Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Liam Fowl

dblp:241/6940 · also Liam H. Fowl · DBLP profile ↗
← Back
15ranked-venue papers
3as first author
10since 2021 · last 2023
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 12 · 3 first-author · 8 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5 · 3 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
8 papers
Security and privacy of machine learning · 71% Privacy and data protection · 29%
Artificial intelligence
9 papers
Trustworthy machine learning · 42% Efficient and distributed learning · 22% Transfer learning and domain adaptation · 19%

Topics — the 24 heaviest of 25, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Security and privacy of machine learning
poisoning attack
2.042022
Sleeper Agent: Scalable Hidden Trigger Backdoors for Neural Networks Trained from Scratch · NeurIPS 2022
Adversarial Examples Make Strong Poisons · NeurIPS 2021
Witches' Brew: Industrial Scale Data Poisoning via Gradient Matching · ICLR 2021
Security and privacy of machine learning
privacy attack
1.932023
Decepticons: Corrupted Transformers Breach Privacy in Federated Learning for Language Models · ICLR 2023
Panning for Gold in Federated Learning: Targeted Text Extraction under Arbitrarily Large-Scale Aggregation · ICLR 2023
Robbing the Fed: Directly Obtaining Private Data in Federated Learning with Modified Models · ICLR 2022
Privacy and data protection › privacy-preserving machine learning
federated learning privacy
1.832023
Decepticons: Corrupted Transformers Breach Privacy in Federated Learning for Language Models · ICLR 2023
Fishing for User Data in Large-Batch Federated Learning via Gradient Magnification · ICML 2022
Robbing the Fed: Directly Obtaining Private Data in Federated Learning with Modified Models · ICLR 2022
Privacy and data protection › privacy-preserving machine learning › federated learning privacy
gradient inversion attack
1.122022
Fishing for User Data in Large-Batch Federated Learning via Gradient Magnification · ICML 2022
Robbing the Fed: Directly Obtaining Private Data in Federated Learning with Modified Models · ICLR 2022
Security and privacy of machine learning › poisoning attack
clean-label poisoning
1.022022
Sleeper Agent: Scalable Hidden Trigger Backdoors for Neural Networks Trained from Scratch · NeurIPS 2022
MetaPoison: Practical General-purpose Clean-label Data Poisoning · NeurIPS 2020
Machine learning › Trustworthy machine learning › robustness
adversarial robustness
0.922020
Adversarially Robust Few-Shot Learning: A Meta-Learning Approach · NeurIPS 2020
Adversarially Robust Distillation · AAAI 2020
Machine learning › Transfer learning and domain adaptation
few-shot learning
0.922020
Adversarially Robust Few-Shot Learning: A Meta-Learning Approach · NeurIPS 2020
Unraveling Meta-Learning: Understanding Feature Representations for Few-Shot Tasks · ICML 2020
Machine learning › Efficient and distributed learning
federated learning
0.822023
Panning for Gold in Federated Learning: Targeted Text Extraction under Arbitrarily Large-Scale Aggregation · ICLR 2023
Fishing for User Data in Large-Batch Federated Learning via Gradient Magnification · ICML 2022
Security and privacy of machine learning › privacy attack
training data extraction
0.712023
Panning for Gold in Federated Learning: Targeted Text Extraction under Arbitrarily Large-Scale Aggregation · ICLR 2023
Machine learning › Trustworthy machine learning › interpretability › visual explanation
decision boundary visualization
0.612022
Can Neural Nets Learn the Same Model Twice? Investigating Reproducibility and Double Descent from the Decision Boundary Perspective · CVPR 2022
Machine learning › Learning theory › over-parameterization
double descent
0.612022
Can Neural Nets Learn the Same Model Twice? Investigating Reproducibility and Double Descent from the Decision Boundary Perspective · CVPR 2022
Machine learning › Learning theory
generalization
0.612022
Can Neural Nets Learn the Same Model Twice? Investigating Reproducibility and Double Descent from the Decision Boundary Perspective · CVPR 2022
Machine learning › Trustworthy machine learning
interpretability
0.612022
Can Neural Nets Learn the Same Model Twice? Investigating Reproducibility and Double Descent from the Decision Boundary Perspective · CVPR 2022
Security and privacy of machine learning › adversarial attack
backdoor attack
0.612022
Sleeper Agent: Scalable Hidden Trigger Backdoors for Neural Networks Trained from Scratch · NeurIPS 2022
Security and privacy of machine learning › privacy attack
data extraction attack
0.612022
Fishing for User Data in Large-Batch Federated Learning via Gradient Magnification · ICML 2022
Machine learning › Trustworthy machine learning › robustness
