It is shown that seemingly benign crowdsourced contributions can amplify leakage of other records while remaining difficult to identify through data filtering, demonstrating that seemingly benign crowdsourced contributions can amplify leakage of other records while remaining difficult to identify through data filtering...
Translating natural-language access-control requirements into policies requires careful reasoning about permissions, constraints, and exceptions, and even frontier LLMs often produce policies that violate the intended authorization semantics. We construct CedarInstruct, to our knowledge the first dataset that supports...
Ying-Ming Zhou, Adarsh Vatsa, William Eiers· 0 citations
Redwing is proposed, a design principle for robust token-level watermarking that generalizes to TTS models at a speech-quality cost close to that of KGW and shows that retokenization is not merely a source of noise: its transition structure can be exploited as a design principle for robust token-level watermarking.
When must a foundation-model safety gateway generate tokens, and when should it directly output a calibrated decision? We study calibrated standalone direct-decision foundation models for real-time pre-ingestion safety guardrails, jointly addressing probability calibration, dual-use false-positive control, and heteroge...
Hao Chen· 0 citations
Reach audiences
Advertise in front of researchers, engineers, and readers.
Side-channel evaluators routinely inspect leakage tests while acquisition is still running, and extend or stop the campaign based on what they see. Fixed-horizon screening such as the Welch $t$-test with threshold $|t|>4.5$ gives no error guarantee for this monitored decision rule. We study anytime-valid leakage detect...
Generating differentially private synthetic data with meaningful Wasserstein utility guarantees is challenging in high dimensions. For datasets of size \(n\) on $[0,1]^d$ with $d\ge2$, existing pure \(\varepsilon\)-differentially private mechanisms achieve expected $1$-Wasserstein error of order $(\varepsilon n)^{-1/d}...
Raoof Zare Moayedi, Amir R. Asadi, Mohammad Hossein Yassaee et al.· 0 citations
It is argued that evaluation validity is a prerequisite for, not a footnote to, defense claims in agentic security, and a harness is provided to provide an instrument that enforces it.
Secure Transformer inference protects sensitive inputs but incurs substantial cryptographic overhead, with nonlinear operations such as Softmax and GeLU becoming major bottlenecks. Existing compression methods reduce nonlinear complexity, sequence-dependent computation, or model structure through separately defined com...
Yifei Cai, Zhuoran Li, Xiaozuo Shen et al.· 0 citations
As Internet of Things (IoT) networks increasingly depend on machine learning for anomaly, malware, intrusion detection, and network monitoring, such systems have become attractive targets for evasion attacks. Evasion attacks pose a major security risk because an adversary intentionally modifies input data to mislead a...
Chukwunonso Henry Nwokoye, Wajiha Zaheer, Khalil El-Khatib et al.· 0 citations
TANGO is presented, a watermark for masked-diffusion language models that keys each new token to a nearby token that is already unmasked, and TANGO biases the new token toward a color determined by the key and the nearby token's color.
Kasra Arabi, Nir Weinberger, Micah Goldblum et al.· 0 citations
Progress in machine learning cannot outpace our ability to verify it. With an explosion in papers today, every scientific claim rests initially on trust in the trainer, leading to uneven evaluation, baselines, and forestalling of reliable progress. Traditionally, the burden of verification falls on the reader, who must...
Across vision and language models, it is shown that efficiency-oriented training increases susceptibility to adversarial and privacy attacks, and is called for a paradigm shift toward multi-objective training that jointly optimizes for performance, cost, and security.
Yi-Yong Liu, Jun Sakuma, Michael Backes et al.· 0 citations