Paper evaluates and mitigates privacy risks in deep learning models.
problem Quantifying and defending against privacy attacks in deep learning.
method Quantitative evaluation of trade-offs, reformulating attacks, and proposing a novel SPN.
result Model accuracy improved by 5-20% while maintaining data privacy.
Modern neural networks often contain significantly more parameters than the size of their training data. We show that this excess capacity provides an opportunity for embedding secret machine learning models within a trained neural network. Our novel framework hides the existence of a secret neural network with arbitra…
Deep-Lock secures DNN models with secret keys.
problem Preventing unauthorized usage of DNN models.
method Uses S-Boxes and key scheduling to encrypt DNN parameters.
result Ensures correct functioning only with the correct secret key.
Adversarial training was recently shown to be competitive against supervised learning methods on computer vision tasks, however, studies have mainly been confined to generative tasks such as image synthesis. In this paper, we apply adversarial training techniques to the discriminative task of learning a steganographic …
Researchers show how to secretly train models with hidden data, detect usage with high confidence.
problem Protecting training data from traceability in large language models.
method Gradient-based optimization to learn secret sequences absent from training data.
result Secret sequences can be learned by models without performance degradation, detectable with high confidence.
AriaNN enables private deep learning with minimal interaction and reduced key sizes.
problem Private deep learning with minimal interaction and reduced key sizes.
method Semi-honest 2-party computation protocol with function secret sharing, optimized primitives for neural network operations.
result Efficient private comparison for ReLU operations with reduced key size and improved performance.
Paper proposes protecting DNN models with secret key preprocessing.
problem Protecting deep learning models from unauthorized access.
method Block-wise pixel shuffling with secret key for preprocessing.
result Protected models maintain close performance to non-protected models with correct key, but accuracy drops significantly with incorrect key.
Supervised machine learning (ML) algorithms are aimed at maximizing classification performance under available energy and storage constraints. They try to map the training data to the corresponding labels while ensuring generalizability to unseen data. However, they do not integrate meaning-based relationships among la…
This paper improves privacy accounting in decentralized FL using f-Differential Privacy.
problem Challenges in accurately quantifying privacy budget in decentralized FL.
method Develops two new f-DP-based accounting methods for decentralized FL.
result Yields tighter (ε,δ) bounds and improved utility compared to existing methods.
A new federated learning method protects privacy in mobile crowdsensing.
problem Data and model privacy protection in federated extreme gradient boosting for mobile crowdsensing.
method Secret sharing based federated learning architecture FedXGB.
result FedXGB achieves less than 1% accuracy loss while preserving model privacy.
New insights link diverse statistical problems via secret leakage planted clique.
problem Statistical-computational gaps in inference problems.
method Secret leakage planted clique as a new hardness assumption for reductions.
result Establishes tight statistical-computational tradeoffs for various problems.
Securely trains regression models with secret sharing for data collaboration.
problem Balancing data collaboration for technological improvements with security concerns.
method Secret sharing scheme for scalable and efficient secure multiparty training.
result Scalable and efficient protocols for training linear and logistic regression models.
Novel fusion network combines polarization and radiomics features for liver cancer classification.
problem Challenges in histopathological diagnosis of HCC and ICC.
method Two-tier fusion approach: feature-level and classification-level.
result Significantly enhances classification accuracy, even at reduced resolutions.
Matryoshka hides secret models in a carrier model, achieving high capacity and robustness.
problem Stealing functionality of private ML data by hiding models in a carrier model.
method Parameter sharing approach exploiting the learning capacity of the carrier model.
result Hides a 26x larger secret model or 8 secret models in the carrier model.
Paper uses ResUNet-CMB to reconstruct cosmic polarization rotation from CMB data.
problem Reconstructing anisotropic cosmic polarization rotation from CMB data.
method Extended ResUNet-CMB to handle gravitational lensing and patchy reionization.
result ResUNet-CMB outperforms standard quadratic estimator in reconstructing all three effects.
SLIM model predicts social network polarization using signed links.
problem Polarization and filter bubbles in social networks.
method Signed relational Latent dIstance Model (SLIM) using Skellam distribution.
result SLIM model accurately predicts friendships and animosity in social networks.
