1,720,981 research outputs found

    BTDT: Membership Inference Attacks against Large Language Models

    No full text
    Given a machine learning model and a record, Membership Inference Attacks (MIAs) determine whether this record was used as part of the model’s training dataset. This can raise privacy issues. MIAs pose a significant threat to the privacy of machine learning models, particularly when the training dataset contains sensitive or confidential information. MIAs often take advantage of a model’s tendency to overfit its training data, resulting in lower loss values for the training data than for non-training data. Recently, a new MIA against language models was designed that is based on a decision rule that compares the difference between the loss value of the target sample under the target model and the average loss of its neighboring samples against a threshold. They generate neighborhoods with simple word replacements that preserve the semantics and fit the context of the original word using Masked Language Models (MLMs). In this thesis, we propose Back Translation and Dynamic Thresholding (BTDT), a novel MIA. BTDT generates more realistic and diverse neighbor samples using back translation and introduces a dynamic thresholding mechanism, resulting in more adaptive and accurate membership inference. The results indicate that by employing dynamic thresholding, the attack’s false positive and false negative rates can be effectively managed, thereby enhancing its robustness and efficiency

    Reducing Model Memorization to Mitigate Membership Inference Attacks

    Get PDF
    Given a machine learning model and a record, membership inference attacks determine whether this record was used as part of the model’s training dataset. This can raise privacy issues. There is a desideratum to providing robust mitigation techniques against this attack that will not affect utility. One of the state-of-the-art frameworks in this area is SELENA, which has two phases: Split-AI and Distillation to train a protected model, which by giving non-members behavior to members tries to mitigate membership inference attacks. In this thesis, we introduce a novel approach to the Split-AI phase, which tries to weaken the membership inference by using the Jacobian matrix norm and entropy. We experimentally demonstrate that by using our approach, we can decrease the memorization of the machine-learning model for two datasets: Purchase100 and CIFAR-10. We experimentally also show that our approach outperforms SELENA by 11.98% and 6.44% in terms of attack recall for Purchase100 and CIFAR-10, respectively

    Comparative Analysis of Membership Inference Attacks in Federated Learning

    Get PDF
    Given a federated learning model and a record, a membership inference attack can determine whether this record is part of the model’s training dataset. Federated learning is a machine learning technique that enables different parties to train a model without the need to centralize or share their local data. Membership inference attack risks the private datasets if those datasets are used to train the federated learning model and access to the generated model is available. There is a need to study the membership inference attack in the federated learning setting. In this thesis, we empirically investigated and compared various membership inference attack approaches in a federated learning environment. We evaluated these attacks on three datasets(MNIST, FMINST, CIFAR-10) using different optimizers(SGD, RMSProp, AdaGrad) and analyzed them with and without countermeasures. The experimental results show that the membership inference approach using the prediction sensitivity approach is the worst for attackers. Additionally, among all the countermeasures, knowledge distillation has significant advantages in handling the trade-off between privacy and utility

    Meta-Heuristic Approach for Course Scheduling Problem

    Get PDF
    Nowadays, much research is being carried out to find efficient algorithms for optimal automated university course timetable problems (UCTP). UCTP allocates the university's events like lectures, exams to the various resources, including instructors, students, lecture time and classrooms. Class scheduling is one of the biggest challenging problems of educational institutions. In this thesis, the aim is to improve the state-of-art for a class scheduling problem considering some hard and soft constraints. Hard constraints must be satisfied. Soft constraints need not be satisfied, but there is a penalty for each soft constraint violation. We also have a timing penalty for scheduling each class to a specific schedule. The goal is to allocate classes to their schedule so that the total penalty is minimized. The proposed method adopts the meta-heuristic strategy to improve existing solutions. An acceptance criterion is defined on neighbouring solutions with cooling and an energy function to avoid getting stuck at a local optimum. This criterion extends the same in Simulated Annealing (SA) by giving infeasible neighbours a chance to become candidates. We then compared our proposed models for the feasible and infeasible solution on two different datasets based on iteration vs. penalty with the local search algorithm. The results obtained based on our experiment show that the proposed model for a feasible solution outperformed the local search algorithm by about 20% in 20k iterations on average. While the model for the infeasible solution performed about 52% better than the local search algorithm for the 20k iterations on average. However, both of the proposed models take more execution time compared to the local search algorithm

