Paper proposes protecting DNN models with secret key preprocessing.
arXiv research
A locally-built, LLM-digested index of recent arXiv papers in quant finance, geometry/topology, and statistical ML — keyword search served straight from SQLite on this machine.
Trend · papers per month
Deep-Lock secures DNN models with secret keys.
The vulnerability of machine learning systems to adversarial attacks questions their usage in many applications. In this paper, we propose a randomized diversification as a defense strategy. We introduce a multi-channel architecture in a gray-box scenario, which assumes that the architecture of the classifier and the t…
AriaNN enables private deep learning with minimal interaction and reduced key sizes.
New insights link diverse statistical problems via secret leakage planted clique.
Modern neural networks often contain significantly more parameters than the size of their training data. We show that this excess capacity provides an opportunity for embedding secret machine learning models within a trained neural network. Our novel framework hides the existence of a secret neural network with arbitra…
Researchers show how to secretly train models with hidden data, detect usage with high confidence.
InstaHide encrypts images for privacy in distributed learning.
Supervised machine learning (ML) algorithms are aimed at maximizing classification performance under available energy and storage constraints. They try to map the training data to the corresponding labels while ensuring generalizability to unseen data. However, they do not integrate meaning-based relationships among la…
Securely trains regression models with secret sharing for data collaboration.
In the last decade, deep learning algorithms have become very popular thanks to the achieved performance in many machine learning and computer vision tasks. However, most of the deep learning architectures are vulnerable to so called adversarial examples. This questions the security of deep neural networks (DNN) for ma…
Matryoshka hides secret models in a carrier model, achieving high capacity and robustness.
In this paper, we address a problem of machine learning system vulnerability to adversarial attacks. We propose and investigate a Key based Diversified Aggregation (KDA) mechanism as a defense strategy. The KDA assumes that the attacker (i) knows the architecture of classifier and the used defense strategy, (ii) has an…
Adversarial training was recently shown to be competitive against supervised learning methods on computer vision tasks, however, studies have mainly been confined to generative tasks such as image synthesis. In this paper, we apply adversarial training techniques to the discriminative task of learning a steganographic …
A novel approach to federated learning with strong privacy guarantees.
SharedMF uses secret sharing to protect privacy in distributed recommendation systems.
A new federated learning method protects privacy in mobile crowdsensing.
This paper improves privacy accounting in decentralized FL using f-Differential Privacy.
Local regularization fails in transductive learning for some multiclass problems.
Data taggants verify dataset ownership without harming models or requiring model internals.
Fully Homomorphic Encryption (FHE) refers to a set of encryption schemes that allow computations to be applied directly on encrypted data without requiring a secret key. This enables novel application scenarios where a client can safely offload storage and computation to a third-party cloud provider without having to t…
Paper evaluates and mitigates privacy risks in deep learning models.
FastSecAgg improves federated learning security and efficiency.
We develop a secure aggregation protocol for federated learning that reduces communication and computation costs.
Paper improves privacy for language models against reconstruction attacks.
FaceSigns embeds a secret watermark in images to authenticate and detect deepfakes.
New defense method inspired by encryption improves visual classification accuracy.
End-to-end learning of codes for secure BPSK communication in Gaussian wiretap channel.
Survey solves curvature problems with hyperbolic spaces.
This work addresses privacy issues in IoT data sharing by balancing information disclosure and user privacy.
Study explores learning behavior of GFlowNets, revealing key mechanisms.
Machine Learning (ML) algorithms are used to train computers to perform a variety of complex tasks and improve with experience. Computers learn how to recognize patterns, make unintended decisions, or react to a dynamic environment. Certain trained machines may be more effective than others because they are based on mo…
Proposes a method for private aggregation in heterogeneous federated learning.
Privacy improves robustness in statistical estimation.
Nowadays, privacy preserving machine learning has been drawing much attention in both industry and academy. Meanwhile, recommender systems have been extensively adopted by many commercial platforms (e.g. Amazon) and they are mainly built based on user-item interactions. Besides, social platforms (e.g. Facebook) have ri…
The method of moving frames in Lie sphere geometry has produced significant results in the classification of Dupin hypersurfaces in spheres. What is the secret of its effectiveness? The answer emerges in the classification of nonumbilic isoparametric surfaces in the space form geometries. Using the method of moving fra…
Today, large amounts of valuable data are distributed among millions of user-held devices, such as personal computers, phones, or Internet-of-things devices. Many companies collect such data with the goal of using it for training machine learning models allowing them to improve their services. User-held data is, howeve…
Despite the widespread usage of machine learning throughout organizations, there are some key principles that are commonly missed. In particular: 1) There are at least four main families for supervised learning: logical modeling methods, linear combination methods, case-based reasoning methods, and iterative summarizat…
Machine learning models benefit from large and diverse datasets. Using such datasets, however, often requires trusting a centralized data aggregator. For sensitive applications like healthcare and finance this is undesirable as it could compromise patient privacy or divulge trade secrets. Recent advances in secure and …
Recent work on adversarial attack has shown that Projected Gradient Descent (PGD) Adversary is a universal first-order adversary, and the classifier adversarially trained by PGD is robust against a wide range of first-order attacks. It is worth noting that the original objective of an attack/defense model relies on a d…
Generative Adversarial Networks (GANs) have been used to model the underlying probability distribution of sample based datasets. GANs are notoriuos for training difficulties and their dependence on arbitrary hyperparameters. One recent improvement in GAN literature is to use the Wasserstein distance as loss function le…
Detecting aggressive cancer tumors using ctDNA dynamics from few blood samples.
Image steganography is a procedure for hiding messages inside pictures. While other techniques such as cryptography aim to prevent adversaries from reading the secret message, steganography aims to hide the presence of the message itself. In this paper, we propose a novel technique for hiding arbitrary binary data in i…
Paper introduces a statistical framework for watermarking LLM-generated text.
New design method improves Lasso performance in sparse regression.
Efficient framework for training machine learning models at edge without data movement.
We show through theory and experiment that gradient-based explanations of a model quickly reveal the model itself. Our results speak to a tension between the desire to keep a proprietary model secret and the ability to offer model explanations. On the theoretical side, we give an algorithm that provably learns a two-la…
BERT-based architectures currently give state-of-the-art performance on many NLP tasks, but little is known about the exact mechanisms that contribute to its success. In the current work, we focus on the interpretation of self-attention, which is one of the fundamental underlying components of BERT. Using a subset of G…