Sanjay Kariyappa

dblp:223/6062 · DBLP profile ↗
← Back
9ranked-venue papers
6as first author
7since 2021 · last 2024
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 7 · 6 first-author · 6 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 first-author · 2 since 2021Systems, architecture and hardware · 1Security and privacy · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
6 papers
Security and privacy of machine learning · 64% Privacy and data protection · 34% Cryptographic protocols and secure computation · 2%
Artificial intelligence
3 papers
Trustworthy machine learning · 96% Deep learning architectures and training · 4%
Computer architecture, parallel and distributed computing, and storage systems
1 paper
Memory systems · 100%

Topics — the 18 heaviest of 20, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Machine learning › Trustworthy machine learning
interpretability
1.522024
Progressive Inference: Explaining Decoder-Only Sequence Classification Models Using Intermediate Predictions · ICML 2024
SHAP@k: Efficient and Probably Approximately Correct (PAC) Identification of Top-K Features · AAAI 2024
Security and privacy of machine learning
model stealing
1.432021
Protecting DNNs from Theft using an Ensemble of Diverse Models · ICLR 2021
MAZE: Data-Free Model Stealing Attack Using Zeroth-Order Gradient Estimation · CVPR 2021
Defending Against Model Stealing Attacks With Adaptive Misinformation · CVPR 2020
Security and privacy of machine learning › model stealing
model stealing defense
0.922021
Protecting DNNs from Theft using an Ensemble of Diverse Models · ICLR 2021
Defending Against Model Stealing Attacks With Adaptive Misinformation · CVPR 2020
Machine learning › Trustworthy machine learning › interpretability
attribution methods
0.812024
Progressive Inference: Explaining Decoder-Only Sequence Classification Models Using Intermediate Predictions · ICML 2024
Machine learning › Trustworthy machine learning › interpretability
feature importance
0.812024
SHAP@k: Efficient and Probably Approximately Correct (PAC) Identification of Top-K Features · AAAI 2024
Machine learning › Trustworthy machine learning › interpretability
shapley value
0.812024
SHAP@k: Efficient and Probably Approximately Correct (PAC) Identification of Top-K Features · AAAI 2024
Machine learning › Trustworthy machine learning › interpretability › neural network interpretation
transformer interpretability
0.812024
Progressive Inference: Explaining Decoder-Only Sequence Classification Models Using Intermediate Predictions · ICML 2024
Privacy and data protection › privacy-preserving machine learning
federated learning privacy
0.712023
Cocktail Party Attack: Breaking Aggregation-Based Privacy in Federated Learning Using Independent Component Analysis · ICML 2023
Privacy and data protection › privacy-preserving machine learning › federated learning privacy
gradient inversion attack
0.712023
Cocktail Party Attack: Breaking Aggregation-Based Privacy in Federated Learning Using Independent Component Analysis · ICML 2023
Security and privacy of machine learning › privacy attack › data reconstruction attack
gradient leakage attack
0.712023
Cocktail Party Attack: Breaking Aggregation-Based Privacy in Federated Learning Using Independent Component Analysis · ICML 2023
Security and privacy of machine learning
privacy attack
0.712023
Cocktail Party Attack: Breaking Aggregation-Based Privacy in Federated Learning Using Independent Component Analysis · ICML 2023
Privacy and data protection
privacy-preserving machine learning
0.712023
Bounding the Invertibility of Privacy-preserving Instance Encoding using Fisher Information · NeurIPS 2023
Machine learning › Trustworthy machine learning
robustness
0.512021
Protecting DNNs from Theft using an Ensemble of Diverse Models · ICLR 2021
Security and privacy of machine learning › model stealing
data-free model stealing
0.512021
MAZE: Data-Free Model Stealing Attack Using Zeroth-Order Gradient Estimation · CVPR 2021
Memory systems
memory compression
0.412019
Enabling Transparent Memory-Compression for Commodity Memory Systems · HPCA 2019
Machine learning › Deep learning architectures and training › transformer
transformer decoder
0.212024
Progressive Inference: Explaining Decoder-Only Sequence Classification Models Using Intermediate Predictions · ICML 2024
Cryptographic protocols and secure computation
secure aggregation
0.212023
Cocktail Party Attack: Breaking Aggregation-Based Privacy in Federated Learning Using Independent Component Analysis · ICML 2023
Memory systems
DRAM
0.112019
Enabling Transparent Memory-Compression for Commodity Memory Systems · HPCA 2019

Methods — techniques the papers use, named apart from their topics

KernelSHAP · 1.5ensemble of diverse models · 1.0multi-armed bandit · 0.8masked attention · 0.8intermediate predictions · 0.8SamplingSHAP · 0.8information-theoretic bounds · 0.7independent component analysis · 0.7fisher information · 0.7blind source separation · 0.7zeroth-order gradient estimation · 0.5generative model · 0.5out-of-distribution detection · 0.4line location prediction · 0.4inline metadata · 0.4
YearPublicationVenuePosition
2024 SHAP@k: Efficient and Probably Approximately Correct (PAC) Identification of Top-K Features
abstract
The SHAP framework provides a principled method to explain the predictions of a model by computing feature importance. Motivated by applications in finance, we introduce the Top-k Identification Problem (TkIP) (and its ordered variant TkIP- O), where the objective is to identify the subset (or ordered subset for TkIP-O) of k features corresponding to the highest SHAP values with PAC guarantees. While any sampling-based method that estimates SHAP values (such as KernelSHAP and SamplingSHAP) can be trivially adapted to solve TkIP, doing so is highly sample inefficient. Instead, we leverage the connection between SHAP values and multi-armed bandits (MAB) to show that both TkIP and TkIP-O can be reduced to variants of problems in MAB literature. This reduction allows us to use insights from the MAB literature to develop sample-efficient variants of KernelSHAP and SamplingSHAP. We propose KernelSHAP@k and SamplingSHAP@k for solving TkIP; along with KernelSHAP-O and SamplingSHAP-O to solve the ordering problem in TkIP-O. We perform extensive experiments using several credit-related datasets to show that our methods offer significant improvements of up to 40× in sample efficiency and 39× in runtime.
