8 papers
Manipulation-Proof Oblivious Audits against Deceptive Model Providers
Augustin Godinot, Sofiane Azogagh, Julien Ferry +1
Audits have emerged as a critical instrument for algorithmic governance, providing a mechanism for external scrutiny and governance of machine learning models. However, ensuring th…
Embedding Inference Attack
Cedric Fitiavana Raelijohn, Sébastien Gambs, Jean-Francois Rajotte
Embedding models are essential components of modern Information Retrieval (IR) systems, yet they are typically hidden behind APIs. Recent works have shown that dense IR system can…
Quantifying the Privacy of Counterfactuals by Leveraging Membership Inference Attacks Against Synthetic Data
Maryam Babaei, Yingke Wang, Hadrien Lautraite +3
Counterfactuals are typically used in high-stakes decision areas to explain a machine learning model by showing how changes to the user profiles result in the desired outcome. Howe…
Revisiting Locally Differentially Private Protocols: Towards Better Trade-offs in Privacy, Utility, and Attack Resistance
Héber H. Arcolezi, Sébastien Gambs
Local Differential Privacy (LDP) offers strong privacy protection, especially in settings in which the server collecting the data is untrusted. However, designing LDP mechanisms th…
Training Set Reconstruction from Differentially Private Forests: How Effective is DP?
Alice Gorgé, Julien Ferry, Sébastien Gambs +1
Recent research has shown that structured machine learning models such as tree ensembles are vulnerable to privacy attacks targeting their training data. To mitigate these risks, d…
WaKA: Data Attribution using K-Nearest Neighbors and Membership Privacy Principles
Patrick Mesana, Clément Bénesse, Hadrien Lautraite +2
In this paper, we introduce WaKA (Wasserstein K-nearest-neighbors Attribution), a novel attribution method that leverages principles from the LiRA (Likelihood Ratio Attack) framewo…