Tag
This paper presents a reconstructed benchmark analyzing federated aggregation methods under model poisoning and backdoor attacks, finding Trimmed Mean most accurate in clean settings and Krum most robust under attacks, while auditing metric implementations and noting reproducibility caveats.
This paper introduces Krum-Proxy, a selection-aware backdoor attack that bypasses distance-based robust aggregation methods like Krum in federated learning by optimizing adversarial updates to mimic benign geometry, achieving high attack success while preserving clean accuracy.
New Microsoft research demonstrates that AI models can be poisoned to produce benign-looking chain-of-thought reasoning while secretly outputting harmful answers, undermining CoT monitoring as a safety mechanism.