This Github repository summarizes a list of research papers on AI security from the four top academic conferences.
186
49 commits
updated May 21, 2025
This Github repository summarizes a list of BIG-4 academic conferences papers on AI security, namely IEEE Symposium on Security and Privacy (S&P), Network and Distributed System Security Symposium (NDSS), USENIX Security Symposium, and ACM Conference on Computer and Communications Security (CCS).
This repository is supported by the Trustworthy Artificial Intelligence (T-AI) Lab at Huazhong University of Science and Technology (HUST).
Feel free to contact zhouziqi@hust.edu.cn for any issues.
GRID: Protecting Training Graph from Link Stealing Attacks on GNN Models. [Topic: GNN] [pdf]
Preference Poisoning Attacks on Reward Model Learning. [Topic: AEs] [pdf]
Prevalence Overshadows Concerns? Understanding Chinese Users' Privacy Awareness and Expectations Towards LLM-based Healthcare Consultation. [Topic: LLM] [pdf]
Adversarial Robust ViT-based Automatic Modulation Recognition in Practical Deep Learning-based Wireless Systems. [Topic: vit] [pdf]
HarmonyCloak: Making Music Unlearnable for Generative AI. [Topic: AI] [pdf]
Exploring Parent-Child Perceptions on Safety in Generative AI: Concerns, Mitigation Strategies, and Design Implications. [Topic: AI] [pdf]
Supporting Human Raters with the Detection of Harmful Content using Large Language Models. [Topic: LLM] [pdf]
Watermarking Language Models for Many Adaptive Users. [Topic: LLM] [pdf]
Benchmarking Attacks on Learning with Errors. [Topic: AEs] [pdf]
Fight Fire with Fire: Combating Adversarial Patch Attacks using Pattern-randomized Defensive Patches. [Topic: AEs] [pdf]
UnMarker: A Universal Attack on Defensive Image Watermarking. [Topic: AEs] [pdf]
My Model is Malware to You: Transforming AI Models into Malware by Abusing TensorFlow APIs. [Topic: AI] [pdf]
BAIT: Large Language Model Backdoor Scanning by Inverting Attack Target. [Topic: LLM] [pdf]
GuardAIn: Protecting Emerging Generative AI Workloads on Heterogeneous NPU. [Topic: AI] [pdf]
Comet: Accelerating Private Inference for Large Language Model by Predicting Activation Sparsity. [Topic: LLM] [pdf]
Prompt Inversion Attack against Collaborative Inference of Large Language Models. [Topic: LLM] [pdf]
The Inadequacy of Similarity-based Privacy Metrics: Privacy Attacks against ``Truly Anonymous'' Synthetic Datasets. [Topic: AEs] [pdf]
PEFTGuard: Detecting Backdoor Attacks Against Parameter-Efficient Fine-Tuning. [Topic: AEs] [pdf]
An Attack-Agnostic Defense Framework Against Manipulation Attacks under Local Differential Privacy. [Topic: AEs] [pdf]
CODEBREAKER: Dynamic Extraction Attacks on Code Language Models. [Topic: AEs] [pdf] -Changzhou Han, Zehang Deng, Wanlun Ma, Xiaogang Zhu, Jason (Minhui) Xue, Tianqing Zhu, Sheng Wen, Yang Xiang. IEEE Symposium on Security and Privacy, 2025.
Secure Transfer Learning: Training Clean Model Against Backdoor in Pre-Trained Encoder and Downstream Dataset. [Topic: backdoor] [pdf] -Yechao Zhang, Yuxuan Zhou, Tianyu Li, Minghui Li, Shengshan Hu, Wei Luo, Leo Yu Zhang. IEEE Symposium on Security and Privacy, 2025.
Make a Feint to the East While Attacking in the West: Blinding LLM-Based Code Auditors with Flashboom Attacks. [Topic: LLM] [pdf] -Xiao Li, Yue Li, Hao Wu, Yue Zhang, Kaidi Xu, Xiuzhen Cheng, Sheng Zhong, Fengyuan Xu. IEEE Symposium on Security and Privacy, 2025.
Alleviating the Fear of Losing Alignment in LLM Fine-tuning. [Topic: LLM] [pdf] -Kang Yang, Guanhong Tao, Xun Chen, Jun Xu. IEEE Symposium on Security and Privacy, 2025.
Fun-tuning: Characterizing the Vulnerability of Proprietary LLMs to Optimization-based Prompt Injection Attacks via the Fine-Tuning Interface. [Topic: LLM] [pdf] -Andrey Labunets, Nishit V. Pandya, Ashish Hooda, Xiaohan Fu, Earlence Fernandes. IEEE Symposium on Security and Privacy, 2025.
Fuzz-Testing Meets LLM-Based Agents: An Automated and Efficient Framework for Jailbreaking Text-To-Image Generation Models. [Topic: LLM] [pdf] -Yingkai Dong, Xiangtao Meng, Ning Yu, Zheng Li, Shanqing Guo. IEEE Symposium on Security and Privacy, 2025.
Understanding Users' Security and Privacy Concerns and Attitudes Towards Conversational AI Platforms. [Topic: AI] [pdf] -Mutahar Ali, Arjun Arunasalam, Habiba Farrukh. IEEE Symposium on Security and Privacy, 2025.
Securely Fine-tuning Pre-trained Encoders Against Adversarial Examples. [Topic: AEs] [pdf]
Why Does Little Robustness Help? A Further Step Towards Understanding Adversarial Transferability. [Topic: AEs] [Code][pdf]
LABRADOR: Response Guided Directed Fuzzing for Black-box IoT Devices. [Topic: AEs] [pdf]
SneakyPrompt: Jailbreaking Text-to-image Generative Models. [Topic: AEs] [Code][pdf]
SmartInv: Multimodal Learning for Smart Contract Invariant Inference.[Topic: AEs] [Code][pdf]
AVA: Inconspicuous Attribute Variation-based Adversarial Attack bypassing DeepFake Detection.[Topic: AEs] [pdf]
Robust Backdoor Detection for Deep Learning via Topological Evolution Dynamics.[Topic: Backdoor] [pdf]
MEA-Defender: A Robust Watermark against Model Extraction Attack.[Topic: AEs] [pdf]
BounceAttack: A Query-Efficient Decision-based Adversarial Attack by Bouncing into the Wild.[Topic: AEs] [pdf]
SoK: Explainable Machine Learning in Adversarial Environments.[Topic: AEs] [pdf]
Poisoned ChatGPT Finds Work for Idle Hands: Exploring Developers' Coding Practices with Insecure Suggestions from Poisoned AI Models.[Topic: AEs] [pdf]
Transferable Multimodal Attack on Vision-Language Pre-training Models.[Topic: AEs] [pdf]
Exploring the Orthogonality and Linearity of Backdoor Attacks.[Topic: Backdoor] [pdf]
OdScan: Backdoor Scanning for Object Detection Models.[Topic: Backdoor] [pdf]
Need for Speed: Taming Backdoor Attacks with Speed and Precision.[Topic: Backdoor] [pdf]
BAFFLE: Hiding Backdoors in Offline Reinforcement Learning Datasets.[Topic: Backdoor] [pdf]
DeepVenom: Persistent DNN Backdoors Exploiting Transient Weight Perturbations in Memories.[Topic: Backdoor] [Code][pdf]
LLMs Cannot Reliably Identify and Reason About Security Vulnerabilities (Yet?): A Comprehensive Evaluation, Framework, and Benchmarks.[Topic: AEs] [pdf]
BELT: Old-School Backdoor Attacks can Evade the State-of-the-Art Defense with Backdoor Exclusivity Lifting.[Topic: Backdoor] [pdf]
You Only Prompt Once: On the Capabilities of Prompt Learning on Large Language Models to Tackle Toxic Content.[Topic: AEs] [pdf]
LOKI: Large-scale Data Reconstruction Attack against Federated Learning through Model Manipulation.[Topic: AEs] [pdf]
Text-CRS: A Generalized Certified Robustness Framework against Textual Adversarial Attacks.[Topic: AEs] [pdf]
MM-BD: Post-Training Detection of Backdoor Attacks with Arbitrary Backdoor Pattern Types Using a Maximum Margin Statistic.[Topic: Backdoor] [pdf]
-BadVFL: Backdoor Attacks in Vertical Federated Learning.[Topic: Backdoor] [pdf]
-Multi-Instance Adversarial Attack on GNN-Based Malicious Domain Detection.[Topic: GNN] [pdf]
-Distribution Preserving Backdoor Attack in Self-supervised Learning.[Topic: Backdoor] [pdf]
SoK: Let the Privacy Games Begin! A Unified Treatment of Data Inference Privacy in Machine Learning.[Topic: ML] [pdf]
Analyzing Leakage of Personally Identifiable Information in Language Models.[Topic: LM] [pdf]
D-DAE: Defense-Penetrating Model Extraction Attacks.[Topic: AEs] [Code][pdf]
Disguising Attacks with Explanation-Aware Backdoors.[Topic: Backdoor] [pdf]
AI-Guardian: Defeating Adversarial Attacks using Backdoors.[Topic: Backdoor] [pdf]
BayBFed: Bayesian Backdoor Defense for Federated Learning.[Topic: Backdoor] [pdf]
edeem Myself: Purifying Backdoors in Deep Learning Models using Self Attention Distillation.[Topic: Backdoor] [pdf]
ImU: Physical Impersonating Attack for Face Recognition System with Natural Style Changes.[Topic: AEs] [pdf]
FedRecover: Recovering from Poisoning Attacks in Federated Learning using Historical Information.[Topic: AEs] [pdf]
On The Empirical Effectiveness of Unrealistic Adversarial Hardening Against Realistic Adversarial Attacks.[Topic: AEs] [pdf]
“Adversarial Examples” for Proof-of-Learning. [Topic: AEs] [pdf]
Transfer Attacks Revisited: A Large-Scale Empirical Study in Real Computer Vision Settings. [Topic:AEs] [pdf]
Bad Characters: Imperceptible NLP Attacks. [Topic: AEs] [Code][pdf]
Universal 3-Dimensional Perturbations for Black-Box Attacks on Video Recognition Systems. [Topic: AEs] [pdf]
BadEncoder: Backdoor Attacks to Pre-trained Encoders in Self-Supervised Learning. [Topic: Backdoor] [Code][pdf]
PICCOLO: Exposing Complex Backdoors in NLP Transformer Models. [Topic: Backdoor] [pdf]
Membership Inference Attacks From First Principles. [Topic: MIA] [pdf]
Back to the Drawing Board: A Critical Evaluation of Poisoning Attacks on Production Federated Learning. [Topic: PA & FL] [pdf]
Model Stealing Attacks Against Inductive Graph Neural Networks. [Topic: MSA & GNN] [pdf]
SoK: How Robust is Image Classification Deep Neural Network Watermarking? [Topic: Watermark] [pdf]
Hear "No Evil", See "Kenansville": Efficient and Transferable Black-Box Attacks on Speech Recognition and Voice Identification Systems. [Topic: AEs] [pdf]
SoK: The Faults in our ASRs: An Overview of Attacks against Automatic Speech Recognition and Speaker Identification Systems. [Topic: AEs] [pdf]
Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World Attacks. [Topic: AEs] [pdf]
Who is Real Bob? Adversarial Attacks on Speaker Recognition Systems. [Topic: AEs] [pdf]
Adversarial Watermarking Transformer: Towards Tracing Text Provenance with Data Hiding. [Topic: Watermark] [pdf]
A Method to Facilitate Membership Inference Attacks in Deep Learning Models.[Topic: ML] [pdf]
Black-box Membership Inference Attacks against Fine-tuned Diffusion Models.[Topic:Diffusion Model] [pdf]
BumbleBee: Secure Two-party Inference Framework for Large Transformers.[Topic: Transformer] [pdf]
CENSOR: Defense Against Gradient Inversion via Orthogonal Subspace Bayesian Sampling.[Topic: FL] [pdf]
CLIBE: Detecting Dynamic Backdoors in Transformer-based NLP Models.[Topic: Backdoor] [pdf]
Compiled Models, Built-In Exploits: Uncovering Pervasive Bit-Flip Attack Surfaces in DNN Executables.[Topic: DNN] [pdf]
Difference: Fencing Membership Privacy With Diffusion Models.[Topic:Diffusion Model] [pdf]
Explanation as a Watermark: Towards Harmless and Multi-bit Model Ownership Verification via Watermarking Feature Attribution.[Topic:Backdoor] [pdf]
Generating API Parameter Security Rules with LLM for API Misuse Detection.[Topic:LLM] [pdf]
Magmaw: Modality-Agnostic Adversarial Attacks on Machine Learning-Based Wireless Communication Systems.[Topic:ML] [pdf]
Passive Inference Attacks on Split Learning via Adversarial Regularization.[Topic:SL] [pdf]
Reinforcement Unlearning.[Topic:Machine unlearning] [pdf]
The Midas Touch: Triggering the Capability of LLMs for RM-API Misuse Detection.[Topic:LLM] [pdf]
The Philosopher's Stone: Trojaning Plugins of Large Language Models.[Topic:LLM] [pdf]
TrajDeleter: Enabling Trajectory Forgetting in Offline Reinforcement Learning Agents.[Topic:RL] [pdf]
Understanding Data Importance in Machine Learning Attacks: Does Valuable Data Pose Greater Harm?[Topic:ML] [pdf]
A New PPML Paradigm for Quantized Models.[Topic:PPML] [pdf]
ASGARD: Protecting On-Device Deep Neural Networks with Virtualization-Based Trusted Execution Environments.[Topic:DNN] [pdf]
BARBIE: Robust Backdoor Detection Based on Latent Separability.[Topic:Backdoor] [pdf]
Beyond Classification: Inferring Function Names in Stripped Binaries via Domain Adapted LLMs.[Topic:LLM] [pdf]
BitShield: Defending Against Bit-Flip Attacks on DNN Executables.[Topic:DNN] [pdf]
Defending Against Membership Inference Attacks on Iteratively Pruned Deep Neural Networks.[Topic:MIA] [pdf]
DLBox: New Model Training Framework for Protecting Training Data.[Topic:model training framework] [pdf]
