2024 · paper
Mitigating data injection attacks on federated learning
The institutional publication list records work on federated-learning robustness against injected data.[111]
statistical signal processing, wireless communications and network learning
אמיר לשם
Identity: verifiedThe Bar-Ilan research portal and university-hosted CV identify Amir Leshem in the Faculty of Engineering and match the roster spelling. [111][112]
Documented foundation
Bar-Ilan engineering professor whose institutional record spans statistical signal processing, wireless systems, distributed learning and robust federated methods.[111][112]
distributed learningwireless resource allocationgame-theoretic signal processingadversarially robust federated learning
A 23-page university-hosted academic CV was inspected; the institutional research portal supplies the more current output list.[111][112]
Open CVRepresentative records, not a complete publication list. Metadata confirms attribution; it does not independently replicate a result.
2024 · paper
The institutional publication list records work on federated-learning robustness against injected data.[111]
4 catalogued patent records · 4 identified families
Coverage: Partial inventor search
Four additions: two Metalink-origin patents, the Goldberger communication-system application and separately inspected WO2018198118A1 with Itshak Bergel/Bar-Ilan. CV page 21 cites US20090257581 for Leshem/Bergel, but the inspected publication has a different title and inventors Biyani/Mahadevan/Duvaut; that citation was rejected. The 2018 record is not asserted to repair the CV’s 2015 institutional date or erroneous number. No exhaustive legal-family audit.
WO2018198118A1 · Published 2018-11-01
Published patent document inspected
Publication assignee: Bar Ilan University
The inspected inventor field names Amir Leshem. The record names Amir Leshem and Itshak Bergel at Bar-Ilan. This is independently attributable; it is not assumed to correct the CV year or erroneous 2009 publication number. Assignee means the observed original-assignee field; no current ownership conclusion.[340]
US20110142181A1 · Published 2011-06-16
Published patent document inspected
The inspected inventor field names Amir Leshem. The university-hosted CV lists the same identifier and inventor. Assignee means the observed original-assignee field; no current ownership conclusion.[317][420]
US7636406B2 · Published 2009-12-22
Published patent document inspected
Publication assignee: Metalink Ltd
The inspected inventor field names Amir Leshem. The university-hosted CV lists the same identifier and inventor. Assignee means the observed original-assignee field; no current ownership conclusion.[335][420]
US7609789B2 · Published 2009-10-27
Published patent document inspected
Publication assignee: Metalink Ltd
The inspected inventor field names Amir Leshem. The university-hosted CV lists the same identifier and inventor. Assignee means the observed original-assignee field; no current ownership conclusion.[334][420]
Original evidence: not verified
The bounded pass did not inspect a specific attributable patent record; no absence claim is made.
Records are counted separately from identified families. Author-reported entries are labelled and may still need publication verification. Inventorship, publication-time applicant and current ownership are different facts. No legal-status, patentability or freedom-to-operate conclusion is made.
Scores prioritize research fit from 1–10; they are not probabilities.
Review: Reviewed with limitations
Proposed capability matches, not confirmed relationships. Scores are analyst judgments with low forecast confidence; researcher interests, capacity and feasibility need confirmation.
11 candidates
Connection 1
Original proposal
Proposal hypothesis: Zaidel's multiuser/MIMO analysis can bound the interference regime in which Leshem's distributed resource-allocation method should be evaluated.[102][111][112]
Proposed first test: Simulate a fixed multiuser uplink and compare distributed allocation with static allocation and a capacity-informed reference under congestion.
Rank 1/11; fit 10/10: topic overlap 4/4, complementarity 3/3, first-test feasibility 3/3. Original initiative connection retained. No higher-scoring new candidate displaces this original. Equal scores retain originals first, then stable profile order. The underlying capabilities and proposed first test explain the component judgments. Specific scientific limitation: Feasible analytical/simulation comparison; attack resilience requires a separately specified adversary.
Analyst proposal hypothesis, not an established collaboration, commitment, evidence-confidence rating or assessment of researcher quality; confirm participation and access before work.
