Fetching the paper…
Reading the bibliography…
Most current approaches for protecting privacy in machine learning (ML) assume that models exist in a vacuum.
Timing attacks on implementations of Diffie-Hellman, RSA, DSS, and other systems
Paul C Kocher · 1996
Earlier work this paper cites.
Chosen ciphertext attacks against protocols based on the RSA encryption standard PKCS# 1
Daniel Bleichenbacher · 1998
Earlier work this paper cites.
DEAL-a 128-bit block cipher
Lars Knudsen · 1998
Earlier work this paper cites.
Cryptanalysis of Skipjack reduced to 31 rounds using impossible differentials
Eli Biham, Alex Biryukov, and Adi Shamir · 1999
Earlier work this paper cites.
Differential power analysis
Paul Kocher, Joshua Jaffe, and Benjamin Jun · 1999
Earlier work this paper cites.
Security flaws induced by CBC padding—applications to SSL, IPSEC, WTLS…
Serge Vaudenay · 2002
Earlier work this paper cites.
Calibrating noise to sensitivity in private data analysis
Cynthia Dwork, Frank McSherry, Kobbi Nissim, and Adam Smith · 2006
Earlier work this paper cites.
Labeled faces in the wild: A database for studying face recognition in unconstrained environments
Gary B. Huang, Manu Ramesh, Tamara Berg, and Erik Learned-Miller · 2007
Earlier work this paper cites.
Recurrent neural network based language model
Tomas Mikolov, Martin Karafiát, Lukas Burget, Jan Cernockỳ, and Sanjeev Khudanpur · 2010
Earlier work this paper cites.
Proofs of ownership in remote storage systems
Shai Halevi, Danny Harnik, Benny Pinkas, and Alexandra Shulman-Peleg · 2011
Earlier work this paper cites.
Poisoning attacks against support vector machines
Battista Biggio, Blaine Nelson, and Pavel Laskov · 2012
Earlier work this paper cites.
Evasion attacks against machine learning at test time
Battista Biggio, Igino Corona, Davide Maiorca, Blaine Nelson, Nedim Šrndić, Pavel Laskov, Giorgio Giacinto, and Fabio Roli · 2013
Earlier work this paper cites.
Intriguing properties of neural networks
Christian Szegedy, Wojciech Zaremba, Ilya Sutskever, Joan Bruna, Dumitru Erhan, Ian Goodfellow, and Rob Fergus · 2013
Earlier work this paper cites.
Model inversion attacks that exploit confidence information and basic countermeasures
Matt Fredrikson, Somesh Jha, and Thomas Ristenpart · 2015
Earlier work this paper cites.
Deep learning with differential privacy
Martin Abadi, Andy Chu, Ian Goodfellow, H Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang · 2016
Earlier work this paper cites.
Deep residual learning for image recognition
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun · 2016
Earlier work this paper cites.
Neural machine translation of rare words with subword units
Rico Sennrich, Barry Haddow, and Alexandra Birch · 2016
Earlier work this paper cites.
Stealing machine learning models via prediction APIs
Florian Tramèr, Fan Zhang, Ari Juels, Michael K Reiter, and Thomas Ristenpart · 2016
Earlier work this paper cites.
Targeted backdoor attacks on deep learning systems using data poisoning
Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song · 2017
Earlier work this paper cites.
BadNets: Identifying vulnerabilities in the machine learning model supply chain
Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg · 2017
Earlier work this paper cites.
Communication-efficient learning of deep networks from decentralized data
Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Aguera y Arcas · 2017
Earlier work this paper cites.
Practical black-box attacks against machine learning
Nicolas Papernot, Patrick McDaniel, Ian Goodfellow, Somesh Jha, Z Berkay Celik, and Ananthram Swami · 2017
Earlier work this paper cites.
Membership inference attacks against machine learning models
Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov · 2017
Earlier work this paper cites.
Detecting backdoor attacks on deep neural networks by activation clustering
Bryant Chen, Wilka Carvalho, Nathalie Baracaldo, Heiko Ludwig, Benjamin Edwards, Taesung Lee, Ian Molloy, and Biplav Srivastava · 2018
Earlier work this paper cites.
Stealing neural networks via timing side channels
Vasisht Duddu, Debasis Samanta, D Vijay Rao, and Valentina E Balas · 2018
Earlier work this paper cites.
