190 citations · 269 across the 7 of their papers we have counts for
11 papers
FoolHD: Fooling speaker identification by Highly imperceptible adversarial Disturbances
Ali Shahin Shamsabadi, Francisco Sepúlveda Teixeira, Alberto Abad +3
Speaker identification models are vulnerable to carefully designed adversarial perturbations of their input signals that induce misclassification. In this work, we propose a white-…
Exploiting vulnerabilities of deep neural networks for privacy protection
Ricardo Sanchez-Matilla, Chau Yi Li, Ali Shahin Shamsabadi +2
Adversarial perturbations can be added to images to protect their content from unwanted inferences. These perturbations may, however, be ineffective against classifiers that were n…
DarkneTZ: Towards Model Privacy at the Edge using Trusted Execution Environments
Fan Mo, Ali Shahin Shamsabadi, Kleomenis Katevas +4
We present DarkneTZ, a framework that uses an edge device's Trusted Execution Environment (TEE) in conjunction with model partitioning to limit the attack surface against Deep Neur…
PrivEdge: From Local to Distributed Private Training and Prediction
Ali Shahin Shamsabadi, Adria Gascon, Hamed Haddadi +1
Machine Learning as a Service (MLaaS) operators provide model training and prediction on the cloud. MLaaS applications often rely on centralised collection and aggregation of user…
ColorFool: Semantic Adversarial Colorization
Ali Shahin Shamsabadi, Ricardo Sanchez-Matilla, Andrea Cavallaro
Adversarial attacks that generate small L_p-norm perturbations to mislead classifiers have limited success in black-box settings and with unseen classifiers. These attacks are also…
EdgeFool: An Adversarial Image Enhancement Filter
Ali Shahin Shamsabadi, Changjae Oh, Andrea Cavallaro
Adversarial examples are intentionally perturbed images that mislead classifiers. These images can, however, be easily detected using denoising algorithms, when high-frequency spat…