Sébastien Gambs

dblp:09/2378 · DBLP profile ↗
← Back
59ranked-venue papers
9as first author
32since 2021 · last 2026
0000-0002-7326-7377ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 29 · 7 first-author · 13 since 2021Artificial intelligence and machine learning · 17 · 13 since 2021Databases, data management, data science and information retrieval · 12 · 1 first-author · 9 since 2021Human-computer interaction and ubiquitous computing · 2Computer networks · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Theory of computation · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 Revisiting Locally Differentially Private Protocols: Towards Better Trade-Offs in Privacy, Utility, and Attack Resistance
abstract
Local Differential Privacy (LDP) offers strong privacy protection, especially in settings in which the server collecting the data is untrusted. However, designing LDP mechanisms that achieve an optimal trade-off between privacy, utility and robustness to adversarial inference and integrity attacks remains challenging. In this work, we introduce a general multi-objective optimization framework for refining LDP protocols, enabling the joint optimization of privacy and utility under various adversarial settings. While our framework is flexible to accommodate multiple privacy and security attacks as well as utility metrics, in this paper, we specifically optimize for Attacker Success Rate (ASR) under \emph{data reconstruction attack} as a concrete measure of privacy leakage and Mean Squared Error (MSE) as a measure of utility. Complementarily, we evaluate integrity-oriented threats through data poisoning attacks, providing an additional adversarial perspective. More precisely, we systematically revisit these trade-offs by analyzing eight state-of-the-art LDP frequency estimation protocols and proposing refined counterparts that leverage tailored optimization techniques. Experimental results demonstrate that our proposed adaptive mechanisms consistently outperform their non-adaptive counterparts, achieving substantial reductions in ASR while preserving utility, and pushing closer to the ASR-MSE Pareto frontier. By bridging the gap between theoretical guarantees and real-world vulnerabilities, our framework enables modular and context-aware deployment of LDP mechanisms with tunable privacy-utility-attackability trade-offs.
Héber Hwang Arcolezi, Sébastien Gambs
ICDE2
2026 POPPY: Scalable and Secure Spectral Centrality for Distributed Graphs via Homomorphic Encryption
abstract
In this paper, we introduce POPPY, a novel suite of privacy-preserving algorithms designed for computing spectral centrality measures over graphs distributed across mutually distrustful data centers. POPPY is the first approach that achieves together generality, accuracy, and scalability with respect to the number of participants. POPPY uses the CKKS fully homomorphic encryption scheme to support the arithmetic division operation over ciphertexts. POPPY consists of three variants: POPPYs, optimized for sparse graphs using SIMD operations; POPPYd, tailored for dense graphs through efficient encrypted matrix-vector multiplication; and POPPYh, a hybrid between POPPYs and POPPYd for coping with contexts involving a large number of remote nodes. In addition to its core algorithms, POPPY comes with a pruning strategy based on a new notion of node equivalence called INC-equivalence. Pruning is indeed of utmost importance when using fully homomorphic encryption in order to minimize the number of encrypted operations performed. The INC-equivalence notion allows us to eliminate redundant nodes efficiently and without any impact on the accuracy of the centrality scores. Our comprehensive theoretical analysis and empirical evaluation on real-world and synthetic datasets demonstrate that POPPY achieves together generality, accuracy, and scalability.
Claire Guichemerre, Tristan Allard, Sofiane Azogagh, Marc-Olivier Killijian, Sébastien Gambs, Amr El Abbadi
Proc. Priv. Enhancing Technol.5
2025 QRisk: Think Before You Scan QR Codes
Abhishek Kumar Mishra 0001, Guillaume Gagnon, Mathieu Cunche, Sébastien Gambs
ARES (2)4
2025 Privacy-Preserving Trajectory Data Publication Via Differentially-Private Representation Learning
Youcef Korichi, Josée Desharnais, Sébastien Gambs, Nadia Tawbi
ESORICS (4)3
2025 GRAND : Graph Reconstruction from Potential Partial Adjacency and Neighborhood Data
abstract
Cryptographic approaches, such as secure multiparty computation, can be used to securely compute a function of a distributed graph without centralizing the data of each participant. However, the output of the protocol can leak sensitive information about the structure of the original graph. In particular, we propose an approach by which an adversary observing the result of a private protocol for the computation of the number of common neighbors between all pairs of vertices, can reconstruct the adjacency matrix of the graph. In fact, this can only be done up to co-squareness, a notion we introduce, as two different graphs can have the same matrix of common neighbors. To realize this, we consider two adversary models, one who observes the common neighbors matrix only and a more informed one that has partial knowledge of the original graph. Our results demonstrate that, from their common neighbors matrix, graphs can be reconstructed with high accuracy (up to co-squareness). The proposed reconstruction is also interesting in itself from the point of view of graph theory.
Sofiane Azogagh, Zelma Aubin Birba, Josée Desharnais, Sébastien Gambs, Marc-Olivier Killijian, Nadia Tawbi
KDD (2)4
2025 Responsible AI Day
abstract
This special day event on Responsible Artificial Intelligence (AI) brings together researchers, practitioners, and policymakers to explore how data mining and machine learning systems can be designed to align with ethical principles, societal values, and human well-being. As AI technologies increasingly influence decisions in healthcare, finance, governance, and social systems, there is a critical need to develop frameworks that embed fairness, accountability, and privacy directly into the foundations of knowledge discovery. This full-day event will feature a mix of invited talks, interactive debates, expert panels, and peer-reviewed research presentations, all focused on the practical integration of ethical design into data-driven systems. The Responsible AI Day builds on the success of Canada's NSERC CREATE Program on Responsible AI, an interdisciplinary initiative training the next generation of AI researchers across computer science, law, bioethics, public health, and media studies. Topics will span scalable AI governance, privacy-preserving computation, algorithmic bias mitigation, and the socio-legal tensions emerging in generative AI. By positioning responsible AI as a sociotechnical challenge, this special day aligns with KDD's mission of advancing data science that is not only technically robust but also socially conscious.
