Jiachun Liao

dblp:134/5942 · DBLP profile ↗
← Back
14ranked-venue papers
7as first author
5since 2021 · last 2024
0000-0001-7439-4645ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Applied, interdisciplinary, general and emerging computing · 6 · 3 first-author · 2 since 2021Security and privacy · 3 · 1 first-author · 2 since 2021Theory of computation · 2 · 2 first-authorArtificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 first-author
YearPublicationVenuePosition
2024 THEF: A Privacy-Preserving Framework for Transformer Inference leveraging HE and TEE
Jiachun Liao, Jinhao Yu, Lei Zhang 0238
TrustCom2
2023 An Adaptive Auxiliary Training Method of Autoencoders and Its Application in Anomaly Detection
Jiachun Liao, Feng Sha, Zhaokun Cheng, Yicheng Qiu
ICONIP (7)2
2023 ConvBNet: A Convolutional Network for Building Footprint Extraction
abstract
Building footprint is a key indicator of urban structures and economic development. Automatic extraction of building footprint from very-high-resolution (VHR) remote sensing imagery, which is of great practical interest for various geospatial-related applications, is still a challenging task for complex textures, varying scales and shapes, and other confusing artificial objects. To alleviate these problems and improve the extraction accuracy, this study proposed a novel pure convolutional neural network called ConvBNet, which integrates ConvNeXt-XL with a fusing decoder and adopts deep supervision in the training stage for the middle stage. Two-stage training strategy, using weighted cross-entropy (CE) loss and mask CE loss, respectively, ensures the stable convergence and makes the network focus on the boundary region. The proposed model was tested on the Wuhan University (WHU) building dataset (publicly available) and one private Zhejiang building dataset. Compared with other state-of-the-art (SOTA) methods, ConvBNet achieved the best intersection over Union (IoU), 91.22% and 77.90% for the two datasets, which proves its good performance in the task of extracting buildings from VHR images.
Panpan Tang, Bo Zhao 0017, Peng Gou, Jiachun Liao, Caifeng Jin
IEEE Geosci. Remote. Sens. Lett.6
2022 Generating Fair Universal Representations Using Adversarial Models
abstract
We present a data-driven framework for learning fair universal representations (FUR) that guarantee statistical fairness for any learning task that may not be known a priori. Our framework leverages recent advances in adversarial learning to allow a data holder to learn representations in which a set of sensitive attributes are decoupled from the rest of the dataset. We formulate this as a constrained minimax game between an encoder and an adversary where the constraint ensures a measure of usefulness (utility) of the representation. The resulting problem is that of censoring, i.e., finding a representation that is least informative about the sensitive attributes given a utility constraint. For appropriately chosen adversarial loss functions, our censoring framework precisely clarifies the optimal adversarial strategy against strong information-theoretic adversaries; it also achieves the fairness measure of demographic parity for the resulting constrained representations. We evaluate the performance of our proposed framework on both synthetic and publicly available datasets. For these datasets, we use two tradeoff measures: censoring vs. representation fidelity and fairness vs. utility for downstream tasks, to amply demonstrate that multiple sensitive features can be effectively censored even as the resulting fair representations ensure accuracy for multiple downstream tasks.
Peter Kairouz, Jiachun Liao, Maunil Vyas, Monica Welfert, Lalitha Sankar
IEEE Trans. Inf. Forensics Secur.2
2021 Neural Network-based Estimation of the MMSE
abstract
The minimum mean-square error (MMSE) achievable by optimal estimation of a random variable$S$given another random variable$T$is of much interest in a variety of statistical contexts. Motivated by a growing interest in auditing machine learning models for unintended information leakage, we propose a neural network-based estimator of this MMSE. We derive a lower bound for the MMSE based on the proposed estimator and the Barron constant associated with the conditional expectation of$S$given$T$. Since the latter is typically unknown in practice, we derive a general bound for the Barron constant that produces order optimal estimates for canonical distribution models.
