中文
相关论文

相关论文: On the Robustness of Dataset Inference

200 篇论文

Differentially private training algorithms provide protection against one of the most popular attacks in machine learning: the membership inference attack. However, these privacy algorithms incur a loss of the model's classification…

密码学与安全 · 计算机科学 2021-10-13 Jiaxiang Liu , Simon Oya , Florian Kerschbaum

Deepfake detection systems deployed in real-world environments are subject to adversaries capable of crafting imperceptible perturbations that degrade model performance. While adversarial training is a widely adopted defense, its…

计算机视觉与模式识别 · 计算机科学 2026-01-12 Adrian Serrano , Erwan Umlil , Ronan Thomas

Federated learning (FL) is a distributed machine learning paradigm allowing multiple clients to collaboratively train a global model without sharing their local data. However, FL entails exposing the model to various participants. This…

密码学与安全 · 计算机科学 2024-03-05 Shuo Shao , Wenyuan Yang , Hanlin Gu , Zhan Qin , Lixin Fan , Qiang Yang , Kui Ren

With an increase in low-cost machine learning APIs, advanced machine learning models may be trained on private datasets and monetized by providing them as a service. However, privacy researchers have demonstrated that these models may leak…

Machine learning (ML) models are increasingly deployed in cybersecurity applications such as phishing detection and network intrusion prevention. However, these models remain vulnerable to adversarial perturbations small, deliberate input…

密码学与安全 · 计算机科学 2026-02-09 Mona Rajhans , Vishal Khawarey

Machine Learning as a Service (MLaaS) platforms have gained popularity due to their accessibility, cost-efficiency, scalability, and rapid development capabilities. However, recent research has highlighted the vulnerability of cloud-based…

密码学与安全 · 计算机科学 2024-10-23 Hongwei Yao , Zheng Li , Haiqin Weng , Feng Xue , Zhan Qin , Kui Ren

We consider the problem of a training data proof, where a data creator or owner wants to demonstrate to a third party that some machine learning model was trained on their data. Training data proofs play a key role in recent lawsuits…

机器学习 · 计算机科学 2025-03-10 Jie Zhang , Debeshee Das , Gautam Kamath , Florian Tramèr

Backdoor watermarking is a promising paradigm to protect the copyright of deep neural network (DNN) models. In the existing works on this subject, researchers have intensively focused on watermarking robustness, while the concept of…

密码学与安全 · 计算机科学 2023-11-02 Guang Hua , Andrew Beng Jin Teoh

By and large, existing Intellectual Property (IP) protection on deep neural networks typically i) focus on image classification task only, and ii) follow a standard digital watermarking framework that was conventionally used to protect the…

计算机视觉与模式识别 · 计算机科学 2021-09-01 Jian Han Lim , Chee Seng Chan , Kam Woh Ng , Lixin Fan , Qiang Yang

As large language models are increasingly deployed in sensitive environments, fingerprinting attacks pose significant privacy and security risks. We present a study of LLM fingerprinting from both offensive and defensive perspectives. Our…

密码学与安全 · 计算机科学 2025-08-13 Kevin Kurian , Ethan Holland , Sean Oesch

Machine learning (ML) models, e.g., deep neural networks (DNNs), are vulnerable to adversarial examples: malicious inputs modified to yield erroneous model outputs, while appearing unmodified to human observers. Potential attacks include…

密码学与安全 · 计算机科学 2017-03-21 Nicolas Papernot , Patrick McDaniel , Ian Goodfellow , Somesh Jha , Z. Berkay Celik , Ananthram Swami

The rapid evolution of generative adversarial networks (GANs) and diffusion models has made synthetic media increasingly realistic, raising societal concerns around misinformation, identity fraud, and digital trust. Existing deepfake…

计算机视觉与模式识别 · 计算机科学 2025-11-03 Sales Aribe

Smart metering networks are increasingly susceptible to cyber threats, where false data injection (FDI) appears as a critical attack. Data-driven-based machine learning (ML) methods have shown immense benefits in detecting FDI attacks via…

机器学习 · 计算机科学 2024-11-07 Md Raihan Uddin , Ratun Rahman , Dinh C. Nguyen

Adversarial-example-based fingerprinting approaches, which leverage the decision boundary characteristics of deep neural networks (DNNs) to craft fingerprints, have proven effective for model ownership protection. However, a fundamental…

密码学与安全 · 计算机科学 2026-03-24 Guang Yang , Ziye Geng , Yihang Chen , Changqing Luo

Machine learning models have been shown to leak information violating the privacy of their training set. We focus on membership inference attacks on machine learning models which aim to determine whether a data point was used to train the…

密码学与安全 · 计算机科学 2020-09-02 Shadi Rahimian , Tribhuvanesh Orekondy , Mario Fritz

Recent advancements in diffusion models have enabled high-fidelity and photorealistic image generation across diverse applications. However, these models also present security and privacy risks, including copyright violations, sensitive…

计算机视觉与模式识别 · 计算机科学 2025-06-10 Jiacheng Shi , Yanfu Zhang , Huajie Shao , Ashley Gao

Large language models (LLMs) have attracted significant attention in recent years. Due to their "Large" nature, training LLMs from scratch consumes immense computational resources. Since several major players in the artificial intelligence…

密码学与安全 · 计算机科学 2024-09-12 Heng Jin , Chaoyu Zhang , Shanghao Shi , Wenjing Lou , Y. Thomas Hou

Website Fingerprinting (WF) attacks raise major concerns about users' privacy. They employ Machine Learning (ML) to allow a local passive adversary to uncover the Web browsing behavior of a user, even if she browses through an encrypted…

密码学与安全 · 计算机科学 2017-12-08 Giovanni Cherubin

Deep learning has become popular, and numerous cloud-based services are provided to help customers develop and deploy deep learning applications. Meanwhile, various attack techniques have also been discovered to stealthily compromise the…

密码学与安全 · 计算机科学 2018-08-21 Zecheng He , Tianwei Zhang , Ruby B. Lee

Protecting a fingerprint database against attackers is very vital in order to protect against false acceptance rate or false rejection rate. A key property in distinguishing fingerprint images is by exploiting the characteristics of these…

计算机视觉与模式识别 · 计算机科学 2022-01-10 Aamo Iorliam , Orgem Emmanuel , Yahaya I. Shehu