    Practical Secure Aggregation in Federated Learning Using Additive Secret Sharing

    Get PDF
    Federated learning is a machine learning technique where multiple clients with local data collaborate in training a machine learning model. In FedAvg, the main federated learning algorithm, clients train machine learning models locally and share the trained model with the server. While the sensitive data will never be sent to the server, a malicious server can construct the original training data by having access to the clients’ models in each training round. Secure aggregation techniques such as cryptography, trusted execution environment, or differential privacy are used to solve this problem. However, these techniques incur computation and communication overhead or affect the model’s accuracy. In this thesis, we consider a secure multi-party computation setup where clients use additive secret sharing to send their models to multiple servers. Our solution provides secure aggregation as long as there are at least two non-colluding servers. Moreover, we provide mathematical proof to show that the securely aggregated model at the end of each training round is exactly equal to the one provided by FedAvg without affecting accuracy and with efficient communication and computation. In comparison with SCOTCH, the state-of-the-art secure aggregation solution, experimental results show that our approach is 557% faster compared to SCOTCH and at the same time it reduces the communication cost of clients by 25%. Additionally, the accuracy of the trained model is exactly as FedAvg under balanced, unbalanced, IID, and Non-IID data distributions while it is only 8% slower

    Going Beyond Counting First Authors in Author Co-citation Analysis

    Get PDF
    The present study examines one of the fundamental aspects of author co-citation analysis (ACA) - the way co-citation counts are defined. Co-citation counting provides the data on which all subsequent statistical analyses and mappings are based, and we compare ACA results based on two different types of co-citation counting - the traditional type that only counts the first one among a cited work's authors on the one hand and a non-traditional type that takes into account the first 5 authors of a cited work on the other hand. Results indicate that the picture produced through this non-traditional author co-citation counting contains more coherent author groups and is therefore considerably clearer. However, this picture represents fewer specialties in the research field being studied than that produced through the traditional first-author co-citation counting when the same number of top-ranked authors is selected and analyzed. Reasons for these effects are discussed

    Variations on the Author

    Get PDF
    “Variations on the Author” discusses two of Eduardo Coutinho’s recent films (Um Dia na Vida, from 2010, and Últimas Conversas, posthumously released in 2015) and their contribution to the general question of documentary authorship. The director’s filmography is characterized by a consistent yet self-effacing form of authorial self-inscription: Coutinho often features as an interviewer that rather than express opinions propels discourses; an interviewer that is good at listening. This mode of self-inscription characterizes him as an author who is not expressive but who is nonetheless markedly present on the screen. In Um Dia na Vida, however, Coutinho is completely absent form the image, while Últimas Conversas, on the contrary, includes a confessional prologue that moves the director from the margins to the center of his films. This article examines the ways in which these works stand out in the filmography of a director who offers new insights into the notion of cinematic authorship

    Appropriate Similarity Measures for Author Cocitation Analysis

    Get PDF
    We provide a number of new insights into the methodological discussion about author cocitation analysis. We first argue that the use of the Pearson correlation for measuring the similarity between authors’ cocitation profiles is not very satisfactory. We then discuss what kind of similarity measures may be used as an alternative to the Pearson correlation. We consider three similarity measures in particular. One is the well-known cosine. The other two similarity measures have not been used before in the bibliometric literature. Finally, we show by means of an example that our findings have a high practical relevance.information science;Pearson correlation;cosine;similarity measure;author cocitation analysis

    Dispelling the Myths Behind First-author Citation Counts

    Get PDF
    We conducted a full-scale evaluative citation analysis study of scholars in the XML research field to explore just how different from each other author rankings resulting from different citation counting methods actually are, and to demonstrate the capability of emerging data and tools on the Web in supporting more realistic citation counting methods. Our results contest some common arguments for the continued use of first-author citation counts in the evaluation of scholars, such as high correlations between author rankings by first-author citation counts and other citation counting methods, and high costs of using more realistic citation counting methods that are not well-supported by the ISI databases. It is argued that increasingly available digital full text research papers make it possible for citation analysis studies to go beyond what the ISI databases have directly supported and to employ more sophisticated methods
    corecore