EDBT 2026 Demo / reviewers in the wild / expert
Najeeb Jebreel
dblp:270/3982 · also Najeeb Moharram Jebreel
· DBLP profile ↗
16ranked-venue papers
8as first author
13since 2021 · last 2026
0000-0002-4911-3802ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 10 · 5 first-author · 9 since 2021Security and privacy · 4 · 2 first-author · 3 since 2021Systems, architecture and hardware · 1Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Revisiting the LiRA Membership Inference Attack Under Realistic AssumptionsabstractMembership inference attacks (MIAs) have become the standard tool for evaluating privacy leakage in machine learning (ML). Among them, the Likelihood-Ratio Attack (LiRA) is widely regarded as the state of the art when sufficient shadow models are available. However, prior evaluations have often overstated the effectiveness of LiRA by attacking models overconfident on their training samples, calibrating thresholds on target data, assuming balanced membership priors, and/or overlooking attack reproducibility. We re-evaluate LiRA under a realistic protocol that (i) trains models using anti-overfitting (AOF) (and transfer learning (TL), when applicable) to reduce overconfidence as it would be desirable in production models; (ii) calibrates decision thresholds from shadow models and data rather than (usually unavailable) target data; (iii) measures positive predictive value (PPV, a.k.a. precision) under shadow-based thresholds and skewed - rather than unrealistically balanced - membership priors (pi <= 10%); and (iv) quantifies per-sample membership reproducibility across different seeds and training variations. In this setting, we find that (a) AOF significantly weakens LiRA and TL further reduces the effectiveness of the attack, while improving model accuracy; (b) with shadow-based thresholds and skewed priors, LiRA's PPV often drops from near-perfect to substantially lower levels, especially under AOF/AOF+TL and for pi <= 10%; and (c) LiRA's thresholded vulnerable sets at extremely low FPR exhibit poor reproducibility across runs, while likelihood ratio-based rankings are more stable. These results suggest that (i) LiRA, and likely weaker MIAs, are less effective than previously suggested, and their positive inferences can be less reliable under realistic settings; and (ii) for MIAs to serve as meaningful privacy auditing tools, their evaluation must reflect pragmatic training practices, feasible attacker assumptions, and reproducibility considerations. We release our code at: https://github.com/najeebjebreel/lira_analysis. Najeeb Jebreel, Mona Khalil, David Sánchez 0001, Josep Domingo-Ferrer |
Proc. Priv. Enhancing Technol. | 1 |
| 2025 | Defenses Against Membership Inference Attacks on Unlearned Data
Josep Domingo-Ferrer, Najeeb Jebreel, David Sánchez 0001 |
MDAI | 2 |
| 2025 | DP2Unlearning: An efficient and guaranteed unlearning framework for LLMsabstractLarge language models (LLMs) have recently revolutionized language processing tasks but have also brought ethical and legal issues. LLMs have a tendency to memorize potentially private or copyrighted information present in the training data, which might then be delivered to end users at inference time. When this happens, a naive solution is to retrain the model from scratch after excluding the undesired data. Although this guarantees that the target data have been forgotten, it is also prohibitively expensive for LLMs. Approximate unlearning offers a more efficient alternative, as it consists of ex post modifications of the trained model itself to prevent undesirable results, but it lacks forgetting guarantees because it relies solely on empirical evidence. In this work, we present DP2Unlearning, a novel LLM unlearning framework that offers formal forgetting guarantees at a significantly lower cost than retraining from scratch on the data to be retained. DP2Unlearning involves training LLMs on textual data protected using ϵ-differential privacy (DP), which later enables efficient unlearning with the guarantees against disclosure associated with the chosen ϵ. Our experiments demonstrate that DP2Unlearning achieves similar model performance post-unlearning, compared to an LLM retraining from scratch on retained data -the gold standard exact unlearning- but at approximately half the unlearning cost. In addition, with a reasonable computational cost, it outperforms approximate unlearning methods at both preserving the utility of the model post-unlearning and effectively forgetting the targeted information. The code of our experiments is available at https://github.com/tamimalmahmud/LLM-Unlearning/tree/main/DP2Unlearning. Tamim Al Mahmud, Najeeb Jebreel, Josep Domingo-Ferrer, David Sánchez 0001 |
Neural Networks | 2 |
| 2024 | Defending Against Backdoor Attacks by Layer-wise Feature Analysis (Extended Abstract)
Najeeb Jebreel, Josep Domingo-Ferrer, Yiming Li 0004 |
IJCAI | 1 |
| 2024 | An Examination of the Alleged Privacy Threats of Confidence-Ranked Reconstruction of Census Microdata
David Sánchez 0001, Najeeb Jebreel, Krishnamurty Muralidhar, Josep Domingo-Ferrer, Alberto Blanco-Justicia |
PSD | 2 |
| 2024 | LFighter: Defending against the label-flipping attack in federated learning
Najeeb Jebreel, Josep Domingo-Ferrer, David Sánchez 0001, Alberto Blanco-Justicia |
Neural Networks | 1 |