Sanjay Kariyappa, Leonidas Tsepenekas, Freddy Lécué, Daniele Magazzeni
AAAI1
2024 Progressive Inference: Explaining Decoder-Only Sequence Classification Models Using Intermediate Predictions
abstract
This paper proposes Progressive inference–a framework to explain the predictions of decoder-only transformer models trained to perform sequence classification tasks. Our work is based on the insight that the classification head of a decoder-only model can be used to make intermediate predictions by evaluating them at different points in the input sequence. Due to the masked attention mechanism used in decoder-only models, these intermediate predictions only depend on the tokens seen before the inference point, allowing us to obtain the model’s prediction on a masked input sub-sequence, with negligible computational overheads. We develop two methods to provide sub-sequence level attributions using this core insight. First, we propose Single Pass-Progressive Inference (SP-PI) to compute attributions by simply taking the difference between intermediate predictions. Second, we exploit a connection with Kernel SHAP to develop Multi Pass-Progressive Inference (MP-PI); this uses intermediate predictions from multiple masked versions of the input to compute higher-quality attributions that approximate SHAP values. We perform studies on several text classification datasets to demonstrate that our proposal provides better explanations compared to prior work, both in the single-pass and multi-pass settings.
Sanjay Kariyappa, Freddy Lécué, Saumitra Mishra, Christopher Pond, Daniele Magazzeni, Manuela M. Veloso
ICML1
2024 Information Flow Control in Machine Learning through Modular Model Architecture
Trishita Tiwari, Suchin Gururangan, Chuan Guo 0001, Weizhe Hua, Sanjay Kariyappa, Udit Gupta 0001, Wenjie Xiong 0001, Kiwan Maeng, Hsien-Hsin S. Lee, G. Edward Suh
USENIX Security Symposium5
2023 Cocktail Party Attack: Breaking Aggregation-Based Privacy in Federated Learning Using Independent Component Analysis
abstract
Federated learning (FL) aims to perform privacy-preserving machine learning on distributed data held by multiple data owners. To this end, FL requires the data owners to perform training locally and share the gradients or weight updates (instead of the private inputs) with the central server, which are then securely aggregated over multiple data owners. Although aggregation by itself does not offer provable privacy protection, prior work suggested that if the batch size is sufficiently large the aggregation may be secure enough. In this paper, we propose the Cocktail Party Attack (CPA) that, contrary to prior belief, is able to recover the private inputs from gradients/weight updates aggregated over as many as 1024 samples. CPA leverages the crucial insight that aggregate gradients from a fully connected (FC) layer is a linear combination of its inputs, which allows us to frame gradient inversion as a blind source separation (BSS) problem. We adapt independent component analysis (ICA)—a classic solution to the BSS problem—to recover private inputs for FC and convolutional networks, and show that CPA significantly outperforms prior gradient inversion attacks, scales to ImageNet-sized inputs, and works on large batch sizes of up to 1024.
Sanjay Kariyappa, Chuan Guo 0001, Kiwan Maeng, Wenjie Xiong 0001, G. Edward Suh, Moinuddin K. Qureshi, Hsien-Hsin S. Lee
ICML1
2023 Bounding the Invertibility of Privacy-preserving Instance Encoding using Fisher Information
abstract
Privacy-preserving instance encoding aims to encode raw data into feature vectors without revealing their privacy-sensitive information. When designed properly, these encodings can be used for downstream ML applications such as training and inference with limited privacy risk. However, the vast majority of existing schemes do not theoretically justify that their encoding is non-invertible, and their privacy-enhancing properties are only validated empirically against a limited set of attacks. In this paper, we propose a theoretically-principled measure for the invertibility of instance encoding based on Fisher information that is broadly applicable to a wide range of popular encoders. We show that dFIL can be used to bound the invertibility of encodings both theoretically and empirically, providing an intuitive interpretation of the privacy of instance encoding.