adversarial examples
0.512021
Adversarial Examples Make Strong Poisons · NeurIPS 2021
Machine learning › Trustworthy machine learning › adversarial machine learning › adversarial defense
adversarial robustness distillation
0.412020
Adversarially Robust Distillation · AAAI 2020
Machine learning › Efficient and distributed learning › model compression
knowledge distillation
0.412020
Adversarially Robust Distillation · AAAI 2020
Machine learning › Transfer learning and domain adaptation
meta-learning
0.412020
Adversarially Robust Few-Shot Learning: A Meta-Learning Approach · NeurIPS 2020
Machine learning › Efficient and distributed learning
model compression
0.412020
Adversarially Robust Distillation · AAAI 2020
Security and privacy of machine learning
adversarial attack
0.412020
MetaPoison: Practical General-purpose Clean-label Data Poisoning · NeurIPS 2020
Machine learning › Deep learning architectures and training
transformer
0.212023
Decepticons: Corrupted Transformers Breach Privacy in Federated Learning for Language Models · ICLR 2023
Machine learning › Trustworthy machine learning
training reproducibility
0.212022
Can Neural Nets Learn the Same Model Twice? Investigating Reproducibility and Double Descent from the Decision Boundary Perspective · CVPR 2022
Machine learning › Trustworthy machine learning › robustness › adversarial robustness
adversarial training
0.112020
Adversarially Robust Distillation · AAAI 2020

Methods — techniques the papers use, named apart from their topics

gradient leakage · 1.3corrupted transformer · 1.3meta-learning · 1.3gradient magnification · 1.1gradient matching · 1.1label reassignment · 1.0adversarial examples · 1.0target model re-training · 0.6modified model attack · 0.6gradient inversion · 0.6decision boundary visualization · 0.6data selection · 0.6regularization · 0.4knowledge distillation · 0.4adversarial training · 0.4
YearPublicationVenuePosition
2023 Exploring Sequence-to-Sequence Transformer-Transducer Models for Keyword Spotting
abstract
In this paper, we present a novel approach to adapt a sequence-to-sequence Transformer-Transducer ASR system to the keyword spotting (KWS) task. We achieve this by replacing the keyword in the text transcription with a special tokenand training the system to detect thetoken in an audio stream. At inference time, we create a decision function inspired by conventional KWS approaches, to make our approach more suitable for the KWS task. Furthermore, we introduce a specific keyword spotting loss by adapting the sequence-discriminative Minimum Bayes-Risk training technique. We find that our approach significantly outperforms ASR based KWS systems. When compared with a conventional keyword spotting system, our proposal has similar performance while bringing the advantages and flexibility of sequence-to-sequence training. Additionally, when combined with the conventional KWS system, our approach can improve the performance at any operation point.
Beltran Labrador, Guanlong Zhao, Ignacio López-Moreno, Angelo Scorza Scarpati, Liam Fowl
ICASSP5
2023 Panning for Gold in Federated Learning: Targeted Text Extraction under Arbitrarily Large-Scale Aggregation
Hong-Min Chu, Jonas Geiping, Liam Fowl, Micah Goldblum, Tom Goldstein
ICLR3
2023 Decepticons: Corrupted Transformers Breach Privacy in Federated Learning for Language Models
Liam Fowl, Jonas Geiping, Steven Reich, Yuxin Wen, Wojciech Czaja, Micah Goldblum, Tom Goldstein
ICLR1
2022 Can Neural Nets Learn the Same Model Twice? Investigating Reproducibility and Double Descent from the Decision Boundary Perspective
abstract
We discuss methods for visualizing neural network decision boundaries and decision regions. We use these visual-izations to investigate issues related to reproducibility and generalization in neural network training. We observe that changes in model architecture (and its associate inductive bias) cause visible changes in decision boundaries, while multiple runs with the same architecture yield results with strong similarities, especially in the case of wide architectures. We also use decision boundary methods to visualize double descent phenomena. We see that decision boundary reproducibility depends strongly on model width. Near the threshold of interpolation, neural network decision bound-aries become fragmented into many small decision regions, and these regions are non-reproducible. Meanwhile, very narrows and very wide networks have high levels of re-producibility in their decision boundaries with relatively few decision regions. We discuss how our observations re-late to the theory of double descent phenomena in convex models. Code is available at https://github.com/somepago/dbViz.
