activity
20182022
most citedAuditing Differentially Private Machine Learning: How Private is Private SGD?

73 citations · 108 across the 6 of their papers we have counts for

collaborators

12 papers

cs.CR2022

Bad Citrus: Reducing Adversarial Costs with Model Distances

Giorgio Severi, Will Pearce, Alina Oprea

Recent work by Jia et al., showed the possibility of effectively computing pairwise model distances in weight space, using a model explanation technique known as LIME. This method…

cs.LG20225 cited

How to Combine Membership-Inference Attacks on Multiple Updated Models

Matthew Jagielski, Stanley Wu, Alina Oprea +2

A large body of research has shown that machine learning models are vulnerable to membership inference (MI) attacks that violate the privacy of the participants in the training dat…

cs.CR2021

Collaborative Information Sharing for ML-Based Threat Detection

Talha Ongun, Simona Boboila, Alina Oprea +4

Recently, coordinated attack campaigns started to become more widespread on the Internet. In May 2017, WannaCry infected more than 300,000 machines in 150 countries in a few days a…

cs.CR2020

Extracting Training Data from Large Language Models

Nicholas Carlini, Florian Tramer, Eric Wallace +9

It has become common to publish large (billion parameter) language models that have been trained on private datasets. This paper demonstrates that in such settings, an adversary ca…

cs.CR202073 cited

Auditing Differentially Private Machine Learning: How Private is Private SGD?

Matthew Jagielski, Jonathan Ullman, Alina Oprea

We investigate whether Differentially Private SGD offers better privacy in practice than what is guaranteed by its state-of-the-art analysis. We do so via novel data poisoning atta…

cs.CR2020

Explanation-Guided Backdoor Poisoning Attacks Against Malware Classifiers

Giorgio Severi, Jim Meyer, Scott Coull +1

Training pipelines for machine learning (ML) based malware classification often rely on crowdsourced threat feeds, exposing a natural attack injection point. In this paper, we stud…