Ebrahim Bagheri, Faezeh Ensan, Calvin Hillis, Reihaneh Rabbany, Robin Cohen, Benjamin C. M. Fung, Sébastien Gambs
KDD (2)7
2025 P2NIA: Privacy-Preserving Non-iterative Auditing
Jade Garcia Bourrée, Hadrien Lautraite, Sébastien Gambs, Gilles Trédan, Erwan Le Merrer, Benoît Rottembourg
ECML/PKDD (5)3
2025 Fairness Evaluation of Neural Networks Through Computational Profile Likelihood
abstract
ABSTRACT Despite high predictive performance, machine learning models can be unfair towards specific demographic subgroups characterized by sensitive attributes such as gender or race. This paper presents a novel approach using Computational Profile Likelihood (CPL) to assess potential bias in neural network decisions with respect to sensitive attributes. CPL estimates the conditional probability of a network's internal neuron excitation levels during predictions. To assess the impact of sensitive attributes on predictions, the CPL distribution of individuals sharing a particular value of a sensitive attribute and a specific outcome (e.g., “women” and “high income”) is compared to a subgroup sharing another value of the sensitive attribute but with the same outcome (e.g., “men” and “high income”). The resulting disparities between distributions can be used to quantify the bias with respect to the sensitive attribute and the outcome class. We also assess the efficacy of bias reduction techniques through their influence on the resulting disparities. Experimental results on three widely used datasets indicate that the CPL of the trained models can be used to characterize significant differences between multiple protected groups, highlighting that these models display quantifiable biases. Furthermore, after applying bias mitigation methods, the gaps in CPL distributions are reduced, indicating a more similar internal representation for profiles of different protected groups.
Benjamin Djian, Ettore Merlo, Sébastien Gambs, Rosin Claude Ngueveu
Comput. Intell.3
2025 Taming the Triangle: On the Interplays Between Fairness, Interpretability, and Privacy in Machine Learning
abstract
ABSTRACT Machine learning techniques are increasingly used for high‐stakes decision‐making, such as college admissions, loan attribution, or recidivism prediction. Thus, it is crucial to ensure that the models learnt can be audited or understood by human users, do not create or reproduce discrimination or bias and do not leak sensitive information regarding their training data. Indeed, interpretability, fairness, and privacy are key requirements for the development of responsible machine learning, and all three have been studied extensively during the last decade. However, they were mainly considered in isolation, while in practice they interplay with each other, either positively or negatively. In this survey paper, we review the literature on the interactions between these three desiderata. More precisely, for each pairwise interaction, we summarize the identified synergies and tensions. These findings highlight several fundamental theoretical and empirical conflicts, while also demonstrating that jointly considering these different requirements is challenging when one aims at preserving a high level of utility. To solve this issue, we also discuss possible conciliation mechanisms, showing that a careful design can enable to successfully handle these different concerns in practice.
Julien Ferry, Ulrich Aïvodji, Sébastien Gambs, Marie-José Huguet, Mohamed Siala 0002
Comput. Intell.3
2025 Representation-based fairness evaluation and bias correction robustness assessment in neural networks
abstract
Context: While machine learning has achieved high predictive performance in many domains, decisions may still be biased and unfair regarding specific demographic groups characterized by sensitive attributes such as gender, age, or race. Objectives: In this paper, we introduce a novel approach to assess model fairness and bias correction robustness based on Computational Profile Distance (CPD) analysis with respect to sensitive attributes. Methods: To study model fairness, we quantify the model’s representation difference using the computational profile learned from different subgroups (e.g., male and female) on the individual and group level. To analyze the robustness of bias correction outcomes, we compare the correction suggestions provided based on confidence (i.e., softmax score) and likelihood (i.e., CPD). Results: To demonstrate the potential of the proposed approach, experiments have been performed using 24 models targeting 3 datasets used in previous fairness studies. Our experiments showed that computational profile distributions can effectively address model fairness from a representation perspective. Further, the experiments indicated that confidence-based bias correction decisions can vary largely from likelihood-based ones, and we should take both suggestions into account to obtain robust outcomes. Conclusion: Demonstrated with a set of experiments, our CPD-based approaches can help users build their trust in fairness assessment and bias mitigation of AI decisions, in ethically sensitive domains such as human resources, finance, health, and more.
Qiaolin Qin, Benjamin Djian, Ettore Merlo, Heng Li 0007, Sébastien Gambs
Inf. Softw. Technol.5
2025 Towards Privacy-preserving and Fairness-aware Federated Learning Framework
abstract
Federated Learning (FL) enables the distributed training of a model across multiple data owners under the orchestration of a central server responsible for aggregating the models generated by the different clients. However, the original approach of FL has significant shortcomings related to privacy and fairness requirements. Specifically, the observation of the model updates may lead to privacy issues, such as membership inference attacks, while the use of imbalanced local datasets can introduce or amplify classification biases, especially for minority groups. In this work, we show that these biases can be exploited to increase the likelihood of privacy attacks against these groups. To do so, we propose a novel inference attack exploiting the knowledge of group fairness metrics during the training of the global model. Then to thwart this attack, we define a fairness-aware encrypted-domain aggregation algorithm that is differentially-private by design thanks to the approximate precision loss of the threshold multi-key CKKS homomorphic encryption scheme. Finally, we demonstrate the good performance of our proposal both in terms of fairness and privacy through experiments conducted over three real datasets.
