Aoting Hu

dblp:293/5527 · DBLP profile ↗
← Back
3ranked-venue papers
3as first author
3since 2021 · last 2024
0000-0002-9554-5817ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2024 ${\sf VeriDIP}$VeriDIP: Verifying Ownership of Deep Neural Networks Through Privacy Leakage Fingerprints
abstract
Deploying Machine Learning as a Service gives rise to model plagiarism, leading to copyright infringement. Ownership testing techniques are designed to identify model fingerprints for verifying plagiarism. However, previous works often rely on overfitting or robustness features as fingerprints, lacking theoretical guarantees and exhibiting under-performance on generalized models. In this paper, we propose a novel ownership testing method called VeriDIP, whichverifies aDNN model'sintellectualproperty. VeriDIP makes two major contributions. (1) It utilizes membership inference attacks to estimate the lower bound of privacy leakage, which reflects the fingerprint of a given model. The privacy leakage fingerprints highlight the unique patterns through which the models memorize sensitive training datasets. (2) We introduce a novel approach using less private samples to enhance the performance of ownership testing. Extensive experimental results confirm that VeriDIP is effective and efficient in validating the ownership of deep learning models trained on both image and tabular datasets. VeriDIP achieves comparable performance to state-of-the-art methods on image datasets while significantly reducing computation and communication costs. Enhanced VeriDIP demonstrates superior verification performance on generalized deep learning models, particularly on table-trained models. Additionally, VeriDIP exhibits similar effectiveness on utility-preserving differentially private models compared to non-differentially private baselines.
Aoting Hu, Zhigang Lu 0001, Renjie Xie, Minhui Xue 0001
IEEE Trans. Dependable Secur. Comput.1
2021 TableGAN-MCA: Evaluating Membership Collisions of GAN-Synthesized Tabular Data Releasing
abstract
Generative Adversarial Networks (GAN)-synthesized table publishing lets people privately learn insights without access to the private table. However, existing studies on Membership Inference (MI) Attacks show promising results on disclosing membership of training datasets of GAN-synthesized tables. Different from those works focusing on discovering membership of a given data point, in this paper, we propose a novel Membership Collision Attack against GANs (TableGAN-MCA), which allows an adversary given only synthetic entries randomly sampled from a black-box generator to recover partial GAN training data. Namely, a GAN-synthesized table immune to state-of-the-art MI attacks is vulnerable to the TableGAN-MCA. The success of TableGAN-MCA is boosted by an observation that GAN-synthesized tables potentially collide with the training data of the generator.
Aoting Hu, Renjie Xie, Zhigang Lu 0001, Aiqun Hu, Minhui Xue 0001
CCS1
2021 Identity-Preserving Public Integrity Checking with Dynamic Groups for Cloud Storage
abstract
Despite a variety of security threats, cloud storage is on the increase especially when a group of users need to store and share data. Identity-privacy and user dynamic operation are of growing concern in public integrity checking (PIC) scheme. In this paper, we develop an identity-preserving public integrity checking scheme with dynamic groups (IPIC-DG) for cloud storage. Firstly, our IPIC-DG scheme can realize the whole anonymity. On the one hand, no one except the group manager can discover the real identity of users. On the other hand, even the manager, who issues user's secret key, is not capable of forging signatures on behalf of others. Secondly, we propose an anonymous public integrity verification protocol which not only supports integrity checking without retrieving whole data from the cloud, but also protects the signer's identity during the whole process. We utilize group signature to construct a homomorphic authenticator on each file block to guarantee the anonymous remote data integrity checking. Thirdly, our scheme supports a way of dynamic user operation that greatly improves the efficiency and feasibility of user revocation. At last, we formally prove our IPIC-DG scheme is IND-CCA security. Experimental results show that our work performs well in practical application.
Aoting Hu, Bharat K. Bhargava
IEEE Trans. Serv. Comput.1