Security analysis of deep neural networks operating in the presence of cache side-channel attacks
Sanghyun Hong, Michael Davinroy, Yiǧitcan Kaya, Stuart Nevans Locke, Ian Rackow, Kevin Kulda, Dana Dachman-Soled, and Tudor Dumitraş · 2018
Earlier work this paper cites.
Black-box adversarial attacks with limited queries and information
Andrew Ilyas, Logan Engstrom, Anish Athalye, and Jessy Lin · 2018
Earlier work this paper cites.
Poison frogs! targeted clean-label poisoning attacks on neural networks
Ali Shafahi, W Ronny Huang, Mahyar Najibi, Octavian Suciu, Christoph Studer, Tudor Dumitras, and Tom Goldstein · 2018
Cited alongside, same era.
I know what you see: Power side-channel attack on convolutional neural network accelerators
Lingxiao Wei, Bo Luo, Yu Li, Yannan Liu, and Qiang Xu · 2018
Cited alongside, same era.
Privacy risk in machine learning: Analyzing the connection to overfitting
Samuel Yeom, Irene Giacomelli, Matt Fredrikson, and Somesh Jha · 2018
Cited alongside, same era.
CSINN: Reverse engineering of neural network architectures through electromagnetic side channel
Lejla Batina, Shivam Bhasin, Dirmanto Jap, and Stjepan Picek · 2019
Cited alongside, same era.
The secret sharer: Evaluating and testing unintended memorization in neural networks
Nicholas Carlini, Chang Liu, Úlfar Erlingsson, Jernej Kos, and Dawn Song · 2019
Cited alongside, same era.
Scaling language models: Methods, analysis & insights from training Gopher
Jack W Rae, Sebastian Borgeaud, Trevor Cai, Katie Millican, Jordan Hoffmann, Francis Song, John Aslanides, Sarah Henderson, Roman Ring, Susannah Young, et al · 2021
Later among the works it cites.
SEAT: similarity encoder by adversarial training for detecting model extraction attack queries
Zhanyuan Zhang, Yizheng Chen, and David Wagner · 2021
Later among the works it cites.
Reconstructing training data with informed adversaries
Borja Balle, Giovanni Cherubin, and Jamie Hayes · 2022
Later among the works it cites.
Membership inference attacks from first principles
Nicholas Carlini, Steve Chien, Milad Nasr, Shuang Song, Andreas Terzis, and Florian Tramer · 2022
Later among the works it cites.
Multi-epoch matrix factorization mechanisms for private machine learning
Christopher A Choquette-Choo, H Brendan McMahan, Keith Rush, and Abhradeep Thakurta · 2022
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
Searching for MobileNetV3
Andrew Howard, Mark Sandler, Grace Chu, Liang-Chieh Chen, Bo Chen, Mingxing Tan, Weijun Wang, Yukun Zhu, Ruoming Pang, Vijay Vasudevan, et al · 2019
Cited alongside, same era.
PRADA: protecting against DNN model stealing attacks
Mika Juuti, Sebastian Szyller, Samuel Marchal, and N Asokan · 2019
Cited alongside, same era.
Language models are unsupervised multitask learners
Alec Radford, Jeffrey Wu, Rewon Child, David Luan, Dario Amodei, Ilya Sutskever, et al · 2019
Cited alongside, same era.
Privacy risks of securing machine learning models against adversarial examples
Liwei Song, Reza Shokri, and Prateek Mittal · 2019
Cited alongside, same era.
Seeing is not believing: Camouflage attacks on image scaling algorithms
Qixue Xiao, Yufei Chen, Chao Shen, Yu Chen, and Kang Li · 2019
Cited alongside, same era.
Stateful detection of black-box adversarial attacks
Steven Chen, Nicholas Carlini, and David Wagner · 2020
Cited alongside, same era.
Mitigating sybils in federated learning poisoning
Clement Fung, Chris JM Yoon, and Ivan Beschastnikh · 2020
Cited alongside, same era.
Unlocking high-accuracy differentially private image classification through scale
Soham De, Leonard Berrada, Jamie Hayes, Samuel L Smith, and Borja Balle · 2022
Later among the works it cites.
About GitHub Copilot
GitHub · 2022
Later among the works it cites.
Deduplicating training data mitigates privacy risks in language models
Nikhil Kandpal, Eric Wallace, and Colin Raffel · 2022
Later among the works it cites.
