EDBT 2026 Demo / reviewers in the wild / expert
Liam Fowl
dblp:241/6940 · also Liam H. Fowl
· DBLP profile ↗
15ranked-venue papers
3as first author
10since 2021 · last 2023
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 12 · 3 first-author · 8 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5 · 3 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
8 papers |
Security and privacy of machine learning · 71% Privacy and data protection · 29% | |
| Artificial intelligence
9 papers |
Trustworthy machine learning · 42% Efficient and distributed learning · 22% Transfer learning and domain adaptation · 19% |
Topics — the 24 heaviest of 25, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Security and privacy of machine learning
poisoning attack |
2.0 | 4 | 2022 | Sleeper Agent: Scalable Hidden Trigger Backdoors for Neural Networks Trained from Scratch · NeurIPS 2022 Adversarial Examples Make Strong Poisons · NeurIPS 2021 Witches' Brew: Industrial Scale Data Poisoning via Gradient Matching · ICLR 2021 |
Security and privacy of machine learning
privacy attack |
1.9 | 3 | 2023 | Decepticons: Corrupted Transformers Breach Privacy in Federated Learning for Language Models · ICLR 2023 Panning for Gold in Federated Learning: Targeted Text Extraction under Arbitrarily Large-Scale Aggregation · ICLR 2023 Robbing the Fed: Directly Obtaining Private Data in Federated Learning with Modified Models · ICLR 2022 |
Privacy and data protection › privacy-preserving machine learning
federated learning privacy |
1.8 | 3 | 2023 | Decepticons: Corrupted Transformers Breach Privacy in Federated Learning for Language Models · ICLR 2023 Fishing for User Data in Large-Batch Federated Learning via Gradient Magnification · ICML 2022 Robbing the Fed: Directly Obtaining Private Data in Federated Learning with Modified Models · ICLR 2022 |
Privacy and data protection › privacy-preserving machine learning › federated learning privacy
gradient inversion attack |
1.1 | 2 | 2022 | Fishing for User Data in Large-Batch Federated Learning via Gradient Magnification · ICML 2022 Robbing the Fed: Directly Obtaining Private Data in Federated Learning with Modified Models · ICLR 2022 |
Security and privacy of machine learning › poisoning attack
clean-label poisoning |
1.0 | 2 | 2022 | Sleeper Agent: Scalable Hidden Trigger Backdoors for Neural Networks Trained from Scratch · NeurIPS 2022 MetaPoison: Practical General-purpose Clean-label Data Poisoning · NeurIPS 2020 |
Machine learning › Trustworthy machine learning › robustness
adversarial robustness |
0.9 | 2 | 2020 | Adversarially Robust Few-Shot Learning: A Meta-Learning Approach · NeurIPS 2020 Adversarially Robust Distillation · AAAI 2020 |
Machine learning › Transfer learning and domain adaptation
few-shot learning |
0.9 | 2 | 2020 | Adversarially Robust Few-Shot Learning: A Meta-Learning Approach · NeurIPS 2020 Unraveling Meta-Learning: Understanding Feature Representations for Few-Shot Tasks · ICML 2020 |
Machine learning › Efficient and distributed learning
federated learning |
0.8 | 2 | 2023 | Panning for Gold in Federated Learning: Targeted Text Extraction under Arbitrarily Large-Scale Aggregation · ICLR 2023 Fishing for User Data in Large-Batch Federated Learning via Gradient Magnification · ICML 2022 |
Security and privacy of machine learning › privacy attack
training data extraction |
0.7 | 1 | 2023 | Panning for Gold in Federated Learning: Targeted Text Extraction under Arbitrarily Large-Scale Aggregation · ICLR 2023 |
Machine learning › Trustworthy machine learning › interpretability › visual explanation
decision boundary visualization |
0.6 | 1 | 2022 | Can Neural Nets Learn the Same Model Twice? Investigating Reproducibility and Double Descent from the Decision Boundary Perspective · CVPR 2022 |
Machine learning › Learning theory › over-parameterization
double descent |
0.6 | 1 | 2022 | Can Neural Nets Learn the Same Model Twice? Investigating Reproducibility and Double Descent from the Decision Boundary Perspective · CVPR 2022 |
Machine learning › Learning theory
generalization |
0.6 | 1 | 2022 | Can Neural Nets Learn the Same Model Twice? Investigating Reproducibility and Double Descent from the Decision Boundary Perspective · CVPR 2022 |
Machine learning › Trustworthy machine learning
interpretability |
0.6 | 1 | 2022 | Can Neural Nets Learn the Same Model Twice? Investigating Reproducibility and Double Descent from the Decision Boundary Perspective · CVPR 2022 |
Security and privacy of machine learning › adversarial attack
backdoor attack |
0.6 | 1 | 2022 | Sleeper Agent: Scalable Hidden Trigger Backdoors for Neural Networks Trained from Scratch · NeurIPS 2022 |
Security and privacy of machine learning › privacy attack
data extraction attack |
0.6 | 1 | 2022 | Fishing for User Data in Large-Batch Federated Learning via Gradient Magnification · ICML 2022 |
Machine learning › Trustworthy machine learning › robustness
adversarial examples |
0.5 | 1 | 2021 | Adversarial Examples Make Strong Poisons · NeurIPS 2021 |
