7 papers
On Arbitrary Predictions from Equally Valid Models
Sarah Lockfisch, Kristian Schwethelm, Martin Menten +4
Model multiplicity refers to the existence of multiple machine learning models that describe the data equally well but may produce different predictions on individual samples. In m…
Your Privacy Depends on Others: Collusion Vulnerabilities in Individual Differential Privacy
Johannes Kaiser, Alexander Ziller, Eleni Triantafillou +2
Individual Differential Privacy (iDP) promises users control over their privacy, but this promise can be broken in practice. We reveal a previously overlooked vulnerability in samp…
Sensitivity, Specificity, and Consistency: A Tripartite Evaluation of Privacy Filters for Synthetic Data Generation
Adil Koeken, Alexander Ziller, Moritz Knolle +1
The generation of privacy-preserving synthetic datasets is a promising avenue for overcoming data scarcity in medical AI research. Post-hoc privacy filtering techniques, designed t…
From Mean to Extreme: Formal Differential Privacy Bounds on the Success of Real-World Data Reconstruction Attacks
Anneliese Riess, Kristian Schwethelm, Johannes Kaiser +4
The gold standard for privacy in machine learning, Differential Privacy (DP), is often interpreted through its guarantees against membership inference. However, translating DP budg…
Visual Privacy Auditing with Diffusion Models
Kristian Schwethelm, Johannes Kaiser, Moritz Knolle +3
Data reconstruction attacks on machine learning models pose a substantial threat to privacy, potentially leaking sensitive information. Although defending against such attacks usin…
How Low Can You Go? Surfacing Prototypical In-Distribution Samples for Unsupervised Anomaly Detection
Felix Meissen, Johannes Getzner, Alexander Ziller +4
Unsupervised anomaly detection (UAD) alleviates large labeling efforts by training exclusively on unlabeled in-distribution data and detecting outliers as anomalies. Generally, the…