9 papers
Provable Robustness against Backdoor Attacks via the Primal-Dual Perspective on Differential Privacy
Aman Saxena, Jan Schuchardt, Yan Scholten +1
Randomized smoothing is a powerful tool for certifying robustness to adversarial perturbations, including poisoning attacks via randomized training and evasion attacks via randomiz…
Sampling-Free Privacy Accounting for Matrix Mechanisms under Random Allocation
Jan Schuchardt, Nikita Kalinin
We study privacy amplification for differentially private model training with matrix factorization under random allocation (also known as the balls-in-bins model). Recent work by C…
Population Risk Bounds for Kolmogorov-Arnold Networks Trained by DP-SGD with Correlated Noise
Puyu Wang, Jan Schuchardt, Nikita Kalinin +4
We establish the first population risk bounds for Kolmogorov-Arnold Networks (KANs) trained by mini-batch SGD with gradient clipping, covering non-private SGD as well as differenti…
Amplified Patch-Level Differential Privacy for Free via Random Cropping
Kaan Durmaz, Jan Schuchardt, Sebastian Schmidt +1
Random cropping is one of the most common data augmentation techniques in computer vision, yet the role of its inherent randomness in training differentially private machine learni…
Privacy Amplification by Structured Subsampling for Deep Differentially Private Time Series Forecasting
Jan Schuchardt, Mina Dalirrooyfard, Jed Guzelkabaagac +3
Many forms of sensitive data, such as web traffic, mobility data, or hospital occupancy, are inherently sequential. The standard method for training machine learning models while e…
Fast Proxies for LLM Robustness Evaluation
Tim Beyer, Jan Schuchardt, Leo Schwinn +1
Evaluating the robustness of LLMs to adversarial attacks is crucial for safe deployment, yet current red-teaming methods are often prohibitively expensive. We compare the ability o…