Adda-Akram Bendoukha, Didem Demirag, Nesrine Kaaniche, Aymen Boudguiga, Renaud Sirdey, Sébastien Gambs
Proc. Priv. Enhancing Technol.6
2025 WaKA: Data Attribution using K-Nearest Neighbors and Membership Privacy Principles
abstract
In this paper, we introduce WaKA (Wasserstein K-nearest neighbors Attribution), a novel attribution method that leverages principles from the LiRA (Likelihood Ratio Attack) framework and k-nearest neighbors classifiers (k-NN). WaKA efficiently measures the contribution of individual data points to the model’s loss distribution, analyzing every possible k-NN that can be constructed using the training set, without requiring to sample subsets of the training set. WaKA is versatile and can be used a posteriori as a membership inference attack (MIA) to assess privacy risks or a priori for privacy influence measurement and data valuation. Thus, WaKA can be seen as bridging the gap between data attribution and membership inference attack (MIA) by providing a unified framework to distinguish between a data point’s value and its privacy risk. For instance, we have shown that self-attribution values are more strongly correlated with the attack success rate than the contribution of a point to the model generalization. WaKA’s different usages were also evaluated across diverse real-world datasets, demonstrating performance very close to LiRA when used as an MIA on k-NN classifiers, but with greater computational efficiency. Additionally, WaKA shows greater robustness than Shapley Values for data minimization tasks (removal or addition) on imbalanced datasets.
Patrick Mesana, Clément Benesse, Hadrien Lautraite, Gilles Caporossi, Sébastien Gambs
Proc. Priv. Enhancing Technol.5
2024 Crypto'Graph: Leveraging Privacy-Preserving Distributed Link Prediction for Robust Graph Learning
abstract
Graphs are a widely used data structure for collecting and analyzing relational data. However, when the graph structure is distributed across several parties, its analysis is challenging. In particular, due to the sensitivity of the data each party might want to keep their partial knowledge of the graph private, while still be willing to collaborate with the other parties for tasks of mutual benefit, such as data curation or the removal of poisoned data. To address this challenge, we propose Crypto'Graph, an efficient protocol for privacy-preserving link prediction on distributed graphs. More precisely, it allows parties partially sharing a graph with distributed links to infer the likelihood of formation of new links in the future. Through the use of cryptographic primitives, Crypto'Graph is able to compute the likelihood of these new links on the joint network without revealing the structure of the private graph of each party, even though they know the number of nodes they have, since they share the same graph in terms of nodes but not the same links. Crypto'Graph improves on previous works by enabling the computation of a diverse set of similarity metrics in parallel without any additional cost. The use of Crypto'Graph is illustrated for defense against graph poisoning attacks, in which potential adversarial links are identified without compromising the privacy of the graphs of individual parties. The effectiveness of Crypto'Graph in mitigating graph poisoning attacks and achieving high prediction accuracy on a node classification task using graph neural networks is demonstrated through extensive experimentation on two real-world datasets.
Sofiane Azogagh, Zelma Aubin Birba, Sébastien Gambs, Marc-Olivier Killijian
CODASPY3
2024 Leveraging Transformer Architecture for Effective Trajectory-User Linking (TUL) Attack and Its Mitigation
Youcef Korichi, Josée Desharnais, Sébastien Gambs, Nadia Tawbi
ESORICS (4)3
2024 PANORAMIA: Privacy Auditing of Machine Learning Models without Retraining
abstract
We present PANORAMIA, a privacy leakage measurement framework for machine learning models that relies on membership inference attacks using generated data as non-members. By relying on generated non-member data, PANORAMIA eliminates the common dependency of privacy measurement tools on in-distribution non-member data. As a result, PANORAMIA does not modify the model, training data, or training process, and only requires access to a subset of the training data. We evaluate PANORAMIA on ML models for image and tabular data classification, as well as on large-scale language models.
Mishaal Kazmi, Hadrien Lautraite, Alireza Akbari, Qiaoyue Tang, Mauricio Soroco, Sébastien Gambs, Mathias Lécuyer
NeurIPS7
2024 Synthetic Data: Generate Avatar Data on Demand
Thomas Lebrun, Louis Béziaud, Tristan Allard, Antoine Boutet, Sébastien Gambs, Mohamed Maouche
WISE (5)5
2024 RSSI-based attacks for identification of BLE devices
abstract
International audience
Guillaume Gagnon, Sébastien Gambs, Mathieu Cunche
Comput. Secur.2
2024 Revealing the True Cost of Locally Differentially Private Protocols: An Auditing Perspective
abstract
While the existing literature on Differential Privacy (DP) auditing predominantly focuses on the centralized model (e.g., in auditing the DP-SGD algorithm), we advocate for extending this approach to audit Local DP (LDP). To achieve this, we introduce the LDP-Auditor framework for empirically estimating the privacy loss of locally differentially private mechanisms. This approach leverages recent advances in designing privacy attacks against LDP frequency estimation protocols. More precisely, through the analysis of numerous state-of-the-art LDP protocols, we extensively explore the factors influencing the privacy audit, such as the impact of different encoding and perturbation functions. Additionally, we investigate the influence of the domain size and the theoretical privacy loss parameters ϵ and δ on local privacy estimation. In-depth case studies are also conducted to explore specific aspects of LDP auditing, including distinguishability attacks on LDP protocols for longitudinal studies and multidimensional data. Finally, we present a notable achievement of our LDP-Auditor framework, which is the discovery of a bug in a state-of-the-art LDP Python package. Overall, our LDP-Auditor framework as well as our study offer valuable insights into the sources of randomness and information loss in LDP protocols. These contributions collectively provide a realistic understanding of the local privacy loss, which can help practitioners in selecting the LDP mechanism and privacy parameters that best align with their specific requirements. We open-sourced LDP-Auditor in [4].
