EDBT 2026 Demo / reviewers in the wild / expert
Ayse Ünsal
dblp:132/9072
· DBLP profile ↗
13ranked-venue papers
7as first author
4since 2021 · last 2024
0000-0001-5313-1168ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Theory of computation · 5 · 3 first-author · 1 since 2021Security and privacy · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-authorComputer networks · 2 · 2 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Link Inference Attacks in Vertical Federated Graph LearningabstractVertical Federated Graph Learning (VFGL) is a novel privacy-preserving technology that enables entities to collaborate on training Machine Learning (ML) models without exchanging their raw data. In VFGL, some of the entities hold a graph dataset capturing sensitive user relations, as in the case of social networks. This collaborative effort aims to leverage diverse features from each entity about shared users to enhance predictive models or recommendation systems, while safeguarding data privacy in the process. Despite these advantages, recent studies have revealed a critical vulnerability that appears in intermediate data representations, which may inadvertently expose link information in the graph. This work proposes a novel Link Inference Attack (LIA) that exploits gradients as a new source of link information leakage. Assuming a semi-honest adversary, we demonstrate through extensive experiments on seven real-world datasets that our LIA outperforms state-of-the-art attacks, achieving over 10% higher Area Under the Curve (AUC) in some instances, thereby highlighting a significant risk of link information leakage through gradients. Our attack’s effectiveness primarily stems from label information embedded in gradients, as evidenced by comparison with a label-only LIA. We analytically derive our Label-based LIA’s accuracy using graph characteristics, assessing target graph vulnerability. To address these vulnerabilities, we evaluate two types of defenses: edge perturbation based on differential privacy and a novel label perturbation approach, demonstrating that our proposed label perturbation defense is more effective against all attack types across all datasets examined, offering a more favorable privacy-utility trade-off. Our comprehensive analysis shows why LIAs are effective and identifies potential defenses, highlighting the need for further research to improve the security of VFGL systems against link information leakage. Oualid Zari, Chuan Xu 0002, Javier Parra-Arnau, Ayse Ünsal, Melek Önen |
ACSAC | 4 |
| 2024 | Node Injection Link Stealing Attack
Oualid Zari, Javier Parra-Arnau, Ayse Ünsal, Melek Önen |
PSD | 3 |
| 2022 | Membership Inference Attack Against Principal Component Analysis
Oualid Zari, Javier Parra-Arnau, Ayse Ünsal, Thorsten Strufe, Melek Önen |
PSD | 3 |
| 2021 | A Statistical Threshold for Adversarial Classification in Laplace MechanismsabstractThis paper studies the statistical characterization of detecting an adversary who wants to harm some computation such as machine learning models or aggregation by altering the output of a differentially private mechanism in addition to discovering some information about the underlying dataset. An adversary who is able to modify the published information from a differentially private mechanism aims to maximize the possible damage to the system while remaining undetected. We present a trade-off between the privacy parameter of the system, the sensitivity and the attacker’s advantage (the bias) through determining the threshold for the best critical region of the hypothesis testing problem for deciding whether or not the adversary’s attack is detected. Such tradeoffs are provided for Laplace mechanisms using one-sided and two-sided hypothesis tests. Corresponding error probabilities are analytically derived and ROC curves are presented for various levels of the sensitivity, the absolute mean of the attack and the privacy parameter. Subsequently, we provide an interval for the bias induced by the adversary so that the defender detects the attack. Finally, we adapt the Kullback-Leibler differential privacy to adversarial classification. Ayse Ünsal, Melek Önen |
ITW | 1 |
