EDBT 2026 Demo / reviewers in the wild / expert
Vasisht Duddu
dblp:217/3190
· DBLP profile ↗
12ranked-venue papers
6as first author
10since 2021 · last 2026
0000-0003-2138-4341ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 3 first-author · 7 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Locket: Robust Feature-Locking Technique for Language ModelsabstractChatbot service providers (e.g., OpenAI) rely on tiered subscription plans to generate revenue, offering black-box access to basic models for free users and advanced models to paying subscribers.However, this approach is unprofitable and inflexible.A pay-to-unlock scheme for premium features (e.g., math, coding) offers a more sustainable alternative.Enabling such a scheme requires a feature-locking technique (FLoTE) that is (i) effective in refusing locked features, (ii) utility-preserving for unlocked features, (iii) robust against evasion or unauthorized credential sharing, and (iv) scalable to multiple features and clients.Existing FLoTEs (e.g., password-locked models) fail to meet these criteria.To fill this gap, we present LOCKET, a more robust and scalable FLoTE to enable pay-to-unlock schemes.We develop a framework for adversarial training and merging of feature-locking adapters, which enables LOCKET to selectively disable specific features of a model.Evaluation shows that LOCKET is effective (100% refusal rate), utility-preserving (≤ 7% utility degradation), robust (≤ 5% attack success rate), and scalable to multiple features and clients. Lipeng He, Vasisht Duddu, N. Asokan |
ACL (1) | 2 |
| 2026 | Privacy Bias in Language Models: A Contextual Integrity-based Auditing MetricabstractAs large language models (LLMs) are integrated into sociotechnical systems, it is crucial to examine the privacy biases they exhibit. We define privacy bias as the appropriateness value of information flows in LLM responses. A deviation between privacy biases and expected values, referred to as privacy bias delta, may indicate privacy violations. As an auditing metric, privacy bias can help (a) model trainers evaluate the ethical and societal impact of LLMs, (b) service providers select context-appropriate LLMs, and (c) policymakers assess the appropriateness of privacy biases in deployed LLMs. We formulate and answer a novel research question: how can we reliably examine privacy biases in LLMs and the factors that influence them? We present a novel approach for assessing privacy biases using a contextual integrity-based methodology to evaluate the responses from various LLMs. Our approach accounts for the sensitivity of responses across prompt variations, which hinders the evaluation of privacy biases. Finally, we investigate how privacy biases are affected by model capacities and optimizations. Yan Shvartzshnaider, Vasisht Duddu |
Proc. Priv. Enhancing Technol. | 2 |
| 2025 | Espresso: Robust Concept Filtering in Text-to-Image ModelsabstractDiffusion based text-to-image models are trained on large datasets scraped from the Internet, potentially containing unacceptable concepts (e.g., copyright-infringing or unsafe). We need concept removal techniques (CRTs) which are i) effective in preventing the generation of images with unacceptable concepts, ii) utility-preserving on acceptable concepts, and, iii) robust against evasion with adversarial prompts. No prior CRT satisfies all these requirements simultaneously. We introduce Espresso, the first robust concept filter based on Contrastive Language-Image Pre-Training (CLIP). We identify unacceptable concepts by using the distance between the embedding of a generated image to the text embeddings of both unacceptable and acceptable concepts. This lets us fine-tune for robustness by separating the text embeddings of unacceptable and acceptable concepts while preserving utility. We present a pipeline to evaluate various CRTs to show that Espresso is more effective and robust than prior CRTs, while retaining utility Anudeep Das, Vasisht Duddu, Rui Zhang 0118, N. Asokan |
CODASPY | 2 |
| 2025 | Laminator: Verifiable ML Property Cards using Hardware-assisted AttestationsabstractRegulations increasingly call for various assurances from machine learning (ML) model providers about their training data, training process, and model behavior. For better transparency, industry (e.g., Huggingface and Google) has adopted model cards and datasheets to describe various properties of training datasets and models. In the same vein, we introduce the notion of inference cards to describe the properties of a given inference (e.g., binding of the output to the model and its corresponding input). We coin the term ML property cards to collectively refer to these various types of cards. Vasisht Duddu, Lachlan J. Gunn, N. Asokan |
CODASPY | 1 |
| 2024 | Attesting Distributional Properties of Training Data for Machine Learning
Vasisht Duddu, Anudeep Das, Nora Khayata, Hossein Yalame, Thomas Schneider 0003, N. Asokan |
ESORICS (1) | 1 |
| 2024 | SoK: Unintended Interactions among Machine Learning Defenses and RisksabstractMachine learning (ML) models cannot neglect risks to security, privacy, and fairness. Several defenses have been proposed to mitigate such risks. When a defense is effective in mitigating one risk, it may correspond to increased or decreased susceptibility to other risks. Existing research lacks an effective framework to recognize and explain these unintended interactions. We present such a framework, based on the conjecture that overfitting and memorization underlie unintended interactions. We survey existing literature on unintended interactions, accommodating them within our framework. We use our framework to conjecture two previously unexplored interactions, and empirically validate them. Vasisht Duddu, Sebastian Szyller, N. Asokan |
SP | 1 |
| 2024 | GrOVe: Ownership Verification of Graph Neural Networks using EmbeddingsabstractGraph neural networks (GNNs) have emerged as a state-of-the-art approach to model and draw inferences from large scale graph-structured data in various application settings such as social networking. The primary goal of a GNN is to learn an embedding for each graph node in a dataset that encodes both the node features and the local graph structure around the node.Prior work has shown that GNNs are prone to model extraction attacks. Model extraction attacks and defenses have been explored extensively in other non-graph settings. While detecting or preventing model extraction appears to be difficult, deterring them via effective ownership verification techniques offer a potential defense. In non-graph settings, fingerprinting models, or the data used to build them, have shown to be a promising approach toward ownership verification.We present GrOVe, a state-of-the-art GNN model fingerprinting scheme that, given a target model and a suspect model, can reliably determine if the suspect model was trained independently of the target model or if it is a surrogate of the target model obtained via model extraction. We show that GrOVe can distinguish between surrogate and independent models even when the independent model uses the same training dataset and architecture as the original target model.Using six benchmark datasets and three model architectures, we show that GrOVe consistently achieves low falsepositive and false-negative rates. We demonstrate that GrOVe is robust against known fingerprint evasion techniques while remaining computationally efficient. Asim Waheed, Vasisht Duddu, N. Asokan |
