Anisa Halimi

dblp:157/1104 · DBLP profile ↗
← Back
9ranked-venue papers
4as first author
7since 2021 · last 2025
0009-0005-6956-0908ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 3 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 Towards a Re-evaluation of Data Forging Attacks in Practice
Mohamed Suliman 0002, Anisa Halimi, Swanand Kadhe, Nathalie Baracaldo, Douglas J. Leith
USENIX Security Symposium2
2024 AUTOLYCUS: Exploiting Explainable Artificial Intelligence (XAI) for Model Extraction Attacks against Interpretable Models
abstract
Explainable Artificial Intelligence (XAI) aims to uncover the decision-making processes of AI models. However, the data used for such explanations can pose security and privacy risks. Existing literature identifies attacks on machine learning models, including membership inference, model inversion, and model extraction attacks. These attacks target either the model or the training data, depending on the settings and parties involved. XAI tools can increase the vulnerability of model extraction attacks, which is a concern when model owners prefer black-box access, thereby keeping model parameters and architecture private. To exploit this risk, we propose AUTOLYCUS, a novel retraining (learning) based model extraction attack framework against interpretable models under black-box settings. As XAI tools, we exploit Local Interpretable Model-Agnostic Explanations (LIME) and Shapley values (SHAP) to infer decision boundaries and create surrogate models that replicate the functionality of the target model. LIME and SHAP are mainly chosen for their realistic yet information-rich explanations, coupled with their extensive adoption, simplicity, and usability. We evaluate AUTOLYCUS on six machine learning datasets, measuring the accuracy and similarity of the surrogate model to the target model. The results show that AUTOLYCUS is highly effective, requiring significantly fewer queries compared to state-of-the-art attacks, while maintaining comparable accuracy and similarity. We validate its performance and transferability on multiple interpretable ML models, including decision trees, logistic regression, naive bayes, and k-nearest neighbor. Additionally, we show the resilience of AUTOLYCUS against proposed countermeasures.
Abdullah Çaglar Öksüz, Anisa Halimi, Erman Ayday
Proc. Priv. Enhancing Technol.2
2023 Privacy preserving identification of population stratification for collaborative genomic research
abstract
The rapid improvements in genomic sequencing technology have led to the proliferation of locally collected genomic datasets. Given the sensitivity of genomic data, it is crucial to conduct collaborative studies while preserving the privacy of the individuals. However, before starting any collaborative research effort, the quality of the data needs to be assessed. One of the essential steps of the quality control process is population stratification: identifying the presence of genetic difference in individuals due to subpopulations. One of the common methods used to group genomes of individuals based on ancestry is principal component analysis (PCA). In this article, we propose a privacy-preserving framework which utilizes PCA to assign individuals to populations across multiple collaborators as part of the population stratification step. In our proposed client-server-based scheme, we initially let the server train a global PCA model on a publicly available genomic dataset which contains individuals from multiple populations. The global PCA model is later used to reduce the dimensionality of the local data by each collaborator (client). After adding noise to achieve local differential privacy (LDP), the collaborators send metadata (in the form of their local PCA outputs) about their research datasets to the server, which then aligns the local PCA results to identify the genetic differences among collaborators' datasets. Our results on real genomic data show that the proposed framework can perform population stratification analysis with high accuracy while preserving the privacy of the research participants.
Leonard Dervishi, Wenbiao Li, Anisa Halimi, Xiaoqian Jiang, Jaideep Vaidya, Erman Ayday
Bioinform.3
2022 Facilitating Federated Genomic Data Analysis by Identifying Record Correlations while Ensuring Privacy
Leonard Dervishi, Xinyue Wang 0003, Anisa Halimi, Jaideep Vaidya, Xiaoqian Jiang, Erman Ayday
AMIA4
2022 ShareTrace: Contact Tracing with the Actor Model
abstract
Proximity-based contact tracing relies on mobile-device interaction to estimate the spread of disease. ShareTrace is one such approach that improves the efficacy of tracking disease spread by considering direct and indirect forms of contact. In this work, we utilize the actor model to provide an efficient and scalable formulation of ShareTrace with asynchronous, concurrent message passing on a temporal contact network. We also introduce message reachability, an extension of temporal reachability that accounts for network topology and message-passing semantics. Our evaluation on both synthetic and real-world contact networks indicates that correct parameter values optimize for algorithmic accuracy and efficiency. In addition, we demonstrate that message reachability can accurately estimate the risk a user poses to their contacts.
Ryan Tatton, Erman Ayday, Youngjin Yoo, Anisa Halimi
HealthCom4
2022 Privacy-Preserving and Efficient Verification of the Outcome in Genome-Wide Association Studies
abstract
Providing provenance in scientific workflows is essential for reproducibility and auditability purposes. In this work, we propose a framework that verifies the correctness of the aggregate statistics obtained as a result of a genome-wide association study (GWAS) conducted by a researcher while protecting individuals' privacy in the researcher's dataset. In GWAS, the goal of the researcher is to identify highly associated point mutations (variants) with a given phenotype. The researcher publishes the workflow of the conducted study, its output, and associated metadata. They keep the research dataset private while providing, as part of the metadata, a partial noisy dataset (that achieves local differential privacy). To check the correctness of the workflow output, a verifier makes use of the workflow, its metadata, and results of another GWAS (conducted using publicly available datasets) to distinguish between correct statistics and incorrect ones. For evaluation, we use real genomic data and show that the correctness of the workflow output can be verified with high accuracy even when the aggregate statistics of a small number of variants are provided. We also quantify the privacy leakage due to the provided workflow and its associated metadata and show that the additional privacy risk due to the provided metadata does not increase the existing privacy risk due to sharing of the research results. Thus, our results show that the workflow output (i.e., research results) can be verified with high confidence in a privacy-preserving way. We believe that this work will be a valuable step towards providing provenance in a privacy-preserving way while providing guarantees to the users about the correctness of the results.
Anisa Halimi, Leonard Dervishi, Erman Ayday, Apostolos Pyrgelis, Juan Ramón Troncoso-Pastoriza, Jean-Pierre Hubaux, Xiaoqian Jiang, Jaideep Vaidya
Proc. Priv. Enhancing Technol.1
2021 Real-time privacy risk quantification in online social networks
abstract
Matching the anonymous profile of an individual in an online social network (OSN) to their real identity raises serious privacy concerns as one can obtain sensitive information about that individual. Previous work has formulated the profile matching risk in several different ways and has shown that there exists a non-negligible risk of matching user profiles across OSNs. However, they are not practical to convey the risk to OSN users in real-time. In this work, using the output of such formulation, we model the profile characteristics of users that are vulnerable to profile matching via machine learning and make probabilistic inferences about how the vulnerabilities of users change as they share new content in OSNs (or as their graph connectivity changes). We evaluate the generated models in real data. Our results show that the generated models determine with high accuracy whether a user profile is vulnerable to profile matching risk by only analyzing their publicly available information in the anonymous OSN. In addition, we develop optimization-based countermeasures to preserve the user's privacy as they share their OSN profile with third parties. We believe that this work will be crucial for OSN users to understand their privacy risks due to their public sharings and be more conscious about their online privacy.
Anisa Halimi, Erman Ayday
ASONAM1
2020 Efficient Quantification of Profile Matching Risk in Social Networks Using Belief Propagation
Anisa Halimi, Erman Ayday
ESORICS (1)1
2020 Profile Matching Across Online Social Networks
Anisa Halimi, Erman Ayday
ICICS1