| 2020 | Fundamental Limits of Coded Caching With Multiple Antennas, Shared Caches and Uncoded PrefetchingabstractThe work explores the fundamental limits of coded caching in the setting where a transmitter with potentially multiple (N0) antennas serves different users that are assisted by a smaller number of caches. Under the assumption of uncoded cache placement, the work derives the exact optimal worst-case delay and DoF, for a broad range of user-to-cache association profiles where each such profile describes how many users are helped by each cache. This is achieved by presenting an information-theoretic converse based on index coding that succinctly captures the impact of the user-to-cache association, as well as by presenting a coded caching scheme that optimally adapts to the association profile by exploiting the benefits of encoding across users that share the same cache. The work reveals a powerful interplay between shared caches and multiple senders/antennas, where we can now draw the striking conclusion that, as long as each cache serves at least N0users, adding a single degree of cache-redundancy can yield a DoF increase equal to N0, while at the same time - irrespective of the profile - going from 1 to N0antennas reduces the delivery time by a factor of N0. Finally some conclusions are also drawn for the related problem of coded caching with multiple file requests. Emanuele Parrinello, Ayse Ünsal, Petros Elia |
IEEE Trans. Inf. Theory | 2 |
| 2019 | Optimal Coded Caching under Statistical QoS InformationabstractThe work studies the K -user shared-link broadcast channel with coded caching, where each user's file-request comes with a certain Quality-of-Service (QoS) requirement, thus allowing - in the context of multi-layered coding - users to download only those file layers that are necessary to meet their own QoS requirements. The work characterizes the exact optimal worst-case delivery time, under the assumption of uncoded cache placement that is oblivious to the individual QoS requirement of each user. The work derives a new index coding based information theoretic converse, which interestingly tells us exactly how to optimally cache. Emanuele Parrinello, Ayse Ünsal, Petros Elia |
ISIT | 2 |
| 2018 | Optimal coded caching in heterogeneous networks with uncoded prefetchingabstractIn the context of caching in heterogeneous networks, the work explores the setting where a multi-antenna transmitter (No antennas), broadcasts to K receiving users, each assisted by one of Λ ≤ K helper nodes serving as limited-sized caches. Our aim is to identify the limits of coded caching when there are fewer caches than users (Λ0, adding a single degree of cache-redundancy yields a caching-gain increase equal to No, and similarly, adding antennas has a multiplicative DoF impact where for example introducing a second transmit antenna can double the DoF. Emanuele Parrinello, Ayse Ünsal, Petros Elia |
ITW | 2 |
| 2018 | Converse Bounds on Modulation-Estimation Performance for the Gaussian Multiple-Access ChannelabstractThis paper focuses on the problem of separately modulating and jointly estimating two independent continuous-valued parameters sent over a Gaussian multiple-access channel (MAC) under the mean square error (MSE) criterion without bandwidth constraints. To this end, we first improve an existing lower bound on the MSE that is obtained using the parameter modulation-estimation techniques for the single-user additive white Gaussian noise (AWGN) channel. As for the main contribution of this paper, this improved modulation-estimation analysis is generalized to the model of the two-user Gaussian MAC. We present outer bounds to the achievable region in the plane of the MSE's of the two user parameters, which provides a trade-off between the MSE's, where we used zero-rate lower bounds on the error probability of Gaussian channels by Shannon and Polyanskiy et al. Numerical results showed that, the multi-user adaptation of the zero-rate lower bound by Polyanskiy et al. provides a tighter overall lower bound on the MSE pairs than the classical Shannon bound. In addition, we introduced upper bounds on the MSE exponents, namely, the exponential decay rates of these MSE's in the asymptotic regime of long blocks that could make use of any bound on the error exponent of a single-user AWGN channel. The obtained results are numerically evaluated for three different bounds on the reliability function of the Gaussian channel. It is shown that the adaptation of the reliability function by Ashikhmin et al. to the MAC provides a significantly tighter characterization than Shannon's sphere-packing bound and the divergence bound. Ayse Ünsal, Raymond Knopp, Neri Merhav |
IEEE Trans. Inf. Theory | 1 |
