secure

Title: Bicoptor: Two-round Secure Three-party Non-linear Computation without Preprocessing for Privacy-preserving Machine Learning. (arXiv:2210.01988v1 [cs.CR])

security

Title: Hiding Images in Deep Probabilistic Models. (arXiv:2210.02257v1 [cs.CR])

Title: Security and Privacy Concerns in Cloud-based Scientific and Business Workflows: A Systematic Review. (arXiv:2210.02161v1 [cs.CR])

privacy

Title: Privacy-Patterns for IoT Application Developers. (arXiv:2210.01853v1 [cs.CR])

Title: Recycling Scraps: Improving Private Learning by Leveraging Intermediate Checkpoints. (arXiv:2210.01864v1 [cs.LG])

Title: Fine-Tuning with Differential Privacy Necessitates an Additional Hyperparameter Search. (arXiv:2210.02156v1 [cs.LG])

In this work, we identify an oversight of existing approaches for differentially private fine tuning. They do not tailor the fine-tuning approach to the specifics of learning with privacy. Our main result is to show how carefully selecting the layers being fine-tuned in the pretrained neural network allows us to establish new state-of-the-art tradeoffs between privacy and accuracy. For instance, we achieve 77.9% accuracy for $(\varepsilon, \delta)=(2, 10^{-5})$ on CIFAR-100 for a model pretrained on ImageNet. Our work calls for additional hyperparameter search to configure the differentially private fine-tuning procedure itself.

Title: On the Statistical Complexity of Estimation and Testing under Privacy Constraints. (arXiv:2210.02215v1 [cs.LG])

Title: Over-the-Air Federated Learning with Privacy Protection via Correlated Additive Perturbations. (arXiv:2210.02235v1 [cs.LG])

Title: Differentially Private Propensity Scores for Bias Correction. (arXiv:2210.02360v1 [cs.CR])

protect

defense

Title: On the Robustness of Deep Clustering Models: Adversarial Attacks and Defenses. (arXiv:2210.01940v1 [cs.LG])

Title: Robust Fair Clustering: A Novel Fairness Attack and Defense Framework. (arXiv:2210.01953v1 [cs.LG])

Title: When Physical Layer Key Generation Meets RIS: Opportunities, Challenges, and Road Ahead. (arXiv:2210.02337v1 [cs.CR])

attack

Title: Natural Color Fool: Towards Boosting Black-box Unrestricted Attacks. (arXiv:2210.02041v1 [cs.CV])

Title: Jitter Does Matter: Adapting Gaze Estimation to New Domains. (arXiv:2210.02082v1 [cs.CV])

Title: On Attacking Out-Domain Uncertainty Estimation in Deep Neural Networks. (arXiv:2210.02191v1 [cs.LG])

Title: Invariant Aggregator for Defending Federated Backdoor Attacks. (arXiv:2210.01834v1 [cs.LG])

Title: Thermal (and Hybrid Thermal/Audio) Side-Channel Attacks on Keyboard Input. (arXiv:2210.02234v1 [cs.CR])

We conduct and describe a user study that collected thermal residues from 30 users entering 10 unique passwords (both weak and strong) on 4 popular commodity keyboards. Results show that entire sets of key-presses can be recovered by non-expert users as late as 30 seconds after initial password entry, while partial sets can be recovered as late as 1 minute after entry. However, the thermal residue side-channel lacks information about password length, duplicate key-presses, and key-press ordering. To overcome these limitations, we leverage keyboard acoustic emanations and combine the two to yield AcuTherm, the first hybrid side-channel attack on keyboards. AcuTherm significantly reduces password search without the need for any training on the victim's typing. We report results gathered for many representative passwords based on a user study involving 19 subjects.

The takeaway of this work is three-fold: (1) using plastic keyboards to enter secrets (such as passwords and PINs) is even less secure than previously recognized, (2) post-factum thermal imaging attacks are realistic, and (3) hybrid (multiple side-channel) attacks are both realistic and effective.

