We study differentially private learning problems in the realizable setting, where a hypothesis is specified by $k$ components. A direct iteration of private component learners is obstructed by a simple difficulty: an approximate choice of the next component may destroy exact realizability of the labeled sample, even w...
Machine unlearning is seen as a promising approach to enable users to exercise the "right to erasure" in the context of AI models. We ask how users might influence the behavior of models when exercising this right. We define two types of behaviors that users might adopt when requesting the deletion of their data: adapt...
Large language model (LLM) agents are increasingly deployed in tool-augmented environments, but their reliance on external inputs makes them highly vulnerable to prompt injection attacks that can hijack task objectives. Existing safety alignment methods rely on static expert trajectories or preference optimization, lim...
Zixuan Wang, Hao Li, Fengyu Gao et al.· 0 citations
Artificial intelligence (AI)-enabled security decision systems in telecom and IoT networks can draw on heterogeneous models whose outputs may trigger operational actions. Recording such decisions on a blockchain does not establish that they are authorised, applicable, policy-consistent, or still valid at execution time...
Saviz Changizi, Nasibeh Mohammadzadeh, Mohammad Shojafar et al.· 0 citations
Reach audiences
Advertise in front of researchers, engineers, and readers.
Machine learning network intrusion detection systems (IDS) operate on aggregate flow statistics that discard the distributional structure of traffic, and although information-theoretic measures capture that structure, established entropy estimators require raw packet sequences that pre-aggregated flow datasets do not c...
Mohamed Aly Bouke, Md Shohel Sayeed, Swee-Huay Heng et al.· 0 citations
Accurately evaluating adversarial robustness is a longstanding challenge. A flawed attack design can inflate robustness estimates, making deployment risk assessment and defense comparison unreliable. Historically, standardized attacks such as AutoAttack have largely resolved this for image classifiers, providing a reli...
Vincent Limbach, Jonas Dornbusch, David L\"udke et al.· 0 citations
Test Vector Leakage Assessment (TVLA) is widely used for side-channel leakage detection, but its reliance on Welch's t-test makes it primarily sensitive to differences in the means of two leakage populations. Consequently, TVLA may fail to detect leakage that manifests through changes in other characteristics of the un...
J\'an Mikulec, Jakub Breier, Xiaolu Hou· 0 citations
Mixture-of-Experts (MoE) language models introduce unique challenges for safety alignment due to their sparse routing mechanisms, which can enable degenerate optimization behaviors under standard full-parameter fine-tuning. In our preliminary experiments, we observe that naively applying full-parameter safety fine-tuni...
Jiacheng Liang, Yuhui Wang, Tanqiu Jiang et al.· 0 citations
Vertical localization, particularly floor separation, remains a major challenge in indoor positioning systems operating in GPS-denied multistory environments. This paper proposes a fully data-driven, graph-based framework for blind floor separation using only Wi-Fi fingerprint trajectories, without requiring prior buil...
The expansion of text-to-image diffusion models has raised concerns about harmful outputs, from fabricated depictions of public figures to sexually explicit imagery. To mitigate such risks, prior work has proposed concept erasure methods that aim to sever unwanted concepts from the model via fine-tuning, yet it remains...
Tobias Braun, Jonas Henry Grebe, Patrick Mohr et al.· 0 citations
Instruction tuning aligns large language models (LLMs) with human intentions but requires diverse, high-quality data that are difficult to collect in privacy-sensitive domains. Federated instruction tuning (FedIT) enables collaborative training across data owners, yet existing methods typically assume sufficient local...
Zhuo Zhang, Jingyuan Zhang, Jintao Huang et al.· 0 citations
Many machine learning applications involve sensitive data and therefore require training under differential privacy (DP). However, DP training often degrades model utility. In some cases, first pre-training the model on"public"data before finetuning with DP on the sensitive data can reduce the drop in utility. However,...
Yu-Fei Chen, Tejumade Afonja, Anvith Thudi et al.· 0 citations