| 2017 | The dispersion of superposition coding for Gaussian broadcast channelsabstractIn this paper, we analyze the performance of superposition coding for Gaussian broadcast channels with finite blocklength. To this end, we adapt two different achievability bounds, the dependence testing and the κβ bounds introduced by Polyanskiy et al. in 2010 to the broadcast setting. The distinction between these bounds lies in fixing either the input or the output distributions of the channel. For the first case of the dependence testing bound, an upper bound on the average error probability of the system is derived whereas for the latter, lower bounds on the maximal code sizes of each user are presented1. Ayse Ünsal, Jean-Marie Gorce |
ITW | 1 |
| 2016 | Lower bounds on joint modulation-estimation performance for the Gaussian MACabstractThis paper considers the problem of jointly estimating two independent continuous-valued parameters sent over a Gaussian multiple-access channel (MAC) subject to the mean square error (MSE) as a fidelity criterion. We generalize the parameter modulation-estimation analysis techniques proposed by Merhav in 2012 to a two-user multiple-access channel model to obtain outer bounds to the achievable region in the plane of the MSE's of the two user parameters, as well as the achievable region of the exponential decay rates of these MSE's in the asymptotic regime of long blocks. Ayse Ünsal, Raymond Knopp, Neri Merhav |
ISIT | 1 |
| 2016 | Transmission of Sporadic Analog Samples Over Wireless ChannelsabstractA low-latency, parameter modulation-estimation feedback protocol for wide-band channels is introduced for both pure line-of-sight and more general fading channels with several degrees of freedom. One round of the protocol consists of a data phase and a control phase and uses noncoherent detection. The asymptotic optimality in energy efficiency of the protocol is analyzed and an upper bound on the distortion level is derived for two rounds. The proposed scheme, as well as known one-way schemes, are compared with classical and very recent lower bounds. Both the lower bounds and performance evaluation of the feedback protocol are extended to a multichannel fading model. The improvement of the feedback protocol over one-shot transmission is shown to be very significant on both line-of-sight and fading channels. Ayse Ünsal, Raymond Knopp |
IEEE Trans. Commun. | 1 |
| 2015 | Distributed Sensing and Transmission of Sporadic Random Samples Over a Multiple-Access ChannelabstractThis work considers distributed sensing and transmission of sporadic random samples. A new lower-bound is presented on the reconstruction error of a common vector imperfectly measured by a network of sensors. The noisy correlated observations of the source vector are transmitted with finite energy to a single receiver via an additive white Gaussian noise asynchronous multiple-access channel (MAC). Transmission makes use of a perfect causal feedback link to the encoder connected to each sensor. Asymptotic upper-bounds on the distortion are provided for a retransmission protocol which is inspired by the classical scheme of Yamamoto and Itoh and extended to a more general network scenario. Additionally, we introduce lower-bounds on the reconstruction error for individual estimators of the noisy observations themselves. Both the upper and lower-bounds show that collaboration can be achieved through energy accumulation under certain circumstances. To investigate the practical performance of the proposed protocol we provide a numerical evaluation of the upper-bounds in the non-asymptotic energy regime using low-order quantization in the sensors. It is shown that an increase in the size of the network brings benefit in terms of performance, but that the gain in terms of energy efficiency diminishes quickly at finite energies due to a non-coherent combining loss. Ayse Ünsal, Raymond Knopp |
IEEE Trans. Commun. | 1 |
| 2013 | Distributed sensing and transmission of sporadic random samplesabstractThis work considers distributed sensing and transmission of sporadic random samples. Lower bounds are derived for the reconstruction error of a single normally or uniformly-distributed vector imperfectly measured by a network of sensors and transmitted with finite energy to a common receiver via an additive white Gaussian noise asynchronous multiple-access channel. Transmission makes use of a perfect causal feedback link to the encoder connected to each sensor. A retransmission protocol inspired by the classical scheme in [1] applied to the transmission of single and bi-variate analog samples analyzed in [2] and [3] is extended to the more general network scenario, for which asymptotic upper-bounds on the reconstruction error are provided. Both the upper and lower-bounds show that collaboration can be achieved through energy accumulation under certain circumstances. Ayse Ünsal, Raymond Knopp |
ISIT | 1 |