Do We Really Need to Design New Byzantine-robust Aggregation Rules?[Topic:FL] [pdf]
DShield: Defending against Backdoor Attacks on Graph Neural Networks via Discrepancy Learning.[Topic:Backdoor] [pdf]
From Large to Mammoth: A Comparative Evaluation of Large Language Models in Vulnerability Detection.[Topic:LLM] [pdf]
I Know What You Asked: Prompt Leakage via KV-Cache Sharing in Multi-Tenant LLM Serving.[Topic:LLM] [pdf]
I know what you MEME! Understanding and Detecting Harmful Memes with Multimodal Large Language Models.[Topic:MLLM] [pdf]
IsolateGPT: An Execution Isolation Architecture for LLM-Based Agentic Systems.[Topic:LLM] [pdf]
L-HAWK: A Controllable Physical Adversarial Patch Against a Long-Distance Target.[Topic:physical adversarial patch attacks] [pdf]
LADDER: Multi-Objective Backdoor Attack via Evolutionary Algorithm.[Topic:Backdoor] [pdf]
LLMPirate: LLMs for Black-box Hardware IP Piracy.[Topic:LLM] [pdf]
PBP: Post-training Backdoor Purification for Malware Classifiers.[Topic:Backdoor] [pdf]
Privacy-Preserving Data Deduplication for Enhancing Federated Learning of Language Models.[Topic:FL] [pdf]
Probe-Me-Not: Protecting Pre-trained Encoders from Malicious Probing.[Topic:transfer learning] [pdf]
PropertyGPT: LLM-driven Formal Verification of Smart Contracts through Retrieval-Augmented Property Generation.[Topic:LLM] [pdf]
RAIFLE: Reconstruction Attacks on Interaction-based Federated Learning with Adversarial Data Manipulation.[Topic:FL] [pdf]
SafeSplit: A Novel Defense Against Client-Side Backdoor Attacks in Split Learning.[Topic:Backdoor] [pdf]
Safety Misalignment Against Large Language Models.[Topic:LLM] [pdf]
Scale-MIA: A Scalable Model Inversion Attack against Secure Federated Learning via Latent Space Reconstruction.[Topic:MIA&FL] [pdf]
SHAFT: Secure, Handy, Accurate and Fast Transformer Inference.[Topic:transformer-based machine learning] [pdf]
Try to Poison My Deep Learning Data? Nowhere to Hide Your Trajectory Spectrum![Topic:DaaS] [pdf]
URVFL: Undetectable Data Reconstruction Attack on Vertical Federated Learning.[Topic:VFL] [pdf]
VoiceRadar: Voice Deepfake Detection using Micro-Frequency and Compositional Analysis.[Topic:ML] [pdf]
Attributions for ML-based ICS Anomaly Detection: From Theory to Practice.[Topic:ML] [pdf]
Compensating Removed Frequency Components: Thwarting Voice Spectrum Reduction Attacks.[Topic:ASR] [pdf]
Crafter: Facial Feature Crafting against Inversion-based Identity Theft on Deep Models.[Topic:防御攻击] [pdf]
CrowdGuard: Federated Backdoor Detection in Federated Learning.[Topic:Backdoor] [pdf]
Enhance Stealthiness and Transferability of Adversarial Attacks with Class Activation Mapping Ensemble Attack.[Topic:对抗攻击] [pdf]
GNNIC: Finding Long-Lost Sibling Functions with Abstract Similarity.[Topic:GNN] [pdf]
LiDAR Spoofing Meets the New-Gen: Capability Improvements, Broken Assumptions, and New Attack Strategies.[Topic:欺骗攻击] [pdf]
LMSanitator: Defending Prompt-Tuning Against Task-Agnostic Backdoors.[Topic:Backdoor] [pdf]
Low-Quality Training Data Only? A Robust Framework for Detecting Encrypted Malicious Network Traffic.[Topic:数据集] [pdf]
MPCDiff: Testing and Repairing MPC-Hardened Deep Learning Models.[Topic:MPC-Hardened] [pdf]
On Precisely Detecting Censorship Circumvention in Real-World Networks.[Topic:Censorship Circumvention] [pdf]
Overconfidence is a Dangerous Thing: Mitigating Membership Inference Attacks by Enforcing Less Confident Prediction.[Topic:MIA] [pdf]
SigmaDiff: Semantics-Aware Deep Graph Matching for Pseudocode Diffing.[Topic:DNN] [pdf]
Transpose Attack: Stealing Datasets with Bidirectional Training.[Topic:数据集窃取] [pdf]
A Duty to Forget, a Right to be Assured? Exposing Vulnerabilities in Machine Unlearning Services.[Topic:MLaaS] [pdf]
ActiveDaemon: Unconscious DNN Dormancy and Waking Up via User-specific Invisible Token.[Topic:Watermark] [pdf]
Automatic Adversarial Adaption for Stealthy Poisoning Attacks in Federated Learning.[Topic:FL] [pdf]
CamPro: Camera-based Anti-Facial Recognition.[Topic:AFR] [pdf]
DeepGo: Predictive Directed Greybox Fuzzing.[Topic:RL] [pdf]
DeGPT: Optimizing Decompiler Output with LLM.[Topic:LLM] [pdf]
DEMASQ: Unmasking the ChatGPT Wordsmith.[Topic:LLM] [pdf]
Don't Interrupt Me - A Large-Scale Study of On-Device Permission Prompt Quieting in Chrome.[Topic:ML] [pdf]
DorPatch: Distributed and Occlusion-Robust Adversarial Patch to Evade Certifiable Defenses.[Topic:DNN] [pdf]
DRAINCLoG: Detecting Rogue Accounts with Illegally-obtained NFTs using Classifiers Learned on Graphs.[Topic:DNN] [pdf]
Flow Correlation Attacks on Tor Onion Service Sessions with Sliding Subset Sum.[Topic:machine learning classifiers] [pdf]
FreqFed: A Frequency Analysis-Based Approach for Mitigating Poisoning Attacks in Federated Learning.[Topic:FL] [pdf]
Gradient Shaping: Enhancing Backdoor Attack Against Reverse Engineering.[Topic:Backdoor] [pdf]
GraphGuard: Detecting and Counteracting Training Data Misuse in Graph Neural Networks.[Topic:GNN] [pdf]
Group-based Robustness: A General Framework for Customized Robustness in the Real World.[Topic:规避攻击] [pdf]
Improving the Robustness of Transformer-based Large Language Models with Dynamic Attention.[Topic:LLM] [pdf]
Large Language Model guided Protocol Fuzzing.[Topic:LLM] [pdf]
MASTERKEY: Automated Jailbreaking of Large Language Model Chatbots.[Topic:LLM] [pdf]
Parrot-Trained Adversarial Examples: Pushing the Practicality of Black-Box Audio Attacks against Speaker Recognition Models.[Topic:AE] [pdf]
Pencil: Private and Extensible Collaborative Learning without the Non-Colluding Assumption.[Topic:Collaborative Learning] [pdf]
SLMIA-SR: Speaker-Level Membership Inference Attacks against Speaker Recognition Systems.[Topic:MIA] [pdf]
Sneaky Spikes: Uncovering Stealthy Backdoor Attacks in Spiking Neural Networks with Neuromorphic Data.[Topic:Backdoor] [pdf]
SSL-WM: A Black-Box Watermarking Approach for Encoders Pre-trained by Self-Supervised Learning.[Topic:水印] [pdf]
TextGuard: Provable Defense against Backdoor Attacks on Text Classification.[Topic:Backdoor] [pdf]
You Can Use But Cannot Recognize: Preserving Visual Privacy in Deep Neural Networks.[Topic:DNN] [pdf]
Fusion: Efficient and Secure Inference Resilient to Malicious Servers. [Topic: MLaaS] [pdf]
Machine Unlearning of Features and Labels. [Topic: Machine-Unlearning] [pdf]
PPA: Preference Profiling Attack Against Federated Learning. [Topic: FL] [pdf]
RoVISQ: Reduction of Video Service Quality via Adversarial Attacks on Deep Learning-based Video Compression. [Topic: AEs] [pdf]
Securing Federated Sensitive Topic Classification against Poisoning Attacks. [Topic: FL] [pdf]
The “Beatrix” Resurrections: Robust Backdoor Detection via Gram Matrices. [Topic: Backdoor] [pdf]
Adversarial Robustness for Tabular Data through Cost and Utility Awareness. [Topic: AEs] [pdf]
Backdoor Attacks Against Dataset Distillation. [Topic: Backdoor] [pdf]
BEAGLE: Forensics of Deep Learning Backdoor Attack for Better Defense. [Topic: Backdoor] [pdf]
Focusing on Pinocchio's Nose: A Gradients Scrutinizer to Thwart Split-Learning Hijacking Attacks Using Intrinsic Attributes. [Topic: SL] [pdf]
REaaS: Enabling Adversarially Robust Downstream Classifiers via Robust Encoder as a Service. [Topic: AEs] [pdf]
DeepSight: Mitigating Backdoor Attacks in Federated Learning Through Deep Model Inspection. [Topic: Backdoor] [pdf]
FedCRI: Federated Mobile Cyber-Risk Intelligence. [Topic: FL] [pdf]
Get a Model! Model Hijacking Attack Against Machine Learning Models. [Topic: Model-Hijacking] [pdf]
Local and Central Differential Privacy for Robustness and Privacy in Federated Learning. [Topic: FL] [pdf]
Property Inference Attacks Against GANs. [Topic: IA & GAN] [pdf]
ATTEQ-NN: Attention-based QoE-aware Evasive Backdoor Attacks. [Topic: Backdoor] [pdf]
Fooling the Eyes of Autonomous Vehicles: Robust Physical Adversarial Examples Against Traffic Sign Recognition Systems. [Topic: AEs] [pdf]
MIRROR: Model Inversion for Deep Learning Network with High Fidelity. [Topic: MIA] [pdf]
RamBoAttack: A Robust and Query Efficient Deep Neural Network Decision Exploit. [Topic: AEs] [pdf]
Data Poisoning Attacks to Deep Learning Based Recommender Systems. [Topic: PAs] [pdf]
FLTrust: Byzantine-robust Federated Learning via Trust Bootstrapping. [Topic: PA & FL] [pdf]
Manipulating the Byzantine: Optimizing Model Poisoning Attacks and Defenses for Federated Learning. [Topic: PA & FL] [pdf]
Practical Blind Membership Inference Attack via Differential Comparisons. [Topic: MIA] [pdf]
POSEIDON: Privacy-Preserving Federated Neural Network Learning. [Topic: FL] [pdf]
AttackGNN: Red-Teaming GNNs in Hardware Security Using Reinforcement Learning.[Topic:GNN&RL] [pdf]
INSIGHT: Attacking Industry-Adopted Learning Resilient Logic Locking Techniques Using Explainable Graph Neural Network.[Topic:ML] [pdf]
FAMOS: Robust Privacy-Preserving Authentication on Payment Apps via Federated Multi-Modal Contrastive Learning.[Topic:FL] [pdf]
Efficient Privacy Auditing in Federated Learning.[Topic:FL] [pdf]
Defending Against Data Reconstruction Attacks in Federated Learning: An Information Theory Approach.[Topic:FL] [pdf]
Lotto: Secure Participant Selection against Adversarial Servers in Federated Learning.[Topic:FL] [pdf]
KnowPhish: Large Language Models Meet Multimodal Knowledge Graphs for Enhancing Reference-Based Phishing Detection.[Topic:LLM for Security] [pdf]
Exploring ChatGPT's Capabilities on Vulnerability Management.[Topic:LLM for Security] [pdf]
Large Language Models for Code Analysis: Do LLMs Really Do Their Job?[Topic:LLM for Security] [pdf]
PentestGPT: Evaluating and Harnessing Large Language Models for Automated Penetration Testing.[Topic:LLM for Security] [pdf]
Fuzzing BusyBox: Leveraging LLM and Crash Reuse for Embedded Bug Unearthing.[Topic:LLM] [pdf]
DNN-GP: Diagnosing and Mitigating Model's Faults Using Latent Concepts.[Topic:DNN] [pdf]
Yes, One-Bit-Flip Matters! Universal DNN Model Inference Depletion with Runtime Code Fault Injection.[Topic:DNN] [pdf]
Tossing in the Dark: Practical Bit-Flipping on Gray-box Deep Neural Networks for Runtime Trojan Injection.[Topic:DNN] [pdf]
Forget and Rewire: Enhancing the Resilience of Transformer-based Models against Bit-Flip Attacks.[Topic:DNN] [pdf]
Automated Large-Scale Analysis of Cookie Notice Compliance.[Topic:ML for Security] [pdf]
Detecting and Mitigating Sampling Bias in Cybersecurity with Unlabeled Data.[Topic:ML for Security] [pdf]
An LLM-Assisted Easy-to-Trigger Backdoor Attack on Code Completion Models: Injecting Disguised Vulnerabilities against Strong Detection.[Topic:LLM] [pdf]
REMARK-LLM: A Robust and Efficient Watermarking Framework for Generative Large Language Models.[Topic:LLM] [pdf]
Formalizing and Benchmarking Prompt Injection Attacks and Defenses.[Topic:LLM] [pdf]
Instruction Backdoor Attacks Against Customized LLMs.[Topic:LLM] [pdf]
AutoFHE: Automated Adaption of CNNs for Efficient Evaluation over FHE.[Topic:CNN] [pdf]
Fast and Private Inference of Deep Neural Networks by Co-designing Activation Functions.[Topic:MLaaS] [pdf]
OblivGNN: Oblivious Inference on Transductive and Inductive Graph Neural Network.[Topic:GNN] [pdf]
MD-ML: Super Fast Privacy-Preserving Machine Learning for Malicious Security with a Dishonest Majority.[Topic:PPML] [pdf]
Accelerating Secure Collaborative Machine Learning with Protocol-Aware RDMA.[Topic:SCML] [pdf]
Did the Neurons Read your Book? Document-level Membership Inference for Large Language Models.[Topic:LLM] [pdf]
MIST: Defending Against Membership Inference Attacks Through Membership-Invariant Subspace Training.[Topic:MI attack] [pdf]
Neural Network Semantic Backdoor Detection and Mitigation: A Causality-Based Approach.[Topic:Backdoor] [pdf]
On the Difficulty of Defending Contrastive Learning against Backdoor Attacks.[Topic:Backdoor] [pdf]
Mudjacking: Patching Backdoor Vulnerabilities in Foundation Models.[Topic:Backdoor] [pdf]
