[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-126466-en":3,"doc-seo-126466-105":31,"detail-sidebar-cat-0-en-105":93},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":28,"seo_description":14,"update_tm":29,"read_time":30},126466,962084925290,"Ophelia","https://ap-avatar.wpscdn.com/davatar_085a072bc5b1113ac321206ff7593b45",8,"Research & Report","On the Robustness of Distributed Machine Learning against Transfer Attacks - arXiv 2412.14080v1","Distributed machine learning attracts wide interest, yet existing studies analyze robustness in distributed settings by isolating either training or inference. This work investigates the combined robustness achieved when both learning and inference are distributed, including fully heterogeneous configurations across training data, architecture, scheduler, optimizer, and other parameters. Theory and extensive CIFAR10 and FashionMNIST experiments show consistent improvements in the accuracy–robustness tradeoff against strong transfer-based attacks. On CIFAR10, for the Common Weakness attack, robust accuracy increases by up to 40% with minimal impact on clean accuracy.","On the Robustness of Distributed Machine Learning against  \nTransfer Attacks  \nSébastien Andreina 1 , Pascal Zimmer2 , Ghassan Karame2  \n1 NEC Labs Europe, Germany  \n2 Ruhr University Bochum, Germany  \n[sebastien.andreina@neclab.eu](sebastien.andreina@neclab.eu), {pascal.zimmer, [ghassan.karame}@rub.de](ghassan.karame}@rub.de)  \narXiv :2412 . 14080v1 [ cs .LG] 18 Dec 2024  \nAbstract  \nAlthough distributed machine learning (distributed ML) is gaining considerable attention in the community, prior works have independently looked at instances of distributed ML in either the training or the inference phase. No prior work has examined the combined robustness stemming from distributing both the learning and the inference process.  \nIn this work, we explore, for the first time, the robustness of distributed ML models that are fully heterogeneous in training data, architecture, scheduler, optimizer, and other model parameters. Supported by theory and extensive experimental validation using CIFAR10 and FashionMNIST, we show that such properly distributed ML instantiations achieve across-the-board improvements in accuracy-robustness tradeoffs against state-of-the-art transfer-based attacks that could otherwise not be realized by current ensemble or federated learning instantiations. For instance, our experiments on CIFAR10 show that for the Common Weakness attack, one of the most powerful state-of-the-art transfer-based attacks, our method improves robust accuracy by up to 40%, with a minimal impact on clean task accuracy. 1  \n1 Introduction  \nNowadays, many applications increasingly rely on various forms of distributed learning. For instance, Google spell-checking utilizes horizontal federated learning (Zhang et al. 2023b), and Apple, among others, may also be adopting similar approaches (Paulik et al. 2021) . Autonomous vehicles are soon expected to follow suit (Chellapandi et al. 2024) . In the financial sector, vertical federated learning is currently employed (Liu et al. 2024), and many researchers have already begun exploring decentralized learning without a central authority (Lian et al. 2017; Dhasade et al. 2023) .  \nAlthough federated and decentralized learning is gaining considerable interest and attention from practitioners and researchers, the concept of distributed learning was first attempted with ensemble learning. Here, weak learners employing different model architectures (typically co-located on the same machine) jointly train  \n1 The code is available at [https://github](https://github.com/RUB)[.](https://github.com/RUB)[com/RUB](https://github.com/RUB)InfSec/distributed_learning_robustness.  \nusing the same dataset; inference requires some sort of majority vote among those weak learners. Unlike ensemble learning, federated learning typically requires weak learners to jointly train a global model (optionally with the help of a central server) . The main motivation of these instantiations is to obviate the need for weak learners to share their local training data, hence increasing learners’ privacy while allowing for diverse data to be effectively used for training. As such, current federated learning approaches primarily aim to diversify data sources for training but do not directly alter the inference process. In contrast, ensemble learning focuses mainly on inference by enhancing model diversity. The literature features a number of contributions that analyze the privacy provisions of FL and its resistance to backdoors on the one hand and the robustness offered by ensemble learning on the other hand. No prior work has examined the combined robustness and security pro visions stemming from distributing both the learning and the inference process . This is particularly relevant since centralized ML models, such as deep neural networks, have been shown to lack robustness against adversarial examples (Szegedy et al. 2014; Biggio et al. 2013) .  \nIn this paper, we address this gap and explore whether pure distributed lear","cbCaip6wQbKgqLQ0","https://ap.wps.com/l/cbCaip6wQbKgqLQ0","pdf",546402,9,1,11,"English","en",105,"# Introduction\n## Background and Motivation\n## Research Questions\n## Robustness Evaluation","[{\"question\":\"What gap does the paper address about robustness in distributed machine learning?