secure

Title: Hardware Trojan Threats to Cache Coherence in Modern 2.5D Chiplet Systems. (arXiv:2210.00058v1 [cs.CR])

Title: Technical Report-IoT Devices Proximity Authentication In Ad Hoc Network Environment. (arXiv:2210.00175v1 [cs.CR])

security

Title: Evaluation of Pre-Trained CNN Models for Geographic Fake Image Detection. (arXiv:2210.00361v1 [cs.CV])

Title: ImpNet: Imperceptible and blackbox-undetectable backdoors in compiled neural networks. (arXiv:2210.00108v1 [cs.LG])

Title: zkBridge: Trustless Cross-chain Bridges Made Practical. (arXiv:2210.00264v1 [cs.CR])

Title: Artificial Replay: A Meta-Algorithm for Harnessing Historical Data in Bandits. (arXiv:2210.00025v1 [cs.LG])

privacy

Title: Differentially Private Bias-Term only Fine-tuning of Foundation Models. (arXiv:2210.00036v1 [cs.LG])

We propose differentially private bias-term fine-tuning (DP-BiTFiT), which matches the state-of-the-art accuracy for DP algorithms and the efficiency of the standard BiTFiT. DP-BiTFiT is model agnostic (not modifying the network architecture), parameter efficient (only training about $0.1\%$ of the parameters), and computation efficient (almost removing the overhead caused by DP, in both the time and space complexity). On a wide range of tasks, DP-BiTFiT is $2\sim 30\times$ faster and uses $2\sim 8\times$ less memory than DP full fine-tuning, even faster than the standard full fine-tuning. This amazing efficiency enables us to conduct DP fine-tuning on language and vision tasks with long-sequence texts and high-resolution images, which were computationally difficult using existing methods.

Title: Differentially Private Optimization on Large Model at Small Cost. (arXiv:2210.00038v1 [cs.LG])

Title: Kernel Normalized Convolutional Networks for Privacy-Preserving Machine Learning. (arXiv:2210.00053v1 [cs.LG])

Title: Frequency Estimation of Evolving Data Under Local Differential Privacy. (arXiv:2210.00262v1 [cs.CR])

Title: Privacy-preserving Decentralized Federated Learning over Time-varying Communication Graph. (arXiv:2210.00325v1 [cs.CR])

Title: Heterogeneous Graph Neural Network for Privacy-Preserving Recommendation. (arXiv:2210.00538v1 [cs.LG])

protect

Title: Assessing the impact of contextual information in hate speech detection. (arXiv:2210.00465v1 [cs.CL])

defense

attack

Title: Adversarial Attacks on Transformers-Based Malware Detectors. (arXiv:2210.00008v1 [cs.CR])

Title: DeltaBound Attack: Efficient decision-based attack in low queries regime. (arXiv:2210.00292v1 [cs.LG])

Title: Adaptive Smoothness-weighted Adversarial Training for Multiple Perturbations with Its Stability Analysis. (arXiv:2210.00557v1 [cs.LG])

robust

Title: Adaptive Weight Decay: On The Fly Weight Decay Tuning for Improving Robustness. (arXiv:2210.00094v1 [cs.LG])

Title: Robust Person Identification: A WiFi Vision-based Approach. (arXiv:2210.00127v1 [cs.CV])

Title: DARE: A large-scale handwritten date recognition system. (arXiv:2210.00503v1 [cs.CV])

Title: Fast and Robust Video-Based Exercise Classification via Body Pose Tracking and Scalable Multivariate Time Series Classifiers. (arXiv:2210.00507v1 [cs.CV])

Title: Institutional Foundations of Adaptive Planning: Exploration of Flood Planning in the Lower Rio Grande Valley, Texas, USA. (arXiv:2210.00113v1 [cs.CL])

Title: Adversarial Robustness of Representation Learning for Knowledge Graphs. (arXiv:2210.00122v1 [cs.LG])

Title: Understanding Adversarial Robustness Against On-manifold Adversarial Examples. (arXiv:2210.00430v1 [cs.LG])

Title: pMPL: A Robust Multi-Party Learning Framework with a Privileged Party. (arXiv:2210.00486v1 [cs.CR])