Connection 2
Original proposal
Proposal hypothesis: Amir Weiss's task-oriented compression supplies sensing messages for Leshem's distributed learning under congestion and corrupted updates.[108][109][111][112]
Proposed first test: In a synthetic sensor network, compare full and compressed updates with injected poisoning on estimation error, bandwidth and recovery.
Rank 2/11; fit 10/10: topic overlap 4/4, complementarity 3/3, first-test feasibility 3/3. Original initiative connection retained. No higher-scoring new candidate displaces this original. Equal scores retain originals first, then stable profile order. The underlying capabilities and proposed first test explain the component judgments. Specific scientific limitation: Compression and adversarial robustness can conflict; the attack and information-loss models must be explicit.
Analyst proposal hypothesis, not an established collaboration, commitment, evidence-confidence rating or assessment of researcher quality; confirm participation and access before work.
Connection 3
Original proposal
Proposal hypothesis: Leshem's distributed adaptation and Noam's estimation/interference models complement one another when spectrum-sharing decisions alter measurement quality.[111][112][130][131]
Proposed first test: Simulate two sharing networks and compare throughput-oriented and estimation-aware adaptation on rate and localization error under link loss.
Rank 3/11; fit 10/10: topic overlap 4/4, complementarity 3/3, first-test feasibility 3/3. Original initiative connection retained. No higher-scoring new candidate displaces this original. Equal scores retain originals first, then stable profile order. The underlying capabilities and proposed first test explain the component judgments. Specific scientific limitation: A bounded simulator is feasible; broader satellite-terrestrial generalization needs a separate propagation model.
Analyst proposal hypothesis, not an established collaboration, commitment, evidence-confidence rating or assessment of researcher quality; confirm participation and access before work.
Connection 4
Proposal hypothesis: Fetaya's adversarial/federated learning and Leshem's robust distributed learning directly meet on poisoned updates over constrained networks.[73][111][112]
Proposed first test: Compare two robust aggregation methods under identical poisoning and congestion settings on accuracy, bandwidth and recovery.
Rank 4/11; fit 10/10: topic overlap 4/4, complementarity 3/3, first-test feasibility 3/3. Added capability match outside the original initiative graph; prior collaboration or novelty was not established. Equal scores retain originals first, then stable profile order. The underlying capabilities and proposed first test explain the component judgments. Specific scientific limitation: The attack budget and data heterogeneity must be frozen before comparing robustness.
Analyst proposal hypothesis, not an established collaboration, commitment, evidence-confidence rating or assessment of researcher quality; confirm participation and access before work.
Connection 5
Proposal hypothesis: Zehavi's MIMO and coded-link constraints can ground Leshem's distributed wireless resource-allocation policies.[19][20][111][112]
Proposed first test: Simulate a coded MIMO link shared by adaptive users and compare outage and fairness with a fixed resource split.
Rank 5/11; fit 9/10: topic overlap 3/4, complementarity 3/3, first-test feasibility 3/3. Added capability match outside the original initiative graph; prior collaboration or novelty was not established. Equal scores retain originals first, then stable profile order. The underlying capabilities and proposed first test explain the component judgments. Specific scientific limitation: A shared channel and workload specification is needed before comparing algorithms.
Analyst proposal hypothesis, not an established collaboration, commitment, evidence-confidence rating or assessment of researcher quality; confirm participation and access before work.
Connection 6
Proposal hypothesis: Gelles can define correctness under noisy interaction while Leshem evaluates distributed learning under congestion and bad updates.[57][58][111][112]
Proposed first test: Simulate an iterative distributed task with separate channel corruption and poisoned updates; compare convergence and task correctness.
Rank 6/11; fit 9/10: topic overlap 3/4, complementarity 3/3, first-test feasibility 3/3. Added capability match outside the original initiative graph; prior collaboration or novelty was not established. Equal scores retain originals first, then stable profile order. The underlying capabilities and proposed first test explain the component judgments. Specific scientific limitation: Protocol reliability and model robustness are different guarantees and must be measured separately.
