SteganoGAN hides data in images with high capacity and high quality.
problem Hiding secret messages in images without detection.
method Generative adversarial networks (GANs) to optimize image quality and payload size.
result Achieves 4.4 bits per pixel payload, evades steganalysis, works on multiple datasets.
CycleGAN hides information in steganographic images.
problem Steganographic information hiding in images.
method CycleGAN learns to embed hidden information into generated images.
result CycleGAN can recover original images while maintaining realism.
Researchers found PP-GANs can hide sensitive data in sanitized images, undermining privacy checks.
problem Lack of formal proofs of privacy in PP-GANs for image sanitization.
method Subverted PP-GANs for facial expression recognition to hide sensitive data in sanitized images.
result It is possible to hide sensitive identification data in sanitized PP-GAN output images, even allowing reconstruction of entire input images.
New technique hides adversarial attacks in complex images, making them imperceptible.
problem Lack of interpretability in Convolutional Neural Networks (CNNs) and vulnerability to adversarial attacks.
method Developed a technique that hides adversarial attacks in regions of high complexity, making them imperceptible to human observers.
result Significant evidence of concealment of adversarial attacks in images, making them imperceptible to human observers.
Defense against small image patches using occlusions.
problem Vulnerability of deep learning to small adversarial patches.
method Partially occlude image around each patch location.
result Certified security against patch attacks of a certain size.
Survey on spectral gaps of random hyperbolic surfaces.
problem Understanding spectral gaps of random hyperbolic surfaces.
method Brief survey on geometry and spectra, discussion of results by Hide-Magee, Anantharaman-Monk, and Hide-Macera-Thomas.
result Near optimal spectral gaps for random surfaces.
Develops framework to analyze pruning of neural networks.
problem Understanding pruning of neural networks in non-imaging data.
method Develops framework to plant and hide winning tickets in neural networks.
result Similar trends in ticket sparsity observed across different tasks.
A game theory study on optimal hiding and searching strategies in discrete locations.
problem Optimal hiding and searching strategies in a two-person zero-sum game between a hider and a searcher.
method Proved the existence of optimal strategies, developed an algorithm to compute them, and compared with a simple strategy.
result Optimal hiding strategy involves hiding in each location with nonzero probability, and optimal searching strategy can be constructed with up to n simple sequences.
Paper proposes a method to detect glare in document images.
problem Glare obscures text in document images, hindering recognition.
method Divides document into blocks, collects luminance and histogram features, uses CNN to detect glare.
result High recall and f-score in detecting glare.
Hides the complexity of neural networks, making them more transparent.
problem Lack of transparency in Neural Networks hinders their adoption.
method Proposes Hide-and-Seek (HnS) framework for training interpretable neural networks.
result Interpretable neural networks can be trained without sacrificing predictive power.
Automatic video modification to hide faces while maintaining pose, illumination, and expression.
problem Face de-identification in video to protect identities.
method A novel feed-forward encoder-decoder network architecture conditioned on facial image high-level representation.
result Fully automatic video modification at high frame rates with minimal distortion.
AutoDIME automates design of multi-agent environments for RL.
problem Designing multi-agent environments for reinforcement learning is challenging.
method Developed intrinsic teacher rewards for multi-agent settings and evaluated them in various tasks.
result Value disagreement was found to be most consistent and effective across tasks.
Matryoshka hides secret models in a carrier model, achieving high capacity and robustness.
problem Stealing functionality of private ML data by hiding models in a carrier model.
method Parameter sharing approach exploiting the learning capacity of the carrier model.
result Hides a 26x larger secret model or 8 secret models in the carrier model.
Agents learn sophisticated tool use and coordination in hide-and-seek.
problem Training agents to perform complex tasks in multi-agent environments.
method Multi-agent competition with hide-and-seek as a simple objective.
result Agents develop emergent strategies requiring sophisticated tool use and coordination.
Adversarial attacks hide cyber-physical attacks in ICS.
problem Hiding cyber-physical attacks in industrial control systems.
method Modeling an attacker compromising sensors, manipulating data, and evaluating attacks on both continuous and mixed data.
result Successfully hides cyber-physical attacks with 2.87 out of 12 sensors compromised on average.
Advances in deep learning for natural images have prompted a surge of interest in applying similar techniques to medical images. The majority of the initial attempts focused on replacing the input of a deep convolutional neural network with a medical image, which does not take into consideration the fundamental differe…
InstaHide encrypts images for privacy in distributed learning.
problem Private training of deep neural networks on distributed data.
method Encryption of training images with one-time secret keys and pixel-wise masks.
result Preserves privacy with minor accuracy loss, secure against known attacks.
