14 citations · 17 across the 2 of their papers we have counts for
5 papers
Minimax Defense against Gradient-based Adversarial Attacks
Blerta Lindqvist, Rauf Izmailov
State-of-the-art adversarial attacks are aimed at neural network classifiers. By default, neural networks use gradient descent to minimize their loss function. The gradient of a cl…
Privacy Leakage Avoidance with Switching Ensembles
Rauf Izmailov, Peter Lin, Chris Mesterharm +1
We consider membership inference attacks, one of the main privacy issues in machine learning. These recently developed attacks have been proven successful in determining, with conf…
Membership Model Inversion Attacks for Deep Networks
Samyadeep Basu, Rauf Izmailov, Chris Mesterharm
With the increasing adoption of AI, inherent security and privacy vulnerabilities formachine learning systems are being discovered. One such vulnerability makes itpossible for an a…
Subspace Methods That Are Resistant to a Limited Number of Features Corrupted by an Adversary
Chris Mesterharm, Rauf Izmailov, Scott Alexander +1
In this paper, we consider batch supervised learning where an adversary is allowed to corrupt instances with arbitrarily large noise. The adversary is allowed to corrupt any fe…
AutoGAN: Robust Classifier Against Adversarial Attacks
Blerta Lindqvist, Shridatt Sugrim, Rauf Izmailov
Classifiers fail to classify correctly input images that have been purposefully and imperceptibly perturbed to cause misclassification. This susceptability has been shown to be con…