Machine learning › Trustworthy machine learning › adversarial machine learning › adversarial defense
adversarial robustness distillation |
0.4 | 1 | 2020 | Adversarially Robust Distillation · AAAI 2020 |
Machine learning › Efficient and distributed learning › model compression
knowledge distillation |
0.4 | 1 | 2020 | Adversarially Robust Distillation · AAAI 2020 |
Machine learning › Transfer learning and domain adaptation
meta-learning |
0.4 | 1 | 2020 | Adversarially Robust Few-Shot Learning: A Meta-Learning Approach · NeurIPS 2020 |
Machine learning › Efficient and distributed learning
model compression |
0.4 | 1 | 2020 | Adversarially Robust Distillation · AAAI 2020 |
Security and privacy of machine learning
adversarial attack |
0.4 | 1 | 2020 | MetaPoison: Practical General-purpose Clean-label Data Poisoning · NeurIPS 2020 |
Machine learning › Deep learning architectures and training
transformer |
0.2 | 1 | 2023 | Decepticons: Corrupted Transformers Breach Privacy in Federated Learning for Language Models · ICLR 2023 |
Machine learning › Trustworthy machine learning
training reproducibility |
0.2 | 1 | 2022 | Can Neural Nets Learn the Same Model Twice? Investigating Reproducibility and Double Descent from the Decision Boundary Perspective · CVPR 2022 |
Machine learning › Trustworthy machine learning › robustness › adversarial robustness
adversarial training |
0.1 | 1 | 2020 | Adversarially Robust Distillation · AAAI 2020 |
Methods — techniques the papers use, named apart from their topics
gradient leakage · 1.3corrupted transformer · 1.3meta-learning · 1.3gradient magnification · 1.1gradient matching · 1.1label reassignment · 1.0adversarial examples · 1.0target model re-training · 0.6modified model attack · 0.6gradient inversion · 0.6decision boundary visualization · 0.6data selection · 0.6regularization · 0.4knowledge distillation · 0.4adversarial training · 0.4
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Exploring Sequence-to-Sequence Transformer-Transducer Models for Keyword SpottingabstractIn this paper, we present a novel approach to adapt a sequence-to-sequence Transformer-Transducer ASR system to the keyword spotting (KWS) task. We achieve this by replacing the keyword in the text transcription with a special tokenand training the system to detect thetoken in an audio stream. At inference time, we create a decision function inspired by conventional KWS approaches, to make our approach more suitable for the KWS task. Furthermore, we introduce a specific keyword spotting loss by adapting the sequence-discriminative Minimum Bayes-Risk training technique. We find that our approach significantly outperforms ASR based KWS systems. When compared with a conventional keyword spotting system, our proposal has similar performance while bringing the advantages and flexibility of sequence-to-sequence training. Additionally, when combined with the conventional KWS system, our approach can improve the performance at any operation point. Beltran Labrador, Guanlong Zhao, Ignacio López-Moreno, Angelo Scorza Scarpati, Liam Fowl |
ICASSP | 5 |
| 2023 | Panning for Gold in Federated Learning: Targeted Text Extraction under Arbitrarily Large-Scale Aggregation
Hong-Min Chu, Jonas Geiping, Liam Fowl, Micah Goldblum, Tom Goldstein |
ICLR | 3 |
| 2023 | Decepticons: Corrupted Transformers Breach Privacy in Federated Learning for Language Models
Liam Fowl, Jonas Geiping, Steven Reich, Yuxin Wen, Wojciech Czaja, Micah Goldblum, Tom Goldstein |
ICLR | 1 |
| 2022 | Can Neural Nets Learn the Same Model Twice? Investigating Reproducibility and Double Descent from the Decision Boundary PerspectiveabstractWe discuss methods for visualizing neural network decision boundaries and decision regions. We use these visual-izations to investigate issues related to reproducibility and generalization in neural network training. We observe that changes in model architecture (and its associate inductive bias) cause visible changes in decision boundaries, while multiple runs with the same architecture yield results with strong similarities, especially in the case of wide architectures. We also use decision boundary methods to visualize double descent phenomena. We see that decision boundary reproducibility depends strongly on model width. Near the threshold of interpolation, neural network decision bound-aries become fragmented into many small decision regions, and these regions are non-reproducible. Meanwhile, very narrows and very wide networks have high levels of re-producibility in their decision boundaries with relatively few decision regions. We discuss how our observations re-late to the theory of double descent phenomena in convex models. Code is available at https://github.com/somepago/dbViz. Gowthami Somepalli, Liam Fowl, Arpit Bansal, Ping-Yeh Chiang, Yehuda Dar, Richard G. Baraniuk, Micah Goldblum, Tom Goldstein |
CVPR | 2 |
| 2022 | Robbing the Fed: Directly Obtaining Private Data in Federated Learning with Modified Models
Liam Fowl, Jonas Geiping, Wojciech Czaja, Micah Goldblum, Tom Goldstein |
ICLR | 1 |