Mario Díaz, Peter Kairouz, Jiachun Liao, Lalitha Sankar
ISIT3
2020 A Better Bound Gives a Hundred Rounds: Enhanced Privacy Guarantees via f-Divergences
abstract
We derive the optimal differential privacy (DP) parameters of a mechanism that satisfies a given level of Renyí differential privacy (RDP). Our result is based on the joint range of two f-divergences that underlie the approximate and the Renyi variations of differential privacy. We apply our result tó the moments accountant framework for characterizing privacy guarantees of stochastic gradient descent. When compared to the state-of-the-art, our bounds may lead to about 100 more stochastic gradient descent iterations for training deep learning models for the same privacy budget.
Shahab Asoodeh, Jiachun Liao, Flávio P. Calmon, Oliver Kosut, Lalitha Sankar
ISIT2
2019 Robustness of Maximal α-Leakage to Side Information
abstract
Maximal α-leakage is a tunable measure of information leakage based on the accuracy of guessing an arbitrary function of private data based on public data. The parameter α determines the loss function used to measure the accuracy of a belief, ranging from log-loss at α = 1 to the probability of error at α = ∞. To study the effect of side information on this measure, we introduce and define conditional maximal α-leakage. We show that, for a chosen mapping (channel) from the actual (viewed as private) data to the released (public) data and some side information, the conditional maximal α-leakage is the supremum (over all side information) of the conditional Arimoto channel capacity where the conditioning is on the side information. We prove that if the side information is conditionally independent of the public data given the private data, the side information cannot increase the information leakage.
Jiachun Liao, Lalitha Sankar, Oliver Kosut, Flávio P. Calmon
ISIT1
2019 Tunable Measures for Information Leakage and Applications to Privacy-Utility Tradeoffs
abstract
We introduce a tunable measure for information leakage calledmaximal$\alpha $-leakage. This measure quantifies the maximal gain of an adversary in inferring any (potentially random) function of a dataset from a release of the data. The inferential capability of the adversary is, in turn, quantified by a class of adversarial loss functions that we introduce as$\alpha $-loss,$\alpha \in [1,\infty) \cup \{\infty \}$. The choice of$\alpha $determines the specific adversarial action and ranges from refining a belief (about any function of the data) for$\alpha =1$to guessing the most likely value for$\alpha = \infty $while refining the$\alpha ^{\text {th}}$moment of the belief for$\alpha $in between. Maximal$\alpha $-leakage then quantifies the adversarial gain under$\alpha $-loss over all possible functions of the data. In particular, for the extremal values of$\alpha =1$and$\alpha =\infty $, maximal$\alpha $-leakage simplifies to mutual information and maximal leakage, respectively. For$\alpha \in (1,\infty)$this measure is shown to be the Arimoto channel capacity of order$\alpha $. We show that maximal$\alpha $-leakage satisfies data processing inequalities and a sub-additivity property thereby allowing for a weak composition result. Building upon these properties, we use maximal$\alpha $-leakage as the privacy measure and study the problem of data publishing with privacy guarantees, wherein the utility of the released data is ensured via ahard distortionconstraint. Unlike average distortion, hard distortion provides a deterministic guarantee of fidelity. We show that under a hard distortion constraint, for$\alpha >1$the optimal mechanism is independent of$\alpha $, and therefore, the resulting optimal tradeoff is the same for all values of$\alpha >1$. Finally, the tunability of maximal$\alpha $-leakage as a privacy measure is also illustrated for binary data with average Hamming distortion as the utility measure.
Jiachun Liao, Oliver Kosut, Lalitha Sankar, Flávio P. Calmon
IEEE Trans. Inf. Theory1
2018 A Tunable Measure for Information Leakage
abstract
A tunable measure for information leakage called maximal a-leakage is introduced. This measure quantifies the maximal gain of an adversary in refining a tilted version of its prior belief of any (potentially random) function of a dataset conditioning on a disclosed dataset. The choice of α determines the specific adversarial action ranging from refining a belief for α = 1 to guessing the best posterior for α = ∞, and for these extremal values this measure simplifies to mutual information (MI) and maximal leakage (MaxL), respectively. For all other α this measure is shown to be the Arimoto channel capacity. Several properties of this measure are proven including: (i) quasi-convexity in the mapping between the original and disclosed datasets; (ii) data processing inequalities; and (iii) a composition property. A full version of this paper is in [1].