SharedMF uses secret sharing to protect privacy in distributed recommendation systems.
problem Privacy issues in multi-source data for recommendation systems.
method Federated learning and secret sharing technology.
result SharedMF achieves faster execution speed and better data adaptability compared to homomorphic encryption methods.
We develop a secure aggregation protocol for federated learning that reduces communication and computation costs.
problem Expensive communication and privacy concerns in federated learning.
method Adapting compression-based federated techniques to additive secret sharing.
result Our protocol achieves high accuracy with low communication costs and is more efficient than prior work.
The vulnerability of deep neural networks to small, adversarially designed perturbations can be attributed to their "excessive linearity." In this paper, we propose a bottom-up strategy for attenuating adversarial perturbations using a nonlinear front end which polarizes and quantizes the data. We observe that ideal po…
The paper analyzes how multiple classifiers' disagreement and polarization affect overall accuracy.
problem Improving accuracy through ensembling multiple classifiers.
method The paper derives an upper bound for polarization, proposes a neural polarization law, and presents a tight upper bound for the error of majority vote classifiers.
result Disagreement and polarization among classifiers are linearly correlated with the target, and polarization is nearly constant for a dataset.
Neural network implementation of Brenier's polar factorization for vector fields.
problem Implementing Brenier's polar factorization theorem for vector fields using neural networks.
method Parameterizing the convex function u as an input convex neural network and estimating the measure-preserving map M. result Practical neural implementation of Brenier's polar factorization theorem.
FaceSigns embeds a secret watermark in images to authenticate and detect deepfakes.
problem Realistic image and video manipulation threats, especially deepfakes.
method Semi-fragile watermarking using neural networks, robust to face-swapping but fragile to deepfake manipulations.
result FaceSigns can reliably detect deepfake content with high accuracy.
Paper uses polar field data to improve solar flare prediction accuracy.
problem Improving solar flare prediction accuracy using machine learning.
method Incorporates polar field data into machine learning models for solar flare classification.
result Improves solar flare prediction performance by up to 10.1% using a novel probabilistic mixture of experts model.
The vulnerability of machine learning systems to adversarial attacks questions their usage in many applications. In this paper, we propose a randomized diversification as a defense strategy. We introduce a multi-channel architecture in a gray-box scenario, which assumes that the architecture of the classifier and the t…
In this work, we introduce a deep learning-based polar code construction algorithm. The core idea is to represent the information/frozen bit indices of a polar code as a binary vector which can be interpreted as trainable weights of a neural network (NN). For this, we demonstrate how this binary vector can be relaxed t…
Generative Adversarial Networks (GANs) have been used to model the underlying probability distribution of sample based datasets. GANs are notoriuos for training difficulties and their dependence on arbitrary hyperparameters. One recent improvement in GAN literature is to use the Wasserstein distance as loss function le…
This work addresses privacy issues in IoT data sharing by balancing information disclosure and user privacy.
problem Balancing privacy and utility in time-series data sharing from IoT devices.
method Formulated as POMDPs, solved using A2C DRL, evaluated with synthetic and real data.
result Proposed policies achieve a good balance between privacy and utility.
Local regularization fails in transductive learning for some multiclass problems.
problem Whether local regularization can learn all transductive multiclass problems.
method Provided a negative answer by exhibiting a specific multiclass problem.
result Local regularization cannot learn all transductive multiclass problems.
Deep learning helps remove secondary B-mode polarization to detect primordial gravitational waves.
problem Removing secondary B-mode polarization from CMB data to detect primordial gravitational waves. method Applied deep learning (ResUNet-CMB) to estimate and remove multiple sources of secondary B-mode polarization. result Deep learning can produce nearly optimal, unbiased estimates of the amplitude of primordial gravitational waves.
We classify the polar actions on the complex hyperbolic plane up to orbit equivalence. Apart from the trivial and transitive polar actions, there are five polar actions of cohomogeneity one and four polar actions of cohomogeneity two.
Study polar actions on Damek-Ricci spaces, proving existence and finding examples.
problem Characterize polar actions on Damek-Ricci spaces.
method Prove criteria for isometric actions to be polar, find examples, and classify actions.
result Non-trivial polar actions exist on all Damek-Ricci spaces.