Héber Hwang Arcolezi, Sébastien Gambs
Proc. Priv. Enhancing Technol.2
2023 SNAKE Challenge: Sanitization Algorithms under Attack
abstract
While there were already some privacy challenges organized in the domain of data sanitization, they have mainly focused on the defense side of the problem. To favor the organization of successful challenges focusing on attacks, we introduce the SNAKE framework that is designed to facilitate the organization of challenges dedicated to attacking existing data sanitization mechanisms. In particular, it enables to easily automate the redundant tasks that are inherent to any such challenge and exhibits the following salient features: genericity with respect to attacks, ease of use and extensibility. We propose to demonstrate the main features of the SNAKE framework through a specific instantiation focusing on membership inference attacks over differentially-private synthetic data generation schemes. This instance of the SNAKE framework is currently being used for supporting a challenge co-located with APVP 2023 (the French workshop on the protection of privacy).
Tristan Allard, Louis Béziaud, Sébastien Gambs
CIKM3
2023 Frequency Estimation of Evolving Data Under Local Differential Privacy
abstract
International audience
Héber Hwang Arcolezi, Carlos Antonio Pinzón, Catuscia Palamidessi, Sébastien Gambs
EDBT4
2023 Leveraging In-Network Computing for Privacy-Aware Real-Time Surveillance mHealth Applications
abstract
The Internet of Things has become highly popular in the healthcare sector due to its benefits for patients, doctors and health authorities. In particular, the resulting sub-fields, such as medical IoT and mobile health (mHealth), have become essential in pervasive healthcare monitoring and preventing the spread of viruses. However, the massive amount of data generated by millions of IoT devices challenges the current infrastructure of cloud and edge computing, leading to high response times and unreliable results. Security and privacy concerns make these technologies particularly vulnerable to attacks. In this paper, we propose an mHealth solution based on in-network computing paradigm to provide privacy-aware, time-constrained and reliable results for IoT applications in a mobile health context. Our simulation and analytical results show that our solution satisfies mHealth applications requirements and outperforms conventional solution based on edge computing.
Syrine Rajhi, Halima Elbiaze, Sébastien Gambs, Roch H. Glitho
GLOBECOM3
2023 Confidential-PROFITT: Confidential PROof of FaIr Training of Trees
Ali Shahin Shamsabadi, Sierra Calanda Wyllie, Nicholas Franzese, Natalie Dullerud, Sébastien Gambs, Nicolas Papernot, Xiao Wang 0012, Adrian Weller
ICLR5
2023 RSSI-Based Fingerprinting of Bluetooth Low Energy Devices
abstract
Best paper award
Guillaume Gagnon, Sébastien Gambs, Mathieu Cunche
SECRYPT2
2023 Improving fairness generalization through a sample-robust optimization method
Julien Ferry, Ulrich Aïvodji, Sébastien Gambs, Marie-José Huguet, Mohamed Siala 0002
Mach. Learn.3
2023 On the Risks of Collecting Multidimensional Data Under Local Differential Privacy
abstract
The private collection of multiple statistics from a population is a fundamental statistical problem. One possible approach to realize this is to rely on the local model of differential privacy (LDP). Numerous LDP protocols have been developed for the task of frequency estimation of single and multiple attributes. These studies mainly focused on improving the utility of the algorithms to ensure the server performs the estimations accurately. In this paper, we investigate privacy threats (re-identification and attribute inference attacks) against LDP protocols for multidimensional data following two state-of-the-art solutions for frequency estimation of multiple attributes. To broaden the scope of our study, we have also experimentally assessed five widely used LDP protocols, namely, generalized randomized response, optimal local hashing, subset selection, RAPPOR and optimal unary encoding. Finally, we also proposed a countermeasure that improves both utility and robustness against the identified threats. Our contributions can help practitioners aiming to collect users' statistics privately to decide which LDP mechanism best fits their needs.
Héber Hwang Arcolezi, Sébastien Gambs, Jean-François Couchot, Catuscia Palamidessi
Proc. VLDB Endow.2
2022 Leveraging Integer Linear Programming to Learn Optimal Fair Rule Lists
Ulrich Aïvodji, Julien Ferry, Sébastien Gambs, Marie-José Huguet, Mohamed Siala 0002
CPAIOR3
2022 Multi-Freq-LDPy: Multiple Frequency Estimation Under Local Differential Privacy in Python
Héber Hwang Arcolezi, Jean-François Couchot, Sébastien Gambs, Catuscia Palamidessi, Majid Zolfaghari
ESORICS (3)3
2022 Washing The Unwashable : On The (Im)possibility of Fairwashing Detection
abstract
The use of black-box models (e.g., deep neural networks) in high-stakes decision-making systems, whose internal logic is complex, raises the need for providing explanations about their decisions. Model explanation techniques mitigate this problem by generating an interpretable and high-fidelity surrogate model (e.g., a logistic regressor or decision tree) to explain the logic of black-box models. In this work, we investigate the issue of fairwashing, in which model explanation techniques are manipulated to rationalize decisions taken by an unfair black-box model using deceptive surrogate models. More precisely, we theoretically characterize and analyze fairwashing, proving that this phenomenon is difficult to avoid due to an irreducible factor---the unfairness of the black-box model. Based on the theory developed, we propose a novel technique, called FRAUD-Detect (FaiRness AUDit Detection), to detect fairwashed models by measuring a divergence over subpopulation-wise fidelity measures of the interpretable model. We empirically demonstrate that this divergence is significantly larger in purposefully fairwashed interpretable models than in honest ones. Furthermore, we show that our detector is robust to an informed adversary trying to bypass our detector. The code implementing FRAUD-Detect is available at https://github.com/cleverhans-lab/FRAUD-Detect.