Paper shows how to hide individuals in graphs to fool community detection models.
problem Adversarial attack on community detection models by hiding individuals.
method Iterative learning framework that updates a graph generator and a community detection model.
result Adversarial graphs generated by the method can fool multiple community detection models.
NeuroMask provides interpretable explanations for deep neural networks.
problem Understanding how deep neural networks make decisions.
method Applies a mask to reveal or hide parts of an image, tuning mask values to preserve classification results and produce interpretable explanations.
result NeuroMask successfully localizes the most relevant parts of an image to a deep neural network's decision.
The paper shows examples of 2-complexes that can't be embedded in R^4, hiding obstructions in higher Milnor invariants.
problem Embedding 2-complexes in R^4 with hidden obstructions.
method Provides examples of 2-complexes and families of PL immersions that hide embedding obstructions.
result Embedding obstructions vanish for the given examples, answering a question in Avramidi-Okun-Schreve's paper.
A stealthy framework injects faults into DNNs to misclassify images without affecting overall accuracy.
problem Vulnerability of deep neural networks to misclassification attacks.
method Fault sneaking attack using ADMM optimization with constraints on maintaining model accuracy and minimizing parameter modifications.
result The framework can inject multiple sneaking faults into DNNs without reducing overall accuracy.
New method proves exact recovery for tensor decomposition under reshuffling.
problem Numerical defects limit practical applications of tensor decomposition.
method Proves exact-recovery property for latent convex tensor decomposition using reshuffling.
result Generalized LCTD achieves exact recovery under reshuffling.
Secret neural networks hidden within trained models.
problem Excess capacity in neural networks allows embedding secret models.
method Novel framework for hiding secret neural networks within carrier networks.
result Detection of hidden networks is computationally infeasible.
Deep neural networks improve speech steganography for covert messaging.
problem Improving steganography for speech data using deep learning.
method Proposed a new deep neural network model with short-time Fourier transform layers, demonstrating effectiveness on multiple speech datasets.
result Demonstrated that the proposed method can conceal multiple messages in a single carrier and is robust to channel distortions.
Neural networks learn patterns in random data, improving downstream performance.
problem Understanding what deep networks learn with random labels.
method Analytical and empirical study of convolutional and fully connected networks pre-trained on random labels.
result Pre-trained networks on random labels transfer faster to real datasets, despite specialization effects.
Challenge hides and seeks privacy in clinical time-series data.
problem De-identifying clinical time-series data while preserving utility and privacy.
method Synthetic data generation to preserve temporal dynamics and limit re-identification risk.
result A novel competition tracks synthetic data generation and patient re-identification.
PR-GAN preserves data privacy while maintaining utility for specific applications.
problem Privacy concerns in collecting personal data and machine learning inference.
method Generative adversarial networks (GAN) to modify data, incorporating prior knowledge of correlations.
result PR-GAN provides privacy guarantees under the Pufferfish framework, outperforming conventional methods.
Random flat bundles on surfaces have least eigenvalues at least 1/4.
problem Equidistribution of flat bundles on random surfaces.
method Hide--Magee method and probabilistic prime geodesic theorem.
result Flat unitary bundles have least eigenvalue at least 1/4 with high probability.
Pandora hybridizes human and machine methods to explain AI system failures.
problem Understanding and explaining failures in complex AI systems.
method Hybrid human-machine methods and tools for summarizing system malfunction.
result Detailed performance views help in analysis and debugging of AI systems.
HiDe learns hierarchical control for complex tasks by separating planning and control.
problem Solving long horizon control tasks with generalization to unseen scenarios.
method Functional decomposition of state-action spaces, RL-based planner, modular transfer of policy layers.
result Generalizes across unseen test environments and scales to longer horizons.
New method learns cooperation and competition without direct interaction.
problem Learning cooperation and competition without direct interaction.
method Information-theoretic regularizers to encourage intention revelation or hiding.
result Cooperative policies lead to more reward, competitive to less, in asymmetric games.
New neural network method hides input information in complex-valued features to protect privacy.
problem Preventing adversaries from inferring input attributes from neural network features.
method Transforming real-valued features into complex-valued ones, making input hidden in a randomized phase.
result Significantly diminishes adversary's ability to infer input while preserving high accuracy.