Title: Detecting Anomalies within Smart Buildings using Do-It-Yourself Internet of Things. (arXiv:2210.01840v1 [cs.LG])

Title: Dynamical systems' based neural networks. (arXiv:2210.02373v1 [cs.LG])

robust

Title: AdaWAC: Adaptively Weighted Augmentation Consistency Regularization for Volumetric Medical Image Segmentation. (arXiv:2210.01891v1 [cs.CV])

Title: Meta-Ensemble Parameter Learning. (arXiv:2210.01973v1 [cs.CV])

Title: MOTSLAM: MOT-assisted monocular dynamic SLAM using single-view depth estimation. (arXiv:2210.02038v1 [cs.CV])

Title: Exploring The Role of Mean Teachers in Self-supervised Masked Auto-Encoders. (arXiv:2210.02077v1 [cs.CV])

Title: Decanus to Legatus: Synthetic training for 2D-3D human pose lifting. (arXiv:2210.02231v1 [cs.CV])

Title: Image Masking for Robust Self-Supervised Monocular Depth Estimation. (arXiv:2210.02357v1 [cs.CV])

Title: COMPS: Conceptual Minimal Pair Sentences for testing Property Knowledge and Inheritance in Pre-trained Language Models. (arXiv:2210.01963v1 [cs.CL])

Title: BayesFT: Bayesian Optimization for Fault Tolerant Neural Network Architecture. (arXiv:2210.01795v1 [cs.LG])

Title: Neural Distillation as a State Representation Bottleneck in Reinforcement Learning. (arXiv:2210.02224v1 [cs.LG])

Title: Tree Mover's Distance: Bridging Graph Metrics and Stability of Graph Neural Networks. (arXiv:2210.01906v1 [cs.LG])

Title: MAtt: A Manifold Attention Network for EEG Decoding. (arXiv:2210.01986v1 [cs.LG])

Title: ChemAlgebra: Algebraic Reasoning on Chemical Reactions. (arXiv:2210.02095v1 [cs.LG])

Title: SECOE: Alleviating Sensors Failure in Machine Learning-Coupled IoT Systems. (arXiv:2210.02144v1 [cs.LG])

Title: Bayesian Quadrature for Probability Threshold Robustness of Partially Undefined Functions. (arXiv:2210.02168v1 [cs.LG])

Title: A new family of Constitutive Artificial Neural Networks towards automated model discovery. (arXiv:2210.02202v1 [cs.LG])

biometric

steal

extraction

Title: Point Cloud Recognition with Position-to-Structure Attention Transformers. (arXiv:2210.02030v1 [cs.CV])

Title: Spatio-Temporal Learnable Proposals for End-to-End Video Object Detection. (arXiv:2210.02368v1 [cs.CV])

Title: Detect, Retrieve, Comprehend: A Flexible Framework for Zero-Shot Document-Level Question Answering. (arXiv:2210.01959v1 [cs.CL])

Title: STGIN: A Spatial Temporal Graph-Informer Network for Long Sequence Traffic Speed Forecasting. (arXiv:2210.01799v1 [cs.LG])

Title: On Neural Consolidation for Transfer in Reinforcement Learning. (arXiv:2210.02240v1 [cs.LG])

Title: Automated Graph Self-supervised Learning via Multi-teacher Knowledge Distillation. (arXiv:2210.02099v1 [cs.LG])

membership infer

federate

Title: Learning Across Domains and Devices: Style-Driven Source-Free Domain Adaptation in Clustered Federated Learning. (arXiv:2210.02326v1 [cs.CV])

Title: Split Federated Learning on Micro-controllers: A Keyword Spotting Showcase. (arXiv:2210.01961v1 [cs.LG])

Title: Federated Graph-based Networks with Shared Embedding. (arXiv:2210.01803v1 [cs.LG])

Title: FedMT: Federated Learning with Mixed-type Labels. (arXiv:2210.02042v1 [cs.LG])

Title: ISFL: Trustworthy Federated Learning for Non-i.i.d. Data with Local Importance Sampling. (arXiv:2210.02119v1 [cs.LG])

Title: Domain Discrepancy Aware Distillation for Model Aggregation in Federated Learning. (arXiv:2210.02190v1 [cs.LG])

fair

Title: Ten Years after ImageNet: A 360{\deg} Perspective on AI. (arXiv:2210.01797v1 [cs.LG])

interpretability

Title: SIMPLE: A Gradient Estimator for $k$-Subset Sampling. (arXiv:2210.01941v1 [cs.LG])

Title: Towards Prototype-Based Self-Explainable Graph Neural Network. (arXiv:2210.01974v1 [cs.LG])

Title: The Vendi Score: A Diversity Evaluation Metric for Machine Learning. (arXiv:2210.02410v1 [cs.LG])

exlainability

watermark