Ali Shahin Shamsabadi, Mohammad Yaghini, Natalie Dullerud, Sierra Calanda Wyllie, Ulrich Aïvodji, Aisha Alaagib, Sébastien Gambs, Nicolas Papernot
NeurIPS7
2021 DySan: Dynamically Sanitizing Motion Sensor Data Against Sensitive Inferences through Adversarial Networks
abstract
With the widespread development of the quantified-self movement, an increasing number of users rely on mobile applications to monitor their physical activity through their smartphones. However, granting applications a direct access to sensor data exposes users to privacy risks. In particular, motion sensor data are usually transmitted to analytics applications hosted in the cloud, which leverages on machine learning models to provide feedback on their activity status to users. In this setting, nothing prevents the service provider to infer private and sensitive information about a user such as health or demographic attributes. To address this issue, we propose DySan, a privacy-preserving framework to sanitize motion sensor data against unwanted sensitive inferences (i.e., improving privacy) while limiting the loss of accuracy on the physical activity monitoring (i.e., maintaining data utility). Our approach is inspired from the framework of Generative Adversarial Networks to sanitize the sensor data for the purpose of ensuring a good trade-off between utility and privacy. More precisely, by learning in a competitive manner several networks, DySan is able to build models that sanitize motion data against inferences on a specified sensitive attribute (e.g., gender) while maintaining an accurate activity recognition. DySan builds various sanitizing models, characterized by different sets of hyperparameters in the global loss function, to propose a transfer learning scheme over time by dynamically selecting the model which provides the best utility and privacy trade-off according to the incoming data. Experiments conducted on real datasets demonstrate that DySan can drastically limit the gender inference up to 41% (from 98% with raw data to 57% with sanitized data) while only reducing the accuracy of activity recognition by 3% (from 95% with raw data to 92% with sanitized data).
Antoine Boutet, Carole Frindel, Sébastien Gambs, Théo Jourdan, Rosin Claude Ngueveu
AsiaCCS3
2021 FairCORELS, an Open-Source Library for Learning Fair Rule Lists
abstract
FairCORELS is an open-source Python module for building fair rule lists. It is a multi-objective variant of CORELS, a branch-and-bound algorithm to learn certifiably optimal rule lists. FairCORELS supports six statistical fairness metrics, proposes several exploration parameters and leverages on the fairness constraints to prune the search space efficiently. It can easily generate sets of accuracy-fairness trade-offs. The models learnt are interpretable by design and a sparsity parameter can be used to control their length.
Ulrich Aïvodji, Julien Ferry, Sébastien Gambs, Marie-José Huguet, Mohamed Siala 0002
CIKM3
2021 Characterizing the risk of fairwashing
abstract
Fairwashing refers to the risk that an unfair black-box model can be explained by a fairer model through post-hoc explanation manipulation. In this paper, we investigate the capability of fairwashing attacks by analyzing their fidelity-unfairness trade-offs. In particular, we show that fairwashed explanation models can generalize beyond the suing group (i.e., data points that are being explained), meaning that a fairwashed explainer can be used to rationalize subsequent unfair decisions of a black-box model. We also demonstrate that fairwashing attacks can transfer across black-box models, meaning that other black-box models can perform fairwashing without explicitly using their predictions. This generalization and transferability of fairwashing attacks imply that their detection will be difficult in practice. Finally, we propose an approach to quantify the risk of fairwashing, which is based on the computation of the range of the unfairness of high-fidelity explainers.
Ulrich Aïvodji, Hiromi Arai, Sébastien Gambs, Satoshi Hara 0001
NeurIPS3
2021 Growing synthetic data through differentially-private vine copulas
abstract
Abstract In this work, we propose a novel approach for the synthetization of data based on copulas, which are interpretable and robust models, extensively used in the actuarial domain. More precisely, our method COPULA-SHIRLEY is based on the differentially-private training of vine copulas, which are a family of copulas allowing to model and generate data of arbitrary dimensions. The framework of COPULA-SHIRLEY is simple yet flexible, as it can be applied to many types of data while preserving the utility as demonstrated by experiments conducted on real datasets. We also evaluate the protection level of our data synthesis method through a membership inference attack recently proposed in the literature.
Sébastien Gambs, Frédéric Ladouceur, Antoine Laurent, Alexandre Roy-Gaumond
Proc. Priv. Enhancing Technol.1
2019 Inspect What Your Location History Reveals About You: Raising user awareness on privacy threats associated with disclosing his location data
abstract
Location is one of the most extensively collected personal data on mobile by applications and third-party services. However, how the location of users is actually processed in practice by the actors of targeted advertising ecosystem remains unclear. Nonetheless, these providers have a strong incentive to create very detailed profile of users to better monetize the collected data. End users are usually not aware about the strength and wide range of inference that can be performed from their mobility traces. In this demonstration, users interact with a web-based application to inspect their location history and to discover the inferential power of this kind of data. Moreover to better understand the possible countermeasures, users can apply a sanitization to protect their data and visualize the impact on both the mobility traces and the associated inferred information. The objective of this demonstration is to raise the user awareness on the profiling capabilities and the privacy threats associated with disclosing his location data as well as how sanitization mechanisms can be efficient to mitigate these privacy risks. In addition, by collecting users feedbacks on the personal information revealed and the usage of a geosanitization mechanism, we hope that this demonstration will also be useful to constitute a new and valuable dataset on users perceptions on these questions.
