secure

Title: ISC-FLAT: On the Conflict Between Control Flow Attestation and Real-Time Operations. (arXiv:2303.03561v1 [cs.CR])

Despite these advances, current CFA methods share a fundamental limitation: they preclude interrupts during the execution of the software operation being attested. Simply put, existing CFA techniques are insecure unless interrupts are disabled on the MCU. On the other hand, we argue that the lack of interruptability can obscure CFA usefulness, as most embedded applications depend on interrupts to process asynchronous events in real-time.

To address this limitation, we propose Interrupt-Safe Control Flow Attestation (ISC-FLAT): a CFA technique that is compatible with existing MCUs and enables interrupt handling without compromising the authenticity of CFA reports. Similar to other CFA techniques that do not require customized hardware modifications, ISC-FLAT leverages a Trusted Execution Environment (TEE) (in particular, our prototype is built on ARM TrustZone-M) to securely generate unforgeable CFA reports without precluding applications from processing interrupts. We implement a fully functional ISC-FLAT prototype on the ARM Cortex-M33 MCU and demonstrate that it incurs minimal runtime overhead when compared to existing TEE-based CFA methods that do not support interrupts.

Title: Client-specific Property Inference against Secure Aggregation in Federated Learning. (arXiv:2303.03908v1 [cs.CR])

In this paper, we show that simple linear models can effectively capture client-specific properties only from the aggregated model updates due to the linearity of aggregation. We formulate an optimization problem across different rounds in order to infer a tested property of every client from the output of the linear models, for example, whether they have a specific sample in their training data (membership inference) or whether they misbehave and attempt to degrade the performance of the common model by poisoning attacks. Our reconstruction technique is completely passive and undetectable. We demonstrate the efficacy of our approach on several scenarios which shows that secure aggregation provides very limited privacy guarantees in practice. The source code will be released upon publication.

security

Title: SoK: Content Moderation for End-to-End Encryption. (arXiv:2303.03979v1 [cs.CR])

Title: A Comparison of Methods for Neural Network Aggregation. (arXiv:2303.03488v1 [cs.LG])

privacy

Title: Bootstrap The Original Latent: Freeze-and-thaw Adapter for Back-Propagated Black-Box Adaptation. (arXiv:2303.03709v1 [cs.CV])

Title: EavesDroid: Eavesdropping User Behaviors via OS Side-Channels on Smartphones. (arXiv:2303.03700v1 [cs.CR])

protect

defense

attack

Title: Logit Margin Matters: Improving Transferable Targeted Adversarial Attack by Logit Calibration. (arXiv:2303.03680v1 [cs.CV])

Title: Securing Autonomous Vehicles Under Partial-Information Cyber Attacks on LiDAR Data. (arXiv:2303.03470v1 [cs.CR])

Title: Exploring the Limits of Indiscriminate Data Poisoning Attacks. (arXiv:2303.03592v1 [cs.LG])

Title: SCRAMBLE-CFI: Mitigating Fault-Induced Control-Flow Attacks on OpenTitan. (arXiv:2303.03711v1 [cs.CR])

robust

Title: Memory Maps for Video Object Detection and Tracking on UAVs. (arXiv:2303.03508v1 [cs.CV])

Title: Learning Discriminative Representations for Skeleton Based Action Recognition. (arXiv:2303.03729v1 [cs.CV])

Title: Guiding Pseudo-labels with Uncertainty Estimation for Test-Time Adaptation. (arXiv:2303.03770v1 [cs.CV])

Title: Event Voxel Set Transformer for Spatiotemporal Representation Learning on Event Streams. (arXiv:2303.03856v1 [cs.CV])

Title: DeepSeeColor: Realtime Adaptive Color Correction for Autonomous Underwater Vehicles via Deep Learning Methods. (arXiv:2303.04025v1 [cs.CV])

Title: A Challenging Benchmark for Low-Resource Learning. (arXiv:2303.03840v1 [cs.CL])

Title: Can Decentralized Learning be more robust than Federated Learning?. (arXiv:2303.03829v1 [cs.LG])

Title: Decision Transformer under Random Frame Dropping. (arXiv:2303.03391v1 [cs.LG])

Title: Robust Dominant Periodicity Detection for Time Series with Missing Data. (arXiv:2303.03553v1 [cs.LG])

Title: AHPA: Adaptive Horizontal Pod Autoscaling Systems on Alibaba Cloud Container Service for Kubernetes. (arXiv:2303.03640v1 [cs.LG])

Title: Robust Semi-Supervised Anomaly Detection via Adversarially Learned Continuous Noise Corruption. (arXiv:2303.03925v1 [cs.LG])

biometric

steal

extraction

Title: At Your Fingertips: Extracting Piano Fingering Instructions from Videos. (arXiv:2303.03745v1 [cs.CV])

Title: Hidden Knowledge: Mathematical Methods for the Extraction of the Fingerprint of Medieval Paper from Digital Images. (arXiv:2303.03794v1 [cs.CV])

Title: A survey on automated detection and classification of acute leukemia and WBCs in microscopic blood cells. (arXiv:2303.03916v1 [cs.CV])

Title: Classifying Text-Based Conspiracy Tweets related to COVID-19 using Contextualized Word Embeddings. (arXiv:2303.03706v1 [cs.CL])

Title: Exploring the Feasibility of ChatGPT for Event Extraction. (arXiv:2303.03836v1 [cs.CL])

Title: Document-level Relation Extraction with Cross-sentence Reasoning Graph. (arXiv:2303.03912v1 [cs.CL])

Title: Exploiting Asymmetry for Synthetic Training Data Generation: SynthIE and the Case of Information Extraction. (arXiv:2303.04132v1 [cs.CL])

membership infer

Title: Students Parrot Their Teachers: Membership Inference on Model Distillation. (arXiv:2303.03446v1 [cs.CR])

Title: Can Membership Inferencing be Refuted?. (arXiv:2303.03648v1 [cs.LG])

federate

fair

Title: Group conditional validity via multi-group learning. (arXiv:2303.03995v1 [cs.LG])

interpretability

Title: Towards Composable Distributions of Latent Space Augmentations. (arXiv:2303.03462v1 [cs.LG])

Title: Filter Pruning based on Information Capacity and Independence. (arXiv:2303.03645v1 [cs.CV])

Title: Towards Interpretable and Efficient Automatic Reference-Based Summarization Evaluation. (arXiv:2303.03608v1 [cs.CL])

Title: DA-VEGAN: Differentiably Augmenting VAE-GAN for microstructure reconstruction from extremely small data sets. (arXiv:2303.03403v1 [cs.LG])

explainability

Title: Multi-resolution Interpretation and Diagnostics Tool for Natural Language Classifiers. (arXiv:2303.03542v1 [cs.CL])

watermark

diffusion

Title: DLT: Conditioned layout generation with Joint Discrete-Continuous Diffusion Layout Transformer. (arXiv:2303.03755v1 [cs.CV])

Title: Zeroth-Order Optimization Meets Human Feedback: Provable Learning via Ranking Oracles. (arXiv:2303.03751v1 [cs.LG])