{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,14]],"date-time":"2026-07-14T11:19:11Z","timestamp":1784027951373,"version":"3.55.0"},"reference-count":79,"publisher":"IEEE","license":[{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-009"},{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-001"}],"funder":[{"DOI":"10.13039\/501100011318","name":"Fondation Botnar","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100011318","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023,5]]},"DOI":"10.1109\/sp46215.2023.10179291","type":"proceedings-article","created":{"date-parts":[[2023,7,21]],"date-time":"2023-07-21T17:18:15Z","timestamp":1689959895000},"page":"418-436","source":"Crossref","is-referenced-by-count":24,"title":["On the (In)security of Peer-to-Peer Decentralized Machine Learning"],"prefix":"10.1109","author":[{"given":"Dario","family":"Pasquini","sequence":"first","affiliation":[{"name":"EPFL,SPRING Lab,Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mathilde","family":"Raynal","sequence":"additional","affiliation":[{"name":"EPFL,SPRING Lab,Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Carmela","family":"Troncoso","sequence":"additional","affiliation":[{"name":"EPFL,SPRING Lab,Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","article-title":"Personalized and private peer-to-peer machine learning","author":"Bellet","year":"2018"},{"key":"ref2","article-title":"Machine learning with adversaries: Byzantine tolerant gradient descent","author":"Blanchard","year":"2017","journal-title":"NeurIPS"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/eurosp57164.2023.00020"},{"key":"ref4","article-title":"Practical secure aggregation for privacy-preserving machine learning","volume-title":"CCS.","author":"Bonawitz","year":"2017"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833649"},{"key":"ref6","article-title":"The fundamental price of secure aggregation in differentially private federated learning","author":"Chen","year":"2022"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-23502-4_10"},{"key":"ref8","article-title":"An analysis of single-layer networks in unsupervised feature learning","author":"Coates","year":"2011","journal-title":"AISTATS."},{"key":"ref9","article-title":"Privacy amplification by decentralization","author":"Cyffers","year":"2020"},{"key":"ref10","article-title":"Muffliato: Peer-to-peer privacy amplification for decentralized optimization and averaging","volume-title":"Advances in Neural Information Processing Systems","author":"Cyffers","year":"2022"},{"key":"ref11","article-title":"DisPFL: Towards communication-efficient personalized federated learning via decentralized sparse training","volume-title":"ICML.","author":"Dai","year":"2022"},{"key":"ref12","article-title":"Asynchronous byzantine machine learning (the case of SGD)","volume-title":"ICML.","author":"Damaskinos","year":"2018"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1007\/11787006_1"},{"key":"ref14","article-title":"Collaborative learning in the jungle","author":"El-Mhamdi","year":"2020"},{"key":"ref15","article-title":"Robbing the fed: Directly obtaining private data in federated learning with modified models","volume-title":"International Conference on Learning Representations","author":"Fowl"},{"key":"ref16","article-title":"Inverting gradients - how easy is it to break privacy in federated learning?","author":"Geiping","year":"2020","journal-title":"NeurIPS"},{"key":"ref17","article-title":"Herbivore: A Scalable and Efficient Protocol for Anonymous Communication","author":"Goel","year":"2003","journal-title":"Tech. Rep."},{"key":"ref18","article-title":"Badnets: Identifying vulnerabilities in the machine learning model supply chain","author":"Gu","year":"2017"},{"key":"ref19","article-title":"Federated learning for mobile keyboard prediction","author":"Hard","year":"2019"},{"key":"ref20","article-title":"Central server free federated learning over single-sided trust social networks","author":"He","year":"2019"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref22","article-title":"Byzantine-robust decentralized learning via self-centered clipping","author":"He","year":"2022"},{"key":"ref23","article-title":"Gossip learning as a decentralized alternative to federated learning","volume-title":"IFIP International Conference on Distributed Applications and Interoperable Systems","author":"Hegedu\u02dds"},{"key":"ref24","article-title":"Deep models under the gan: Information leakage from collaborative deep learning","volume-title":"CCS.","author":"Hitaj","year":"2017"},{"key":"ref25","article-title":"Decentralized federated learning: A segmented gossip approach","author":"Hu","year":"2019"},{"key":"ref26","article-title":"Gradient inversion with generative image prior","author":"Jeon","year":"2021","journal-title":"NeurIPS"},{"key":"ref27","article-title":"The distributed discrete gaussian mechanism for federated learning with secure aggregation","volume-title":"ICML.","author":"Kairouz","year":"2021"},{"key":"ref28","article-title":"Advances and open problems in federated learning","author":"Kairouz","year":"2019","journal-title":"CoRR"},{"key":"ref29","article-title":"Learning from history for byzantine robust optimization","volume-title":"ICML.","author":"Karimireddy","year":"2021"},{"key":"ref30","article-title":"Decentralized deep learning with arbitrary communication compression","volume-title":"International Conference on Learning Representations","author":"Koloskova"},{"key":"ref31","article-title":"A unified theory of decentralized SGD with changing topology and local updates","volume-title":"ICML.","author":"Koloskova","year":"2020"},{"key":"ref32","article-title":"Decentralized stochastic optimization and gossip algorithms with compressed communication","volume-title":"ICML.","author":"Koloskova","year":"2019"},{"key":"ref33","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009","journal-title":"Tech. Rep."