Analyst proposal hypothesis, not an established collaboration, commitment, evidence-confidence rating or assessment of researcher quality; confirm participation and access before work.
Connection 7
Proposal hypothesis: Somekh-Baruch can bound coding reliability while Leshem adapts wireless resources under uncertain and congested conditions.[87][111][112]
Proposed first test: Simulate an adaptive link policy with a mismatched decoder and compare empirical reliability to an explicitly applicable bound.
Rank 7/11; fit 9/10: topic overlap 3/4, complementarity 3/3, first-test feasibility 3/3. Added capability match outside the original initiative graph; prior collaboration or novelty was not established. Equal scores retain originals first, then stable profile order. The underlying capabilities and proposed first test explain the component judgments. Specific scientific limitation: A policy cannot inherit a bound outside its channel assumptions.
Analyst proposal hypothesis, not an established collaboration, commitment, evidence-confidence rating or assessment of researcher quality; confirm participation and access before work.
Connection 8
Proposal hypothesis: Medina's fault-tolerant network algorithms and Leshem's distributed learning can separate recovery from node faults and adaptation to congestion.[100][111][112]
Proposed first test: Simulate node loss during a distributed optimization task; compare recovery time, objective error and extra messages with a static topology.
Rank 8/11; fit 9/10: topic overlap 3/4, complementarity 3/3, first-test feasibility 3/3. Added capability match outside the original initiative graph; prior collaboration or novelty was not established. Equal scores retain originals first, then stable profile order. The underlying capabilities and proposed first test explain the component judgments. Specific scientific limitation: An algorithmic fault model does not establish resistance to poisoned training data.
Analyst proposal hypothesis, not an established collaboration, commitment, evidence-confidence rating or assessment of researcher quality; confirm participation and access before work.
Connection 9
Proposal hypothesis: Leshem's distributed resource allocation and Ilan Cohen's online/fair-allocation algorithms could compare efficiency against repeated-access inequity.[111][112][119][120]
Proposed first test: Simulate changing network demand and compare a throughput-only policy with an online fairness constraint on regret and access gaps.
Rank 9/11; fit 9/10: topic overlap 3/4, complementarity 3/3, first-test feasibility 3/3. Added capability match outside the original initiative graph; prior collaboration or novelty was not established. Equal scores retain originals first, then stable profile order. The underlying capabilities and proposed first test explain the component judgments. Specific scientific limitation: Fairness criteria are design choices; no deployment or participant agreement is implied.
Analyst proposal hypothesis, not an established collaboration, commitment, evidence-confidence rating or assessment of researcher quality; confirm participation and access before work.
Connection 10
Identity check needed: Conditional proposal: confirm the researcher identity and research interests before assessing this match.
Proposal hypothesis: Conditional on confirmation, Shtern's robust optimization can formulate uncertainty sets for Leshem's distributed wireless resource allocation.[83][84][85][111][112]
Conditional proposed first test: After identity confirmation, solve a small robust interference-allocation model and compare throughput and constraint violations with nominal allocation.
Rank 10/11; fit 8/10: topic overlap 3/4, complementarity 3/3, first-test feasibility 2/3. Added capability match outside the original initiative graph; prior collaboration or novelty was not established. Equal scores retain originals first, then stable profile order. The underlying capabilities and proposed first test explain the component judgments. Specific scientific limitation: No joint wireless project is established; the proposed contribution is optimization modelling.
Analyst proposal hypothesis, not an established collaboration, commitment, evidence-confidence rating or assessment of researcher quality; confirm participation and access before work. Conditional: confirm Shimrit Shtern identity mapping and current institutional affiliation before any internal team assignment. The BIU directory and current Technion appointment leave affiliation unresolved. Documented optimization expertise is conditional on that mapping; excluded from confirmed-team claims.
Connection 11
Proposal hypothesis: Leshem can define an adversarial federated-update problem and Mor Weiss can test private verification of a limited update property.[111][112][123]
Proposed first test: Compare a toy proof of update-bound compliance with plaintext inspection on verification cost and accepted invalid updates.
