Using Ml to Protect Ml: Defending Collaborative Privacy-Preserving Model Training
AJAS · 2026 Robotics and Intelligent Machines (inferred)
Overview
In machine learning applications using sensitive, distributed big data, i.e., medical data, voting records, etc., it must be assured that model training data cannot be recovered or exposed publicly. Currently, this inhibits wide-scale analysis of sensitive data across research institutions and industry partners. Next-generation models must be trained collectively, introducing a new set of security risks to the confidentiality of sensitive data. These security risks, such as model inversion, reconstruction attacks, etc., allow adversaries to extract the sensitive data on which models have been trained. To address this issue, differentially private training architectures, such as SplitFed Learning, have been introduced; these architectures keep sensitive data on-site and secure while training the model using information from the public gradients and following a distributed machine learning computing pattern. Still, they do not prevent the intrusion of malicious clients who can send incorrect data to collective training servers to leak parts of the sensitive data on which the model is trained. This paper addresses this vulnerability, developing robust detection mechanisms against adversaries who insert less than 1/3 of malicious clients into training and attempt to reveal sensitive data. Specifically, we propose a novel reinforcement learning machine-learning-based solution that can consistently defend against fixed and variable-based distance attacks from malicious clients and actively train itself to recognize malicious clients in numerous public model training scenarios. We then perform tests on publicly available datasets using edge devices and demonstrate the resilience of our approach against state-of-the-art attacks.
Competition history
- AJAS 2026
Related projects
JSHS · 2020
Towards Privacy-Preserving Intelligence: Differential Privacy in Machine Learning
ISEF · 2025
SplitSafe: A Novel Adversarial Attack Detection and Mitigation Technique for Artificial Intelligence Image Recognition Systems
AJAS · 2025
Privacy-Preserving Fundus Disease Diagnosis Using Federated Learning
CSEF · 2026
A Novel Mechanistic Framework for Identifying and Neutralizing Latent Deception Signatures in Large Language Models
ISEF · 2024
AdvMed: Detecting Adversarial Attacks in Medical Deep Learning Systems
ISEF · 2024
Enhancing Federated Learning Using Mathematical Theorems and Coding Technologies
AJAS · 2026
Evaluating Corruption Defenses for Model Robustness
ISEF · 2019
Protection of Deep Neural Networks against Adversarial Attacks with Application to Facial Recognition
Closest projects by meaning, across every fair and year in the corpus.
Browse more like this
Source: AAAS Annual Meeting (Confex) / American Junior Academy of Science