| 2022 | Fishing for User Data in Large-Batch Federated Learning via Gradient MagnificationabstractFederated learning (FL) has rapidly risen in popularity due to its promise of privacy and efficiency. Previous works have exposed privacy vulnerabilities in the FL pipeline by recovering user data from gradient updates. However, existing attacks fail to address realistic settings because they either 1) require toy settings with very small batch sizes, or 2) require unrealistic and conspicuous architecture modifications. We introduce a new strategy that dramatically elevates existing attacks to operate on batches of arbitrarily large size, and without architectural modifications. Our model-agnostic strategy only requires modifications to the model parameters sent to the user, which is a realistic threat model in many scenarios. We demonstrate the strategy in challenging large-scale settings, obtaining high-fidelity data extraction in both cross-device and cross-silo federated learning. Code is available at https://github.com/JonasGeiping/breaching. Yuxin Wen, Jonas Geiping, Liam Fowl, Micah Goldblum, Tom Goldstein |
ICML | 3 |
| 2022 | Sleeper Agent: Scalable Hidden Trigger Backdoors for Neural Networks Trained from ScratchabstractAs the curation of data for machine learning becomes increasingly automated, dataset tampering is a mounting threat. Backdoor attackers tamper with training data to embed a vulnerability in models that are trained on that data. This vulnerability is then activated at inference time by placing a "trigger'' into the model's input. Typical backdoor attacks insert the trigger directly into the training data, although the presence of such an attack may be visible upon inspection. In contrast, the Hidden Trigger Backdoor Attack achieves poisoning without placing a trigger into the training data at all. However, this hidden trigger attack is ineffective at poisoning neural networks trained from scratch. We develop a new hidden trigger attack, Sleeper Agent, which employs gradient matching, data selection, and target model re-training during the crafting process. Sleeper Agent is the first hidden trigger backdoor attack to be effective against neural networks trained from scratch. We demonstrate its effectiveness on ImageNet and in black-box settings. Our implementation code can be found at: https://github.com/hsouri/Sleeper-Agent. Hossein Souri, Liam Fowl, Rama Chellappa, Micah Goldblum, Tom Goldstein |
NeurIPS | 2 |
| 2021 | Strong Data Augmentation Sanitizes Poisoning and Backdoor Attacks Without an Accuracy TradeoffabstractData poisoning and backdoor attacks manipulate victim models by maliciously modifying training data. In light of this growing threat, a recent survey of industry professionals revealed heightened fear in the private sector regarding data poisoning. Many previous defenses against poisoning either fail in the face of increasingly strong attacks, or they significantly degrade performance. However, we find that strong data augmentations, such as mixup and CutMix, can significantly diminish the threat of poisoning and backdoor attacks without trading off performance. We further verify the effectiveness of this simple defense against adaptive poisoning methods, and we compare to baselines including the popular differentially private SGD (DP-SGD) defense. In the context of backdoors, CutMix greatly mitigates the attack while simultaneously increasing validation accuracy by 9%. Eitan Borgnia, Valeriia Cherepanova, Liam Fowl, Amin Ghiasi, Jonas Geiping, Micah Goldblum, Tom Goldstein |
ICASSP | 3 |
| 2021 | Witches' Brew: Industrial Scale Data Poisoning via Gradient Matching
Jonas Geiping, Liam Fowl, W. Ronny Huang, Wojciech Czaja, Gavin Taylor, Michael Möller 0001, Tom Goldstein |
ICLR | 2 |
| 2021 | Adversarial Examples Make Strong PoisonsabstractThe adversarial machine learning literature is largely partitioned into evasion attacks on testing data and poisoning attacks on training data. In this work, we show that adversarial examples, originally intended for attacking pre-trained models, are even more effective for data poisoning than recent methods designed specifically for poisoning. In fact, adversarial examples with labels re-assigned by the crafting network remain effective for training, suggesting that adversarial examples contain useful semantic content, just with the "wrong" labels (according to a network, but not a human). Our method, adversarial poisoning, is substantially more effective than existing poisoning methods for secure dataset release, and we release a poisoned version of ImageNet, ImageNet-P, to encourage research into the strength of this form of data obfuscation. Liam Fowl, Micah Goldblum, Ping-Yeh Chiang, Jonas Geiping, Wojciech Czaja, Tom Goldstein |
NeurIPS | 1 |
