VLDB 2026 Research / reviewers in the wild / expert
Rishav Chourasia
dblp:205/0997
· DBLP profile ↗
5ranked-venue papers
4as first author
4since 2021 · last 2026
0000-0001-7975-0530ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 3 · 2 first-author · 2 since 2021Security and privacy · 2 · 2 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Auditing Apple's DifferentialPrivacy.framework: Implementation Bugs, Misconfigurations, and Practical RisksabstractSince 2016, Apple has claimed that device analytics collected to improve user experience are protected by differential privacy (DP). Apple's DifferentialPrivacy framework is deployed across its operating systems and handles sensitive signals such as Safari domains, keyboard events, photo attributes, and health-related reports. Because Apple has not open-sourced its privatization algorithms, these privacy claims have been difficult to verify independently. We present a client-side audit of Apple's DP framework on macOS Sonoma 14.2 and Sequoia 15.6. We reverse engineer the shipped binaries, recover Objective-C interfaces, build runtime harnesses that execute Apple's deployed mechanisms, and test whether their outputs match the advertised privacy guarantees. Our audit covers nearly all active deployed mechanisms, including Count Median Sketch, Hadamard-CMS, randomized-response mechanisms, and Prio-style secure aggregation. We find multiple implementation bugs and misconfigurations. Every audited mechanism that relies on floating-point noise fails to meet its advertised DP or zero-knowledge proof guarantee, due to insecure samplers with known floating-point vulnerabilities. We also find secure-aggregation configurations with local DP disabled, exposing pre-aggregation records to any party with access to those logs. Overall, we find DP violations in 5 of 9 audited mechanisms, affecting 87% of data collection in macOS Sonoma and 68% in Sequoia. We also identify public leaked iPhone logs that can be decoded to recover private information, including Safari domains and keyboard emoji signals. Rishav Chourasia, Ergute Bao, Uzair Javaid, Xiaokui Xiao |
SP | 1 |
| 2023 | Forget Unlearning: Towards True Data-Deletion in Machine LearningabstractUnlearning algorithms aim to remove deleted data's influence from trained models at a cost lower than full retraining. However, prior guarantees of unlearning in literature are flawed and don't protect the privacy of deleted records. We show that when people delete their data as a function of published models, records in a database become interdependent. So, even retraining a fresh model after deletion of a record doesn't ensure its privacy. Secondly, unlearning algorithms that cache partial computations to speed up the processing can leak deleted information over a series of releases, violating the privacy of deleted records in the long run. To address these, we propose a sound deletion guarantee and show that ensuring the privacy of existing records is necessary for the privacy of deleted records. Under this notion, we propose an optimal, computationally efficient, and sound machine unlearning algorithm based on noisy gradient descent. Rishav Chourasia, Neil Shah |
ICML | 1 |
| 2022 | Knowledge Cross-Distillation for Membership PrivacyabstractAbstract A membership inference attack (MIA) poses privacy risks for the training data of a machine learning model. With an MIA, an attacker guesses if the target data are a member of the training dataset. The state-of-the-art defense against MIAs, distillation for membership privacy (DMP), requires not only private data for protection but a large amount of unlabeled public data. However, in certain privacy-sensitive domains, such as medicine and finance, the availability of public data is not guaranteed. Moreover, a trivial method for generating public data by using generative adversarial networks significantly decreases the model accuracy, as reported by the authors of DMP. To overcome this problem, we propose a novel defense against MIAs that uses knowledge distillation without requiring public data. Our experiments show that the privacy protection and accuracy of our defense are comparable to those of DMP for the benchmark tabular datasets used in MIA research, Purchase100 and Texas100, and our defense has a much better privacy-utility trade-off than those of the existing defenses that also do not use public data for the image dataset CIFAR10. Rishav Chourasia, Batnyam Enkhtaivan, Kunihiro Ito, Junki Mori, Isamu Teranishi, Hikaru Tsuchida 0001 |
Proc. Priv. Enhancing Technol. | 1 |
| 2021 | Differential Privacy Dynamics of Langevin Diffusion and Noisy Gradient DescentabstractWhat is the information leakage of an iterative randomized learning algorithm about its training data, when the internal state of the algorithm is \emph{private}? How much is the contribution of each specific training epoch to the information leakage through the released model? We study this problem for noisy gradient descent algorithms, and model the \emph{dynamics} of R\'enyi differential privacy loss throughout the training process. Our analysis traces a provably \emph{tight} bound on the R\'enyi divergence between the pair of probability distributions over parameters of models trained on neighboring datasets. We prove that the privacy loss converges exponentially fast, for smooth and strongly convex loss functions, which is a significant improvement over composition theorems (which over-estimate the privacy loss by upper-bounding its total value over all intermediate gradient computations). For Lipschitz, smooth, and strongly convex loss functions, we prove optimal utility with a small gradient complexity for noisy gradient descent algorithms. Rishav Chourasia, Jiayuan Ye 0001, Reza Shokri |
NeurIPS | 1 |
| 2017 | Type reduction techniques for two-dimensional interval type-2 fuzzy setsabstractIn this paper, we address the issue of type reduction of multi-dimensional interval type-2 (IT2) fuzzy sets (FSs). We utilize the Karnik-Mendel (KM) algorithm to estimate the centroid boundary of a multi-dimensional footprint of uncertainty (FOU). We deal with two-dimensional (2-D) fuzzy sets as we can visualize the FOU using 3-D plots, thus making the illustration of the methods simple. However, the basic idea can be extended to multiple dimensions. We give a formal definition of the centroid boundary of a 2-D IT2 fuzzy membership function (FMF) and propose two methods for its estimation. The first method computes embedded type-1 (T1) FSs whose centroids constitute the centroid boundary. We obtain the embedded sets by producing slices of the domain using different sets of parallel planes and then apply the KM algorithm over each slice, to obtain “embedded-curves.” For the second method, we approximate our first method by restricting embedded-curves to be “embedded-lines” thus enhancing computational speed. These type reduction techniques can be applied to applications involving multi-dimensional centroid estimation such as, clustering, support vector estimation for dimensionality reduction, fuzzy logic controllers, to mention a few. Vaibhav Saxena, Nikhil Yadala, Rishav Chourasia, Frank Chung-Hoon Rhee |
FUZZ-IEEE | 3 |