Motivated by the above scenarios, we propose \pmpl, a robust MPL framework with a \textit{privileged party}. \pmpl supports three-party training in the semi-honest setting. By setting alternate shares for the \textit{privileged party}, \pmpl is robust to tolerate one of the rest two parties dropping out during the training. With the above settings, we design a series of efficient protocols based on vector space secret sharing for \pmpl to bridge the gap between vector space secret sharing and machine learning. Finally, the experimental results show that the performance of \pmpl is promising when we compare it with the state-of-the-art MPL frameworks. Especially, in the LAN setting, \pmpl is around $16\times$ and $5\times$ faster than \texttt{TF-encrypted} (with \texttt{ABY3} as the back-end framework) for the linear regression, and logistic regression, respectively. Besides, the accuracy of trained models of linear regression, logistic regression, and BP neural networks can reach around 97\%, 99\%, and 96\% on MNIST dataset respectively.

Title: Learning Robust Kernel Ensembles with Kernel Average Pooling. (arXiv:2210.00062v1 [cs.LG])

Title: Predicting Cellular Responses with Variational Causal Inference and Refined Relational Information. (arXiv:2210.00116v1 [cs.LG])

Title: Robust Bayesian optimization with reinforcement learned acquisition functions. (arXiv:2210.00476v1 [cs.LG])

Title: Task Formulation Matters When Learning Continually: A Case Study in Visual Question Answering. (arXiv:2210.00044v1 [cs.LG])

Title: On the tightness of linear relaxation based robustness certification methods. (arXiv:2210.00178v1 [cs.LG])

Title: Solving practical multi-body dynamics problems using a single neural operator. (arXiv:2210.00222v1 [cs.LG])

Title: Subspace Learning for Feature Selection via Rank Revealing QR Factorization: Unsupervised and Hybrid Approaches with Non-negative Matrix Factorization and Evolutionary Algorithm. (arXiv:2210.00418v1 [cs.LG])

Title: Comparison of Data Representations and Machine Learning Architectures for User Identification on Arbitrary Motion Sequences. (arXiv:2210.00527v1 [cs.LG])

biometric

steal

extraction

Title: Alignment-guided Temporal Attention for Video Action Recognition. (arXiv:2210.00132v1 [cs.CV])

Title: Structure-Aware NeRF without Posed Camera via Epipolar Constraint. (arXiv:2210.00183v1 [cs.CV])

Title: A Dual-Attention Learning Network with Word and Sentence Embedding for Medical Visual Question Answering. (arXiv:2210.00220v1 [cs.CV])

Title: Gait-based Age Group Classification with Adaptive Graph Neural Network. (arXiv:2210.00294v1 [cs.LG])

Title: Seeing Through The Noisy Dark: Toward Real-world Low-Light Image Enhancement and Denoising. (arXiv:2210.00545v1 [cs.CV])

membership infer

federate

Title: Federated Training of Dual Encoding Models on Small Non-IID Client Datasets. (arXiv:2210.00092v1 [cs.LG])

Title: FedTrees: A Novel Computation-Communication Efficient Federated Learning Framework Investigated in Smart Grids. (arXiv:2210.00060v1 [cs.LG])

Title: Towards Understanding and Mitigating Dimensional Collapse in Heterogeneous Federated Learning. (arXiv:2210.00226v1 [cs.LG])

Title: Federated Representation Learning via Maximal Coding Rate Reduction. (arXiv:2210.00299v1 [cs.LG])

fair

Title: Multi-Task Option Learning and Discovery for Stochastic Path Planning. (arXiv:2210.00068v1 [cs.LG])

Our main contributions are (1) data-driven methods for creating abstract states that serve as endpoints for helpful options, (2) methods for computing option policies using auto-generated option guides in the form of dense pseudo-reward functions, and (3) an overarching algorithm for composing the computed options. We show that this approach yields strong guarantees of executability and solvability: under fairly general conditions, the computed option guides lead to composable option policies and consequently ensure downward refinability. Empirical evaluation on a range of robots, environments, and tasks shows that this approach effectively transfers knowledge across related tasks and that it outperforms existing approaches by a significant margin.

Title: Neural Causal Models for Counterfactual Identification and Estimation. (arXiv:2210.00035v1 [cs.LG])

interpretability

Title: Data-driven discovery of non-Newtonian astronomy via learning non-Euclidean Hamiltonian. (arXiv:2210.00090v1 [cs.LG])

exlainability

watermark