Kiwan Maeng, Chuan Guo 0001, Sanjay Kariyappa, G. Edward Suh
NeurIPS3
2021 MAZE: Data-Free Model Stealing Attack Using Zeroth-Order Gradient Estimation
abstract
High quality Machine Learning (ML) models are often considered valuable intellectual property by companies. Model Stealing (MS) attacks allow an adversary with blackbox access to a ML model to replicate its functionality by training a clone model using the predictions of the target model for different inputs. However, best available existing MS attacks fail to produce a high-accuracy clone without access to the target dataset or a representative dataset necessary to query the target model. In this paper, we show that preventing access to the target dataset is not an adequate defense to protect a model. We propose MAZE – a data-free model stealing attack using zeroth-order gradient estimation that produces high-accuracy clones. In contrast to prior works, MAZE uses only synthetic data created using a generative model to perform MS.Our evaluation with four image classification models shows that MAZE provides a normalized clone accuracy in the range of 0.90× to 0.99×, and outperforms even the recent attacks that rely on partial data (JBDA, clone accuracy 0.13× to 0.69×) and on surrogate data (KnockoffNets, clone accuracy 0.52× to 0.97×). We also study an extension of MAZE in the partial-data setting, and develop MAZE-PD, which generates synthetic data closer to the target distribution. MAZE-PD further improves the clone accuracy (0.97× to 1.0×) and reduces the query budget required for the attack by 2×-24×.
Sanjay Kariyappa, Atul Prakash 0001, Moinuddin K. Qureshi
CVPR1
2021 Protecting DNNs from Theft using an Ensemble of Diverse Models
Sanjay Kariyappa, Atul Prakash 0001, Moinuddin K. Qureshi
ICLR1
2020 Defending Against Model Stealing Attacks With Adaptive Misinformation
abstract
Deep Neural Networks (DNNs) are susceptible to model stealing attacks, which allows a data-limited adversary with no knowledge of the training dataset to clone the functionality of a target model, just by using black-box query access. Such attacks are typically carried out by querying the target model using inputs that are synthetically generated or sampled from a surrogate dataset to construct a labeled dataset. The adversary can use this labeled dataset to train a clone model, which achieves a classification accuracy comparable to that of the target model. We propose "Adaptive Misinformation" to defend against such model stealing attacks. We identify that all existing model stealing attacks invariably query the target model with Out-Of-Distribution (OOD) inputs. By selectively sending incorrect predictions for OOD queries, our defense substantially degrades the accuracy of the attacker's clone model (by up to 40%), while minimally impacting the accuracy (<; 0.5%) for benign users. Compared to existing defenses, our defense has a significantly better security vs accuracy trade-off and incurs minimal computational overhead.
Sanjay Kariyappa, Moinuddin K. Qureshi
CVPR1
2019 Enabling Transparent Memory-Compression for Commodity Memory Systems
abstract
Transparent Memory-Compression (TMC) allows the system to obtain the bandwidth benefits of memory compression in an OS-transparent manner. Unfortunately, prior designs for TMC (MemZip) rely on using non-commodity memory modules, which can limit their adoption. We show that TMC can be implemented with commodity memories by storing multiple compressed lines in a single memory location and retrieving all these lines in a single memory access, thereby increasing the effective memory bandwidth. TMC requires metadata to specify the compressibility and location of the line. Unfortunately, even with dedicated metadata caches, maintaining and accessing this metadata incurs significant bandwidth overheads and causes slowdown. Our goal is to enable TMC for commodity memories by eliminating the bandwidth overheads of metadata accesses. This paper proposes PTMC (Practical and Transparent Memory-Compression), a simple design for obtaining bandwidth benefits of memory compression while relying only on commodity (nonECC) memory modules and avoiding any OS support. Our design uses a novel inline-metadata mechanism, whereby the compressibility of the line can be determined by scanning the line for a special marker word, eliminating the overheads of metadata access. We also develop a low-cost Line Location Predictor (LLP) that can determine the location of the line with 98% accuracy and a dynamic solution that disables compression if the benefits of compression are smaller than the overheads. Our evaluations show that PTMC provides a speedup of up to 73%, is robust (no slowdown for any workload), and can be implemented with a total storage overhead of less than 300 bytes.
Vinson Young, Sanjay Kariyappa, Moinuddin K. Qureshi
HPCA2