Rishav Chourasia

dblp:205/0997 · DBLP profile ↗
← Back
5ranked-venue papers
4as first author
4since 2021 · last 2026
0000-0001-7975-0530ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 3 · 2 first-author · 2 since 2021Security and privacy · 2 · 2 first-author · 2 since 2021
YearPublicationVenuePosition
2026 Auditing Apple's DifferentialPrivacy.framework: Implementation Bugs, Misconfigurations, and Practical Risks
abstract
Since 2016, Apple has claimed that device analytics collected to improve user experience are protected by differential privacy (DP). Apple's DifferentialPrivacy framework is deployed across its operating systems and handles sensitive signals such as Safari domains, keyboard events, photo attributes, and health-related reports. Because Apple has not open-sourced its privatization algorithms, these privacy claims have been difficult to verify independently. We present a client-side audit of Apple's DP framework on macOS Sonoma 14.2 and Sequoia 15.6. We reverse engineer the shipped binaries, recover Objective-C interfaces, build runtime harnesses that execute Apple's deployed mechanisms, and test whether their outputs match the advertised privacy guarantees. Our audit covers nearly all active deployed mechanisms, including Count Median Sketch, Hadamard-CMS, randomized-response mechanisms, and Prio-style secure aggregation. We find multiple implementation bugs and misconfigurations. Every audited mechanism that relies on floating-point noise fails to meet its advertised DP or zero-knowledge proof guarantee, due to insecure samplers with known floating-point vulnerabilities. We also find secure-aggregation configurations with local DP disabled, exposing pre-aggregation records to any party with access to those logs. Overall, we find DP violations in 5 of 9 audited mechanisms, affecting 87% of data collection in macOS Sonoma and 68% in Sequoia. We also identify public leaked iPhone logs that can be decoded to recover private information, including Safari domains and keyboard emoji signals.
Rishav Chourasia, Ergute Bao, Uzair Javaid, Xiaokui Xiao
SP1
2023 Forget Unlearning: Towards True Data-Deletion in Machine Learning
abstract
Unlearning algorithms aim to remove deleted data's influence from trained models at a cost lower than full retraining. However, prior guarantees of unlearning in literature are flawed and don't protect the privacy of deleted records. We show that when people delete their data as a function of published models, records in a database become interdependent. So, even retraining a fresh model after deletion of a record doesn't ensure its privacy. Secondly, unlearning algorithms that cache partial computations to speed up the processing can leak deleted information over a series of releases, violating the privacy of deleted records in the long run. To address these, we propose a sound deletion guarantee and show that ensuring the privacy of existing records is necessary for the privacy of deleted records. Under this notion, we propose an optimal, computationally efficient, and sound machine unlearning algorithm based on noisy gradient descent.
Rishav Chourasia, Neil Shah
ICML1
2022 Knowledge Cross-Distillation for Membership Privacy
abstract
Abstract A membership inference attack (MIA) poses privacy risks for the training data of a machine learning model. With an MIA, an attacker guesses if the target data are a member of the training dataset. The state-of-the-art defense against MIAs, distillation for membership privacy (DMP), requires not only private data for protection but a large amount of unlabeled public data. However, in certain privacy-sensitive domains, such as medicine and finance, the availability of public data is not guaranteed. Moreover, a trivial method for generating public data by using generative adversarial networks significantly decreases the model accuracy, as reported by the authors of DMP. To overcome this problem, we propose a novel defense against MIAs that uses knowledge distillation without requiring public data. Our experiments show that the privacy protection and accuracy of our defense are comparable to those of DMP for the benchmark tabular datasets used in MIA research, Purchase100 and Texas100, and our defense has a much better privacy-utility trade-off than those of the existing defenses that also do not use public data for the image dataset CIFAR10.
Rishav Chourasia, Batnyam Enkhtaivan, Kunihiro Ito, Junki Mori, Isamu Teranishi, Hikaru Tsuchida 0001
Proc. Priv. Enhancing Technol.1
2021 Differential Privacy Dynamics of Langevin Diffusion and Noisy Gradient Descent
abstract
What is the information leakage of an iterative randomized learning algorithm about its training data, when the internal state of the algorithm is \emph{private}? How much is the contribution of each specific training epoch to the information leakage through the released model? We study this problem for noisy gradient descent algorithms, and model the \emph{dynamics} of R\'enyi differential privacy loss throughout the training process. Our analysis traces a provably \emph{tight} bound on the R\'enyi divergence between the pair of probability distributions over parameters of models trained on neighboring datasets. We prove that the privacy loss converges exponentially fast, for smooth and strongly convex loss functions, which is a significant improvement over composition theorems (which over-estimate the privacy loss by upper-bounding its total value over all intermediate gradient computations). For Lipschitz, smooth, and strongly convex loss functions, we prove optimal utility with a small gradient complexity for noisy gradient descent algorithms.
Rishav Chourasia, Jiayuan Ye 0001, Reza Shokri
NeurIPS1
2017 Type reduction techniques for two-dimensional interval type-2 fuzzy sets
abstract
In this paper, we address the issue of type reduction of multi-dimensional interval type-2 (IT2) fuzzy sets (FSs). We utilize the Karnik-Mendel (KM) algorithm to estimate the centroid boundary of a multi-dimensional footprint of uncertainty (FOU). We deal with two-dimensional (2-D) fuzzy sets as we can visualize the FOU using 3-D plots, thus making the illustration of the methods simple. However, the basic idea can be extended to multiple dimensions. We give a formal definition of the centroid boundary of a 2-D IT2 fuzzy membership function (FMF) and propose two methods for its estimation. The first method computes embedded type-1 (T1) FSs whose centroids constitute the centroid boundary. We obtain the embedded sets by producing slices of the domain using different sets of parallel planes and then apply the KM algorithm over each slice, to obtain “embedded-curves.” For the second method, we approximate our first method by restricting embedded-curves to be “embedded-lines” thus enhancing computational speed. These type reduction techniques can be applied to applications involving multi-dimensional centroid estimation such as, clustering, support vector estimation for dimensionality reduction, fuzzy logic controllers, to mention a few.
Vaibhav Saxena, Nikhil Yadala, Rishav Chourasia, Frank Chung-Hoon Rhee
FUZZ-IEEE3