Rank 11/11; fit 8/10: topic overlap 3/4, complementarity 3/3, first-test feasibility 2/3. Added capability match outside the original initiative graph; prior collaboration or novelty was not established. Independent review lowered feasibility by one point: The update-bound proof test has essentially the same unresolved proof-statement/security assumptions as Ethan Fetaya-Mor Weiss, which receives feasibility 2/3. Name the committed update, bounded predicate, adversary and concrete proof implementation, or apply the same 2/3 feasibility here. Equal scores retain originals first, then stable profile order. The underlying capabilities and proposed first test explain the component judgments. Specific scientific limitation: A proven update bound does not establish that training data or model updates are benign.
Analyst proposal hypothesis, not an established collaboration, commitment, evidence-confidence rating or assessment of researcher quality; confirm participation and access before work.
10 candidates
Connection 1
Stony Brook University
Original proposal
Goldsmith's documented wireless and interconnected-systems research complements Leshem's distributed-learning and spectrum-management methods; this is a proposed match only.[21][103][111][112][456]
Simulate heterogeneous radios with congestion, poisoned updates and intermittent links; compare throughput, fairness and attack recovery with non-learning baselines.
Rank 1/10 after semantic revision; analyst score 10 = max(1, 4+3+3): topic overlap 4/4, complementarity 3/3, feasible first test 3/3. A bounded offline comparison is specified; required datasets and domain assumptions must still be checked. Original remains first under these components; original status breaks equal-score ties only, without a prestige bonus.
Proposed fit, not an assertion of a new or active relationship. Independent review pending; forecast confidence low. Partner interest, capacity, data access and any required experimental approvals/resources are unverified.
Connection 2
New York University
Proposed capability match: Amir Leshem's distributed learning, wireless resource allocation can be paired with Elza Erkip's documented information theory, communication theory for adversarially resilient shared-spectrum learning. The specific contribution is wireless channel and reliability analysis; this transfer is an analyst hypothesis.[111][112][451]
Compare two cooperative or non-cooperative link models with matched rate and power constraints using a simulated shared-spectrum learning workload with congestion, poisoned updates and intermittent links. Compare outage probability, achievable rate and power sensitivity with non-learning allocation and unprotected distributed learning.
Rank 2/10 after semantic revision; analyst score 9 = max(1, 3+3+3): topic overlap 3/4, complementarity 3/3, feasible first test 3/3. A bounded offline comparison is specified; required datasets and domain assumptions must still be checked.
Proposed fit, not an assertion of a new or active relationship. Independent review pending; forecast confidence low. Partner interest, capacity, data access and any required experimental approvals/resources are unverified.
Connection 3
University of Oxford
Proposed capability match: Amir Leshem's distributed learning, wireless resource allocation can be paired with Yarin Gal's documented Bayesian deep learning, uncertainty estimation for adversarially resilient shared-spectrum learning. The specific contribution is uncertainty and selective prediction; this transfer is an analyst hypothesis.[78][111][112][452]
Compare uncertainty estimates with calibrated single-model and ensemble baselines under a predefined shift using a simulated shared-spectrum learning workload with congestion, poisoned updates and intermittent links. Compare calibration error, risk-coverage and confident-error rate with non-learning allocation and unprotected distributed learning.
Rank 3/10 after semantic revision; analyst score 9 = max(1, 3+3+3): topic overlap 3/4, complementarity 3/3, feasible first test 3/3. A bounded offline comparison is specified; required datasets and domain assumptions must still be checked.
Proposed fit, not an assertion of a new or active relationship. Independent review pending; forecast confidence low. Partner interest, capacity, data access and any required experimental approvals/resources are unverified.
Connection 4
Stanford University
Proposed capability match: Amir Leshem's distributed learning, wireless resource allocation can be paired with Andrea Montanari's documented high-dimensional statistics, posterior sampling for adversarially resilient shared-spectrum learning. The specific contribution is high-dimensional statistical baselines; this transfer is an analyst hypothesis.[111][112][479]
Compare a regularized low-complexity estimator with a flexible model while varying sample size and dimensionality using a simulated shared-spectrum learning workload with congestion, poisoned updates and intermittent links. Compare generalization error, calibration and the sample-size threshold with non-learning allocation and unprotected distributed learning.