\",\"answer\":\"Prior work examined robustness by looking separately at distributed learning instances during either training or inference. The paper studies robustness that arises when both learning and inference are distributed together.\"},{\"question\":\"What makes the proposed distributed ML setting different from ensemble or federated learning?\",\"answer\":\"The setting is a hybrid that keeps benefits of federated/decentralized learning and traditional ensembles, allowing learners to independently choose both training parameters (e.g., optimizer and scheduler) and model architecture parameters, in addition to training data.\"},{\"question\":\"How does the method perform against transfer-based attacks on CIFAR10?\",\"answer\":\"Experiments on CIFAR10 show that for the Common Weakness attack, robust accuracy improves by up to 40% while causing minimal impact on clean-task accuracy.\"}]","On the Robustness of Distributed Machine Learning against Transfer Attacks - arXiv 2412.14080v1 | PDF",1785905203,28,{"code":4,"msg":32,"data":33},"ok",{"site_id":25,"language":24,"slug":34,"title":13,"keywords":35,"description":14,"schema_data":36,"social_meta":88,"head_meta":90,"extra_data":92,"updated_unix":29},"on-the-robustness-of-distributed-machine-learning-against-transfer-attacks-arxiv-241214080v1","",{"@graph":37,"@context":87},[38,55,70],{"@type":39,"itemListElement":40},"BreadcrumbList",[41,45,49,52],{"item":42,"name":43,"@type":44,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":46,"name":47,"@type":44,"position":48},"https://docshare.wps.com/document/","Document",2,{"item":50,"name":12,"@type":44,"position":51},"https://docshare.wps.com/document/research-report/",3,{"item":53,"name":13,"@type":44,"position":54},"https://docshare.wps.com/document/on-the-robustness-of-distributed-machine-learning-against-transfer-attacks-arxiv-241214080v1/126466/",4,{"url":53,"name":13,"@type":56,"author":57,"headline":13,"publisher":59,"fileFormat":62,"inLanguage":24,"description":14,"dateModified":63,"datePublished":64,"encodingFormat":62,"isAccessibleForFree":65,"interactionStatistic":66},"DigitalDocument",{"name":9,"@type":58},"Person",{"url":42,"name":60,"@type":61},"DocShare","Organization","application/pdf","2026-08-23","2026-08-05",true,{"@type":67,"interactionType":68,"userInteractionCount":20},"InteractionCounter",{"@type":69},"ViewAction",{"@type":71,"mainEntity":72},"FAQPage",[73,79,83],{"name":74,"@type":75,"acceptedAnswer":76},"What gap does the paper address about robustness in distributed machine learning?","Question",{"text":77,"@type":78},"Prior work examined robustness by looking separately at distributed learning instances during either training or inference. The paper studies robustness that arises when both learning and inference are distributed together.","Answer",{"name":80,"@type":75,"acceptedAnswer":81},"What makes the proposed distributed ML setting different from ensemble or federated learning?",{"text":82,"@type":78},"The setting is a hybrid that keeps benefits of federated/decentralized learning and traditional ensembles, allowing learners to independently choose both training parameters (e.g., optimizer and scheduler) and model architecture parameters, in addition to training data.",{"name":84,"@type":75,"acceptedAnswer":85},"How does the method perform against transfer-based attacks on CIFAR10?",{"text":86,"@type":78},"Experiments on CIFAR10 show that for the Common Weakness attack, robust accuracy improves by up to 40% while causing minimal impact on clean-task accuracy.","https://schema.org",{"og:url":53,"og:type":89,"og:title":13,"og:site_name":60,"og:description":14},"article",{"robots":91,"canonical":53},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":94},[95,99,103,107,112,117,122,125,129,132,136],{"id":21,"doc_module":4,"doc_module_name":47,"category_name":96,"show_sort_weight":97,"slug":98},"Story & Novel",90,"story-novel",{"id":48,"doc_module":4,"doc_module_name":47,"category_name":100,"show_sort_weight":101,"slug":102},"Literature",80,"literature",{"id":54,"doc_module":4,"doc_module_name":47,"category_name":104,"show_sort_weight":105,"slug":106},"Exam",70,"exam",{"id":108,"doc_module":4,"doc_module_name":47,"category_name":109,"show_sort_weight":110,"slug":111},5,"Comic",60,"comic",{"id":113,"doc_module":4,"doc_module_name":47,"category_name":114,"show_sort_weight":115,"slug":116},6,"Technology",50,"technology",{"id":118,"doc_module":4,"doc_module_name":47,"category_name":119,"show_sort_weight":120,"slug":121},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":47,"category_name":12,"show_sort_weight":123,"slug":124},30,"research-report",{"id":20,"doc_module":4,"doc_module_name":47,"category_name":126,"show_sort_weight":127,"slug":128},"Religion & Spirituality",20,"religion-spirituality",{"id":127,"doc_module":4,"doc_module_name":47,"category_name":130,"show_sort_weight":127,"slug":131},"World Cup","world-cup",{"id":133,"doc_module":4,"doc_module_name":47,"category_name":134,"show_sort_weight":133,"slug":135},10,"Lifestyle","lifestyle",{"id":137,"doc_module":4,"doc_module_name":47,"category_name":138,"show_sort_weight":108,"slug":139},19,"General","general"]