| 2020 | Adversarially Robust DistillationabstractKnowledge distillation is effective for producing small, high-performance neural networks for classification, but these small networks are vulnerable to adversarial attacks. This paper studies how adversarial robustness transfers from teacher to student during knowledge distillation. We find that a large amount of robustness may be inherited by the student even when distilled on only clean images. Second, we introduce Adversarially Robust Distillation (ARD) for distilling robustness onto student networks. In addition to producing small models with high test accuracy like conventional distillation, ARD also passes the superior robustness of large networks onto the student. In our experiments, we find that ARD student models decisively outperform adversarially trained networks of identical architecture in terms of robust accuracy, surpassing state-of-the-art methods on standard robustness benchmarks. Finally, we adapt recent fast adversarial training methods to ARD for accelerated robust distillation. Micah Goldblum, Liam Fowl, Soheil Feizi, Tom Goldstein |
AAAI | 2 |
| 2020 | Headless Horseman: Adversarial Attacks on Transfer Learning ModelsabstractTransfer learning facilitates the training of task-specific classifiers using pre-trained models as feature extractors. We present a family of transferable adversarial attacks against such classifiers, generated without access to the classification head; we call these headless attacks. We first demonstrate successful transfer attacks against a victim network using only its feature extractor. This motivates the introduction of a label-blind adversarial attack. This transfer attack method does not require any information about the class-label space of the victim. Our attack lowers the accuracy of a ResNet18 trained on CIFAR10 by over 40%. Ahmed Abdelkader, Michael J. Curry, Liam Fowl, Tom Goldstein, Avi Schwarzschild, Manli Shu, Christoph Studer, Chen Zhu 0001 |
ICASSP | 3 |
| 2020 | Unraveling Meta-Learning: Understanding Feature Representations for Few-Shot TasksabstractMeta-learning algorithms produce feature extractors which achieve state-of-the-art performance on few-shot classification. While the literature is rich with meta-learning methods, little is known about why the resulting feature extractors perform so well. We develop a better understanding of the underlying mechanics of meta-learning and the difference between models trained using meta-learning and models which are trained classically. In doing so, we introduce and verify several hypotheses for why meta-learned models perform better. Furthermore, we develop a regularizer which boosts the performance of standard training routines for few-shot classification. In many cases, our routine outperforms meta-learning while simultaneously running an order of magnitude faster. Micah Goldblum, Steven Reich, Liam Fowl, Renkun Ni, Valeriia Cherepanova, Tom Goldstein |
ICML | 3 |
| 2020 | Adversarially Robust Few-Shot Learning: A Meta-Learning ApproachabstractPrevious work on adversarially robust neural networks for image classification requires large training sets and computationally expensive training procedures. On the other hand, few-shot learning methods are highly vulnerable to adversarial examples. The goal of our work is to produce networks which both perform well at few-shot classification tasks and are simultaneously robust to adversarial examples. We develop an algorithm, called Adversarial Querying (AQ), for producing adversarially robust meta-learners, and we thoroughly investigate the causes for adversarial vulnerability. Moreover, our method achieves far superior robust performance on few-shot image classification tasks, such as Mini-ImageNet and CIFAR-FS, than robust transfer learning. Micah Goldblum, Liam Fowl, Tom Goldstein |
NeurIPS | 2 |
| 2020 | MetaPoison: Practical General-purpose Clean-label Data PoisoningabstractData poisoning---the process by which an attacker takes control of a model by making imperceptible changes to a subset of the training data---is an emerging threat in the context of neural networks. Existing attacks for data poisoning neural networks have relied on hand-crafted heuristics, because solving the poisoning problem directly via bilevel optimization is generally thought of as intractable for deep models. We propose MetaPoison, a first-order method that approximates the bilevel problem via meta-learning and crafts poisons that fool neural networks. MetaPoison is effective: it outperforms previous clean-label poisoning methods by a large margin. MetaPoison is robust: poisoned data made for one model transfer to a variety of victim models with unknown training settings and architectures. MetaPoison is general-purpose, it works not only in fine-tuning scenarios, but also for end-to-end training from scratch, which till now hasn't been feasible for clean-label attacks with deep nets. MetaPoison can achieve arbitrary adversary goals---like using poisons of one class to make a target image don the label of another arbitrarily chosen class. Finally, MetaPoison works in the real-world. We demonstrate for the first time successful data poisoning of models trained on the black-box Google Cloud AutoML API. W. Ronny Huang, Jonas Geiping, Liam Fowl, Gavin Taylor, Tom Goldstein |
NeurIPS | 3 |