The paper studies how Kähler polarizations degenerate to mixed polarizations on toric varieties.
problem Degeneration of Kähler polarizations to mixed polarizations on toric varieties.
method Constructing polarizations by Hamiltonian actions, finding one-parameter families of Kähler polarizations, and analyzing convergence of spaces of holomorphic sections.
result Kähler polarizations degenerate to mixed polarizations as k increases, with specific convergence results for one-parameter families. Polarized and G-polarized CR manifolds are smooth manifolds endowed with a double structure: a real foliation $\Cal F$ (given by the action of a Lie group G in the G-polarized case) and a transverse CR distribution (E,J). Polarized means that (E,J) is roughly speaking invariant by $\Cal F$. Both structures ar…
A polarity of a projective plane is a map, often assumed to be involutive, mapping a generic point to a generic line and reciprocally. The most classical polarity is the polarity with respect to a conic, but other exist: the harmonic polarity with respect to a triangle, the polarities with respect to high-degree algebr…
FastSecAgg improves federated learning security and efficiency.
problem Privacy leakage in federated learning due to model parameter sharing.
method Introduces FastSecAgg, a secure aggregation protocol with FFT-based multi-secret sharing (FastShare).
result Efficient in computation and communication, robust to client dropouts.
The generic fiber of a Lagrangian fibration on an irreducible holomorphic symplectic manifold is an abelian variety. Associate a polarization type to such Lagrangian fibrations coming from polarizations on a generic fiber. We prove that this polarization type is constant in families of Lagrangian fibrations. Further, w…
The study introduces polarization of generalized Nijenhuis torsions and their relevance in operator fields.
problem Characterization of Haantjes C∞(M)-modules of operator fields. method Introducing polarization of generalized Nijenhuis torsions and proving algebraic identities.
result Polarizations of generalized Nijenhuis torsions are relevant in the characterization of Haantjes C∞(M)-modules of operator fields. Paper improves privacy for language models against reconstruction attacks.
problem Reconstruction attacks can regenerate training data from language models.
method Uses Rényi differential privacy with optimized privacy budgets.
result Better privacy guarantees for extraction of rare secrets.
Classifies polar foliations on symmetric spaces.
problem Classifying polar foliations on symmetric spaces.
method Orbit equivalence and classification up to codimension two.
result Foliations are either hyperpolar or extensions of rank one foliations.
Assume that a projective variety together with a polarization is uniformly K-stable. If the polarization is canonical or anti-canonical, then the projective variety is uniformly K-stable with respects to any polarization sufficiently close to the original polarization.
Classifies totally geodesic submanifolds and polar actions on Stiefel manifolds.
problem Classifying totally geodesic submanifolds and polar actions on Stiefel manifolds.
method Classification through polar actions and cohomogeneity-one actions.
result Classification of orbits of polar actions on Stiefel manifolds.
The main result of this paper is that a polar action on a compact irreducible homogeneous Kaehler manifold is coisotropic. This is then used to give new examples of polar actions and to classify coisotropic and polar actions on quadrics.
Secure neural network inference on untrusted platforms using holographic reduced representations.
problem Secure neural network inference on untrusted platforms.
method Connectionist Symbolic Pseudo Secrets using Holographic Reduced Representations (HRR).
result Empirical robustness to attack under various threat models.
Classifies hexagonal circular 3-webs with cubic polar curves.
problem Classifying hexagonal circular 3-webs with algebraic polar curves of degree three.
method Analyzes hexagonal circular 3-webs on unit sphere with polar points on a twisted cubic.
result Completes the classification of hexagonal circular 3-webs with algebraic polar curves of degree three.
Study empty polar varieties' impact on singular function-germs.
problem Topology of singular function-germs with nonisolated singularities.
method Analysis of empty polar varieties.
result Topology implications of nonempty polar varieties.
In the last decade, deep learning algorithms have become very popular thanks to the achieved performance in many machine learning and computer vision tasks. However, most of the deep learning architectures are vulnerable to so called adversarial examples. This questions the security of deep neural networks (DNN) for ma…
For complex projective manifolds we introduce polar homology groups, which are holomorphic analogues of the homology groups in topology. The polar k-chains are subvarieties of complex dimension k with meromorphic forms on them, while the boundary operator is defined by taking the polar divisor and the Poincare residue …
Totally geodesic sections found in polar actions.
problem Understanding sections of polar actions on Riemannian manifolds.
method Elementary proof of a folklore result.
result Sections of polar actions are totally geodesic.