Rank 4/10 after semantic revision; analyst score 9 = max(1, 3+3+3): topic overlap 3/4, complementarity 3/3, feasible first test 3/3. A bounded offline comparison is specified; required datasets and domain assumptions must still be checked.
Proposed fit, not an assertion of a new or active relationship. Independent review pending; forecast confidence low. Partner interest, capacity, data access and any required experimental approvals/resources are unverified.
Connection 5
Massachusetts Institute of Technology
Proposed capability match: Amir Leshem's distributed learning, wireless resource allocation can be paired with Gregory Wornell's documented signal processing, statistical inference for adversarially resilient shared-spectrum learning. The specific contribution is joint statistical inference and information constraints; this transfer is an analyst hypothesis.[110][111][112][503]
Compare full-data inference with task-specific compressed statistics at fixed communication or storage budget using a simulated shared-spectrum learning workload with congestion, poisoned updates and intermittent links. Compare estimation error, calibration and bits per valid decision with non-learning allocation and unprotected distributed learning.
Rank 5/10 after semantic revision; analyst score 9 = max(1, 3+3+3): topic overlap 3/4, complementarity 3/3, feasible first test 3/3. A bounded offline comparison is specified; required datasets and domain assumptions must still be checked.
Proposed fit, not an assertion of a new or active relationship. Independent review pending; forecast confidence low. Partner interest, capacity, data access and any required experimental approvals/resources are unverified.
Connection 6
Harvard University
Proposed capability match: Amir Leshem's distributed learning, wireless resource allocation can be paired with Michael Mitzenmacher's documented algorithms and theory, systems and networks for adversarially resilient shared-spectrum learning. The specific contribution is algorithmic and systems baselines; this transfer is an analyst hypothesis.[101][111][112][478]
Compare two explicit sampling, load-balancing or scheduling algorithms under the same adversarial event trace using a simulated shared-spectrum learning workload with congestion, poisoned updates and intermittent links. Compare tail latency, failure rate and sensitivity to the event distribution with non-learning allocation and unprotected distributed learning.
Rank 6/10 after semantic revision; analyst score 8 = max(1, 2+3+3): topic overlap 2/4, complementarity 3/3, feasible first test 3/3. A bounded offline comparison is specified; required datasets and domain assumptions must still be checked.
Proposed fit, not an assertion of a new or active relationship. Independent review pending; forecast confidence low. Partner interest, capacity, data access and any required experimental approvals/resources are unverified.
Connection 7
Stanford University
Proposed capability match: Amir Leshem's distributed learning, wireless resource allocation can be paired with David Tse's documented information-theoretic methods, decentralized systems for adversarially resilient shared-spectrum learning. The specific contribution is first-principles data and decentralized-system modelling; this transfer is an analyst hypothesis.[111][112][496]
Compare a decentralized or information-constrained algorithm with a centralized reference on a small reproducible workload using a simulated shared-spectrum learning workload with congestion, poisoned updates and intermittent links. Compare communication cost, correctness and sensitivity to missing participants with non-learning allocation and unprotected distributed learning.
Rank 7/10 after semantic revision; analyst score 8 = max(1, 3+2+3): topic overlap 3/4, complementarity 2/3, feasible first test 3/3. A bounded offline comparison is specified; required datasets and domain assumptions must still be checked.
Proposed fit, not an assertion of a new or active relationship. Independent review pending; forecast confidence low. Partner interest, capacity, data access and any required experimental approvals/resources are unverified. His refreshed lab page describes wireless as a previous application and current work on decentralized systems; no active wireless project is assumed.
Connection 8
ETH Zurich and INSAIT
Proposed capability match for Amir Leshem with Bernhard Haeupler: Interactive coding addresses transport corruption; robust learning requires a separate poisoning model and aggregator, so complementarity is bounded.[59][111][112][459]
Simulate a fixed federated-learning task with two independent factors: corrupted/dropped transmitted bits and semantically poisoned but validly transmitted updates. Compare interactive message protection with retransmission while holding aggregation and poisoning defense fixed. Report recovered-message error, test loss and attack-induced loss separately under equal communication budget; do not claim coding defeats poisoned updates.
