EDBT 2026 Demo / reviewers in the wild / expert
Batnyam Enkhtaivan
dblp:256/2043
· DBLP profile ↗
5ranked-venue papers
3as first author
4since 2021 · last 2024
0000-0002-4463-2478ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 2 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Trojan attribute inference attack on gradient boosting decision treesabstractWe propose a Trojan horse-type attribute inference attack (AlA) against the gradient boosting decision trees (GBDT) in the federated learning setting. Our Trojan AlA consists of a Trojan tree creation and an attribute inference. Both algorithms leverage the characteristics of the federated learning protocol for the GBDT training. First, the adversary creates a decision tree, a Trojan tree, that isolates a target data record from other data records. The adversary sends the Trojan tree to the server through the federated learning protocol at their round. Trojan tree forces the victim's tree to “memorize” a target attribute value of target data record that the adversary wants to know. The adversary can recover the target attribute value by observing the tree submitted by the victim if the victim uses the target data record for training the tree. For the regression task, we derive sufficient conditions for a successful attack. According to our theorem, if the target data record is distinct in the victim's dataset, the proposed attack is always successful. Experiments on multiple datasets and settings show results that align with the above theoretical analysis. Even if some conditions for theoretical analysis are relaxed, the proposed attack outperforms baseline attacks. To the best of our knowledge, this is the first study of an attribute inference attack against the GBDT in the federated learning setting. Kunihiro Ito, Batnyam Enkhtaivan, Isamu Teranishi, Jun Sakuma |
EuroS&P | 2 |
| 2024 | A Novel Confidence Score Exploiting Attacks on Classification Trees and Random Forest ClassifiersabstractThe need for studies on the privacy risks of machine learning models has been increasing as using sensitive data in training them has become prevalent in real-world applications. Decision tree and random forest models have been used for data mining for several decades. Yet, there are not enough studies on the privacy risks of these models. In this paper, we present two novel attribute inference attacks, i.e., CTAIA and RFAIA, for the decision tree and random forest classifiers, respectively. CTAIA is a black-box attack, and RFAIA is a white-box attack. Our attacks utilize the confidence score information from the model outputs in a novel way. Specifically, our attacks use the zero values in confidence scores of the decision tree classifiers. A zero confidence score for a specific class means that there is no training data sample for that class. This fact, the embedding of the information about the number of the train data samples in the confidence score, is used to exclude the candidate values of the target attribute. We define the train data samples, which an attacker of an attribute inference attack can infer the values of the sensitive attribute with 100% confidence, as "high-risk" data records. For the decision tree classifiers or classification trees, CTAIA selects some data records and infers the values of the target attribute of them with 100% accuracy, making them "high-risk" data records. Similarly, for the random forest classifiers, RFAIA selects some data records. Depending on whether the bootstrap sampling is used in training the classifiers or not, the RFAIA has 100% or near 100% attack accuracy for the selected data records. Therefore, in the case of random forest classifiers, for simplicity, we loosen the above-mentioned definition of the "high-risk" data records and call the data records selected by RFAIA the "high-risk" data in this paper. We have experimentally shown the effectiveness of our attack using three public datasets. Batnyam Enkhtaivan, Isamu Teranishi |
IJCNN | 1 |
| 2023 | pGBF: Personalized Gradient Boosting ForestabstractDue to the regulations to protect user data privacy and concerns about trade secrets, industrial organizations do not share user data with others. Federated learning makes it possible for multiple organizations to train a global model without revealing their data. Since, in real life, data distributions differ between organizations, it is necessary to personalize the model to have better performance for the data of a single participant. In this paper, we present the first personalized federated learning method for Gradient Boosting Decision Trees (GBDT) focusing on classification tasks, i.e., Personalized Gradient Boosting Forest (pGBF). Our method extends the existing federated learning method, Gradient Boosting Forest (GBF). Our experi-ments on three public datasets show that pGBF has better or similar performance to the existing methods, GBDT and GBF, in non-IID settings. Specifically, we find that our method has higher performance than GBDT when the data of the personalization target participant is small enough for GBDT model performance to be low. Moreover, pGBF has better performance than GBF when the data distributions among the participants are non-IID. Batnyam Enkhtaivan, Isamu Teranishi |
IJCNN | 1 |
| 2022 | Knowledge Cross-Distillation for Membership PrivacyabstractAbstract A membership inference attack (MIA) poses privacy risks for the training data of a machine learning model. With an MIA, an attacker guesses if the target data are a member of the training dataset. The state-of-the-art defense against MIAs, distillation for membership privacy (DMP), requires not only private data for protection but a large amount of unlabeled public data. However, in certain privacy-sensitive domains, such as medicine and finance, the availability of public data is not guaranteed. Moreover, a trivial method for generating public data by using generative adversarial networks significantly decreases the model accuracy, as reported by the authors of DMP. To overcome this problem, we propose a novel defense against MIAs that uses knowledge distillation without requiring public data. Our experiments show that the privacy protection and accuracy of our defense are comparable to those of DMP for the benchmark tabular datasets used in MIA research, Purchase100 and Texas100, and our defense has a much better privacy-utility trade-off than those of the existing defenses that also do not use public data for the image dataset CIFAR10. Rishav Chourasia, Batnyam Enkhtaivan, Kunihiro Ito, Junki Mori, Isamu Teranishi, Hikaru Tsuchida 0001 |
Proc. Priv. Enhancing Technol. | 2 |
| 2019 | A Fair Anonymous Auction Scheme Utilizing Trusted Hardware and BlockchainabstractIn this paper, we propose an anonymous English auction scheme that utilizes trusted hardware and blockchain for the enhancement of the privacy of the bidders and the correctness of the auction. We use group signature to provide anonymity to the bidders. The hardware-based trusted execution environment (TEE) is utilized to ensure that the group manager de-anonymizes a group member only once for identifying the winner. To incorporate this idea, the blockchain transactions are signed using a group signature scheme instead of an ordinary signature scheme. Batnyam Enkhtaivan, Takao Takenouchi, Kazue Sako |
PST | 1 |