2 citations · 3 across the 2 of their papers we have counts for
7 papers
Relaxing Local Robustness
Klas Leino, Matt Fredrikson
Certifiable local robustness, which rigorously precludes small-norm adversarial examples, has received significant attention as a means of addressing security concerns in deep lear…
Globally-Robust Neural Networks
Klas Leino, Zifan Wang, Matt Fredrikson
The threat of adversarial examples has motivated work on training certifiably robust neural networks to facilitate efficient verification of local robustness at inference time. We…
Influence Paths for Characterizing Subject-Verb Number Agreement in LSTM Language Models
Kaiji Lu, Piotr Mardziel, Klas Leino +2
LSTM-based recurrent neural networks are the state-of-the-art for many natural language processing (NLP) tasks. Despite their performance, it is unclear whether, or how, LSTMs lear…
Fast Geometric Projections for Local Robustness Certification
Aymeric Fromherz, Klas Leino, Matt Fredrikson +2
Local robustness ensures that a model classifies all inputs within an -ball consistently, which precludes various forms of adversarial inputs. In this paper, we present a f…
Stolen Memories: Leveraging Model Memorization for Calibrated White-Box Membership Inference
Klas Leino, Matt Fredrikson
Membership inference (MI) attacks exploit the fact that machine learning algorithms sometimes leak information about their training data through the learned model. In this work, we…
Feature-Wise Bias Amplification
Klas Leino, Emily Black, Matt Fredrikson +2
We study the phenomenon of bias amplification in classifiers, wherein a machine learning model learns to predict classes with a greater disparity than the underlying ground truth.…