Xplain: Analyzing Invisible Correlations in Model Explanation.[Topic:Backdoor] [pdf]
Verify your Labels! Trustworthy Predictions and Datasets via Confidence Scores.[Topic:Backdoor] [pdf]
More Simplicity for Trainers, More Opportunity for Attackers: Black-Box Attacks on Speaker Recognition Systems by Inferring Feature Extractor.[Topic:AE] [pdf]
Adversarial Illusions in Multi-Modal Embeddings.[Topic:Multi-modal embeddings] [pdf]
Splitting the Difference on Adversarial Training.[Topic:Adversarial Attack Defense] [pdf]
Machine Learning needs Better Randomness Standards: Randomised Smoothing and PRNG-based attacks.[Topic:Adversarial Attack Defense] [pdf]
Lurking in the shadows: Unveiling Stealthy Backdoor Attacks against Personalized Federated Learning.[Topic:Backdoor and Federated Learning] [pdf]
ACE: A Model Poisoning Attack on Contribution Evaluation Methods in Federated Learning.[Topic:Backdoor and Federated Learning] [pdf]
BackdoorIndicator: Leveraging OOD Data for Proactive Backdoor Detection in Federated Learning.[Topic:Backdoor and Federated Learning] [pdf]
UBA-Inf: Unlearning Activated Backdoor Attack with Influence-Driven Camouflage.[Topic:Backdoor and Federated Learning] [pdf]
LLM-Fuzzer: Scaling Assessment of Large Language Model Jailbreaks.[Topic:LLM Jailbreaking] [pdf]
Don't Listen To Me: Understanding and exploring jailbreak prompts of large language models.[Topic:LLM Jailbreaking] [pdf]
Making Them Ask and Answer: Jailbreaking Large Language Models in Few Queries via Disguise and Reconstruction.[Topic:LLM Jailbreaking] [pdf]
SoK: All You Need to Know About On-Device ML Model Extraction - The Gap Between Research and Practice.[Topic:Watermark] [pdf]
Unveiling the Secrets without Data: Can Graph Neural Networks Be Exploited through Data-Free Model Extraction Attacks?[Topic:GNN] [pdf]
ClearStamp: A Human-Visible and Robust Model-Ownership Proof based on Transposed Model Training.[Topic:Watermark] [pdf]
DeepEclipse: How to Break White-Box DNN-Watermarking Schemes.[Topic:Watermark] [pdf]
Deciphering Textual Authenticity: A Generalized Strategy through the Lens of Large Language Semantics for Detecting Human vs. Machine-Generated Text.[Topic:LLM] [pdf]
How Does a Deep Learning Model Architecture Impact Its Privacy? A Comprehensive Study of Privacy Attacks on CNNs and Transformers.[Topic:Privacy Attacks] [pdf]
FaceObfuscator: Defending Deep Learning-based Privacy Attacks with Gradient Descent-resistant Features in Face Recognition.[Topic:Privacy Attacks] [pdf]
Hijacking Attacks against Neural Network by Analyzing Training Data.[Topic:Hijacking Attacks] [pdf]
Information Flow Control in Machine Learning through Modular Model Architecture.[Topic:ML] [pdf]
Devil in the Room: Triggering Audio Backdoors in the Physical World.[Topic:Physical Adversarial Attacks] [pdf]
FraudWhistler: A Resilient, Robust and Plug-and-play Adversarial Example Detection Method for Speaker Recognition.[Topic:AE] [pdf]
EaTVul: ChatGPT-based Evasion Attack Against Software Vulnerability Detection.[Topic:Evasion Attack] [pdf]
“Security is not my field, I’m a stats guy”: A Qualitative Root Cause Analysis of Barriers to Adversarial Machine Learning Defenses in Industry. [Topic: AEs] [pdf]
A Data-free Backdoor Injection Approach in Neural Networks. [Topic: Backdoor] [pdf]
A Plot is Worth a Thousand Words: Model Information Stealing Attacks via Scientific Plots. [Topic: MSA] [pdf]
Aegis: Mitigating Targeted Bit-flip Attacks against Deep Neural Networks. [Topic: BFA] [pdf]
Black-box Adversarial Example Attack towards FCG Based Android Malware Detection under Incomplete Feature Information. [Topic: AEs] [pdf]
CAPatch: Physical Adversarial Patch against Image Captioning Systems. [Topic: AEs] [pdf]
DiffSmooth: Certifiably Robust Learning via Diffusion Models and Local Smoothing. [Topic: AEs] [pdf]
Every Vote Counts: Ranking-Based Training of Federated Learning to Resist Poisoning Attacks. [Topic: PA & FL] [pdf]
Exorcising "Wraith": Protecting LiDAR-based Object Detector in Automated Driving System from Appearing Attacks. [Topic: Appearing-Attack] [pdf]
Fine-grained Poisoning Attack to Local Differential Privacy Protocols for Mean and Variance Estimation. [Topic: DP] [pdf]
FreeEagle: Detecting Complex Neural Trojans in Data-Free Cases. [Topic: Backdoor] [pdf]
GAP: Differentially Private Graph Neural Networks with Aggregation Perturbation. [Topic: DP & GNN] [pdf]
Lost at C: A User Study on the Security Implications of Large Language Model Code Assistants. [Topic: LLM] [pdf]
Meta-Sift: How to Sift Out a Clean Subset in the Presence of Data Poisoning?. [Topic: PA] [pdf]
No more Reviewer #2: Subverting Automatic Paper-Reviewer Assignment using Adversarial Learning. [Topic: AEs] [pdf]
PELICAN: Exploiting Backdoors of Naturally Trained Deep Learning Models In Binary Code Analysis. [Topic: Backdoor] [pdf]
PrivateFL: Accurate, Differentially Private Federated Learning via Personalized Data Transformation. [Topic: DP & FL] [pdf]
Rethinking White-Box Watermarks on Deep Learning Models under Neural Structural Obfuscation. [Topic: Watermark] [pdf]
X-Adv: Physical Adversarial Object Attacks against X-ray Prohibited Item Detection. [Topic: AEs] [pdf]
TPatch: A Triggered Physical Adversarial Patch. [Topic: AEs] [pdf]
UnGANable: Defending Against GAN-based Face Manipulation. [Topic: Deepfake] [pdf]
Squint Hard Enough: Attacking Perceptual Hashing with Adversarial Machine Learning. [Topic: AEs] [pdf]
The Space of Adversarial Strategies. [Topic: AEs] [pdf]
That Person Moves Like A Car: Misclassification Attack Detection for Autonomous Systems Using Spatiotemporal Consistency. [Topic: AEs] [pdf]
NeuroPots: Realtime Proactive Defense against Bit-Flip Attacks in Neural Networks. [Topic: BFA] [pdf]
URET: Universal Robustness Evaluation Toolkit (for Evasion). [Topic: AEs] [pdf]
SMACK: Semantically Meaningful Adversarial Audio Attack. [Topic: AEs] [pdf]
Gradient Obfuscation Gives a False Sense of Security in Federated Learning. [Topic: FL] [pdf]
Fairness Properties of Face Recognition and Obfuscation Systems. [Topic: AEs] [pdf]
PCAT: Functionality and Data Stealing from Split Learning by Pseudo-Client Attack. [Topic: SL] [pdf]
ML-Doctor: Holistic Risk Assessment of Inference Attacks Against Machine Learning Models. [Topic: MIA] [pdf]
Blacklight: Scalable Defense for Neural Networks against Query-Based Black-Box Attacks. [Topic: AEs] [pdf]
AutoDA: Automated Decision-based Iterative Adversarial Attacks. [Topic: AEs] [pdf]
Poison Forensics: Traceback of Data Poisoning Attacks in Neural Networks. [Topic: PA] [pdf]
Teacher Model Fingerprinting Attacks Against Transfer Learning. [Topic: Fingerprinting] [pdf]
Hidden Trigger Backdoor Attack on NLP Models via Linguistic Style Manipulation. [Topic: Backdoor] [pdf]
PoisonedEncoder: Poisoning the Unlabeled Pre-training Data in Contrastive Learning. [Topic: PA] [pdf]
Pool Inference Attacks on Local Differential Privacy: Quantifying the Privacy Guarantees of Apple's Count Mean Sketch in Practice. [Topic: IA & DP] [pdf]
PatchCleanser: Certifiably Robust Defense against Adversarial Patches for Any Image Classifier. [Topic: AEs] [pdf]
Exploring the Security Boundary of Data Reconstruction via Neuron Exclusivity Analysis. [Topic: DRA] [pdf]
Poisoning Attacks to Local Differential Privacy Protocols for Key-Value Data. [Topic: PA & DP] [pdf]
Communication-Efficient Triangle Counting under Local Differential Privacy. [Topic: DP] [pdf]
Security Analysis of Camera-LiDAR Fusion Against Black-Box Attacks on Autonomous Vehicles. [Topic: AEs & AV] [pdf]
Transferring Adversarial Robustness Through Robust Representation Matching. [Topic: AEs] [pdf]
Seeing is Living? Rethinking the Security of Facial Liveness Verification in the Deepfake Era. [Topic: Deepfake] [pdf]
On the Necessity of Auditable Algorithmic Definitions for Machine Unlearning. [Topic: Machine-Unlearning] [pdf]
Mitigating Membership Inference Attacks by Self-Distillation Through a Novel Ensemble Architecture. [Topic: MIA] [pdf]
Membership Inference Attacks and Defenses in Neural Network Pruning. [Topic: MIA] [pdf]
Efficient Differentially Private Secure Aggregation for Federated Learning via Hardness of Learning with Errors. [Topic: DP & FL] [pdf]
Who Are You (I Really Wanna Know)? Detecting Audio DeepFakes Through Vocal Tract Reconstruction. [Topic: Deepfake] [pdf]
Are Your Sensitive Attributes Private? Novel Model Inversion Attribute Inference Attacks on Classification Models. [Topic: MIAI] [pdf]
FLAME: Taming Backdoors in Federated Learning. [Topic: FL & Backdoor] [pdf]
Synthetic Data – Anonymisation Groundhog Day. [Topic: Synthetic-Data] [pdf]
On the Security Risks of AutoML. [Topic: NAS] [pdf]
Inference Attacks Against Graph Neural Networks. [Topic: IA & GNN] [pdf]
Adversarial Detection Avoidance Attacks: Evaluating the robustness of perceptual hashing-based client-side scanning. [Topic: AEs] [pdf]
Label Inference Attacks Against Vertical Federated Learning. [Topic: IA & FL] [pdf]
Rolling Colors: Adversarial Laser Exploits against Traffic Light Recognition. [Topic: AEs] [pdf]
PatchGuard: A Provably Robust Defense against Adversarial Patches via Small Receptive Fields and Masking. [Topic: AEs] [pdf]
PrivSyn: Differentially Private Data Synthesis. [Topic: DP] [pdf]
Muse: Secure Inference Resilient to Malicious Clients. [Topic: IA] [pdf]
Systematic Evaluation of Privacy Risks of Machine Learning Models. [Topic: IA] [pdf]
Explanation-Guided Backdoor Poisoning Attacks Against Malware Classifiers. [Topic: Backdoor] [pdf]
Cerebro: A Platform for Multi-Party Cryptographic Collaborative Learning. [Topic: MPC] [pdf]
T-Miner: A Generative Approach to Defend Against Trojan Attacks on DNN-based Text Classification. [Topic: Backdoor] [pdf]
Defeating DNN-Based Traffic Analysis Systems in Real-Time With Blind Adversarial Perturbations. [Topic: AEs] [pdf]
Data Poisoning Attacks to Local Differential Privacy Protocols. [Topic: PA & DP] [pdf]
How to Make Private Distributed Cardinality Estimation Practical, and Get Differential Privacy for Free. [Topic: DP] [pdf]
SLAP: Improving Physical Adversarial Examples with Short-Lived Adversarial Perturbations. [Topic: AEs] [pdf]
WaveGuard: Understanding and Mitigating Audio Adversarial Examples. [Topic: AEs] [pdf]
Graph Backdoor. [Topic: Backdoor] [pdf]
Entangled Watermarks as a Defense against Model Extraction. [Topic: Watermark] [pdf]
Too Good to Be Safe: Tricking Lane Detection in Autonomous Driving with Crafted Perturbations. [Topic: AEs] [pdf]
Fantastic Four: Honest-Majority Four-Party Secure Computation With Malicious Security. [Topic: MPC] [pdf]
Locally Differentially Private Analysis of Graph Statistics. [Topic: DP] [pdf]
Demon in the Variant: Statistical Analysis of DNNs for Robust Backdoor Contamination Detection. [Topic: Backdoor] [pdf]
Stealing Links from Graph Neural Networks. [Topic: GNN] [pdf]
Adversarial Policy Training against Deep Reinforcement Learning. [Topic: AEs & RL] [pdf]
Moderator: Moderating Text-to-Image Diffusion Models through Fine-grained Context-based Policies. [Topic: ML and Security: Large Language Models] [pdf]
Training Robust ML-based Raw-Binary Malware Detectors in Hours, not Months. [Topic: Verification, Secure Architectures, and Network Security] [pdf]
TREC: APT Tactic / Technique Recognition via Few-Shot Provenance Subgraph Learning. [Topic: Verification, Secure Architectures, and Network Security] [pdf]
SAFARI: Speech-Associated Facial Authentication for AR/VR Settings via Robust VIbration Signatures [Topic: Verification, Secure Architectures, and Network Security] [pdf]
KnowGraph: Knowledge-Enabled Anomaly Detection via Logical Reasoning on Graph Data. [Topic: Verification, Secure Architectures, and Network Security] [pdf] -Andy Zhou, Xiaojun Xu, Ramesh Raghunathan, Alok Lal, Xinze Guan, Bin Yu, Bo Li. ACM CCS, 2024.
