[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-126179-en":3,"doc-seo-126179-105":31,"detail-sidebar-cat-0-en-105":93},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":28,"seo_description":14,"update_tm":29,"read_time":30},126179,549768072016,"River Wang","https://ap-avatar.wpscdn.com/davatar_155a257f0dc6eb9ab79c44ca47cae57d",8,"Research & Report","Covert Attacks on Machine Learning Training in Passively Secure MPC","Secure multiparty computation (MPC) enables privacy-preserving machine learning training by letting data owners jointly learn from combined datasets while keeping underlying training data confidential. This work studies MPC threat models where adversaries are assumed passive or, alternatively, actively malicious. It presents explicit, simple, and effective attacks on existing passively secure MPC training protocols, showing near-zero likelihood of detection while compromising both integrity and privacy, including attacks that reconstruct exact training data. Results motivate actively secure protocols for PPML training.","Covert Attacks on Machine Learning Training in Passively Secure MPC  \nMatthew Jagielski  \nGoogle DeepMind [jagielski@google.com](jagielski@google.com)  \nRahul Rachuri  \nVisa Research􀀃 [srachuri@visa.com](srachuri@visa.com)  \nDaniel Escudero  \nNo afﬁliation [daniel.escudero@protonmail.com](daniel.escudero@protonmail.com)  \nPeter Scholl  \nAarhus University [peter.scholl@cs.au.dk](peter.scholl@cs.au.dk)  \nAbstract  \nSecure multiparty computation (MPC) allows data owners to train machine learning models on combined data while keeping the underlying training data private. The MPC threat model either considers an adversary who passively corrupts some parties without affecting their overall behavior, or an adversary who actively modiﬁes the behavior of corrupt parties. It has been argued that in some settings, active security is not a major concern, partly because of the potential risk of reputation loss if a party is detected cheating.  \nIn this work we show explicit, simple, and effective attacks that an active adversary can run on existing passively secure MPC training protocols, while keeping essentially zero risk of the attack being detected. The attacks we show can compromise both the integrity and privacy of the model, including attacks reconstructing exact training data. Our results challenge the belief that a threat model that does not include malicious behavior by the involved parties may be reasonable in the context of PPML, motivating the use of actively secure protocols for training.  \n1 Introduction  \nSecure multiparty computation (MPC) allows data owners to jointly train machine learning (ML) models on pooled data, enabling better models while providing provable privacy protection against colluding servers. MPC training protocols can be designed to defend against “passive” or “active”adversaries. A passive adversary follows the rules of the protocol as expected, and only seeks to learn as much as possible from the protocol communication and the resulting model. An active adversary, by contrast, could deviate arbitrarily from the protocol, motivated perhaps by carefully manipulating the model to misbehave or make it leak other parties' data. Naturally, defending from an active adversary is more ideal but also more challenging than defending from a passive adversary, which manifests itself in protocols that require more computation and communication. Due to these complications, it is very common for research in the area of MPC-based ML to consider passive adversaries for both training and inference [1, 2, 3, 4, 5, 6, 7, 8, 9, 10, 11], and several implemented frameworks only withstand passive adversaries [12, 13, 14, 15, 16, 17] .  \nAlthough deploying a passive protocol is appealing in practice due to the smaller costs, this requires arguing that the system will not be attacked by an active adversary. One common “argument” is that active adversaries can be detected since their attacks lead to large deviations from typical protocol behavior (in machine learning training, this may be done by checking the model's accuracy on test  \n􀀃 Work done while at Aarhus University.  \nPreprint. Under review.  \ndata); if cheating is detected, it would be a reputational risk to the party involved (which is especially signiﬁcant for established companies, a common setting studied in privacy-preserving ML) . Our work challenges this argument, ﬁnding that it is possible for an active adversary to achieve a variety of malicious behaviors in machine learning models without being detected. Our ﬁndings can be compared to active adversaries in Bitcoin mining, where strategic manipulation of transactions is hard to detect due to network randomness [18] . Similarly, we ﬁnd parallels with the concrete risks of deploying algorithms with weak privacy guarantees, echoing concerns in differential privacy research [19, 20] . We expect our work to encourage more careful parameter selection in MPC ML training protocols.  \n1.1 Our Contribution  \nWe challeng","cbCairHt3zABxBZV","https://ap.wps.com/l/cbCairHt3zABxBZV","pdf",393812,6,1,20,"English","en",105,"# Abstract\n# Introduction\n## Our Contribution\n# Background and Related Work\n## MPC Background","[{\"question\":\"什么是被动安全（passively secure）MPC 训练模型的威胁模型？\",\"answer\":\"被动安全威胁模型假设对手遵循协议，仅试图从协议通信与最终模型中获取信息；而主动对手可能任意偏离协议并操纵行为。\"},{\"question\":\"论文提出了哪些类型的攻击来对现有被动安全协议进行破坏？\",\"answer\":\"作者给出显式、有效的低层攻击，用于操纵比较与激活函数等安全计算；并进一步提出高层攻击策略，如梯度平移、梯度置零和梯度缩放，以影响完整学习算法。\"},{\"question\":\"这些攻击如何影响模型的完整性与隐私保护？\",\"answer\":\"攻击不仅会破坏模型的完整性，还可能泄露训练数据隐私，甚至实现重建精确训练数据；同时强调其被检测风险几乎为零。\"}]","Covert Attacks on Machine Learning Training in Passively Secure MPC | PDF",1785903648,50,{"code":4,"msg":32,"data":33},"ok",{"site_id":25,"language":24,"slug":34,"title":13,"keywords":35,"description":14,"schema_data":36,"social_meta":88,"head_meta":90,"extra_data":92,"updated_unix":29},"covert-attacks-on-machine-learning-training-in-passively-secure-mpc","",{"@graph":37,"@context":87},[38,55,70],{"@type":39,"itemListElement":40},"BreadcrumbList",[41,45,49,52],{"item":42,"name":43,"@type":44,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":46,"name":47,"@type":44,"position":48},"https://docshare.wps.com/document/","Document",2,{"item":50,"name":12,"@type":44,"position":51},"https://docshare.wps.com/document/research-report/",3,{"item":53,"name":13,"@type":44,"position":54},"https://docshare.wps.com/document/covert-attacks-on-machine-learning-training-in-passively-secure-mpc/126179/",4,{"url":53,"name":13,"@type":56,"author":57,"headline":13,"publisher":59,"fileFormat":62,"inLanguage":24,"description":14,"dateModified":63,"datePublished":64,"encodingFormat":62,"isAccessibleForFree":65,"interactionStatistic":66},"DigitalDocument",{"name":9,"@type":58},"Person",{"url":42,"name":60,"@type":61},"DocShare","Organization","application/pdf","2026-08-23","2026-08-05",true,{"@type":67,"interactionType":68,"userInteractionCount":20},"InteractionCounter",{"@type":69},"ViewAction",{"@type":71,"mainEntity":72},"FAQPage",[73,79,83],{"name":74,"@type":75,"acceptedAnswer":76},"什么是被动安全（passively secure）MPC 训练模型的威胁模型？","Question",{"text":77,"@type":78},"被动安全威胁模型假设对手遵循协议，仅试图从协议通信与最终模型中获取信息；而主动对手可能任意偏离协议并操纵行为。","Answer",{"name":80,"@type":75,"acceptedAnswer":81},"论文提出了哪些类型的攻击来对现有被动安全协议进行破坏？",{"text":82,"@type":78},"作者给出显式、有效的低层攻击，用于操纵比较与激活函数等安全计算；并进一步提出高层攻击策略，如梯度平移、梯度置零和梯度缩放，以影响完整学习算法。",{"name":84,"@type":75,"acceptedAnswer":85},"这些攻击如何影响模型的完整性与隐私保护？",{"text":86,"@type":78},"攻击不仅会破坏模型的完整性，还可能泄露训练数据隐私，甚至实现重建精确训练数据；同时强调其被检测风险几乎为零。","https://schema.org",{"og:url":53,"og:type":89,"og:title":13,"og:site_name":60,"og:description":14},"article",{"robots":91,"canonical":53},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":94},[95,99,103,107,112,115,120,123,127,130,134],{"id":21,"doc_module":4,"doc_module_name":47,"category_name":96,"show_sort_weight":97,"slug":98},"Story & Novel",90,"story-novel",{"id":48,"doc_module":4,"doc_module_name":47,"category_name":100,"show_sort_weight":101,"slug":102},"Literature",80,"literature",{"id":54,"doc_module":4,"doc_module_name":47,"category_name":104,"show_sort_weight":105,"slug":106},"Exam",70,"exam",{"id":108,"doc_module":4,"doc_module_name":47,"category_name":109,"show_sort_weight":110,"slug":111},5,"Comic",60,"comic",{"id":20,"doc_module":4,"doc_module_name":47,"category_name":113,"show_sort_weight":30,"slug":114},"Technology","technology",{"id":116,"doc_module":4,"doc_module_name":47,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":47,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":47,"category_name":125,"show_sort_weight":22,"slug":126},9,"Religion & Spirituality","religion-spirituality",{"id":22,"doc_module":4,"doc_module_name":47,"category_name":128,"show_sort_weight":22,"slug":129},"World Cup","world-cup",{"id":131,"doc_module":4,"doc_module_name":47,"category_name":132,"show_sort_weight":131,"slug":133},10,"Lifestyle","lifestyle",{"id":135,"doc_module":4,"doc_module_name":47,"category_name":136,"show_sort_weight":108,"slug":137},19,"General","general"]