{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/a-little-is-enough-circumventing-defenses-for","title":"A Little Is Enough: Circumventing Defenses For Distributed Learning","arxiv_id":"1902.06156","date":"2019-02-16","proceeding":"NeurIPS 2019 12","authors":["Moran Baruch","Gilad Baruch","Yoav Goldberg"],"abstract":"Distributed learning is central for large-scale training of deep-learning\nmodels. However, they are exposed to a security threat in which Byzantine\nparticipants can interrupt or control the learning process. Previous attack\nmodels and their corresponding defenses assume that the rogue participants are\n(a) omniscient (know the data of all other participants), and (b) introduce\nlarge change to the parameters. We show that small but well-crafted changes are\nsufficient, leading to a novel non-omniscient attack on distributed learning\nthat go undetected by all existing defenses. We demonstrate our attack method\nworks not only for preventing convergence but also for repurposing of the model\nbehavior (backdooring). We show that 20% of corrupt workers are sufficient to\ndegrade a CIFAR10 model accuracy by 50%, as well as to introduce backdoors into\nMNIST and CIFAR10 models without hurting their accuracy","url_abs":"http://arxiv.org/abs/1902.06156v1","url_pdf":"http://arxiv.org/pdf/1902.06156v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"a-little-is-enough-circumventing-defenses-for","repo_url":"https://github.com/moranant/attacking_distributing_learning","is_official":1,"mentioned_in_paper":0,"mentioned_in_github":0,"framework":"pytorch","reach":{"status":"ok"}},{"paper_slug":"a-little-is-enough-circumventing-defenses-for","repo_url":"https://github.com/hwang595/DETOX","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":null},{"paper_slug":"a-little-is-enough-circumventing-defenses-for","repo_url":"https://github.com/kkonstantinidis/ByzShield","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":null},{"paper_slug":"a-little-is-enough-circumventing-defenses-for","repo_url":"https://github.com/kkonstantinidis/aspis","is_official":0,"mentioned_in_paper":0,"mentioned_in_github":1,"framework":"pytorch","reach":{"status":"ok"}}],"tasks":[],"methods":[],"datasets_introduced":[],"methods_introduced":[],"results":[],"syntology":{"atlas_url":"https://app.syntology.ai/?focus=1902.06156","mcp":{"get_harvested_code_for_paper":{"arxiv_id":"1902.06156"}},"developers":"https://syntology.ai/developers","read_at":"2026-09-24T18:15:14+00:00","read_at_is":"when the build read Syntology's graph, not when any sample ran","claim":"Per-sample execution status on synthesized fixtures; not a correctness claim about the paper. Samples come from repositories linked to the paper, official or community; repo_kind says which.","repos":[{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/hwang595/DETOX","reach":null},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/kkonstantinidis/aspis","reach":{"status":"ok"}},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/kkonstantinidis/ByzShield","reach":null},{"provenance":"external:paperswithcode_snapshot_2025-07-28","url":"https://github.com/moranant/attacking_distributing_learning","reach":{"status":"ok"}}],"summary":{"ran_draft_wrong":1,"unverified":1},"by_repo_kind":{"listed":{"samples":2,"ran":1,"repositories":1}},"repo_kind_vocabulary":{"official":"The archive marks this repository official for the paper","named_in_paper":"The archive records that the paper mentions this repository; it is not marked official","listed":"In the archive's code links for this paper, not marked official and not recorded as mentioned in the paper","found_in_text":"Syntology found this repository in the paper's own text; whether it is the authors' implementation is not asserted","community":"Not in the archive's code links for this paper; a community repository Syntology harvested"},"n_pointer_only_for_licence":2,"samples":[{"code_sha256_prefix":"ad4da1db77b0c2a2","entry":"add_fit_args","repo":"kkonstantinidis/ByzShield","repo_kind":"listed","path":"src/distributed_evaluator.py","file_url":"https://github.com/kkonstantinidis/ByzShield/blob/HEAD/src/distributed_evaluator.py","link_basis":"first_harvest_node","language":"python","status":"ran_draft_wrong","verification_level":1,"contract_check":"OUTPUT_MISDECLARED","metamorphic_tier":"deterministic","behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"ad4da1db77b0c2a2"}},{"code_sha256_prefix":"4d3faaaa1c706b0b","entry":"accuracy","repo":"kkonstantinidis/ByzShield","repo_kind":"listed","path":"src/distributed_evaluator.py","file_url":"https://github.com/kkonstantinidis/ByzShield/blob/HEAD/src/distributed_evaluator.py","link_basis":"first_harvest_node","language":"python","status":"unverified","verification_level":0,"contract_check":null,"metamorphic_tier":null,"behaviour_fingerprint":false,"licence":"NONE","inline_ok":false,"mcp_get_code":{"code_sha256":"4d3faaaa1c706b0b"}}]},"arxiv_metadata":null,"syntology_extracted_results":null}