Cryptanalytic model extraction aims to reconstruct a functionally equivalent model through black-box interactions with the victim model. Under the fundamental assumption that the network architecture is completely known, existing attacks achieve the goal by recovering the model parameters. In this paper, we explore whe...
This work proves that the operational validity of the CLWE backdoor critically hinges on assumptions that are incompatible with the realistic RFF learning deployment and analyzes the adversarial robustness of RFF learning models and provides a concrete certified robustness analysis, enabling a deeper security assessmen...
Tianshuo Cong, Pei Li, Hao-Jie Wu et al.· Proceedings of the 32nd ACM...· 0 citations
Random Fourier Features (RFF) learning is a classical technique in scalable data mining. However, at FOCS 2022, Goldwasser et al. proposed a theoretical framework for planting cryptographically undetectable backdoors in RFF learning based on the hardness of the Continuous Learning With Errors (CLWE) problem. Their cons...
Tianshuo Cong, Pei Li, Haojie Wu et al.· Proceedings of the 32nd ACM...· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.