques [3] to compare global model decisions
Global model trained using only benign agents Global model trained with one malicious model and the rest benign Only two which appear to be significantly visually different Using a suite of interpretability techniques [3] to compare global model decisions
0.2 0.4 0.6 0.8 1 5 10 15 20 25 30 35 40 20 40 60 80 100 Confidence Classification accuracy Time
mod-
mechanisms
Takeaways
against model poisoning attacks
effective
✦ Convergence: prove good performance of global models ✦ Scalability: implementing attacks at scale ✦ Robustness: behavior of poisoned models in parameter space ✦ Generalizability: behavior in input space around poisoned points