Jiachun Liao, Oliver Kosut, Lalitha Sankar, Flávio P. Calmon
ISIT1
2018 Privacy Under Hard Distortion Constraints
abstract
We study the problem of data disclosure with privacy guarantees, wherein the utility of the disclosed data is ensured via a hard distortion constraint. Unlike average distortion, hard distortion provides a deterministic guarantee of fidelity. For the privacy measure, we use a tunable information leakage measure, namely maximal α-leakage (α ∈ [1, ∞]), and formulate the privacy-utility tradeoff problem. The resulting solution highlights that under a hard distortion constraint, the nature of the solution remains unchanged for both local and nonlocal privacy requirements. More precisely, we show that both the optimal mechanism and the optimal tradeoff are invariant for any α > 1; i.e., the tunable leakage measure only behaves as either of the two extrema, i.e., mutual information for α = 1 and maximal leakage for α = ∞.
Jiachun Liao, Oliver Kosut, Lalitha Sankar, Flávio P. Calmon
ITW1
2018 Hypothesis Testing Under Mutual Information Privacy Constraints in the High Privacy Regime
abstract
Hypothesis testing is a statistical inference framework for determining the true distribution among a set of possible distributions for a given data set. Privacy restrictions may require the curator of the data or the respondents themselves to share data with the test only after applying a randomizing privacy mechanism. This work considers mutual information (MI) as the privacy metric for measuring leakage. In addition, motivated by the Chernoff-Stein lemma, the relative entropy between pairs of distributions of the output (generated by the privacy mechanism) is chosen as the utility metric. For these metrics, the goal is to find the optimal privacy-utility tradeoff (PUT) and the corresponding optimal privacy mechanism for both binary and m-ary hypothesis testing. Focusing on the high privacy regime, Euclidean information-theoretic approximations of the binary and m-ary PUT problems are developed. The solutions for the approximation problems clarify that an MI-based privacy metric preserves the privacy of the source symbols in inverse proportion to their likelihoods.
Jiachun Liao, Lalitha Sankar, Vincent Y. F. Tan, Flávio P. Calmon
IEEE Trans. Inf. Forensics Secur.1
2017 Hypothesis testing under maximal leakage privacy constraints
abstract
The problem of publishing privacy-guaranteed data for hypothesis testing is studied using the maximal leakage (ML) as a metric for privacy and the type-II error exponent as the utility metric. The optimal mechanism (random mapping) that maximizes utility for a bounded leakage guarantee is determined for the entire leakage range for binary datasets. For non-binary datasets, approximations in the high privacy and high utility regimes are developed. The results show that, for any desired leakage level, maximizing utility forces the ML privacy mechanism to reveal partial to complete knowledge about a subset of the source alphabet. The results developed on maximizing a convex function over a polytope may also of an independent interest.
Jiachun Liao, Lalitha Sankar, Flávio P. Calmon, Vincent Y. F. Tan
ISIT1
2014 Which is better: One-way or two-way relaying with an amplify-and-forward relay?
abstract
Amplify-and-forward (AF) based two-way relaying (TWR) has shown its sum rate advantage over AF based one-way relaying (OWR) in the literature. However, this advantage can not be achieved in some cases. In this paper, we evaluate the sum rates of AF based OWR/TWR and provide the relationship with respect to the relative channel gains and the relative transmit power of the three nodes, i.e., the relay node and two source nodes. Upon this, we determine the metric on choosing OWR or TWR given instantaneous channel state information and we further devise power allocation schemes. At last, the numerical results validate our conclusion and reveal some interesting facts.
Jiachun Liao, Fanggang Wang 0001, Dongping Yao, Miao Wang 0011
WCNC1
2012 Research on Downlink Synchronization for TETRA Release II
abstract
A frequency-timing synchronization scheme for the downlink of filtered multitone modulation (FMT) based Terrestrial Trunked Radio (TETRA) system is presented. To achieve high-rate data transmission and better transmission quality, TETRA2 has been proposed in recent years. However, there are serious issues with the new wide-band TETRA system in frequency-timing synchronization. TETRA mainly specifies 2 sequences for downlink synchronization, i.e. downlink sync sequence set (DSS) and frequency correction set (FrCS). Researching the cross-correlation properties of these sequences and the existing data-aided synchronization algorithm for FMT, we propose an efficient method to estimate the frequency-offset and timing-offset for TETRA2 and analyze its performance in AWGN.
Hongpeng Liu, Dongping Yao, Jiachun Liao
PDCAT3