Gowthami Somepalli, Liam Fowl, Arpit Bansal, Ping-Yeh Chiang, Yehuda Dar, Richard G. Baraniuk, Micah Goldblum, Tom Goldstein
CVPR2
2022 Robbing the Fed: Directly Obtaining Private Data in Federated Learning with Modified Models
Liam Fowl, Jonas Geiping, Wojciech Czaja, Micah Goldblum, Tom Goldstein
ICLR1
2022 Fishing for User Data in Large-Batch Federated Learning via Gradient Magnification
abstract
Federated learning (FL) has rapidly risen in popularity due to its promise of privacy and efficiency. Previous works have exposed privacy vulnerabilities in the FL pipeline by recovering user data from gradient updates. However, existing attacks fail to address realistic settings because they either 1) require toy settings with very small batch sizes, or 2) require unrealistic and conspicuous architecture modifications. We introduce a new strategy that dramatically elevates existing attacks to operate on batches of arbitrarily large size, and without architectural modifications. Our model-agnostic strategy only requires modifications to the model parameters sent to the user, which is a realistic threat model in many scenarios. We demonstrate the strategy in challenging large-scale settings, obtaining high-fidelity data extraction in both cross-device and cross-silo federated learning. Code is available at https://github.com/JonasGeiping/breaching.
Yuxin Wen, Jonas Geiping, Liam Fowl, Micah Goldblum, Tom Goldstein
ICML3
2022 Sleeper Agent: Scalable Hidden Trigger Backdoors for Neural Networks Trained from Scratch
abstract
As the curation of data for machine learning becomes increasingly automated, dataset tampering is a mounting threat. Backdoor attackers tamper with training data to embed a vulnerability in models that are trained on that data. This vulnerability is then activated at inference time by placing a "trigger'' into the model's input. Typical backdoor attacks insert the trigger directly into the training data, although the presence of such an attack may be visible upon inspection. In contrast, the Hidden Trigger Backdoor Attack achieves poisoning without placing a trigger into the training data at all. However, this hidden trigger attack is ineffective at poisoning neural networks trained from scratch. We develop a new hidden trigger attack, Sleeper Agent, which employs gradient matching, data selection, and target model re-training during the crafting process. Sleeper Agent is the first hidden trigger backdoor attack to be effective against neural networks trained from scratch. We demonstrate its effectiveness on ImageNet and in black-box settings. Our implementation code can be found at: https://github.com/hsouri/Sleeper-Agent.
Hossein Souri, Liam Fowl, Rama Chellappa, Micah Goldblum, Tom Goldstein
NeurIPS2
2021 Strong Data Augmentation Sanitizes Poisoning and Backdoor Attacks Without an Accuracy Tradeoff
abstract
Data poisoning and backdoor attacks manipulate victim models by maliciously modifying training data. In light of this growing threat, a recent survey of industry professionals revealed heightened fear in the private sector regarding data poisoning. Many previous defenses against poisoning either fail in the face of increasingly strong attacks, or they significantly degrade performance. However, we find that strong data augmentations, such as mixup and CutMix, can significantly diminish the threat of poisoning and backdoor attacks without trading off performance. We further verify the effectiveness of this simple defense against adaptive poisoning methods, and we compare to baselines including the popular differentially private SGD (DP-SGD) defense. In the context of backdoors, CutMix greatly mitigates the attack while simultaneously increasing validation accuracy by 9%.
Eitan Borgnia, Valeriia Cherepanova, Liam Fowl, Amin Ghiasi, Jonas Geiping, Micah Goldblum, Tom Goldstein
ICASSP3
2021 Witches' Brew: Industrial Scale Data Poisoning via Gradient Matching
Jonas Geiping, Liam Fowl, W. Ronny Huang, Wojciech Czaja, Gavin Taylor, Michael Möller 0001, Tom Goldstein
ICLR2
2021 Adversarial Examples Make Strong Poisons
abstract
The adversarial machine learning literature is largely partitioned into evasion attacks on testing data and poisoning attacks on training data. In this work, we show that adversarial examples, originally intended for attacking pre-trained models, are even more effective for data poisoning than recent methods designed specifically for poisoning. In fact, adversarial examples with labels re-assigned by the crafting network remain effective for training, suggesting that adversarial examples contain useful semantic content, just with the "wrong" labels (according to a network, but not a human). Our method, adversarial poisoning, is substantially more effective than existing poisoning methods for secure dataset release, and we release a poisoned version of ImageNet, ImageNet-P, to encourage research into the strength of this form of data obfuscation.