Understanding Implosion in Text-to-Image Generative Models. [Topic: ML and Security: Large Language Models] [pdf]
Legilimens: Practical and Unified Content Moderation for Large Language Model Services. [Topic: ML and Security: Large Language Models] [pdf]
Optimization-based Prompt Injection Attack to LLM-as-a-Judge. [Topic: ML and Security: Machine Learning Attacks] [pdf]
PromSec: Prompt Optimization for Secure Generation of Functional Source Code with Large Language Models (LLMs). [Topic: ML and Security: Generative Models] [pdf]
Certifiable Black-Box Attacks with Randomized Adversarial Examples: Breaking Defenses with Provable Confidence [Topic: ML and Security: Machine Learning Attacks] [pdf]
Phantom: Untargeted Poisoning Attacks on Semi-Supervised Learning (Full Version) [Topic: ML and Security: Machine Learning Attacks] [pdf]
Zero-Query Adversarial Attack on Black-box Automatic Speech Recognition Systems [Topic: ML and Security: Machine Learning Attacks] [pdf]
SUB-PLAY: Adversarial Policies against Partially Observed Multi-Agent Reinforcement Learning Systems [Topic: ML and Security: Machine Learning Attacks] [pdf]
Optimization-based Prompt Injection Attack to LLM-as-a-Judge [Topic: ML and Security: Machine Learning Attacks] [pdf]
Neural Dehydration: Effective Erasure of Black-box Watermarks from DNNs with Limited Data [Topic: ML and Security: Machine Learning Attacks] [pdf]
Is Difficulty Calibration All We Need? Towards More Practical Membership Inference Attacks [Topic: Blockchain & Distributed Systems: Blockchain Attacks] [pdf]
Evaluations of Machine Learning Privacy Defenses are Misleading [Topic: Blockchain & Distributed Systems: Blockchain Attacks] [pdf]
A Unified Membership Inference Method for Visual Self-supervised Encoder via Part-aware Capability [Topic: Blockchain & Distributed Systems: Blockchain Attacks] [pdf]
The Janus Interface: How Fine-Tuning in Large Language Models Amplifies the Privacy Risks [Topic: Blockchain & Distributed Systems: Blockchain Attacks] [pdf]
A General Framework for Data-Use Auditing of ML Models [Topic: Blockchain & Distributed Systems: Blockchain Attacks] [pdf]
Dye4AI: Assuring Data Boundary on Generative AI Services [Topic: ML and Security: Generative Models] [pdf]
I Don't Know You, But I Can Catch You: Real-Time Defense against Diverse Adversarial Patches for Object Detectors [Topic: Privacy and Anonymity: Privacy Attacks Meet ML] [pdf]
AirGapAgent: Protecting Privacy-Conscious Conversational Agents [Topic: Privacy and Anonymity: Privacy Attacks Meet ML] [pdf]
ERASER: Machine Unlearning in MLaaS via an Inference Serving-Aware Approach [Topic: Privacy and Anonymity: Privacy Attacks Meet ML] [pdf]
NeuJeans: Private Neural Network Inference with Joint Optimization of Convolution and FHE Bootstrapping [Topic: Usability and Measurement: Phishing, Deepfakes, and Other Risks] [pdf]
Ents: An Efficient Three-party Training Framework for Decision Trees by Communication Optimization [Topic: Usability and Measurement: Phishing, Deepfakes, and Other Risks] [pdf]
zkLLM: Zero Knowledge Proofs for Large Language Models [Topic: Usability and Measurement: Phishing, Deepfakes, and Other Risks] [pdf]
Fisher Information guided Purification against Backdoor Attacks [Topic: ML and Security: Model Security] [pdf]
BadMerging: Backdoor Attacks Against Model Merging [Topic: ML and Security: Model Security] [pdf]
SafeGen: Mitigating Sexually Explicit Content Generation in Text-to-Image Models [Topic: Usability and Measurement: AI Risks] [pdf]
Image-Perfect Imperfections: Safety, Bias, and Authenticity in the Shadow of Text-To-Image Model Evolution [Topic: Usability and Measurement: AI Risks] [pdf]
Decoding the Secrets of Machine Learning in Malware Classification: A Deep Dive into Datasets, Feature Extraction, and Model Performance [Topic: Machine Learning Applications I] [pdf]
Efficient Query-Based Attack against ML-Based Android Malware Detection under Zero Knowledge Setting [Topic: Machine Learning Applications I] [pdf]
Your Battery Is a Blast! Safeguarding Against Counterfeit Batteries with Authentication [Topic: Machine Learning Applications I] [pdf]
Narcissus: A Practical Clean-Label Backdoor Attack with Limited Information [Topic: Machine Learning Attacks I] [pdf]
Stateful Defenses for Machine Learning Models Are Not Yet Secure Against Black-box Attacks [Topic: Machine Learning Attacks I] [pdf]
Evading Watermark based Detection of AI-Generated Content [Topic: Machine Learning Attacks II] [pdf]
Verifiable Learning for Robust Tree Ensembless [Topic: Language Models & Verification] [pdf]
Large Language Models for Code: Security Hardening and Adversarial Testing [Topic: Language Models & Verification] [pdf]
Characterizing and Detecting Non-Consensual Photo Sharing on Social Networks. [Topic: Non-consensual Sharing] [pdf]
DPIS: An Enhanced Mechanism for Differentially Private SGD with Importance Sampling. [Topic: DP & DNN] [pdf]
DriveFuzz: Discovering Autonomous Driving Bugs through Driving Quality-Guided Fuzzing. [Topic: AD] [pdf]
EIFFeL: Ensuring Integrity for Federated Learning. [Topic: FL] [pdf]
Eluding Secure Aggregation in Federated Learning via Model Inconsistency. [Topic: FL] [pdf]
Enhanced Membership Inference Attacks against Machine Learning Models. [Topic: MI] [pdf]
Feature Inference Attack on Shapley Values. [Topic: MLaaS] [pdf]
Graph Unlearning. [Topic: Machine Unlearning] [pdf]
Group Property Inference Attacks Against Graph Neural Networks. [Topic: GNNs] [pdf]
Harnessing Perceptual Adversarial Patches for Crowd Counting. [Topic: AEs] [pdf]
Training Set Debugging Using Trusted Items. [Topic: ML] [pdf]
LPGNet: Link Private Graph Networks for Node Classification. [Topic: GCNs & DP] [pdf]
LoneNeuron: a Highly-Effective Feature-Domain Neural Trojan Using Invisible and Polymorphic Watermarks. [Topic: DNNs & Watermark] [pdf]
Membership Inference Attacks and Generalization: A Causal Perspective. [Topic: MI] [pdf]
Membership Inference Attacks by Exploiting Loss Trajectory. [Topic: MI] [pdf]
Order-Disorder: Imitation Adversarial Attacks for Black-box Neural Ranking Models. [Topic: IR] [pdf]
Perception-Aware Attack: Creating Adversarial Music via Reverse-Engineering Human Perception. [Topic: AEs] [pdf]
Physical Hijacking Attacks against Object Trackers. [Topic: AV] [pdf]
Post-breach Recovery: Protection against White-box Adversarial Examples for Leaked DNN Models. [Topic: DNN] [pdf]
QuerySnout: Automating the Discovery of Attribute Inference Attacks against Query-Based Systems. [Topic: QBS] [pdf]
SSLGuard: A Watermarking Scheme for Self-supervised Learning Pre-trained Encoders. [Topic: Watermark] [pdf]
SpecPatch: Human-In-The-Loop Adversarial Audio Spectrogram Patch Attack on Speech Recognition. [Topic: AEs] [pdf]
StolenEncoder: Stealing Pre-trained Encoders in Self-supervised Learning. [Topic: EaaS] [pdf]
Truth Serum: Poisoning Machine Learning Models to Reveal Their Secrets. [Topic: ML] [pdf]
Understanding Real-world Threats to Deep Learning Models in Android Apps. [Topic: AEs] [pdf]
When Evil Calls: Targeted Adversarial Voice over IP Network. [Topic: AEs] [pdf]
Why So Toxic? Measuring and Triggering Toxic Behavior in Open-Domain Chatbots. [Topic: AEs] [pdf]
"Is your explanation stable?": A Robustness Evaluation Framework for Feature Attribution. [Topic: NNs] [pdf]
Cert-RNN: Towards Certifying the Robustness of Recurrent Neural Networks. [Topic: AEs] [pdf]
AHEAD: Adaptive Hierarchical Decomposition for Range Query under Local Differential Privacy. [Topic: LDP] [pdf]
Unleashing the Tiger: Inference Attacks on Split Learning. [Topic: SL] [pdf]
TableGAN-MCA: Evaluating Membership Collisions of GAN-Synthesized Tabular Data Releasing. [Topic: GAN] [pdf]
"I need a better description": An Investigation Into User Expectations For Differential Privacy. [Topic: DP] [pdf]
Locally Private Graph Neural Networks. [Topic: GNNs] [pdf]
A One-Pass Distributed and Private Sketch for Kernel Sums with Applications to Machine Learning at Scale. [Topic: DP] [pdf]
On the Robustness of Domain Constraints. [Topic: AEs] [pdf]
Membership Leakage in Label-Only Exposures. [Topic: MI] [pdf]
Hidden Backdoors in Human-Centric Language Models. [Topic: Backdoor] [pdf]
DataLens: Scalable Privacy Preserving Training via Gradient Compression and Aggregation. [Topic: DP] [pdf]
DeepAID: Interpreting and Improving Deep Learning-based Anomaly Detection in Security Applications. [Topic: DL] [pdf]
Honest-but-Curious Nets: Sensitive Attributes of Private Inputs Can Be Secretly Coded into the Classifiers' Outputs. [Topic: Classifer] [pdf]
Differential Privacy for Directional Data. [Topic: DP] [pdf]
"Hello, It's Me": Deep Learning-based Speech Synthesis Attacks in the Real World. [Topic: Speech Synthesis Attack] [pdf]
EncoderMI: Membership Inference against Pre-trained Encoders in Contrastive Learning. [Topic: MI] [pdf]
Subpopulation Data Poisoning Attacks. [Topic: Poisoning Attack] [pdf]
Continuous Release of Data Streams under both Centralized and Local Differential Privacy. [Topic: DP] [pdf]
When Machine Unlearning Jeopardizes Privacy. [Topic: MI] [pdf]
DetectorGuard: Provably Securing Object Detectors against Localized Patch Hiding Attacks. [Topic: AEs] [pdf]
I Can See the Light: Attacks on Autonomous Vehicles Using Invisible Lights. [Topic: AV] [pdf]
Backdoor Pre-trained Models Can Transfer to All. [Topic: Backdoor] [pdf]
Quantifying and Mitigating Privacy Risks of Contrastive Learning. [Topic: CL] [pdf]
Membership Inference Attacks Against Recommender Systems. [Topic: MI] [pdf]
Learning Security Classifiers with Verified Global Robustness Properties. [Topic: Classifier] [pdf]
Robust Adversarial Attacks Against DNN-Based Wireless Communication Systems. [Topic: AEs] [pdf]
Can We Use Arbitrary Objects to Attack LiDAR Perception in Autonomous Driving? [Topic: AEs] [pdf]
Feature Indistinguishable Attack to Circumvent Trapdoor-enabled Defense. [Topic: AEs] [Code][pdf]
A Hard Label Black-box Adversarial Attack Against Graph Neural Networks. [Topic: AEs & DNN] [pdf]
Reverse Attack: Black-box Attacks on Collaborative Recommendation. [Topic: CF & Poisoning Attack] [pdf]
zkCNN: Zero Knowledge Proofs for Convolutional Neural Network Predictions and Accuracy. [Topic: CNN] [pdf]
Black-box Adversarial Attacks on Commercial Speech Platforms with Minimal Information. [Topic: AEs] [pdf]
AI-Lancet: Locating Error-inducing Neurons to Optimize Neural Networks. [Topic: DNN] [pdf]
This Github repository summarizes a list of research papers on AI security from the four top academic conferences.