},{"key":"ref34","article-title":"Peer-to-peer federated learning on graphs","author":"Lalitha","year":"2019"},{"key":"ref35","article-title":"Fully decentralized federated learning","volume-title":"Third workshop on Bayesian Deep Learning (NeurIPS)","author":"Lalitha"},{"key":"ref36","article-title":"Can decentralized algorithms outperform centralized algorithms? a case study for decentralized parallel stochastic gradient descent","author":"Lian","year":"2017","journal-title":"NeurIPS"},{"key":"ref37","article-title":"Understanding membership inferences on well-generalized learning models","author":"Long","year":"2018"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/CISS48834.2020.1570617414"},{"key":"ref39","article-title":"Federated multi-task learning under a mixture of distributions","author":"Marfoq","year":"2021","journal-title":"NeurIPS"},{"key":"ref40","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Artificial intelligence and statistics.","author":"McMahan","year":"2017"},{"key":"ref41","article-title":"Learning differentially private recurrent language models","author":"McMahan","year":"2017"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00029"},{"key":"ref43","article-title":"Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning","author":"Milad","year":"2019","journal-title":"IEEE S&P"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653683"},{"key":"ref45","article-title":"Local and central differential privacy for robustness and privacy in federated learning","author":"Naseri","year":"2020"},{"key":"ref46","article-title":"Comprehensive privacy analysis of deep learning","author":"Nasr","year":"2018","journal-title":"IEEE S&P"},{"key":"ref47","article-title":"Federated learning with buffered asynchronous aggregation","author":"Nguyen","year":"2021"},{"key":"ref48","article-title":"Theory-oriented deep leakage from gradients via linear equation solver","author":"Pan","year":"2020"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.23919\/IFIPNetworking52078.2021.9472790"},{"key":"ref50","article-title":"Eluding secure aggregation in federated learning via model inconsistency","author":"Pasquini","year":"2021"},{"key":"ref51","article-title":"Decentralized federated graph neural networks","author":"Pei","year":"2021","journal-title":"FTL-IJCAI"},{"key":"ref52","article-title":"Braintorrent: A peer-to-peer environment for decentralized federated learning","author":"Roy","year":"2019"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1145\/1866919.1866921"},{"key":"ref54","article-title":"A survey on routing in anonymous communication protocols","author":"Shirazi","year":"2018","journal-title":"ACM Comput. Surv."},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/ALLERTON.2015.7447103"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref57","article-title":"Systematic evaluation of privacy risks of machine learning models","volume-title":"USENIX Security Symposium","author":"Song"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2022.3196503"},{"key":"ref59","article-title":"Text classification with movie reviews","year":"2023"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560554"},{"key":"ref61","article-title":"Relaysum for decentralized deep learning on heterogeneous data","author":"Vogels","year":"2021","journal-title":"NeurIPS"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/ICC47138.2019.9123209"},{"key":"ref63","article-title":"In search of an anonymous and secure lookup: attacks on structured peer-to-peer anonymous communication systems","volume-title":"CCS.","author":"Wang","year":"2010"},{"key":"ref64","article-title":"Fishing for user data in large-batch federated learning via gradient magnification","volume-title":"ICML","author":"Wen","year":"2022"},{"key":"ref65","article-title":"Local differential privacy in decentralized optimization","author":"Xiao","year":"2019"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1109\/SPAWC48557.2020.9154332"},{"key":"ref67","article-title":"Applied federated learning: Improving google keyboard query suggestions","author":"Yang","year":"2018"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560675"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2018.00027"},{"key":"ref70","article-title":"Byzantine-robust distributed learning: Towards optimal statistical rates","author":"Yin","year":"2018"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01607"},{"key":"ref72","article-title":"Exponential graph is provably efficient for decentralized deep training","author":"Ying","year":"2021","journal-title":"NeurIPS"},{"key":"ref73","article-title":"Bluefog: Make decentralized algorithms practical for optimization and deep learning","author":"Ying","year":"2021"},{"key":"ref74","article-title":"Defed: A principled decentralized and privacy-preserving federated learning algorithm","author":"Yuan","year":"2021"},{"key":"ref75","article-title":"Event-triggered decentralized federated learning over resource-constrained edge devices","author":"Zehtabi","year":"2022"},{"key":"ref76","article-title":"Personalized federated learning with first order model optimization","volume-title":"International Conference on Learning Representations","author":"Zhang"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP51992.2021.00025"},{"key":"ref78","article-title":"R-GAP: recursive gradient attack on privacy","author":"Zhu","year":"2020"},{"key":"ref79","article-title":"Deep leakage from gradients","author":"Zhu","year":"2019","journal-title":"NeurIPS"}],"event":{"name":"2023 IEEE Symposium on Security and Privacy (SP)","location":"San Francisco, CA, USA","start":{"date-parts":[[2023,5,21]]},"end":{"date-parts":[[2023,5,25]]}},"container-title":["2023 IEEE Symposium on Security and Privacy (SP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10179215\/10179280\/10179291.pdf?arnumber=10179291","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,20]],"date-time":"2024-07-20T05:17:27Z","timestamp":1721452647000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10179291\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,5]]},"references-count":79,"URL":"https:\/\/doi.org\/10.1109\/sp46215.2023.10179291","relation":{},"subject":[],"published":{"date-parts":[[2023,5]]}}}