Bipin Paudel

dblp:329/9567 · DBLP profile ↗
← Back
5ranked-venue papers
3as first author
5since 2021 · last 2026
0009-0006-6693-6743ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Theory of computation · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Sanitization or Deception? Rethinking Privacy Protection in Large Language Models
abstract
Large language models have shown considerable abilities across many tasks, but their capacity to detect sensitive user information from text raises significant privacy concerns. While recent approaches have explored sanitizing text to hide private features, a deeper challenge remains: distinguishing true privacy preservation from deceptive transformations. In this paper, we investigate whether LLM-based sanitization reduces private feature leakage without misleading an adversary into confidently predicting incorrect labels. Using LLM as both sanitizer and adversary, we measure leakage using two entropy-based metrics: Empirical Average Objective Leakage (E-AOL) and Empirical Average Confidence Boost (E-ACB). These allow us to quantify not only how accurate adversarial predictions are, but also how confident they remain post-sanitization. We posit that deception, while reducing adversarial accuracy, will also increase confidence in incorrect inferences, and hence reduced accuracy alone should not be interpreted as true privacy. We show that while current LLMs can hide private features, their transformations sometimes cause deception. Finally, we evaluate the semantic utility of sanitized outputs using sentence embeddings, LLM-based similarity judgments, and standard metrics like BLEU and ROUGE. Our findings emphasize the importance of explicitly distinguishing between privacy and deception in LLM-based sanitization and provide a framework for evaluating this distinction under realistic adversarial conditions.
Bipin Paudel, Bishwas Mandal, George T. Amariucai, Shuangqing Wei
Proc. Priv. Enhancing Technol.1
2025 Semi-Supervised Relation Extraction Informed by Area Under the Margin Ranking and Large Language Models
abstract
Relation extraction is an important task for understanding relationships between entities, building knowledge graphs, and facilitating knowledge discovery. Pre-trained models can be fine-tuned for relation extraction if a substantial amount of labeled data is available. However, acquiring extensive labeled data is generally challenging. Semi-supervised techniques for low-resource relation extraction, such as self-training, offer a promising solution by leveraging both limited labeled data and vast unlabeled data to mitigate this challenge. Traditional self-training methods use a teacher-student framework, where a student is iteratively trained with pseudo-labels generated by the teacher. This may lead to noisy pseudo-labels and impact performance. To address this limitation, we introduce a new model called RE-AUM-LLM that generates high-quality pseudo-labels using self-training combined with Area Under the Margin (AUM) and Large Language Models (LLMs), such as Llama 3.1. Experimental results on two benchmark datasets show that the proposed approach achieves state-of-the-art results for low-resource relation extraction by comparison with several strong baselines. We will make the code publicly available to enable reproducibility and further research in this area.
Nikita Gautam, Bipin Paudel, Doina Caragea, Cornelia Caragea
DSAA2
2024 Robust Detection in Power Systems: Iterative Reinforcement Learning Based Adversarial Training
abstract
Stealthy cyberattacks pose a significant threat to modern power systems by exploiting advanced techniques to manipulate system behavior while avoiding detection by traditional security measures. In this study, we focus on the impact of Deep Reinforcement Learning (DRL) based attackers on a sample microgrid and develop robust detectors to mitigate these threats. Leveraging an iterative training process, we enhance the capabilities of successive attackers and detectors, resulting in improved system security. Our experiments demonstrate that DRL-based attackers can effectively disrupt system operations, highlighting the importance of robust detection mechanisms. Subsequently, we develop robust detection mechanisms, making new attacker attempts unsuccessful. We show that detectors developed through our mechanism are more effective in mitigating system impact and quickly identifying anomalies.
Bipin Paudel, George T. Amariucai, Alireza Zare, Mohammad B. Shadmand
IECON1
2023 Reinforcement Learning Approach to Generate Zero-Dynamics Attacks on Control Systems Without State Space Models
Bipin Paudel, George T. Amariucai
ESORICS (4)1
2022 Neural Fuzzy Extractors: A Secure Way to Use Artificial Neural Networks for Biometric User Authentication
abstract
Powered by new advances in sensor development and artificial intelligence, the decreasing cost of computation, and the pervasiveness of handheld computation devices, biometric user authentication (and identification) is rapidly becoming ubiquitous. Modern approaches to biometric authentication, based on sophisticated machine learning techniques, cannot avoid storing either trained-classifier details or explicit user biometric data, thus exposing users’ credentials to falsification. In this paper, we introduce a secure way to handle user-specific information involved with the use of artificial neural networks for biometric authentication. Our proposed architecture, called a Neural Fuzzy Extractor (NFE), allows the coupling of pre-existing classifiers with fuzzy extractors, through an artificial-neuralnetwork-based buffer called an expander, with minimal or no performance degradation. The NFE thus offers all the performance advantages of modern deep-learningbased classifiers and all the security of standard fuzzy extractors. We demonstrate the NFE retrofit of a few classic artificial neural networks, for simple biometric authentication scenarios.
Abhishek Jana, Bipin Paudel, Md. Kamruzzaman Sarker, Monireh Ebrahimi, Pascal Hitzler, George T. Amariucai
Proc. Priv. Enhancing Technol.2