186
49 commits
updated May 21, 2025
This Github repository summarizes a list of BIG-4 academic conferences papers on AI security, namely IEEE Symposium on Security and Privacy (S&P), Network and Distributed System Security Symposium (NDSS), USENIX Security Symposium, and ACM Conference on Computer and Communications Security (CCS).
This repository is supported by the Trustworthy Artificial Intelligence (T-AI) Lab at Huazhong University of Science and Technology (HUST).
Feel free to contact zhouziqi@hust.edu.cn for any issues.
GRID: Protecting Training Graph from Link Stealing Attacks on GNN Models. [Topic: GNN] [pdf]
Preference Poisoning Attacks on Reward Model Learning. [Topic: AEs] [pdf]
Prevalence Overshadows Concerns? Understanding Chinese Users' Privacy Awareness and Expectations Towards LLM-based Healthcare Consultation. [Topic: LLM] [pdf]
Adversarial Robust ViT-based Automatic Modulation Recognition in Practical Deep Learning-based Wireless Systems. [Topic: vit] [pdf]
HarmonyCloak: Making Music Unlearnable for Generative AI. [Topic: AI] [pdf]
Exploring Parent-Child Perceptions on Safety in Generative AI: Concerns, Mitigation Strategies, and Design Implications. [Topic: AI] [pdf]
Supporting Human Raters with the Detection of Harmful Content using Large Language Models. [Topic: LLM] [pdf]
Watermarking Language Models for Many Adaptive Users. [Topic: LLM] [pdf]
Benchmarking Attacks on Learning with Errors. [Topic: AEs] [pdf]
Fight Fire with Fire: Combating Adversarial Patch Attacks using Pattern-randomized Defensive Patches. [Topic: AEs] [pdf]
UnMarker: A Universal Attack on Defensive Image Watermarking. [Topic: AEs] [pdf]
My Model is Malware to You: Transforming AI Models into Malware by Abusing TensorFlow APIs. [Topic: AI] [pdf]
BAIT: Large Language Model Backdoor Scanning by Inverting Attack Target. [Topic: LLM] [pdf]
GuardAIn: Protecting Emerging Generative AI Workloads on Heterogeneous NPU. [Topic: AI] [pdf]
Comet: Accelerating Private Inference for Large Language Model by Predicting Activation Sparsity. [Topic: LLM] [pdf]
Prompt Inversion Attack against Collaborative Inference of Large Language Models. [Topic: LLM] [pdf]
The Inadequacy of Similarity-based Privacy Metrics: Privacy Attacks against ``Truly Anonymous'' Synthetic Datasets. [Topic: AEs] [pdf]
PEFTGuard: Detecting Backdoor Attacks Against Parameter-Efficient Fine-Tuning. [Topic: AEs] [pdf]
An Attack-Agnostic Defense Framework Against Manipulation Attacks under Local Differential Privacy. [Topic: AEs] [pdf]
CODEBREAKER: Dynamic Extraction Attacks on Code Language Models. [Topic: AEs] [pdf] -Changzhou Han, Zehang Deng, Wanlun Ma, Xiaogang Zhu, Jason (Minhui) Xue, Tianqing Zhu, Sheng Wen, Yang Xiang. IEEE Symposium on Security and Privacy, 2025.
Secure Transfer Learning: Training Clean Model Against Backdoor in Pre-Trained Encoder and Downstream Dataset. [Topic: backdoor] [pdf] -Yechao Zhang, Yuxuan Zhou, Tianyu Li, Minghui Li, Shengshan Hu, Wei Luo, Leo Yu Zhang. IEEE Symposium on Security and Privacy, 2025.
Make a Feint to the East While Attacking in the West: Blinding LLM-Based Code Auditors with Flashboom Attacks. [Topic: LLM] [pdf] -Xiao Li, Yue Li, Hao Wu, Yue Zhang, Kaidi Xu, Xiuzhen Cheng, Sheng Zhong, Fengyuan Xu. IEEE Symposium on Security and Privacy, 2025.
Alleviating the Fear of Losing Alignment in LLM Fine-tuning. [Topic: LLM] [pdf] -Kang Yang, Guanhong Tao, Xun Chen, Jun Xu. IEEE Symposium on Security and Privacy, 2025.
Fun-tuning: Characterizing the Vulnerability of Proprietary LLMs to Optimization-based Prompt Injection Attacks via the Fine-Tuning Interface. [Topic: LLM] [pdf] -Andrey Labunets, Nishit V. Pandya, Ashish Hooda, Xiaohan Fu, Earlence Fernandes. IEEE Symposium on Security and Privacy, 2025.
Fuzz-Testing Meets LLM-Based Agents: An Automated and Efficient Framework for Jailbreaking Text-To-Image Generation Models. [Topic: LLM] [pdf] -Yingkai Dong, Xiangtao Meng, Ning Yu, Zheng Li, Shanqing Guo. IEEE Symposium on Security and Privacy, 2025.
Understanding Users' Security and Privacy Concerns and Attitudes Towards Conversational AI Platforms. [Topic: AI] [pdf] -Mutahar Ali, Arjun Arunasalam, Habiba Farrukh. IEEE Symposium on Security and Privacy, 2025.
Securely Fine-tuning Pre-trained Encoders Against Adversarial Examples. [Topic: AEs] [pdf]
Why Does Little Robustness Help? A Further Step Towards Understanding Adversarial Transferability. [Topic: AEs] [Code][pdf]
LABRADOR: Response Guided Directed Fuzzing for Black-box IoT Devices. [Topic: AEs] [pdf]
SneakyPrompt: Jailbreaking Text-to-image Generative Models. [Topic: AEs] [Code][pdf]
SmartInv: Multimodal Learning for Smart Contract Invariant Inference.[Topic: AEs] [Code][pdf]
AVA: Inconspicuous Attribute Variation-based Adversarial Attack bypassing DeepFake Detection.[Topic: AEs] [pdf]
Robust Backdoor Detection for Deep Learning via Topological Evolution Dynamics.[Topic: Backdoor] [pdf]
MEA-Defender: A Robust Watermark against Model Extraction Attack.[Topic: AEs] [pdf]
BounceAttack: A Query-Efficient Decision-based Adversarial Attack by Bouncing into the Wild.[Topic: AEs] [pdf]
SoK: Explainable Machine Learning in Adversarial Environments.[Topic: AEs] [pdf]
Poisoned ChatGPT Finds Work for Idle Hands: Exploring Developers' Coding Practices with Insecure Suggestions from Poisoned AI Models.[Topic: AEs] [pdf]
Transferable Multimodal Attack on Vision-Language Pre-training Models.[Topic: AEs] [pdf]
Exploring the Orthogonality and Linearity of Backdoor Attacks.[Topic: Backdoor] [pdf]
OdScan: Backdoor Scanning for Object Detection Models.[Topic: Backdoor] [pdf]
Need for Speed: Taming Backdoor Attacks with Speed and Precision.[Topic: Backdoor] [pdf]
BAFFLE: Hiding Backdoors in Offline Reinforcement Learning Datasets.[Topic: Backdoor] [pdf]
DeepVenom: Persistent DNN Backdoors Exploiting Transient Weight Perturbations in Memories.[Topic: Backdoor] [Code][pdf]
LLMs Cannot Reliably Identify and Reason About Security Vulnerabilities (Yet?): A Comprehensive Evaluation, Framework, and Benchmarks.[Topic: AEs] [pdf]
BELT: Old-School Backdoor Attacks can Evade the State-of-the-Art Defense with Backdoor Exclusivity Lifting.[Topic: Backdoor] [pdf]
You Only Prompt Once: On the Capabilities of Prompt Learning on Large Language Models to Tackle Toxic Content.[Topic: AEs] [pdf]
LOKI: Large-scale Data Reconstruction Attack against Federated Learning through Model Manipulation.[Topic: AEs] [pdf]
Text-CRS: A Generalized Certified Robustness Framework against Textual Adversarial Attacks.[Topic: AEs] [pdf]
MM-BD: Post-Training Detection of Backdoor Attacks with Arbitrary Backdoor Pattern Types Using a Maximum Margin Statistic.[Topic: Backdoor] [pdf]
-BadVFL: Backdoor Attacks in Vertical Federated Learning.[Topic: Backdoor] [pdf]
-Multi-Instance Adversarial Attack on GNN-Based Malicious Domain Detection.[Topic: GNN] [pdf]
-Distribution Preserving Backdoor Attack in Self-supervised Learning.[Topic: Backdoor] [pdf]
SoK: Let the Privacy Games Begin! A Unified Treatment of Data Inference Privacy in Machine Learning.[Topic: ML] [pdf]
Analyzing Leakage of Personally Identifiable Information in Language Models.[Topic: LM] [pdf]
D-DAE: Defense-Penetrating Model Extraction Attacks.[Topic: AEs] [Code][pdf]
Disguising Attacks with Explanation-Aware Backdoors.[Topic: Backdoor] [pdf]
AI-Guardian: Defeating Adversarial Attacks using Backdoors.[Topic: Backdoor] [pdf]
BayBFed: Bayesian Backdoor Defense for Federated Learning.[Topic: Backdoor] [pdf]
edeem Myself: Purifying Backdoors in Deep Learning Models using Self Attention Distillation.[Topic: Backdoor] [pdf]
ImU: Physical Impersonating Attack for Face Recognition System with Natural Style Changes.[Topic: AEs] [pdf]
FedRecover: Recovering from Poisoning Attacks in Federated Learning using Historical Information.[Topic: AEs] [pdf]
On The Empirical Effectiveness of Unrealistic Adversarial Hardening Against Realistic Adversarial Attacks.[Topic: AEs] [pdf]
“Adversarial Examples” for Proof-of-Learning. [Topic: AEs] [pdf]
Transfer Attacks Revisited: A Large-Scale Empirical Study in Real Computer Vision Settings. [Topic:AEs] [pdf]
Bad Characters: Imperceptible NLP Attacks. [Topic: AEs] [Code][pdf]
Universal 3-Dimensional Perturbations for Black-Box Attacks on Video Recognition Systems. [Topic: AEs] [pdf]
BadEncoder: Backdoor Attacks to Pre-trained Encoders in Self-Supervised Learning. [Topic: Backdoor] [Code][pdf]
PICCOLO: Exposing Complex Backdoors in NLP Transformer Models. [Topic: Backdoor] [pdf]
Membership Inference Attacks From First Principles. [Topic: MIA] [pdf]
Back to the Drawing Board: A Critical Evaluation of Poisoning Attacks on Production Federated Learning. [Topic: PA & FL] [pdf]
Model Stealing Attacks Against Inductive Graph Neural Networks. [Topic: MSA & GNN] [pdf]
SoK: How Robust is Image Classification Deep Neural Network Watermarking? [Topic: Watermark] [pdf]
Hear "No Evil", See "Kenansville": Efficient and Transferable Black-Box Attacks on Speech Recognition and Voice Identification Systems. [Topic: AEs] [pdf]
SoK: The Faults in our ASRs: An Overview of Attacks against Automatic Speech Recognition and Speaker Identification Systems. [Topic: AEs] [pdf]
Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World Attacks. [Topic: AEs] [pdf]
Who is Real Bob? Adversarial Attacks on Speaker Recognition Systems. [Topic: AEs] [pdf]
Adversarial Watermarking Transformer: Towards Tracing Text Provenance with Data Hiding. [Topic: Watermark] [pdf]
A Method to Facilitate Membership Inference Attacks in Deep Learning Models.[Topic: ML] [pdf]
Black-box Membership Inference Attacks against Fine-tuned Diffusion Models.[Topic:Diffusion Model] [pdf]
BumbleBee: Secure Two-party Inference Framework for Large Transformers.[Topic: Transformer] [pdf]
CENSOR: Defense Against Gradient Inversion via Orthogonal Subspace Bayesian Sampling.[Topic: FL] [pdf]
CLIBE: Detecting Dynamic Backdoors in Transformer-based NLP Models.[Topic: Backdoor] [pdf]
Compiled Models, Built-In Exploits: Uncovering Pervasive Bit-Flip Attack Surfaces in DNN Executables.[Topic: DNN] [pdf]
Difference: Fencing Membership Privacy With Diffusion Models.[Topic:Diffusion Model] [pdf]
Explanation as a Watermark: Towards Harmless and Multi-bit Model Ownership Verification via Watermarking Feature Attribution.[Topic:Backdoor] [pdf]
Generating API Parameter Security Rules with LLM for API Misuse Detection.[Topic:LLM] [pdf]
Magmaw: Modality-Agnostic Adversarial Attacks on Machine Learning-Based Wireless Communication Systems.[Topic:ML] [pdf]
Passive Inference Attacks on Split Learning via Adversarial Regularization.[Topic:SL] [pdf]
Reinforcement Unlearning.[Topic:Machine unlearning] [pdf]
The Midas Touch: Triggering the Capability of LLMs for RM-API Misuse Detection.[Topic:LLM] [pdf]
The Philosopher's Stone: Trojaning Plugins of Large Language Models.[Topic:LLM] [pdf]
TrajDeleter: Enabling Trajectory Forgetting in Offline Reinforcement Learning Agents.[Topic:RL] [pdf]
Understanding Data Importance in Machine Learning Attacks: Does Valuable Data Pose Greater Harm?[Topic:ML] [pdf]
A New PPML Paradigm for Quantized Models.[Topic:PPML] [pdf]
ASGARD: Protecting On-Device Deep Neural Networks with Virtualization-Based Trusted Execution Environments.[Topic:DNN] [pdf]
BARBIE: Robust Backdoor Detection Based on Latent Separability.[Topic:Backdoor] [pdf]
Beyond Classification: Inferring Function Names in Stripped Binaries via Domain Adapted LLMs.[Topic:LLM] [pdf]
BitShield: Defending Against Bit-Flip Attacks on DNN Executables.[Topic:DNN] [pdf]
Defending Against Membership Inference Attacks on Iteratively Pruned Deep Neural Networks.[Topic:MIA] [pdf]
DLBox: New Model Training Framework for Protecting Training Data.[Topic:model training framework] [pdf]
Do We Really Need to Design New Byzantine-robust Aggregation Rules?[Topic:FL] [pdf]
