Goto

Collaborating Authors

 Industry



DiversityCanBeTransferred: OutputDiversification for White-andBlack-boxAttacks

Neural Information Processing Systems

Adversarial attacks ofteninvolverandom perturbations oftheinputsdrawnfrom uniform or Gaussian distributions, e.g., to initialize optimization-based whitebox attacks or generate update directions in black-box attacks. These simple perturbations, however, could be sub-optimal as they are agnostic to the model being attacked.


DataPerf: Benchmarks for Data-Centric AI Development Mark Mazumder

Neural Information Processing Systems

Machine learning research has long focused on models rather than datasets, and prominent datasets are used for common ML tasks without regard to the breadth, difficulty, and faithfulness of the underlying problems. Neglecting the fundamental importance of data has given rise to inaccuracy, bias, and fragility in real-world applications, and research is hindered by saturation across existing dataset benchmarks.



OnPrivacyandPersonalizationin Cross-SiloFederatedLearning

Neural Information Processing Systems

While theapplication ofdifferential privacy(DP) hasbeen well-studied incrossdevice federated learning (FL), there is a lack of work considering DP and its implications for cross-silo FL, a setting characterized by a limited number of clients each containing many data subjects.



271ec4d1a9ff5e6b81a6e21d38b1ba96-Paper-Conference.pdf

Neural Information Processing Systems

Motivated by recent applications requiring differential privacy over adaptive streams, we investigate optimal instantiations of the matrix mechanism [1] in this setting. Weprovefundamental theoretical results ontheapplicability ofmatrix factorizations to adaptive streams, and provide a parameter-free fixed-point algorithm for computing optimal factorizations.