Rank 8/10 after semantic revision; analyst score 7 = max(1, 3+2+2): topic overlap 3/4, complementarity 2/3, feasible first test 2/3. Interactive coding addresses transport corruption; robust learning requires a separate poisoning model and aggregator, so complementarity is bounded. A bounded offline comparison is specified; required datasets and domain assumptions must still be checked.
Proposed fit, not an assertion of a new or active relationship. Independent review pending; forecast confidence low. Partner interest, capacity, data access and any required experimental approvals/resources are unverified. Post-review scope: Interactive coding addresses transport corruption; robust learning requires a separate poisoning model and aggregator, so complementarity is bounded. This revised proposal awaits independent targeted re-review; simulated outcomes would establish model behavior only, not biological, clinical or deployed benefit.
Connection 9
Massachusetts Institute of Technology
Proposed capability match for Amir Leshem with Muriel Medard: Coded transport may reduce communication-induced learning degradation, but valid poisoned updates are not channel errors and require independent protection.[88][111][112][474]
Fix a small synthetic learning dataset, client updates and aggregation rule. Cross a burst-erasure channel with a separately specified label-flip or update-poisoning process. Compare coded transport with retransmission at equal bit budget by message recovery and final learning loss; keep the poisoning defense identical and report any benefit separately for clean versus poisoned clients.
Rank 9/10 after semantic revision; analyst score 7 = max(1, 3+2+2): topic overlap 3/4, complementarity 2/3, feasible first test 2/3. Coded transport may reduce communication-induced learning degradation, but valid poisoned updates are not channel errors and require independent protection. A bounded offline comparison is specified; required datasets and domain assumptions must still be checked.
Proposed fit, not an assertion of a new or active relationship. Independent review pending; forecast confidence low. Partner interest, capacity, data access and any required experimental approvals/resources are unverified. Post-review scope: Coded transport may reduce communication-induced learning degradation, but valid poisoned updates are not channel errors and require independent protection. This revised proposal awaits independent targeted re-review; simulated outcomes would establish model behavior only, not biological, clinical or deployed benefit.
Connection 10
Duke University
Proposed capability match for Amir Leshem with Robert Calderbank: Coding can protect update transmission, not its semantic honesty; a shared learning objective and separate corruption/poisoning controls are prerequisites.[111][112][444]
Serialize identical client updates into fixed-length bit strings and simulate a declared bit-flip channel separately from malicious update generation. Compare a block code with repetition at matched redundancy, using the same aggregation rule and attack fraction. Report update reconstruction error and final prediction loss in each fault/attack condition.
Rank 10/10 after semantic revision; analyst score 6 = max(1, 2+2+2): topic overlap 2/4, complementarity 2/3, feasible first test 2/3. Coding can protect update transmission, not its semantic honesty; a shared learning objective and separate corruption/poisoning controls are prerequisites. A bounded offline comparison is specified; required datasets and domain assumptions must still be checked.
Proposed fit, not an assertion of a new or active relationship. Independent review pending; forecast confidence low. Partner interest, capacity, data access and any required experimental approvals/resources are unverified. Post-review scope: Coding can protect update transmission, not its semantic honesty; a shared learning objective and separate corruption/poisoning controls are prerequisites. This revised proposal awaits independent targeted re-review; simulated outcomes would establish model behavior only, not biological, clinical or deployed benefit.
Amir Leshem's institutional record covers statistical signal processing, wireless systems, distributed learning and robustness to data-injection attacks. [111][112]
Moderate confidenceReview: reviewedThe CV and live institutional record should be reconciled for a final publication inventory.
Adversarially resilient shared-spectrum learning is a future research hypothesis joining Leshem's distributed-learning methods with external wireless-system design. [103][111]
Low confidenceReview: reviewedThe radio model, adversary model and real-world benefit are untested.