DShield: Defending against Backdoor Attacks on Graph Neural Networks via Discrepancy Learning.[Topic:Backdoor] [pdf]
From Large to Mammoth: A Comparative Evaluation of Large Language Models in Vulnerability Detection.[Topic:LLM] [pdf]
I Know What You Asked: Prompt Leakage via KV-Cache Sharing in Multi-Tenant LLM Serving.[Topic:LLM] [pdf]
I know what you MEME! Understanding and Detecting Harmful Memes with Multimodal Large Language Models.[Topic:MLLM] [pdf]
IsolateGPT: An Execution Isolation Architecture for LLM-Based Agentic Systems.[Topic:LLM] [pdf]
L-HAWK: A Controllable Physical Adversarial Patch Against a Long-Distance Target.[Topic:physical adversarial patch attacks] [pdf]
LADDER: Multi-Objective Backdoor Attack via Evolutionary Algorithm.[Topic:Backdoor] [pdf]
LLMPirate: LLMs for Black-box Hardware IP Piracy.[Topic:LLM] [pdf]
PBP: Post-training Backdoor Purification for Malware Classifiers.[Topic:Backdoor] [pdf]
Privacy-Preserving Data Deduplication for Enhancing Federated Learning of Language Models.[Topic:FL] [pdf]
Probe-Me-Not: Protecting Pre-trained Encoders from Malicious Probing.[Topic:transfer learning] [pdf]
PropertyGPT: LLM-driven Formal Verification of Smart Contracts through Retrieval-Augmented Property Generation.[Topic:LLM] [pdf]
RAIFLE: Reconstruction Attacks on Interaction-based Federated Learning with Adversarial Data Manipulation.[Topic:FL] [pdf]
SafeSplit: A Novel Defense Against Client-Side Backdoor Attacks in Split Learning.[Topic:Backdoor] [pdf]
Safety Misalignment Against Large Language Models.[Topic:LLM] [pdf]
Scale-MIA: A Scalable Model Inversion Attack against Secure Federated Learning via Latent Space Reconstruction.[Topic:MIA&FL] [pdf]
SHAFT: Secure, Handy, Accurate and Fast Transformer Inference.[Topic:transformer-based machine learning] [pdf]
Try to Poison My Deep Learning Data? Nowhere to Hide Your Trajectory Spectrum![Topic:DaaS] [pdf]
URVFL: Undetectable Data Reconstruction Attack on Vertical Federated Learning.[Topic:VFL] [pdf]
VoiceRadar: Voice Deepfake Detection using Micro-Frequency and Compositional Analysis.[Topic:ML] [pdf]
Attributions for ML-based ICS Anomaly Detection: From Theory to Practice.[Topic:ML] [pdf]
Compensating Removed Frequency Components: Thwarting Voice Spectrum Reduction Attacks.[Topic:ASR] [pdf]
Crafter: Facial Feature Crafting against Inversion-based Identity Theft on Deep Models.[Topic:防御攻击] [pdf]
CrowdGuard: Federated Backdoor Detection in Federated Learning.[Topic:Backdoor] [pdf]
Enhance Stealthiness and Transferability of Adversarial Attacks with Class Activation Mapping Ensemble Attack.[Topic:对抗攻击] [pdf]
GNNIC: Finding Long-Lost Sibling Functions with Abstract Similarity.[Topic:GNN] [pdf]
LiDAR Spoofing Meets the New-Gen: Capability Improvements, Broken Assumptions, and New Attack Strategies.[Topic:欺骗攻击] [pdf]
LMSanitator: Defending Prompt-Tuning Against Task-Agnostic Backdoors.[Topic:Backdoor] [pdf]
Low-Quality Training Data Only? A Robust Framework for Detecting Encrypted Malicious Network Traffic.[Topic:数据集] [pdf]
MPCDiff: Testing and Repairing MPC-Hardened Deep Learning Models.[Topic:MPC-Hardened] [pdf]
On Precisely Detecting Censorship Circumvention in Real-World Networks.[Topic:Censorship Circumvention] [pdf]
Overconfidence is a Dangerous Thing: Mitigating Membership Inference Attacks by Enforcing Less Confident Prediction.[Topic:MIA] [pdf]
SigmaDiff: Semantics-Aware Deep Graph Matching for Pseudocode Diffing.[Topic:DNN] [pdf]
Transpose Attack: Stealing Datasets with Bidirectional Training.[Topic:数据集窃取] [pdf]
A Duty to Forget, a Right to be Assured? Exposing Vulnerabilities in Machine Unlearning Services.[Topic:MLaaS] [pdf]
ActiveDaemon: Unconscious DNN Dormancy and Waking Up via User-specific Invisible Token.[Topic:Watermark] [pdf]
Automatic Adversarial Adaption for Stealthy Poisoning Attacks in Federated Learning.[Topic:FL] [pdf]
CamPro: Camera-based Anti-Facial Recognition.[Topic:AFR] [pdf]
DeepGo: Predictive Directed Greybox Fuzzing.[Topic:RL] [pdf]
DeGPT: Optimizing Decompiler Output with LLM.[Topic:LLM] [pdf]
DEMASQ: Unmasking the ChatGPT Wordsmith.[Topic:LLM] [pdf]
Don't Interrupt Me - A Large-Scale Study of On-Device Permission Prompt Quieting in Chrome.[Topic:ML] [pdf]
DorPatch: Distributed and Occlusion-Robust Adversarial Patch to Evade Certifiable Defenses.[Topic:DNN] [pdf]
DRAINCLoG: Detecting Rogue Accounts with Illegally-obtained NFTs using Classifiers Learned on Graphs.[Topic:DNN] [pdf]
Flow Correlation Attacks on Tor Onion Service Sessions with Sliding Subset Sum.[Topic:machine learning classifiers] [pdf]
FreqFed: A Frequency Analysis-Based Approach for Mitigating Poisoning Attacks in Federated Learning.[Topic:FL] [pdf]
Gradient Shaping: Enhancing Backdoor Attack Against Reverse Engineering.[Topic:Backdoor] [pdf]
GraphGuard: Detecting and Counteracting Training Data Misuse in Graph Neural Networks.[Topic:GNN] [pdf]
Group-based Robustness: A General Framework for Customized Robustness in the Real World.[Topic:规避攻击] [pdf]
Improving the Robustness of Transformer-based Large Language Models with Dynamic Attention.[Topic:LLM] [pdf]
Large Language Model guided Protocol Fuzzing.[Topic:LLM] [pdf]
MASTERKEY: Automated Jailbreaking of Large Language Model Chatbots.[Topic:LLM] [pdf]
Parrot-Trained Adversarial Examples: Pushing the Practicality of Black-Box Audio Attacks against Speaker Recognition Models.[Topic:AE] [pdf]
Pencil: Private and Extensible Collaborative Learning without the Non-Colluding Assumption.[Topic:Collaborative Learning] [pdf]
SLMIA-SR: Speaker-Level Membership Inference Attacks against Speaker Recognition Systems.[Topic:MIA] [pdf]
Sneaky Spikes: Uncovering Stealthy Backdoor Attacks in Spiking Neural Networks with Neuromorphic Data.[Topic:Backdoor] [pdf]
SSL-WM: A Black-Box Watermarking Approach for Encoders Pre-trained by Self-Supervised Learning.[Topic:水印] [pdf]
TextGuard: Provable Defense against Backdoor Attacks on Text Classification.[Topic:Backdoor] [pdf]
You Can Use But Cannot Recognize: Preserving Visual Privacy in Deep Neural Networks.[Topic:DNN] [pdf]
Fusion: Efficient and Secure Inference Resilient to Malicious Servers. [Topic: MLaaS] [pdf]
Machine Unlearning of Features and Labels. [Topic: Machine-Unlearning] [pdf]
PPA: Preference Profiling Attack Against Federated Learning. [Topic: FL] [pdf]
RoVISQ: Reduction of Video Service Quality via Adversarial Attacks on Deep Learning-based Video Compression. [Topic: AEs] [pdf]
Securing Federated Sensitive Topic Classification against Poisoning Attacks. [Topic: FL] [pdf]
The “Beatrix” Resurrections: Robust Backdoor Detection via Gram Matrices. [Topic: Backdoor] [pdf]
Adversarial Robustness for Tabular Data through Cost and Utility Awareness. [Topic: AEs] [pdf]
Backdoor Attacks Against Dataset Distillation. [Topic: Backdoor] [pdf]
BEAGLE: Forensics of Deep Learning Backdoor Attack for Better Defense. [Topic: Backdoor] [pdf]
Focusing on Pinocchio's Nose: A Gradients Scrutinizer to Thwart Split-Learning Hijacking Attacks Using Intrinsic Attributes. [Topic: SL] [pdf]
REaaS: Enabling Adversarially Robust Downstream Classifiers via Robust Encoder as a Service. [Topic: AEs] [pdf]
DeepSight: Mitigating Backdoor Attacks in Federated Learning Through Deep Model Inspection. [Topic: Backdoor] [pdf]
FedCRI: Federated Mobile Cyber-Risk Intelligence. [Topic: FL] [pdf]
Get a Model! Model Hijacking Attack Against Machine Learning Models. [Topic: Model-Hijacking] [pdf]
Local and Central Differential Privacy for Robustness and Privacy in Federated Learning. [Topic: FL] [pdf]
Property Inference Attacks Against GANs. [Topic: IA & GAN] [pdf]
ATTEQ-NN: Attention-based QoE-aware Evasive Backdoor Attacks. [Topic: Backdoor] [pdf]
Fooling the Eyes of Autonomous Vehicles: Robust Physical Adversarial Examples Against Traffic Sign Recognition Systems. [Topic: AEs] [pdf]
MIRROR: Model Inversion for Deep Learning Network with High Fidelity. [Topic: MIA] [pdf]
RamBoAttack: A Robust and Query Efficient Deep Neural Network Decision Exploit. [Topic: AEs] [pdf]
Data Poisoning Attacks to Deep Learning Based Recommender Systems. [Topic: PAs] [pdf]
FLTrust: Byzantine-robust Federated Learning via Trust Bootstrapping. [Topic: PA & FL] [pdf]
Manipulating the Byzantine: Optimizing Model Poisoning Attacks and Defenses for Federated Learning. [Topic: PA & FL] [pdf]
Practical Blind Membership Inference Attack via Differential Comparisons. [Topic: MIA] [pdf]
POSEIDON: Privacy-Preserving Federated Neural Network Learning. [Topic: FL] [pdf]
AttackGNN: Red-Teaming GNNs in Hardware Security Using Reinforcement Learning.[Topic:GNN&RL] [pdf]
INSIGHT: Attacking Industry-Adopted Learning Resilient Logic Locking Techniques Using Explainable Graph Neural Network.[Topic:ML] [pdf]
FAMOS: Robust Privacy-Preserving Authentication on Payment Apps via Federated Multi-Modal Contrastive Learning.[Topic:FL] [pdf]
Efficient Privacy Auditing in Federated Learning.[Topic:FL] [pdf]
Defending Against Data Reconstruction Attacks in Federated Learning: An Information Theory Approach.[Topic:FL] [pdf]
Lotto: Secure Participant Selection against Adversarial Servers in Federated Learning.[Topic:FL] [pdf]
KnowPhish: Large Language Models Meet Multimodal Knowledge Graphs for Enhancing Reference-Based Phishing Detection.[Topic:LLM for Security] [pdf]
Exploring ChatGPT's Capabilities on Vulnerability Management.[Topic:LLM for Security] [pdf]
Large Language Models for Code Analysis: Do LLMs Really Do Their Job?[Topic:LLM for Security] [pdf]
PentestGPT: Evaluating and Harnessing Large Language Models for Automated Penetration Testing.[Topic:LLM for Security] [pdf]
Fuzzing BusyBox: Leveraging LLM and Crash Reuse for Embedded Bug Unearthing.[Topic:LLM] [pdf]
DNN-GP: Diagnosing and Mitigating Model's Faults Using Latent Concepts.[Topic:DNN] [pdf]
Yes, One-Bit-Flip Matters! Universal DNN Model Inference Depletion with Runtime Code Fault Injection.[Topic:DNN] [pdf]
Tossing in the Dark: Practical Bit-Flipping on Gray-box Deep Neural Networks for Runtime Trojan Injection.[Topic:DNN] [pdf]
Forget and Rewire: Enhancing the Resilience of Transformer-based Models against Bit-Flip Attacks.[Topic:DNN] [pdf]
Automated Large-Scale Analysis of Cookie Notice Compliance.[Topic:ML for Security] [pdf]
Detecting and Mitigating Sampling Bias in Cybersecurity with Unlabeled Data.[Topic:ML for Security] [pdf]
An LLM-Assisted Easy-to-Trigger Backdoor Attack on Code Completion Models: Injecting Disguised Vulnerabilities against Strong Detection.[Topic:LLM] [pdf]
REMARK-LLM: A Robust and Efficient Watermarking Framework for Generative Large Language Models.[Topic:LLM] [pdf]
Formalizing and Benchmarking Prompt Injection Attacks and Defenses.[Topic:LLM] [pdf]
Instruction Backdoor Attacks Against Customized LLMs.[Topic:LLM] [pdf]
AutoFHE: Automated Adaption of CNNs for Efficient Evaluation over FHE.[Topic:CNN] [pdf]
Fast and Private Inference of Deep Neural Networks by Co-designing Activation Functions.[Topic:MLaaS] [pdf]
OblivGNN: Oblivious Inference on Transductive and Inductive Graph Neural Network.[Topic:GNN] [pdf]
MD-ML: Super Fast Privacy-Preserving Machine Learning for Malicious Security with a Dishonest Majority.[Topic:PPML] [pdf]
Accelerating Secure Collaborative Machine Learning with Protocol-Aware RDMA.[Topic:SCML] [pdf]
Did the Neurons Read your Book? Document-level Membership Inference for Large Language Models.[Topic:LLM] [pdf]
MIST: Defending Against Membership Inference Attacks Through Membership-Invariant Subspace Training.[Topic:MI attack] [pdf]
Neural Network Semantic Backdoor Detection and Mitigation: A Causality-Based Approach.[Topic:Backdoor] [pdf]
On the Difficulty of Defending Contrastive Learning against Backdoor Attacks.[Topic:Backdoor] [pdf]
Mudjacking: Patching Backdoor Vulnerabilities in Foundation Models.[Topic:Backdoor] [pdf]
