EDBT 2026 Demo / reviewers in the wild / expert
Mathilde Raynal
dblp:277/0894
· DBLP profile ↗
4ranked-venue papers
1as first author
4since 2021 · last 2025
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 1 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | On the Conflict Between Robustness and Learning in Collaborative Machine LearningabstractCollaborative Machine Learning (CML) allows participants to jointly train a machine learning model while keeping their training data private. In many scenarios where CML is seen as the solution to privacy issues, such as health-related applications, safety is also a primary concern. To ensure that CML processes produce models that output correct and reliable decisions even in the presence of potentially untrusted participants, researchers propose to use robust aggregators to filter out malicious contributions that negatively influence the training process. In this paper, we prove that the two prevalent forms of robust aggregators in the literature cannot eliminate the risk of compromise without preventing learning: in order to learn from collaboration, participants must always accept the risk of being the subject of harmful adversarial manipulation. Therefore, these robust aggregators are unsuitable for high-stake applications such as health-related or autonomous driving in which errors can result in physical harm. We empirically demonstrate the correctness of our theoretical findings on a selection of existing robust aggregators and relevant applications, including end-to-end results where we show that using existing robust aggregators can lead to an adversary can cause incorrect medical diagnosis or can cause self-driving cars to miss turns. Mathilde Raynal, Carmela Troncoso |
SP | 1 |
| 2023 | On the (In)security of Peer-to-Peer Decentralized Machine LearningabstractIn this work, we carry out the first, in-depth, privacy analysis of Decentralized Learning—a collaborative machine learning framework aimed at addressing the main limitations of federated learning. We introduce a suite of novel attacks for both passive and active decentralized adversaries. We demonstrate that, contrary to what is claimed by decentralized learning proposers, decentralized learning does not offer any security advantage over federated learning. Rather, it increases the attack surface enabling any user in the system to perform privacy attacks such as gradient inversion, and even gain full control over honest users’ local model. We also show that, given the state of the art in protections, privacy-preserving configurations of decentralized learning require fully connected networks, losing any practical advantage over the federated setup and therefore completely defeating the objective of the decentralized approach. Dario Pasquini, Mathilde Raynal, Carmela Troncoso |
SP | 2 |
| 2023 | Private Collection Matching ProtocolsabstractWe introduce Private Collection Matching (PCM) problems, in which a client aims to determine whether a collection of sets owned by a server matches their interests. Existing privacy-preserving cryptographic primitives cannot solve PCM problems efficiently without harming privacy. We propose a modular framework that enables designers to build privacy-preserving PCM systems that output one bit: whether a collection of server sets matches the client's set. The communication cost of our protocols scales linearly with the size of the client's set and is independent of the number of server elements. We demonstrate the potential of our framework by designing and implementing novel solutions for two real-world PCM problems: determining whether a dataset has chemical compounds of interest, and determining whether a document collection has relevant documents. Our evaluation shows that we offer a privacy gain with respect to existing works at a reasonable communication and computation cost. Kasra Edalatnejad, Mathilde Raynal, Wouter Lueks, Carmela Troncoso |
Proc. Priv. Enhancing Technol. | 2 |
| 2022 | HyperLogLog: Exponentially Bad in Adversarial SettingsabstractComputing the count of distinct elements in large data sets is a common task but naive approaches are memory-expensive. The HyperLogLog (HLL) algorithm (Flajolet et al., 2007) estimates a data set's cardinality while using significantly less memory than a naive approach, at the cost of some accuracy. This trade-off makes the HLL algorithm very attractive for a wide range of applications such as database management and network monitoring, where an exact count may not be needed. The HLL algorithm and variants of it are implemented in systems such as Redis and Google Big Query. Recently, the HLL algorithm has started to be proposed for use in scenarios where the inputs may be adversarially generated, for example counting social network users or detection of network scanning attacks. This prompts an examination of the performance of the HLL algorithm in the face of adversarial inputs. We show that in such a setting, the HLL algorithm's estimate of cardinality can be exponentially bad: when an adversary has access to the internals of the HLL algorithm and has some flexibility in choosing what inputs will be recorded, it can manipulate the cardinality estimate to be exponentially smaller than the true cardinality. We study both the original HLL algorithm and a more modern version of it (Ertl, 2017) that is used in Redis. We present experimental results confirming our theoretical analysis. Finally, we consider attack prevention: we show how to modify HLL in a simple way that provably prevents cardinality estimate manipulation attacks. Kenneth G. Paterson, Mathilde Raynal |
EuroS&P | 2 |