Long-term Data Sharing �under Exclusivity Attacks
ITCS, Shanghai University of Finance and Economics, April 2023
Kindly supported by ERC grant 740435
Moshe Tennenholtz
Technion, Israel
Yotam Gafni
Technion, Israel
Motivation: �A growing interest in building shared models…
Building shared models – a simple use case
Great… Where is the problem?
Other works study how competition changes the nature of individual learning (without sharing):
We talk about a different security risk we call exclusivity attacks
Main Question:
where all agents report truthfully and accept the model estimation
can an attacker deviate successfully with an exclusivity attack?
Main Results:
A successful attack with one-shot data sharing
A failed attack with one-shot data sharing
One-shot vs long-term
Why long-term attacks are easier: �Learning average with two requests
Why long-term attacks are hard: �No ‘garbage’ attacks on max
Formal model – Continuous Protocol
‘Garbage Attack’ in the continuous protocol with Max
Revisiting max in the continuous protocol.
Here 90 < y < x.
Agent 1 is strategic. Agent 2 is truthful.
Observed history, Strategy and Vulnerability
Observed history, Strategy and Vulnerability (Cont.)
K-center
In this example:
0
-2
-4
5
6
7
`Sneak attacks’: A Recipe for vulnerability
Sneak attack on k-center with k=3
Sneak attack on K-center (Cont.)
K-center and Vulnerable*
Set-choice algorithms
Attacks on set-choice algorithms with forceable winners can not explicitly lie
Linear regression
Challenge:
How to ‘reverse’ effects of fake points submitted?
A sneak attack
Triangulation attacks
High level construction of triangulation for LR
Example of a triangulation attack (1-LR)
Under truth
Under triangulation
Example of a triangulation attack (2-LR)
The periodic communication model
In periodic model, LR is not vulnerable
Future directions, discussion
Future research preview: �What happens when we introduce noise?��Idea: Return the LR estimator with small additive noise
��Take away messages:�����Thanks for listening!