Xplain: Analyzing Invisible Correlations in Model Explanation.[Topic:Backdoor] [pdf]
Verify your Labels! Trustworthy Predictions and Datasets via Confidence Scores.[Topic:Backdoor] [pdf]
More Simplicity for Trainers, More Opportunity for Attackers: Black-Box Attacks on Speaker Recognition Systems by Inferring Feature Extractor.[Topic:AE] [pdf]
Adversarial Illusions in Multi-Modal Embeddings.[Topic:Multi-modal embeddings] [pdf]
Splitting the Difference on Adversarial Training.[Topic:Adversarial Attack Defense] [pdf]
Machine Learning needs Better Randomness Standards: Randomised Smoothing and PRNG-based attacks.[Topic:Adversarial Attack Defense] [pdf]
Lurking in the shadows: Unveiling Stealthy Backdoor Attacks against Personalized Federated Learning.[Topic:Backdoor and Federated Learning] [pdf]
ACE: A Model Poisoning Attack on Contribution Evaluation Methods in Federated Learning.[Topic:Backdoor and Federated Learning] [pdf]
BackdoorIndicator: Leveraging OOD Data for Proactive Backdoor Detection in Federated Learning.[Topic:Backdoor and Federated Learning] [pdf]
UBA-Inf: Unlearning Activated Backdoor Attack with Influence-Driven Camouflage.[Topic:Backdoor and Federated Learning] [pdf]
LLM-Fuzzer: Scaling Assessment of Large Language Model Jailbreaks.[Topic:LLM Jailbreaking] [pdf]
Don't Listen To Me: Understanding and exploring jailbreak prompts of large language models.[Topic:LLM Jailbreaking] [pdf]
Making Them Ask and Answer: Jailbreaking Large Language Models in Few Queries via Disguise and Reconstruction.[Topic:LLM Jailbreaking] [pdf]
SoK: All You Need to Know About On-Device ML Model Extraction - The Gap Between Research and Practice.[Topic:Watermark] [pdf]
Unveiling the Secrets without Data: Can Graph Neural Networks Be Exploited through Data-Free Model Extraction Attacks?[Topic:GNN] [pdf]
ClearStamp: A Human-Visible and Robust Model-Ownership Proof based on Transposed Model Training.[Topic:Watermark] [pdf]
DeepEclipse: How to Break White-Box DNN-Watermarking Schemes.[Topic:Watermark] [pdf]
Deciphering Textual Authenticity: A Generalized Strategy through the Lens of Large Language Semantics for Detecting Human vs. Machine-Generated Text.[Topic:LLM] [pdf]
How Does a Deep Learning Model Architecture Impact Its Privacy? A Comprehensive Study of Privacy Attacks on CNNs and Transformers.[Topic:Privacy Attacks] [pdf]
FaceObfuscator: Defending Deep Learning-based Privacy Attacks with Gradient Descent-resistant Features in Face Recognition.[Topic:Privacy Attacks] [pdf]
Hijacking Attacks against Neural Network by Analyzing Training Data.[Topic:Hijacking Attacks] [pdf]
Information Flow Control in Machine Learning through Modular Model Architecture.[Topic:ML] [pdf]
Devil in the Room: Triggering Audio Backdoors in the Physical World.[Topic:Physical Adversarial Attacks] [pdf]
FraudWhistler: A Resilient, Robust and Plug-and-play Adversarial Example Detection Method for Speaker Recognition.[Topic:AE] [pdf]
EaTVul: ChatGPT-based Evasion Attack Against Software Vulnerability Detection.[Topic:Evasion Attack] [pdf]
“Security is not my field, I’m a stats guy”: A Qualitative Root Cause Analysis of Barriers to Adversarial Machine Learning Defenses in Industry. [Topic: AEs] [pdf]
A Data-free Backdoor Injection Approach in Neural Networks. [Topic: Backdoor] [pdf]
A Plot is Worth a Thousand Words: Model Information Stealing Attacks via Scientific Plots. [Topic: MSA] [pdf]
Aegis: Mitigating Targeted Bit-flip Attacks against Deep Neural Networks. [Topic: BFA] [pdf]
Black-box Adversarial Example Attack towards FCG Based Android Malware Detection under Incomplete Feature Information. [Topic: AEs] [pdf]
CAPatch: Physical Adversarial Patch against Image Captioning Systems. [Topic: AEs] [pdf]
DiffSmooth: Certifiably Robust Learning via Diffusion Models and Local Smoothing. [Topic: AEs] [pdf]
Every Vote Counts: Ranking-Based Training of Federated Learning to Resist Poisoning Attacks. [Topic: PA & FL] [pdf]
Exorcising "Wraith": Protecting LiDAR-based Object Detector in Automated Driving System from Appearing Attacks. [Topic: Appearing-Attack] [pdf]
Fine-grained Poisoning Attack to Local Differential Privacy Protocols for Mean and Variance Estimation. [Topic: DP] [pdf]
FreeEagle: Detecting Complex Neural Trojans in Data-Free Cases. [Topic: Backdoor] [pdf]
GAP: Differentially Private Graph Neural Networks with Aggregation Perturbation. [Topic: DP & GNN] [pdf]
Lost at C: A User Study on the Security Implications of Large Language Model Code Assistants. [Topic: LLM] [pdf]
Meta-Sift: How to Sift Out a Clean Subset in the Presence of Data Poisoning?. [Topic: PA] [pdf]
No more Reviewer #2: Subverting Automatic Paper-Reviewer Assignment using Adversarial Learning. [Topic: AEs] [pdf]
PELICAN: Exploiting Backdoors of Naturally Trained Deep Learning Models In Binary Code Analysis. [Topic: Backdoor] [pdf]
PrivateFL: Accurate, Differentially Private Federated Learning via Personalized Data Transformation. [Topic: DP & FL] [pdf]
Rethinking White-Box Watermarks on Deep Learning Models under Neural Structural Obfuscation. [Topic: Watermark] [pdf]
X-Adv: Physical Adversarial Object Attacks against X-ray Prohibited Item Detection. [Topic: AEs] [pdf]
TPatch: A Triggered Physical Adversarial Patch. [Topic: AEs] [pdf]
UnGANable: Defending Against GAN-based Face Manipulation. [Topic: Deepfake] [pdf]
Squint Hard Enough: Attacking Perceptual Hashing with Adversarial Machine Learning. [Topic: AEs] [pdf]
The Space of Adversarial Strategies. [Topic: AEs] [pdf]
That Person Moves Like A Car: Misclassification Attack Detection for Autonomous Systems Using Spatiotemporal Consistency. [Topic: AEs] [pdf]
NeuroPots: Realtime Proactive Defense against Bit-Flip Attacks in Neural Networks. [Topic: BFA] [pdf]
URET: Universal Robustness Evaluation Toolkit (for Evasion). [Topic: AEs] [pdf]
SMACK: Semantically Meaningful Adversarial Audio Attack. [Topic: AEs] [pdf]
Gradient Obfuscation Gives a False Sense of Security in Federated Learning. [Topic: FL] [pdf]
Fairness Properties of Face Recognition and Obfuscation Systems. [Topic: AEs] [pdf]
PCAT: Functionality and Data Stealing from Split Learning by Pseudo-Client Attack. [Topic: SL] [pdf]
ML-Doctor: Holistic Risk Assessment of Inference Attacks Against Machine Learning Models. [Topic: MIA] [pdf]
Blacklight: Scalable Defense for Neural Networks against Query-Based Black-Box Attacks. [Topic: AEs] [pdf]
AutoDA: Automated Decision-based Iterative Adversarial Attacks. [Topic: AEs] [pdf]
Poison Forensics: Traceback of Data Poisoning Attacks in Neural Networks. [Topic: PA] [pdf]
Teacher Model Fingerprinting Attacks Against Transfer Learning. [Topic: Fingerprinting] [pdf]
Hidden Trigger Backdoor Attack on NLP Models via Linguistic Style Manipulation. [Topic: Backdoor] [pdf]
PoisonedEncoder: Poisoning the Unlabeled Pre-training Data in Contrastive Learning. [Topic: PA] [pdf]
Pool Inference Attacks on Local Differential Privacy: Quantifying the Privacy Guarantees of Apple's Count Mean Sketch in Practice. [Topic: IA & DP] [pdf]
PatchCleanser: Certifiably Robust Defense against Adversarial Patches for Any Image Classifier. [Topic: AEs] [pdf]
Exploring the Security Boundary of Data Reconstruction via Neuron Exclusivity Analysis. [Topic: DRA] [pdf]
Poisoning Attacks to Local Differential Privacy Protocols for Key-Value Data. [Topic: PA & DP] [pdf]
Communication-Efficient Triangle Counting under Local Differential Privacy. [Topic: DP] [pdf]
Security Analysis of Camera-LiDAR Fusion Against Black-Box Attacks on Autonomous Vehicles. [Topic: AEs & AV] [pdf]
Transferring Adversarial Robustness Through Robust Representation Matching. [Topic: AEs] [pdf]
Seeing is Living? Rethinking the Security of Facial Liveness Verification in the Deepfake Era. [Topic: Deepfake] [pdf]
On the Necessity of Auditable Algorithmic Definitions for Machine Unlearning. [Topic: Machine-Unlearning] [pdf]
Mitigating Membership Inference Attacks by Self-Distillation Through a Novel Ensemble Architecture. [Topic: MIA] [pdf]
Membership Inference Attacks and Defenses in Neural Network Pruning. [Topic: MIA] [pdf]
Efficient Differentially Private Secure Aggregation for Federated Learning via Hardness of Learning with Errors. [Topic: DP & FL] [pdf]
Who Are You (I Really Wanna Know)? Detecting Audio DeepFakes Through Vocal Tract Reconstruction. [Topic: Deepfake] [pdf]
Are Your Sensitive Attributes Private? Novel Model Inversion Attribute Inference Attacks on Classification Models. [Topic: MIAI] [pdf]
FLAME: Taming Backdoors in Federated Learning. [Topic: FL & Backdoor] [pdf]
Synthetic Data – Anonymisation Groundhog Day. [Topic: Synthetic-Data] [pdf]
On the Security Risks of AutoML. [Topic: NAS] [pdf]
Inference Attacks Against Graph Neural Networks. [Topic: IA & GNN] [pdf]
Adversarial Detection Avoidance Attacks: Evaluating the robustness of perceptual hashing-based client-side scanning. [Topic: AEs] [pdf]
Label Inference Attacks Against Vertical Federated Learning. [Topic: IA & FL] [pdf]
Rolling Colors: Adversarial Laser Exploits against Traffic Light Recognition. [Topic: AEs] [pdf]
PatchGuard: A Provably Robust Defense against Adversarial Patches via Small Receptive Fields and Masking. [Topic: AEs] [pdf]
PrivSyn: Differentially Private Data Synthesis. [Topic: DP] [pdf]
Muse: Secure Inference Resilient to Malicious Clients. [Topic: IA] [pdf]
Systematic Evaluation of Privacy Risks of Machine Learning Models. [Topic: IA] [pdf]
Explanation-Guided Backdoor Poisoning Attacks Against Malware Classifiers. [Topic: Backdoor] [pdf]
Cerebro: A Platform for Multi-Party Cryptographic Collaborative Learning. [Topic: MPC] [pdf]
T-Miner: A Generative Approach to Defend Against Trojan Attacks on DNN-based Text Classification. [Topic: Backdoor] [pdf]
Defeating DNN-Based Traffic Analysis Systems in Real-Time With Blind Adversarial Perturbations. [Topic: AEs] [pdf]
Data Poisoning Attacks to Local Differential Privacy Protocols. [Topic: PA & DP] [pdf]
How to Make Private Distributed Cardinality Estimation Practical, and Get Differential Privacy for Free. [Topic: DP] [pdf]
SLAP: Improving Physical Adversarial Examples with Short-Lived Adversarial Perturbations. [Topic: AEs] [pdf]
WaveGuard: Understanding and Mitigating Audio Adversarial Examples. [Topic: AEs] [pdf]
Graph Backdoor. [Topic: Backdoor] [pdf]
Entangled Watermarks as a Defense against Model Extraction. [Topic: Watermark] [pdf]
Too Good to Be Safe: Tricking Lane Detection in Autonomous Driving with Crafted Perturbations. [Topic: AEs] [pdf]
Fantastic Four: Honest-Majority Four-Party Secure Computation With Malicious Security. [Topic: MPC] [pdf]
Locally Differentially Private Analysis of Graph Statistics. [Topic: DP] [pdf]
Demon in the Variant: Statistical Analysis of DNNs for Robust Backdoor Contamination Detection. [Topic: Backdoor] [pdf]
Stealing Links from Graph Neural Networks. [Topic: GNN] [pdf]
Adversarial Policy Training against Deep Reinforcement Learning. [Topic: AEs & RL] [pdf]
Moderator: Moderating Text-to-Image Diffusion Models through Fine-grained Context-based Policies. [Topic: ML and Security: Large Language Models] [pdf]
Training Robust ML-based Raw-Binary Malware Detectors in Hours, not Months. [Topic: Verification, Secure Architectures, and Network Security] [pdf]
TREC: APT Tactic / Technique Recognition via Few-Shot Provenance Subgraph Learning. [Topic: Verification, Secure Architectures, and Network Security] [pdf]
SAFARI: Speech-Associated Facial Authentication for AR/VR Settings via Robust VIbration Signatures [Topic: Verification, Secure Architectures, and Network Security] [pdf]
KnowGraph: Knowledge-Enabled Anomaly Detection via Logical Reasoning on Graph Data. [Topic: Verification, Secure Architectures, and Network Security] [pdf] -Andy Zhou, Xiaojun Xu, Ramesh Raghunathan, Alok Lal, Xinze Guan, Bin Yu, Bo Li. ACM CCS, 2024.