The paper explores maximal perturbations to hide certain attributes in data while keeping the model's performance intact.
problem Protecting sensitive attributes from both model and human detection.
method Adversarial perturbations applied to raw data to conditionally damage model's classification of one attribute while preserving the rest.
result Maximal perturbations can hide certain attributes from both model and human detection, impacting model performance but not human perception.
A novel approach to federated learning with strong privacy guarantees.
problem Maintaining privacy of clients' data and federator's objective in federated learning.
method Inspired by knowledge distillation and private information retrieval, the approach combines secret-sharing-based multi-party computation and graph-based private information retrieval.
result Strong information-theoretic privacy guarantees for federated learning.
Adversarial machine learning hides 5G communications from eavesdroppers.
problem Hiding 5G communications from eavesdroppers using DL classifiers.
method Craft adversarial perturbations to fool DL classifiers.
result Adversarial perturbations can hide 5G communications with high probability.
We propose a privacy-enhanced matrix factorization recommender that exploits the fact that users can often be grouped together by interest. This allows a form of "hiding in the crowd" privacy. We introduce a novel matrix factorization approach suited to making recommendations in a shared group (or nym) setting and the …
Proposes fair classification method using Wasserstein-1 distances.
problem Ensuring fairness in classification models by protecting sensitive information.
method Minimizes Wasserstein-1 distances to enforce independence between classifier outputs and sensitive information.
result Empirical performance superior to fairness baselines on benchmark datasets.
The Pinned AUC metric hides unintended bias when class distributions vary.
problem Unintended bias in classification models.
method Examines the Pinned AUC metric and its limitations.
result Pinned AUC can obscure different types of unintended bias.
TIPRDC anonymizes data features to protect privacy while retaining useful information.
problem Privacy concerns from crowdsourced data hinder deep learning applications.
method Hybrid training method combining adversarial and mutual information estimation.
result Feature extractor hides private information while preserving original data features.
Proposes methods to find alternative blockmodels in networks.
problem Discover secondary blockmodel representations of networks that are dissimilar to a given blockmodel.
method Incorporates non-negative matrix factorisation (NMF) with inclusion of cannot-link constraints and dissimilarity between image matrices.
result Validated the effectiveness of the proposed methods in discovering alternative blockmodels.
Missing data imputation can help improve the performance of prediction models in situations where missing data hide useful information. This paper compares methods for imputing missing categorical data for supervised classification tasks. We experiment on two machine learning benchmark datasets with missing categorical…
Noise injection improves inference privacy in DNN models.
problem Malicious servers can infer sensitive attributes from input data.
method Adaptive Noise Injection (ANI) using a lightweight DNN on the client.
result Significant improvement in privacy (up to 48.5% degradation in sensitive-task accuracy with <1% degradation in primary accuracy).
Unsupervised learning classifies transient noise in gravitational wave detectors.
problem Transient noise interferes with gravitational wave signals, causing instability.
method Combines variational autoencoder and invariant information clustering.
result Consistent classification with Gravity Spy project labels.
The thesis tackles two stochastic control problems in capital structure and portfolio choice.
problem Optimizing banks' dividend and recapitalization policies and individual's life-cycle portfolio choice.
method Developed stochastic control models to calibrate and analyze U.S. banks' asset values and optimal portfolio selection models.
result Calibrated model reveals that noise in reported asset values can hide up to one-third of true asset return volatility and increase banks' market equity value by 7.8%.
Framework explains deep learning candlestick recognition.
problem Deep learning models explain candlestick patterns in a black box.
method Local search adversarial attacks to explain model reasoning.
result Model perceives candlestick patterns similarly to human traders.
Study minimax optimal RL in factored MDPs with bonus exploration.
problem Optimal reinforcement learning in episodic factored MDPs.
method Proposes two model-based algorithms with bonus exploration for minimax optimal regret.
result Achieves minimax optimal regret guarantees for rich factored structures.
Proposes QNN to protect input privacy in neural networks.
problem Protecting input privacy in neural networks.
method Quaternion-valued neural network (QNN) to hide input information.
result QNN effectively protects input privacy without significant accuracy loss.
Empirical study shows SGD's random seed impacts model weights more than training examples, suggesting intrinsic privacy.
problem Understanding and leveraging the intrinsic randomness of SGD for improved privacy and utility.
method Large-scale empirical study on 120,000 models across four datasets, focusing on convex and non-convex objectives.
result Intrinsic randomness of SGD can reduce the need for additional noise to achieve privacy guarantees, with estimated εi(D) as low as 6.3.