activity
20182026
most citedThe Curse of Recursion: Training on Generated Data Makes Models Forget

158 citations · 343 across the 75 of their papers we have counts for

collaborators
Showing 2023Show all

12 papers · 1 filter

cs.LG2023★ 8 cited

Revisiting Block-based Quantisation: What is Important for Sub-8-bit LLM Inference?

Cheng Zhang, Jianyi Cheng, Ilia Shumailov +2

The inference of Large language models (LLMs) requires immense computation and memory resources. To curtail these costs, quantisation has merged as a promising solution, but existi…

cs.LG2023

Beyond Labeling Oracles: What does it mean to steal ML models?

Avital Shafran, Ilia Shumailov, Murat A. Erdogdu +1

Model extraction attacks are designed to steal trained models with only query access, as is often provided through APIs that ML-as-a-Service providers offer. Machine Learning (ML)…

cs.CV2023

Human-Producible Adversarial Examples

David Khachaturov, Yue Gao, Ilia Shumailov +3

Visual adversarial examples have so far been restricted to pixel-level image manipulations in the digital world, or have required sophisticated equipment such as 2D or 3D printers…

cs.LG2023

SEA: Shareable and Explainable Attribution for Query-based Black-box Attacks

Yue Gao, Ilia Shumailov, Kassem Fawaz

Machine Learning (ML) systems are vulnerable to adversarial examples, particularly those from query-based black-box attacks. Despite various efforts to detect and prevent such atta…

cs.AI2023★ 20 cited

LLM Censorship: A Machine Learning Challenge or a Computer Security Problem?

David Glukhov, Ilia Shumailov, Yarin Gal +2

Large language models (LLMs) have exhibited impressive capabilities in comprehending complex instructions. However, their blind adherence to provided instructions has led to concer…

cs.LG2023

Gradients Look Alike: Sensitivity is Often Overestimated in DP-SGD

Anvith Thudi, Hengrui Jia, Casey Meehan +2

Differentially private stochastic gradient descent (DP-SGD) is the canonical approach to private deep learning. While the current privacy analysis of DP-SGD is known to be tight in…