Deduplicating training data makes language models better
Katherine Lee, Daphne Ippolito, Andrew Nystrom, Chiyuan Zhang, Douglas Eck, Chris Callison-Burch, and Nicholas Carlini · 2022
Later among the works it cites.
Blacklight: Defending black-box adversarial attacks on deep neural networks
Huiying Li, Shawn Shan, Emily Wenger, Jiayun Zhang, Haitao Zheng, and Ben Y Zhao · 2022
Later among the works it cites.
SeInspect: Defending model stealing via heterogeneous semantic inspection
Xinjing Liu, Zhuo Ma, Yang Liu, Zhan Qin, Junwei Zhang, and Zhuzhu Wang · 2022
Later among the works it cites.
Proactive detection of query-based adversarial scenarios in NLP systems
Mohammad Maghsoudi Mehrabani, Amin Azmoodeh, Ali Dehghantanha, Behrouz Zolfaghari, and Gautam Srivastava · 2022
Later among the works it cites.
FLAME: Taming backdoors in federated learning
Thien Duc Nguyen, Phillip Rieger, Roberta De Viti, Huili Chen, Björn B Brandenburg, Hossein Yalame, Helen Möllering, Hossein Fereidooni, Samuel Marchal, Markus Miettinen, et al · 2022
Later among the works it cites.
Training text-to-text transformers with privacy guarantees
Natalia Ponomareva, Jasmijn Bastings, and Sergei Vassilvitskii · 2022
Later among the works it cites.
Hierarchical text-conditional image generation with CLIP latents
Aditya Ramesh, Prafulla Dhariwal, Alex Nichol, Casey Chu, and Mark Chen · 2022
Later among the works it cites.
LAION-5B: An open large-scale dataset for training next generation image-text models
Christoph Schuhmann, Romain Beaumont, Richard Vencu, Cade Gordon, Ross Wightman, Mehdi Cherti, Theo Coombes, Aarush Katta, Clayton Mullis, Mitchell Wortsman, et al · 2022
Later among the works it cites.
Roei Schuster, Jin Peng Zhou, Paul Grubbs, Thorsten Eisenhofer, and Nicolas Papernot · 2022
Later among the works it cites.
Truth serum: Poisoning machine learning models to reveal their secrets
Florian Tramèr, Reza Shokri, Ayrton San Joaquin, Hoang Le, Matthew Jagielski, Sanghyun Hong, and Nicholas Carlini · 2022
Later among the works it cites.
Rohan Anil, Andrew M Dai, Orhan Firat, Melvin Johnson, Dmitry Lepikhin, Alexandre Passos, Siamak Shakeri, Emanuel Taropa, Paige Bailey, Zhifeng Chen, et al · 2023
Closest in time.
Model card and evaluations for Claude models
Anthropic · 2023
Closest in time.
Privacy side channels in machine learning systems
Edoardo Debenedetti, Giorgio Severi, Nicholas Carlini, Christopher A Choquette-Choo, Matthew Jagielski, Milad Nasr, Eric Wallace, and Florian Tramèr · 2023
Closest in time.
Preventing verbatim memorization in language models gives a false sense of privacy
Daphne Ippolito, Florian Tramèr, Milad Nasr, Chiyuan Zhang, Matthew Jagielski, Katherine Lee, Christopher A Choquette-Choo, and Nicholas Carlini · 2023
Closest in time.
Paraphrasing evades detectors of AI-generated text, but retrieval is an effective defense
Kalpesh Krishna, Yixiao Song, Marzena Karpinska, John Wieting, and Mohit Iyyer · 2023
Closest in time.
Malprotect: Stateful defense against adversarial query attacks in ml-based malware detection
Aqib Rashid and Jose Such · 2023
Closest in time.
SolidGoldMagikarp III: Glitch token archaeology
Jessica Rumbelow and Matthew Watkins · 2023
Closest in time.
Diffusion art or digital forgery? investigating data replication in diffusion models
Gowthami Somepalli, Vasu Singla, Micah Goldblum, Jonas Geiping, and Tom Goldstein · 2023
Closest in time.
LLaMA 2: Open foundation and fine-tuned chat models
Hugo Touvron, Louis Martin, Kevin Stone, Peter Albert, Amjad Almahairi, Yasmine Babaei, Nikolay Bashlykov, Soumya Batra, Prajjwal Bhargava, Shruti Bhosale, et al · 2023
Closest in time.