activity
20182022
most citedRobust Anomaly Detection and Backdoor Attack Detection Via Differential Privacy

69 citations · 125 across the 10 of their papers we have counts for

collaborators

20 papers

cs.LG20221 cited

On Solution Functions of Optimization: Universal Approximation and Covering Number Bounds

Ming Jin, Vanshaj Khattar, Harshal Kaushik +2

We study the expressibility and learnability of convex optimization solution functions and their multi-layer architectural extension. The main results are: \emph{(1)} the class of…

cs.CR202219 cited

CATER: Intellectual Property Protection on Text Generation APIs via Conditional Watermarks

Xuanli He, Qiongkai Xu, Yi Zeng +4

Previous works have validated that text generation APIs can be stolen through imitation attacks, causing IP violations. In order to protect the IP of text generation APIs, a recent…

cs.CR2022

Renyi Differential Privacy of Propose-Test-Release and Applications to Private and Robust Machine Learning

Jiachen T. Wang, Saeed Mahloujifar, Shouda Wang +2

Propose-Test-Release (PTR) is a differential privacy framework that works with local sensitivity of functions, instead of their global sensitivity. This framework is typically used…

cs.CR20227 cited

Narcissus: A Practical Clean-Label Backdoor Attack with Limited Information

Yi Zeng, Minzhou Pan, Hoang Anh Just +3

Backdoor attacks insert malicious data into a training set so that, during inference time, it misclassifies inputs that have been patched with a backdoor trigger as the malware spe…

cs.LG20223 cited

Label-Only Model Inversion Attacks via Boundary Repulsion

Mostafa Kahla, Si Chen, Hoang Anh Just +1

Recent studies show that the state-of-the-art deep neural networks are vulnerable to model inversion attacks, in which access to a model is abused to reconstruct private training d…

cs.LG2021

Zero-Round Active Learning

Si Chen, Tianhao Wang, Ruoxi Jia

Active learning (AL) aims at reducing labeling effort by identifying the most valuable unlabeled data points from a large pool. Traditional AL frameworks have two limitations: Firs…