Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Gabriel Ritter

dblp:359/6103 · DBLP profile ↗
← Back
2ranked-venue papers
0as first author
2since 2021 · last 2025
0009-0006-3407-1247ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Artificial intelligence
1 paper
Trustworthy machine learning · 50% Efficient and distributed learning · 50%

Topics — the 1 heaviest of 2, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Machine learning › Trustworthy machine learning › robustness › adversarial robustness
adversarial robustness of language models
0.712023
BERT Lost Patience Won't Be Robust to Adversarial Slowdown · NeurIPS 2023

Methods — techniques the papers use, named apart from their topics

input sanitization · 0.7adversarial training · 0.7adversarial text attack · 0.7
YearPublicationVenuePosition
2025 In Pursuit of Lean OS Kernels: Improving Configuration-Based Debloating
abstract
Modern OS kernels are bloated to support diverse hardware and features, yet most deployments use only a small subset. This paper advances configuration-based kernel debloating to reduce attack surface and code size in systems with known workloads. We present Tracie,a trace-based specialization tool that improves precision through better workload attribution and trace-to-config mapping, achieving a 21.67% reduction—outperforming prior work by 8%—and removing 1 additional CVEs. We also introduce Dice, a novel trace-free, dependency-aware debloating approach that iteratively prunes the configuration graph, achieving 35.59% reduction and eliminating 10 more CVEs. Finally, we empirically analyze the Linux kconfig system and show that structural limitations—such as coarse granularity and rigid dependencies—constrain the effectiveness of configuration-based debloating.
Akshith Gunasekaran, Gabriel Ritter, Rakesh Bobba
ACSAC2
2023 BERT Lost Patience Won't Be Robust to Adversarial Slowdown
abstract
In this paper, we systematically evaluate the robustness of multi-exit language models against adversarial slowdown. To audit their robustness, we design a slowdown attack that generates natural adversarial text bypassing early-exit points. We use the resulting WAFFLE attack as a vehicle to conduct a comprehensive evaluation of three multi-exit mechanisms with the GLUE benchmark against adversarial slowdown. We then show our attack significantly reduces the computational savings provided by the three methods in both white-box and black-box settings. The more complex a mechanism is, the more vulnerable it is to adversarial slowdown. We also perform a linguistic analysis of the perturbed text inputs, identifying common perturbation patterns that our attack generates, and comparing them with standard adversarial text attacks. Moreover, we show that adversarial training is ineffective in defeating our slowdown attack, but input sanitization with a conversational model, e.g., ChatGPT, can remove perturbations effectively. This result suggests that future work is needed for developing efficient yet robust multi-exit models. Our code is available at: https://github.com/ztcoalson/WAFFLE
Zachary Coalson, Gabriel Ritter, Rakesh Bobba, Sanghyun Hong 0001
NeurIPS2