10 citations · 12 across the 4 of their papers we have counts for
10 papers
Optimal Membership Inference Bounds for Adaptive Composition of Sampled Gaussian Mechanisms
Saeed Mahloujifar, Alexandre Sablayrolles, Graham Cormode +1
Given a trained model and a data sample, membership-inference (MI) attacks predict whether the sample was in the model's training set. A common countermeasure against MI attacks is…
NeuraCrypt is not private
Nicholas Carlini, Sanjam Garg, Somesh Jha +3
NeuraCrypt (Yara et al. arXiv 2021) is an algorithm that converts a sensitive dataset to an encoded dataset so that (1) it is still possible to train machine learning models on the…
Is Private Learning Possible with Instance Encoding?
Nicholas Carlini, Samuel Deng, Sanjam Garg +6
A private machine learning algorithm hides as much as possible about its training data while still preserving accuracy. In this work, we study whether a non-private learning algori…
Computational Concentration of Measure: Optimal Bounds, Reductions, and More
Omid Etesami, Saeed Mahloujifar, Mohammad Mahmoody
Product measures of dimension are known to be concentrated in Hamming distance: for any set in the product space of probability , a random point in the space, with proba…
Lower Bounds for Adversarially Robust PAC Learning
Dimitrios I. Diochnos, Saeed Mahloujifar, Mohammad Mahmoody
In this work, we initiate a formal study of probably approximately correct (PAC) learning under evasion attacks, where the adversary's goal is to \emph{misclassify} the adversarial…
Empirically Measuring Concentration: Fundamental Limits on Intrinsic Robustness
Saeed Mahloujifar, Xiao Zhang, Mohammad Mahmoody +1
Many recent works have shown that adversarial examples that fool classifiers can be found by minimally perturbing a normal input. Recent theoretical results, starting with Gilmer e…