Antoine Boutet, Sébastien Gambs
CIKM2
2019 Fairwashing: the risk of rationalization
abstract
Black-box explanation is the problem of explaining how a machine learning model – whose internal logic is hidden to the auditor and generally complex – produces its outcomes. Current approaches for solving this problem include model explanation, outcome explanation as well as model inspection. While these techniques can be beneficial by providing interpretability, they can be used in a negative manner to perform fairwashing, which we define as promoting the false perception that a machine learning model respects some ethical values. In particular, we demonstrate that it is possible to systematically rationalize decisions taken by an unfair black-box model using the model explanation as well as the outcome explanation approaches with a given fairness metric. Our solution, LaundryML, is based on a regularized rule list enumeration algorithm whose objective is to search for fair rule lists approximating an unfair black-box model. We empirically evaluate our rationalization technique on black-box models trained on real-world datasets and show that one can obtain rule lists with high fidelity to the black-box model while being considerably less unfair at the same time.
Ulrich Aïvodji, Hiromi Arai, Olivier Fortineau, Sébastien Gambs, Satoshi Hara 0001, Alain Tapp
ICML4
2018 Entwining Sanitization and Personalization on Databases
abstract
In the last decade, a lot of research has been done to prevent the illegal distribution of digital content, % in the context in which the proprietary content is a medium such as musical works and movies. However, only few works have tackled this problem for databases, and even less for databases containing personal and sensitive information (\emphe.g, a medical database). In this work, we address this latter issue by proposing øuralgo\ (for Sanitization and Personalization of Databases ), an approach in which the owner of a database personalizes it before distributing it to ensure that a malicious buyer can be traced back in case of an illegal redistribution. Our novel solution entwines the personalization step with a sanitization mechanism to prevent the leak of personal information and limit the privacy risks. Thus, our objective is to release a sanitized and personalized database, both to protect the privacy of the concerned individuals and to prevent the illegal redistribution, even from a collusion of malicious buyers.
Sébastien Gambs, Julien Lolive, Jean-Marc Robert 0001
AsiaCCS1
2018 Privacy-preserving Wi-Fi Analytics
abstract
Abstract As communications-enabled devices are becoming more ubiquitous, it becomes easier to track the movements of individuals through the radio signals broadcasted by their devices. Thus, while there is a strong interest for physical analytics platforms to leverage this information for many purposes, this tracking also threatens the privacy of individuals. To solve this issue, we propose a privacy-preserving solution for collecting aggregate mobility patterns while satisfying the strong guarantee of ε-differential privacy. More precisely, we introduce a sanitization mechanism for efficient, privacy-preserving and non-interactive approximate distinct counting for physical analytics based on perturbed Bloom filters called Pan-Private BLIP. We also extend and generalize previous approaches for estimating distinct count of events and joint events (i.e., intersection and more generally t-out-of-n cardinalities). Finally, we evaluate expirementally our approach and compare it to previous ones on real datasets.
Mohammad Alaggan, Mathieu Cunche, Sébastien Gambs
Proc. Priv. Enhancing Technol.3
2017 A Terrorist-fraud Resistant and Extractor-free Anonymous Distance-bounding Protocol
abstract
Distance-bounding protocols have been introduced to thwart relay attacks against contactless authentication protocols. In this context, verifiers have to authenticate the credentials of untrusted provers. Unfortunately, these protocols are themselves subject to complex threats such as terrorist-fraud attacks, in which a malicious prover helps an accomplice to authenticate. Provably guaranteeing the resistance of distance-bounding protocols to these attacks is complex. The classical solutions assume that rational provers want to protect their long-term authentication credentials, even with respect to their accomplices. Thus, terrorist-fraud resistant protocols generally rely on artificial extraction mechanisms, ensuring that an accomplice can retrieve the credential of his partnering prover, if he is able to authenticate. We propose a novel approach to obtain provable terrorist-fraud resistant protocols that does not rely on an accomplice being able to extract any long-term key. Instead, we simply assume that he can replay the information received from the prover. Thus, rational provers should refuse to cooperate with third parties if they can impersonate them freely afterwards. We introduce a generic construction for provably secure distance-bounding protocols, and give three instances of this construction: (1) an efficient symmetric-key protocol, (2) a public-key protocol protecting the identities of provers against external eavesdroppers, and finally (3) a fully anonymous protocol protecting the identities of provers even against malicious verifiers that try to profile them.