SP | 2 |
| 2024 | On the Alignment of Group Fairness with Attribute Privacy
Jan Aalmoes, Vasisht Duddu, Antoine Boutet |
WISE (2) | 2 |
| 2023 | Comprehension from Chaos: Towards Informed Consent for Private ComputationabstractPrivate computation, which includes techniques like multi-party computation and private query execution, holds great promise for enabling organizations to analyze data they and their partners hold while maintaining data subjects' privacy. Despite recent interest in communicating about differential privacy, end users' perspectives on private computation have not previously been studied. To fill this gap, we conducted 22 semi-structured interviews investigating users' understanding of, and expectations for, private computation over data about them. Interviews centered on four concrete data-analysis scenarios (e.g., ad conversion analysis), each with a variant that did not use private computation and another that did. While participants struggled with abstract definitions of private computation, they found the concrete scenarios enlightening and plausible even though we did not explain the complex cryptographic underpinnings. Private computation increased participants' acceptance of data sharing, but not unconditionally; the purpose of data sharing and analysis was the primary driver of their attitudes. Through collective activities, participants emphasized the importance of detailing the purpose of a computation and clarifying that inputs to private computation are not shared across organizations when describing private computation to end users. Bailey Kacsmar, Vasisht Duddu, Kyle Tilbury, Blase Ur, Florian Kerschbaum |
CCS | 2 |
| 2022 | Inferring Sensitive Attributes from Model ExplanationsabstractModel explanations provide transparency into a trained machine learning model's blackbox behavior to a model builder. They indicate the influence of different input attributes to its corresponding model prediction. The dependency of explanations on input raises privacy concerns for sensitive user data. However, current literature has limited discussion on privacy risks of model explanations. Vasisht Duddu, Antoine Boutet |
CIKM | 1 |
| 2020 | Quantifying Privacy Leakage in Graph EmbeddingabstractGraph embeddings have been proposed to map graph data to low dimensional space for downstream processing (e.g., node classification or link prediction). With the increasing collection of personal data, graph embeddings can be trained on private and sensitive data. For the first time, we quantify the privacy leakage in graph embeddings through three inference attacks targeting Graph Neural Networks. Our membership inference attack aims to infer whether a graph node corresponding to an individual user’s data was a member of the model’s private training data or not. We consider a blackbox setting where the adversary exploits the output prediction scores and a whitebox setting where the adversary has also access to the released node embeddings. Our attack provides accuracy up to 28% (blackbox) and 36% (whitebox) beyond the random guess by exploiting the distinguishable footprint between train and test data records left by the graph embedding. In our graph reconstruction attack, the adversary aims to reconstruct the target graph given the corresponding graph embeddings. Here, the adversary can reconstruct the graph with more than 80% of accuracy and infer the link between two nodes with ∼ 30% more accuracy than the random guess. Finally, we propose an attribute inference attack where the adversary aims to infer the sensitive node attributes corresponding to an individual user. We show that the strong correlation between the graph embeddings and node attributes allows the adversary to infer sensitive information (e.g., gender or location). Vasisht Duddu, Antoine Boutet, Virat Shejwalkar |
MobiQuitous | 1 |
| 2020 | Towards Enhancing Fault Tolerance in Neural NetworksabstractDeep Learning Accelerators and Neuromorphic hardware, used in many real-time safety-critical applications, are prone to faults that manifest in the form of errors in Neural Networks. Fault Tolerance in Neural Networks is a critical attribute for applications that require reliable computation for long duration such as IoT and mobile devices. The inherent fault tolerance of Neural Networks can be improved with regularization, however, the current techniques exhibit a trade-off between generalization and classification accuracy. To this extent, in this work, a Neural Network is modelled as two distinct functional components: a Feature Extractor with an unsupervised learning objective and a Fully Connected Classifier with a supervised learning objective. Traditional approaches to train the entire network using a single supervised learning objective are insufficient to achieve the objectives of the individual functional goals optimally. In this work, a novel two phase framework with multi-criteria objective function combining unsupervised training of the Feature Extractor followed by supervised training of the Classifier Network is proposed. In the Phase I, the unsupervised training of the Feature Extractor is modeled using two games solved simultaneously in the presence of Neural Networks with conflicting objectives. The first game with a generative model, trains the Feature Extractor to generate robust features for the input image by minimizing a reconstruction loss between the input and reconstructed image. The second game with a binary classification network, updates the Feature Extractor to smoothen the feature space and match with a prior Gaussian distribution. In Phase II, the resultant Feature Extractor, which is strongly regularized, is combined with the Fully Connected Classifier for fine-tuning on the classification task. The proposed two phase training algorithm is evaluated on four architectures with varying model complexity on standard image classification datasets: FashionMNIST and CIFAR10. The proposed framework is scalable and independent of the network architecture that provides superior tolerance to stuck at “0” faults as compared to existing regularization functions without loss in classification accuracy. Vasisht Duddu, D. Vijay Rao, Valentina Emilia Balas |
MobiQuitous | 1 |