activity
20172022
most citedDarkneTZ: Towards Model Privacy at the Edge using Trusted Execution Environments

190 citations · 269 across the 7 of their papers we have counts for

collaborators

11 papers

cs.SD20201 cited

FoolHD: Fooling speaker identification by Highly imperceptible adversarial Disturbances

Ali Shahin Shamsabadi, Francisco Sepúlveda Teixeira, Alberto Abad +3

Speaker identification models are vulnerable to carefully designed adversarial perturbations of their input signals that induce misclassification. In this work, we propose a white-…

cs.CV202025 cited

Exploiting vulnerabilities of deep neural networks for privacy protection

Ricardo Sanchez-Matilla, Chau Yi Li, Ali Shahin Shamsabadi +2

Adversarial perturbations can be added to images to protect their content from unwanted inferences. These perturbations may, however, be ineffective against classifiers that were n…

cs.LG2020190 cited

DarkneTZ: Towards Model Privacy at the Edge using Trusted Execution Environments

Fan Mo, Ali Shahin Shamsabadi, Kleomenis Katevas +4

We present DarkneTZ, a framework that uses an edge device's Trusted Execution Environment (TEE) in conjunction with model partitioning to limit the attack surface against Deep Neur…

cs.CR2020

PrivEdge: From Local to Distributed Private Training and Prediction

Ali Shahin Shamsabadi, Adria Gascon, Hamed Haddadi +1

Machine Learning as a Service (MLaaS) operators provide model training and prediction on the cloud. MLaaS applications often rely on centralised collection and aggregation of user…

cs.CV2019

ColorFool: Semantic Adversarial Colorization

Ali Shahin Shamsabadi, Ricardo Sanchez-Matilla, Andrea Cavallaro

Adversarial attacks that generate small L_p-norm perturbations to mislead classifiers have limited success in black-box settings and with unseen classifiers. These attacks are also…

cs.LG2019

EdgeFool: An Adversarial Image Enhancement Filter

Ali Shahin Shamsabadi, Changjae Oh, Andrea Cavallaro

Adversarial examples are intentionally perturbed images that mislead classifiers. These images can, however, be easily detected using denoising algorithms, when high-frequency spat…