Gildas Avoine, Xavier Bultel, Sébastien Gambs, David Gérault, Pascal Lafourcade 0001, Cristina Onete, Jean-Marc Robert 0001
AsiaCCS3
2016 An Empirical Study on GSN Usage Intention: Factors Influencing the Adoption of Geo-Social Networks
abstract
Nowadays, geosocial networks (GSNs) have become a significant component of people's daily lives as they are one of the most popular applications that are being widely accessed through smart devices such as smartphones and tablets. Their rapid widespread use and their invasion of our private life warrant a better understanding. In particular, the impact of trust in GSN, the privacy concerns of users, their perception of risk and the social influence on the use of such mobile applications is not yet fully understood. In this paper, we study the factors influencing the usage intention of GSN users. To realize this, we propose a model based on the user's perspective. Our model focuses on four overall factors that influence the users' concerns and in turn their intention and aim of using GSNs: privacy concerns, trust, social influence and risk perception. We tested empirically the proposed research model by running a web-based survey. The participants consisted of 396 persons with at least a past experience with GSNs. The results revealed that among all the possible factors the privacy concerns, social influence and trust have a significant impact on the intention and usage of GSNs. In contrast, personality traits have almost no effects on trust or social influence. One notable exception is computer self-efficacy that was found to induce a strong influence on the four principal factors.
Esma Aïmeur, Sébastien Gambs, Cheu Yien Yep
ARES2
2016 Edge-calibrated noise for differentially private mechanisms on graphs
abstract
In this paper, we introduce new methods for releasing differentially private graphs. Our techniques are based on a new way to distribute noise among edge weights. More precisely, we rely on the addition of noise whose amplitude is edge-calibrated and optimize the distribution of the privacy budget among subsets of edges. The generic privacy framework that we propose can capture most of the privacy notions introduced so far in the literature to release graphs in a differentially private manner. Furthermore, experimental results on real datasets show that our methods outperform the standard existing techniques, in particular in terms of the preservation of utility. In addition, these experiments show that our mechanisms guarantee ε-differential privacy for a reasonable level of privacy ε, while preserving the spectral information of the input graph.
Solenn Brunet, Sébastien Canard, Sébastien Gambs, Baptiste Olivier
PST3
2016 A Prover-Anonymous and Terrorist-Fraud Resistant Distance-Bounding Protocol
abstract
Contactless communications have become omnipresent in our daily lives, from simple access cards to electronic passports. Such systems are particularly vulnerable to relay attacks, in which an adversary relays the messages from a prover to a verifier. Distance-bounding protocols were introduced to counter such attacks. Lately, there has been a very active research trend on improving the security of these protocols, but also on ensuring strong privacy properties with respect to active adversaries and malicious verifiers.
Xavier Bultel, Sébastien Gambs, David Gérault, Pascal Lafourcade 0001, Cristina Onete, Jean-Marc Robert 0001
WISEC2
2015 The Not-so-Distant Future: Distance-Bounding Protocols on Smartphones
Sébastien Gambs, Carlos Eduardo Rosar Kós Lassance, Cristina Onete
CARDIS1
2015 Sanitization of Call Detail Records via Differentially-Private Bloom Filters
Mohammad Alaggan, Sébastien Gambs, Stan Matwin, Mohammed Tuhin
DBSec2
2014 Prover anonymous and deniable distance-bounding authentication
abstract
In distance-bounding authentication protocols, a verifier assesses that a prover is (1) legitimate and (2) in the verifier's proximity. Proximity checking is done by running time-critical exchanges between both parties. This enables the verifier to detect relay attacks (also called mafia fraud). While most distance-bounding protocols offer resistance to mafia, distance, and impersonation attacks, only few protect the privacy of the authenticating prover. One exception is the protocol due to Hermans, Peeters, and Onete, which offers prover untraceability with respect to a Man-in-the-Middle adversary. However in this protocol as well as in all other distance-bounding protocols, any legitimate verifier can identify, and thus track, the prover. In order to counter the threats of possible corruption or data leakage from verifiers, we propose a distance-bounding protocol providing strong prover privacy with respect to the verifier and deniability with respect to a centralized back-end server managing prover creation and revocation. In particular, we first formalize the notion of prover anonymity, which guarantees that even verifiers cannot trace provers, and deniability, which allows provers to deny that they were authenticated by a verifier. Finally, we prove that our protocol achieves these strong guarantees.
Sébastien Gambs, Cristina Onete, Jean-Marc Robert 0001
AsiaCCS1
2014 Challenging Differential Privacy: The Case of Non-interactive Mechanisms
Raghavendran Balu, Teddy Furon, Sébastien Gambs
ESORICS (2)3
2014 PROPS: A PRivacy-Preserving Location Proof System
abstract
A secure location-based service requires that a mobile user certifies his position before gaining access to a resource. Currently, most of the existing solutions addressing this issue assume a trusted third party that can vouch for the position claimed by a user. However, as computation and communication capacities become ubiquitous with the large scale adoption of smartphones by individuals, we propose to leverage on these resources to solve this issue in a collaborative and private manner. More precisely, we introduce PROPS, for PRivacy-preserving lOcation Proof System, which allows users to generate proofs of location in a private and distributed way using neighboring nodes as witnesses. PROPS provides security properties such as unforgeability and non-transferability of the proofs, as well as resistance to classical localization attacks.
Sébastien Gambs, Marc-Olivier Killijian, Matthieu Roy, Moussa Traoré
SRDS1
2014 De-anonymization attack on geolocated data
Sébastien Gambs, Marc-Olivier Killijian, Miguel Núñez del Prado Cortez
J. Comput. Syst. Sci.1
2014 Towards privacy-driven design of a dynamic carpooling system
Jesus Friginal, Sébastien Gambs, Jérémie Guiochet, Marc-Olivier Killijian
Pervasive Mob. Comput.2
2013 Quantum speed-up for unsupervised learning
abstract
We show how the quantum paradigm can be used to speed up unsupervised learning algorithms. More precisely, we explain how it is possible to accelerate learning algorithms by quantizing some of their subroutines. Quantization refers to the process that partially or totally converts a classical algorithm to its quantum counterpart in order to improve performance. In particular, we give quantized versions of clustering via minimum spanning tree, divisive clustering and k -medians that are faster than their classical analogues. We also describe a distributed version of k -medians that allows the participants to save on the global communication cost of the protocol compared to the classical version. Finally, we design quantum algorithms for the construction of a neighbourhood graph, outlier detection as well as smart initialization of the cluster centres.