| 2024 | Enhanced Security and Privacy via Fragmented Federated LearningabstractIn federated learning (FL), a set of participants share updates computed on their local data with an aggregator server that combines updates into a global model. However, reconciling accuracy with privacy and security is a challenge to FL. On the one hand, good updates sent by honest participants may reveal their private local information, whereas poisoned updates sent by malicious participants may compromise the model's availability and/or integrity. On the other hand, enhancing privacy via update distortion damages accuracy, whereas doing so via update aggregation damages security because it does not allow the server to filter out individual poisoned updates. To tackle the accuracy-privacy-security conflict, we propose fragmented FL (FFL), in which participants randomly exchange and mix fragments of their updates before sending them to the server. To achieve privacy, we design a lightweight protocol that allows participants to privately exchange and mix encrypted fragments of their updates so that the server can neither obtain individual updates nor link them to their originators. To achieve security, we design a reputation-based defense tailored for FFL that builds trust in participants and their mixed updates based on the quality of the fragments they exchange and the mixed updates they send. Since the exchanged fragments' parameters keep their original coordinates and attackers can be neutralized, the server can correctly reconstruct a global model from the received mixed updates without accuracy loss. Experiments on four real data sets show that FFL can prevent semi-honest servers from mounting privacy attacks, can effectively counter-poisoning attacks, and can keep the accuracy of the global model. Najeeb Jebreel, Josep Domingo-Ferrer, Alberto Blanco-Justicia, David Sánchez 0001 |
IEEE Trans. Neural Networks Learn. Syst. | 1 |
| 2023 | Defending Against Backdoor Attacks by Layer-wise Feature Analysis
Najeeb Jebreel, Josep Domingo-Ferrer, Yiming Li 0004 |
PAKDD (2) | 1 |
| 2023 | FL-Defender: Combating targeted attacks in federated learning
Najeeb Jebreel, Josep Domingo-Ferrer |
Knowl. Based Syst. | 1 |
| 2022 | Measuring Fairness in Machine Learning Models via Counterfactual Examples
Rami Haffar, Ashneet Khandpur Singh, Josep Domingo-Ferrer, Najeeb Jebreel |
MDAI | 4 |
| 2022 | Generation of Synthetic Trajectory Microdata from Language Models
Alberto Blanco-Justicia, Najeeb Jebreel, Jesús A. Manjón, Josep Domingo-Ferrer |
PSD | 2 |
| 2022 | Generating Deep Learning Model-Specific Explanations at the End User's SideabstractEnd users who cannot afford to collect and label big data to train accurate deep learning (DL) models resort to Machine Learning as a Service (MLaaS) providers, who provide paid access to accurate DL models. However, the lack of transparency in how the providers’ models make predictions causes a problem of trust. A way to increase trust (and also to align with ethical regulations) is for predictions to be accompanied by explanations locally and independently generated by the end users (rather than by explanations offered by the model providers). Explanation methods using internal components of DL models (a.k.a. model-specific explanations) are more accurate and effective than those relying solely on the inputs and outputs (a.k.a. model-agnostic explanations). However, end users lack white-box access to the internal components of the providers’ models. To tackle this issue, we propose a novel approach allowing an end user to locally generate model-specific explanations for a DL classification model accessed via a provider’s API. First, we approximate the provider’s model with a local surrogate model. We then use the surrogate model’s components to locally generate model-specific explanations that approximate the explanations obtainable with white-box access to the provider’s DL model. Specifically, we leverage the surrogate model’s gradients to generate adversarial examples that counterfactually explain why an input example is classified into a specific class. Our approach only requires the end user to have unlabeled data of size [Formula: see text] of the provider’s training data and with a similar distribution; given the small size and unlabeled nature of these data, they can be assumed to be already available to the end user or even to be supplied by the provider to build trust in his model. We demonstrate the accuracy and effectiveness of our approach through extensive experiments on two ML tasks: image classification and tabular data classification. The locally generated explanations are consistent with those obtainable with white-box access to the provider’s model, thus giving end users an independent and reliable way to determine if the provider’s model is trustworthy. Rami Haffar, Najeeb Jebreel, David Sánchez 0001, Josep Domingo-Ferrer |
Int. J. Uncertain. Fuzziness Knowl. Based Syst. | 2 |
| 2021 | Explaining Image Misclassification in Deep Learning via Adversarial Examples
Rami Haffar, Najeeb Jebreel, Josep Domingo-Ferrer, David Sánchez 0001 |
MDAI | 2 |
| 2020 | Co-Utile Peer-to-Peer Decentralized ComputingabstractOutsourcing computation allows wielding huge computational power. Even though cloud computing is the most usual type of outsourcing, resorting to idle edge devices for decentralized computation is an increasingly attractive alternative. We tackle the problem of making peer honesty and thus computation correctness self-enforcing in decentralized computing with untrusted peers. To do so, we leverage the co-utility property, which characterizes a situation in which honest co-operation is the best rational option to take even for purely selfish agents; in particular, if a protocol is co-utile, it is self-enforcing. Reputation is a powerful incentive that can make a P2P protocol co-utile. We present a co-utile P2P decentralized computing protocol that builds on a decentralized reputation calculation, which is itself co-utile and therefore self-enforcing. In this protocol, peers are given a computational task including code and data and they are incentivized to compute it correctly. Based also on co-utile reputation, we then present a protocol for federated learning, whereby peers compute on their local private data and have no incentive to randomly attack or poison the model. Our experiments show the viability of our co-utile approach to obtain correct results in both decentralized computation and federated learning. Josep Domingo-Ferrer, Alberto Blanco-Justicia, David Sánchez 0001, Najeeb Jebreel |
CCGRID | 4 |
| 2020 | Efficient Detection of Byzantine Attacks in Federated Learning Using Last Layer Biases
Najeeb Jebreel, Alberto Blanco-Justicia, David Sánchez 0001, Josep Domingo-Ferrer |
MDAI | 1 |
| 2020 | Detecting Bad Answers in Survey Data Through Unsupervised Machine Learning
Najeeb Jebreel, Rami Haffar, Ashneet Khandpur Singh, David Sánchez 0001, Josep Domingo-Ferrer, Alberto Blanco-Justicia |
PSD | 1 |