A new error metric is introduced that precisely captures model vulnerability to consistent adversarial attacks -- perturbations that preserve the ground-truth labels, offering theoretical insight into the mechanisms underlying model sensitivity to adversarial attacks.
Matteo Vilucchio, Lenka Zdeborová, Bruno Loureiro· arXiv.org· 1 citation
The rapid adoption, usefulness, and resource-intensive training of Graph Neural Network (GNN) models have made them an invaluable intellectual property in graph-based machine learning. However, their wide-spread adoption also makes them susceptible to stealing, necessitating robust Ownership Demonstration (OD) techniqu...
Venkata Sai Pranav Bachina, Ankit Gangwal, Aaryan Ajay Sharma et al.· Trans. Mach. Learn. Res.· 8 citations· ⚡1
It is shown that commonly used EEG features can reveal participant identity and demographic attributes in addition to supporting the intended cognitive task, motivating purpose-limited representations and explicit privacy auditing in wearable neurohealth systems.
Sarmistha Sarna Gomasta, Bhawana Chhaglani, Prashant J. Shenoy· 0 citations
Agentic Provenance (AgentProv), the first action-based identity audit for agentic LLM APIs, is introduced: AgentProv fingerprints a deployed model through its categorical tool-call distribution and decides identity via an MMD permutation test.
Xun Wang, Bihe Zhao, Michael Backes et al.· 1 citation
Reach audiences
Advertise in front of researchers, engineers, and readers.
It is argued for treating privacy as an explicit, evidence-based scientific claim and recommend that ML venues adopt norms requiring privacy-relevant assertions to be clearly scoped, testable, and contestable.
This paper presents a hybrid insider threat detection framework for enterprise environments, integrating multi-agent simulation, layered SIEM correlation, trust-adaptive thresholds, behavioral and communication forensics, and Theory-of-Mind reasoning. Email is treated not as a control channel but as a coordination and...
Firdous Kausar, Asmah Muallem, N. Sattar et al.· 0 citations
X-SG$^2$S is the first framework to unify 1D-to-3D watermarking and enable simultaneous multi-modal watermark embedding in 3DGS, achieving this with minimal rendering interference and zero modifications to parameters or pipelines.
FedReview, a review-based mechanism to identify and dispose the potential poisoned updates in federated learning, is proposed, which enables the server to learn a well-performing global model in adversarial environments.
Tianhang Zheng, Yan-Lu Li, Bo-Han Deng et al.· 0 citations
This work proposes Defense-as-Skill, a defense paradigm that implements the runtime guard itself as an installable, inspectable, and editable skill, and demonstrates transfer across victim models, held-out risk families, and external benchmarks, as well as retained protection against adaptive attackers.
Xiao-Fan Yang, Ziqi Miao, Dian-Bo Sui et al.· 0 citations
Overall, safety failure is best understood as a disruption of a low-rank output-routing mechanism, and it is shown that LoRA and ASAM mitigate early collapse by suppressing output-side sharpness, but their protection weakens at larger fine-tuning scales.
Yi-Tong Guo, Xiaoyi Chen, Si-Yuan Zhang et al.· 0 citations
This work identifies two complementary laundering regimes: OpenAI models produce the strongest payload disruption across the evaluated schemes, whereas Nano Banana 2 shows that DwtDct remains vulnerable under high-fidelity reconstruction.
MutMem V2 supports claims about portable integrity, authorization, traceability, conformance, and reproducibility under stated assumptions; it does not establish semantic truth, universal robustness, or independent replication.