Esma Aïmeur, Gilles Brassard, Sébastien Gambs
Mach. Learn.3
2012 Reconstruction Attack through Classifier Analysis
Sébastien Gambs, Ahmed Gmati, Michel Hurfin
DBSec1
2012 Scalable and Secure Polling in Dynamic Distributed Networks
abstract
We consider the problem of securely conducting a poll in synchronous dynamic networks equipped with a Public Key Infrastructure (PKI). Whereas previous distributed solutions had a communication cost of O(n2) in an n nodes system, we present SPP (Secure and Private Polling), the first distributed polling protocol requiring only a communication complexity of O(n log3n), which we prove is near-optimal. Our protocol ensures perfect security against a computationally-bounded adversary, tolerates (1/2 - ϵ)n Byzantine nodes for any constant 1/2 >; ϵ >; 0 (not depending on n), and outputs the exact value of the poll with high probability. SPP is composed of two sub-protocols, which we believe to be interesting on their own: SPP-Overlay maintains a structured overlay when nodes leave or join the network, and SPP-Computation conducts the actual poll. We validate the practicality of our approach through experimental evaluations and describe briefly two possible applications of SPP: (1) an optimal Byzantine Agreement protocol whose communication complexity is Θ(n log n) and (2) a protocol solving an open question of King and Saia in the context of aggregation functions, namely on the feasibility of performing multiparty secure aggregations with a communication complexity of o(n2).
Sébastien Gambs, Rachid Guerraoui, Hamza Harkous, Florian Huc, Anne-Marie Kermarrec
SRDS1
2012 BLIP: Non-interactive Differentially-Private Similarity Computation on Bloom filters
Mohammad Alaggan, Sébastien Gambs, Anne-Marie Kermarrec
SSS2
2011 Private Similarity Computation in Distributed Systems: From Cryptography to Differential Privacy
Mohammad Alaggan, Sébastien Gambs, Anne-Marie Kermarrec
OPODIS2
2010 Towards a Privacy-Enhanced Social Networking Site
abstract
Social Networking Sites (SNS), such as Facebook and LinkedIn, have become the established place for keeping contact with old friends and meeting new acquaintances. As a result, a user leaves a big trail of personal information about him and his friends on the SNS, sometimes even without being aware of it. This information can lead to privacy drifts such as damaging his reputation and credibility, security risks (for instance identity theft) and profiling risks. In this paper, we first highlight some privacy issues raised by the growing development of SNS and identify clearly three privacy risks. While it may seem a priori that privacy and SNS are two antagonist concepts, we also identified some privacy criteria that SNS could fulfill in order to be more respectful of the privacy of their users. Finally, we introduce the concept of a Privacy-enhanced Social Networking Site (PSNS) and we describe Privacy Watch, our first implementation of a PSNS.
Esma Aïmeur, Sébastien Gambs, Ai Ho
ARES2
2010 Uniform and Ergodic Sampling in Unstructured Peer-to-Peer Systems with Malicious Nodes
Emmanuelle Anceaume, Yann Busnel, Sébastien Gambs
OPODIS3
2009 UPP: User Privacy Policy for Social Networking Sites
abstract
Since their introduction, SNS (Social Networking Sites) such as MySpace, Facebook and LinkedIn have attracted millions of users and have become established places for keeping contact with old acquaintances and meeting new ones. Nonetheless, due to lack of user awareness and proper privacy protection tools, huge quantities of user data, including personal information, pictures and videos are quickly falling into the hands of authorities, strangers, recruiters and even the public at large. By using SNSs and accepting their privacy policy, users have volunteered to relinquish their ownership on their own data, which explains why the proposed privacy solutions based on current SNSs cannot solve all user privacy issues. As such, we start by setting the foundations for privacy and introduce a Privacy Framework for SNSs. Then, based on this framework, we present a User Privacy Policy (UPP) which provides users with an easy and flexible way to specify and communicate their privacy concerns to other users, third parties and to the SNS provider.
Esma Aïmeur, Sébastien Gambs, Ai Ho
ICIW2
2007 Anonymous Quantum Communication
Gilles Brassard, Anne Broadbent, Joseph F. Fitzsimons, Sébastien Gambs, Alain Tapp
ASIACRYPT4
2007 Quantum clustering algorithms
abstract
By the term "quantization", we refer to the process of using quantum mechanics in order to improve a classical algorithm, usually by making it go faster. In this paper, we initiate the idea of quantizing clustering algorithms by using variations on a celebrated quantum algorithm due to Grover. After having introduced this novel approach to unsupervised learning, we illustrate it with a quantized version of three standard algorithms: divisive clustering, k-medians and an algorithm for the construction of a neighbourhood graph. We obtain a significant speedup compared to the classical approach.
Esma Aïmeur, Gilles Brassard, Sébastien Gambs
ICML3
2007 Privacy-preserving boosting
Sébastien Gambs, Balázs Kégl, Esma Aïmeur
Data Min. Knowl. Discov.1
2002 CLARISSE: A Machine Learning Tool to Initialize Student Models
Esma Aïmeur, Gilles Brassard, Hugo Dufort, Sébastien Gambs
Intelligent Tutoring Systems4