Understanding Implosion in Text-to-Image Generative Models. [Topic: ML and Security: Large Language Models] [pdf]
Legilimens: Practical and Unified Content Moderation for Large Language Model Services. [Topic: ML and Security: Large Language Models] [pdf]
Optimization-based Prompt Injection Attack to LLM-as-a-Judge. [Topic: ML and Security: Machine Learning Attacks] [pdf]
PromSec: Prompt Optimization for Secure Generation of Functional Source Code with Large Language Models (LLMs). [Topic: ML and Security: Generative Models] [pdf]
Certifiable Black-Box Attacks with Randomized Adversarial Examples: Breaking Defenses with Provable Confidence [Topic: ML and Security: Machine Learning Attacks] [pdf]
Phantom: Untargeted Poisoning Attacks on Semi-Supervised Learning (Full Version) [Topic: ML and Security: Machine Learning Attacks] [pdf]
Zero-Query Adversarial Attack on Black-box Automatic Speech Recognition Systems [Topic: ML and Security: Machine Learning Attacks] [pdf]
SUB-PLAY: Adversarial Policies against Partially Observed Multi-Agent Reinforcement Learning Systems [Topic: ML and Security: Machine Learning Attacks] [pdf]
Optimization-based Prompt Injection Attack to LLM-as-a-Judge [Topic: ML and Security: Machine Learning Attacks] [pdf]
Neural Dehydration: Effective Erasure of Black-box Watermarks from DNNs with Limited Data [Topic: ML and Security: Machine Learning Attacks] [pdf]
Is Difficulty Calibration All We Need? Towards More Practical Membership Inference Attacks [Topic: Blockchain & Distributed Systems: Blockchain Attacks] [pdf]
Evaluations of Machine Learning Privacy Defenses are Misleading [Topic: Blockchain & Distributed Systems: Blockchain Attacks] [pdf]
A Unified Membership Inference Method for Visual Self-supervised Encoder via Part-aware Capability [Topic: Blockchain & Distributed Systems: Blockchain Attacks] [pdf]
The Janus Interface: How Fine-Tuning in Large Language Models Amplifies the Privacy Risks [Topic: Blockchain & Distributed Systems: Blockchain Attacks] [pdf]
A General Framework for Data-Use Auditing of ML Models [Topic: Blockchain & Distributed Systems: Blockchain Attacks] [pdf]
Dye4AI: Assuring Data Boundary on Generative AI Services [Topic: ML and Security: Generative Models] [pdf]
I Don't Know You, But I Can Catch You: Real-Time Defense against Diverse Adversarial Patches for Object Detectors [Topic: Privacy and Anonymity: Privacy Attacks Meet ML] [pdf]
AirGapAgent: Protecting Privacy-Conscious Conversational Agents [Topic: Privacy and Anonymity: Privacy Attacks Meet ML] [pdf]
ERASER: Machine Unlearning in MLaaS via an Inference Serving-Aware Approach [Topic: Privacy and Anonymity: Privacy Attacks Meet ML] [pdf]
NeuJeans: Private Neural Network Inference with Joint Optimization of Convolution and FHE Bootstrapping [Topic: Usability and Measurement: Phishing, Deepfakes, and Other Risks] [pdf]
Ents: An Efficient Three-party Training Framework for Decision Trees by Communication Optimization [Topic: Usability and Measurement: Phishing, Deepfakes, and Other Risks] [pdf]
zkLLM: Zero Knowledge Proofs for Large Language Models [Topic: Usability and Measurement: Phishing, Deepfakes, and Other Risks] [pdf]
Fisher Information guided Purification against Backdoor Attacks [Topic: ML and Security: Model Security] [pdf]
BadMerging: Backdoor Attacks Against Model Merging [Topic: ML and Security: Model Security] [pdf]
SafeGen: Mitigating Sexually Explicit Content Generation in Text-to-Image Models [Topic: Usability and Measurement: AI Risks] [pdf]
Image-Perfect Imperfections: Safety, Bias, and Authenticity in the Shadow of Text-To-Image Model Evolution [Topic: Usability and Measurement: AI Risks] [pdf]
Decoding the Secrets of Machine Learning in Malware Classification: A Deep Dive into Datasets, Feature Extraction, and Model Performance [Topic: Machine Learning Applications I] [pdf]
Efficient Query-Based Attack against ML-Based Android Malware Detection under Zero Knowledge Setting [Topic: Machine Learning Applications I] [pdf]
Your Battery Is a Blast! Safeguarding Against Counterfeit Batteries with Authentication [Topic: Machine Learning Applications I] [pdf]
Narcissus: A Practical Clean-Label Backdoor Attack with Limited Information [Topic: Machine Learning Attacks I] [pdf]
Stateful Defenses for Machine Learning Models Are Not Yet Secure Against Black-box Attacks [Topic: Machine Learning Attacks I] [pdf]
Evading Watermark based Detection of AI-Generated Content [Topic: Machine Learning Attacks II] [pdf]
Verifiable Learning for Robust Tree Ensembless [Topic: Language Models & Verification] [pdf]
Large Language Models for Code: Security Hardening and Adversarial Testing [Topic: Language Models & Verification] [pdf]
Characterizing and Detecting Non-Consensual Photo Sharing on Social Networks. [Topic: Non-consensual Sharing] [pdf]
DPIS: An Enhanced Mechanism for Differentially Private SGD with Importance Sampling. [Topic: DP & DNN] [pdf]
DriveFuzz: Discovering Autonomous Driving Bugs through Driving Quality-Guided Fuzzing. [Topic: AD] [pdf]
EIFFeL: Ensuring Integrity for Federated Learning. [Topic: FL] [pdf]
Eluding Secure Aggregation in Federated Learning via Model Inconsistency. [Topic: FL] [pdf]
Enhanced Membership Inference Attacks against Machine Learning Models. [Topic: MI] [pdf]
Feature Inference Attack on Shapley Values. [Topic: MLaaS] [pdf]
Graph Unlearning. [Topic: Machine Unlearning] [pdf]
Group Property Inference Attacks Against Graph Neural Networks. [Topic: GNNs] [pdf]
Harnessing Perceptual Adversarial Patches for Crowd Counting. [Topic: AEs] [pdf]
Training Set Debugging Using Trusted Items. [Topic: ML] [pdf]
LPGNet: Link Private Graph Networks for Node Classification. [Topic: GCNs & DP] [pdf]
LoneNeuron: a Highly-Effective Feature-Domain Neural Trojan Using Invisible and Polymorphic Watermarks. [Topic: DNNs & Watermark] [pdf]
Membership Inference Attacks and Generalization: A Causal Perspective. [Topic: MI] [pdf]
Membership Inference Attacks by Exploiting Loss Trajectory. [Topic: MI] [pdf]
Order-Disorder: Imitation Adversarial Attacks for Black-box Neural Ranking Models. [Topic: IR] [pdf]
Perception-Aware Attack: Creating Adversarial Music via Reverse-Engineering Human Perception. [Topic: AEs] [pdf]
Physical Hijacking Attacks against Object Trackers. [Topic: AV] [pdf]
Post-breach Recovery: Protection against White-box Adversarial Examples for Leaked DNN Models. [Topic: DNN] [pdf]
QuerySnout: Automating the Discovery of Attribute Inference Attacks against Query-Based Systems. [Topic: QBS] [pdf]
SSLGuard: A Watermarking Scheme for Self-supervised Learning Pre-trained Encoders. [Topic: Watermark] [pdf]
SpecPatch: Human-In-The-Loop Adversarial Audio Spectrogram Patch Attack on Speech Recognition. [Topic: AEs] [pdf]
StolenEncoder: Stealing Pre-trained Encoders in Self-supervised Learning. [Topic: EaaS] [pdf]
Truth Serum: Poisoning Machine Learning Models to Reveal Their Secrets. [Topic: ML] [pdf]
Understanding Real-world Threats to Deep Learning Models in Android Apps. [Topic: AEs] [pdf]
When Evil Calls: Targeted Adversarial Voice over IP Network. [Topic: AEs] [pdf]
Why So Toxic? Measuring and Triggering Toxic Behavior in Open-Domain Chatbots. [Topic: AEs] [pdf]
"Is your explanation stable?": A Robustness Evaluation Framework for Feature Attribution. [Topic: NNs] [pdf]
Cert-RNN: Towards Certifying the Robustness of Recurrent Neural Networks. [Topic: AEs] [pdf]
AHEAD: Adaptive Hierarchical Decomposition for Range Query under Local Differential Privacy. [Topic: LDP] [pdf]
Unleashing the Tiger: Inference Attacks on Split Learning. [Topic: SL] [pdf]
TableGAN-MCA: Evaluating Membership Collisions of GAN-Synthesized Tabular Data Releasing. [Topic: GAN] [pdf]
"I need a better description": An Investigation Into User Expectations For Differential Privacy. [Topic: DP] [pdf]
Locally Private Graph Neural Networks. [Topic: GNNs] [pdf]
A One-Pass Distributed and Private Sketch for Kernel Sums with Applications to Machine Learning at Scale. [Topic: DP] [pdf]
On the Robustness of Domain Constraints. [Topic: AEs] [pdf]
Membership Leakage in Label-Only Exposures. [Topic: MI] [pdf]
Hidden Backdoors in Human-Centric Language Models. [Topic: Backdoor] [pdf]
DataLens: Scalable Privacy Preserving Training via Gradient Compression and Aggregation. [Topic: DP] [pdf]
DeepAID: Interpreting and Improving Deep Learning-based Anomaly Detection in Security Applications. [Topic: DL] [pdf]
Honest-but-Curious Nets: Sensitive Attributes of Private Inputs Can Be Secretly Coded into the Classifiers' Outputs. [Topic: Classifer] [pdf]
Differential Privacy for Directional Data. [Topic: DP] [pdf]
"Hello, It's Me": Deep Learning-based Speech Synthesis Attacks in the Real World. [Topic: Speech Synthesis Attack] [pdf]
EncoderMI: Membership Inference against Pre-trained Encoders in Contrastive Learning. [Topic: MI] [pdf]
Subpopulation Data Poisoning Attacks. [Topic: Poisoning Attack] [pdf]
Continuous Release of Data Streams under both Centralized and Local Differential Privacy. [Topic: DP] [pdf]
When Machine Unlearning Jeopardizes Privacy. [Topic: MI] [pdf]
DetectorGuard: Provably Securing Object Detectors against Localized Patch Hiding Attacks. [Topic: AEs] [pdf]
I Can See the Light: Attacks on Autonomous Vehicles Using Invisible Lights. [Topic: AV] [pdf]
Backdoor Pre-trained Models Can Transfer to All. [Topic: Backdoor] [pdf]
Quantifying and Mitigating Privacy Risks of Contrastive Learning. [Topic: CL] [pdf]
Membership Inference Attacks Against Recommender Systems. [Topic: MI] [pdf]
Learning Security Classifiers with Verified Global Robustness Properties. [Topic: Classifier] [pdf]
Robust Adversarial Attacks Against DNN-Based Wireless Communication Systems. [Topic: AEs] [pdf]
Can We Use Arbitrary Objects to Attack LiDAR Perception in Autonomous Driving? [Topic: AEs] [pdf]
Feature Indistinguishable Attack to Circumvent Trapdoor-enabled Defense. [Topic: AEs] [Code][pdf]
A Hard Label Black-box Adversarial Attack Against Graph Neural Networks. [Topic: AEs & DNN] [pdf]
Reverse Attack: Black-box Attacks on Collaborative Recommendation. [Topic: CF & Poisoning Attack] [pdf]
zkCNN: Zero Knowledge Proofs for Convolutional Neural Network Predictions and Accuracy. [Topic: CNN] [pdf]
Black-box Adversarial Attacks on Commercial Speech Platforms with Minimal Information. [Topic: AEs] [pdf]
AI-Lancet: Locating Error-inducing Neurons to Optimize Neural Networks. [Topic: DNN] [pdf]