Liam Fowl, Micah Goldblum, Ping-Yeh Chiang, Jonas Geiping, Wojciech Czaja, Tom Goldstein
NeurIPS1
2020 Adversarially Robust Distillation
abstract
Knowledge distillation is effective for producing small, high-performance neural networks for classification, but these small networks are vulnerable to adversarial attacks. This paper studies how adversarial robustness transfers from teacher to student during knowledge distillation. We find that a large amount of robustness may be inherited by the student even when distilled on only clean images. Second, we introduce Adversarially Robust Distillation (ARD) for distilling robustness onto student networks. In addition to producing small models with high test accuracy like conventional distillation, ARD also passes the superior robustness of large networks onto the student. In our experiments, we find that ARD student models decisively outperform adversarially trained networks of identical architecture in terms of robust accuracy, surpassing state-of-the-art methods on standard robustness benchmarks. Finally, we adapt recent fast adversarial training methods to ARD for accelerated robust distillation.
Micah Goldblum, Liam Fowl, Soheil Feizi, Tom Goldstein
AAAI2
2020 Headless Horseman: Adversarial Attacks on Transfer Learning Models
abstract
Transfer learning facilitates the training of task-specific classifiers using pre-trained models as feature extractors. We present a family of transferable adversarial attacks against such classifiers, generated without access to the classification head; we call these headless attacks. We first demonstrate successful transfer attacks against a victim network using only its feature extractor. This motivates the introduction of a label-blind adversarial attack. This transfer attack method does not require any information about the class-label space of the victim. Our attack lowers the accuracy of a ResNet18 trained on CIFAR10 by over 40%.
Ahmed Abdelkader, Michael J. Curry, Liam Fowl, Tom Goldstein, Avi Schwarzschild, Manli Shu, Christoph Studer, Chen Zhu 0001
ICASSP3
2020 Unraveling Meta-Learning: Understanding Feature Representations for Few-Shot Tasks
abstract
Meta-learning algorithms produce feature extractors which achieve state-of-the-art performance on few-shot classification. While the literature is rich with meta-learning methods, little is known about why the resulting feature extractors perform so well. We develop a better understanding of the underlying mechanics of meta-learning and the difference between models trained using meta-learning and models which are trained classically. In doing so, we introduce and verify several hypotheses for why meta-learned models perform better. Furthermore, we develop a regularizer which boosts the performance of standard training routines for few-shot classification. In many cases, our routine outperforms meta-learning while simultaneously running an order of magnitude faster.
Micah Goldblum, Steven Reich, Liam Fowl, Renkun Ni, Valeriia Cherepanova, Tom Goldstein
ICML3
2020 Adversarially Robust Few-Shot Learning: A Meta-Learning Approach
abstract
Previous work on adversarially robust neural networks for image classification requires large training sets and computationally expensive training procedures. On the other hand, few-shot learning methods are highly vulnerable to adversarial examples. The goal of our work is to produce networks which both perform well at few-shot classification tasks and are simultaneously robust to adversarial examples. We develop an algorithm, called Adversarial Querying (AQ), for producing adversarially robust meta-learners, and we thoroughly investigate the causes for adversarial vulnerability. Moreover, our method achieves far superior robust performance on few-shot image classification tasks, such as Mini-ImageNet and CIFAR-FS, than robust transfer learning.
Micah Goldblum, Liam Fowl, Tom Goldstein
NeurIPS2
2020 MetaPoison: Practical General-purpose Clean-label Data Poisoning
abstract
Data poisoning---the process by which an attacker takes control of a model by making imperceptible changes to a subset of the training data---is an emerging threat in the context of neural networks. Existing attacks for data poisoning neural networks have relied on hand-crafted heuristics, because solving the poisoning problem directly via bilevel optimization is generally thought of as intractable for deep models. We propose MetaPoison, a first-order method that approximates the bilevel problem via meta-learning and crafts poisons that fool neural networks. MetaPoison is effective: it outperforms previous clean-label poisoning methods by a large margin. MetaPoison is robust: poisoned data made for one model transfer to a variety of victim models with unknown training settings and architectures. MetaPoison is general-purpose, it works not only in fine-tuning scenarios, but also for end-to-end training from scratch, which till now hasn't been feasible for clean-label attacks with deep nets. MetaPoison can achieve arbitrary adversary goals---like using poisons of one class to make a target image don the label of another arbitrarily chosen class. Finally, MetaPoison works in the real-world. We demonstrate for the first time successful data poisoning of models trained on the black-box Google Cloud AutoML API.
W. Ronny Huang, Jonas Geiping, Liam Fowl, Gavin Taylor, Tom Goldstein
NeurIPS3