Harsh Kasyap

dblp:280/6640 · DBLP profile ↗
← Back
10ranked-venue papers
8as first author
10since 2021 · last 2025
0000-0002-8313-6354ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 3 first-author · 5 since 2021Artificial intelligence and machine learning · 3 · 3 first-author · 3 since 2021Computer networks · 2 · 2 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 first-author · 2 since 2021
YearPublicationVenuePosition
2025 Fairness-Constrained Optimization Attack in Federated Learning
abstract
Federated learning (FL) is a privacy-preserving machine learning technique that facilitates collaboration among participants across demographics. FL enables model sharing, while restricting the movement of data. Since FL provides participants with independence over their training data, it becomes susceptible to poisoning attacks. Such collaboration also propagates bias among the participants, even unintentionally, due to different data distribution or historical bias present in the data. This paper proposes an intentional fairness attack, where a client maliciously sends a biased model, by increasing the fairness loss while training, even considering homogeneous data distribution. The fairness loss is calculated by solving an optimization problem for fairness metrics such as demographic parity and equalized odds. The attack is insidious and hard to detect, as it maintains global accuracy even after increasing the bias. We evaluate our attack against the state-of-the-art Byzantine-robust and fairness-aware aggregation schemes over different datasets, in various settings. The empirical results demonstrate the attack efficacy by increasing the bias up to 90%, even in the presence of a single malicious client in the FL system.
Harsh Kasyap, Minghong Fang, Zhuqing Liu, Carsten Maple, Somanath Tripathy
TrustCom1
2025 An Improved Vector Commitment Construction with Applications to Signatures
abstract
All-but-one Vector Commitments (AVCs) randomly opens all but one of the committed vector values. Typically AVCs are instantiated using Goldwasser-Goldreich-Micali (GGM) trees. Generating these trees comprises a significant computational cost for AVCs due to a large number of hash function calls. Correlated GGM (cGGM) trees have been proposed to halve the number of hash calls and Batched AVCs (BAVCs) using a single GGM tree were integrated in the FAEST signature scheme, which improves efficiency and reduces the signature sizes. This paper proposes BACON, a BAVC with aborts that leverages a single cGGM tree. BACON executes multiple instances of AVC in a single batch and enables an abort mechanism to probabilistically reduce the commitment size. We prove that BACON is secure under the ideal cipher model and the random oracle model. We also discuss the possible application of the proposed BACON and show the theoretical efficiency compared to state-of-the-art.
Yalan Wang, Bryan Kumara, Harsh Kasyap, Liqun Chen 0002, Sumanta Sarkar, Christopher J. P. Newton, Carsten Maple, Ugur-Ilker Atmaca
TrustCom3
2024 Mitigating Bias: Model Pruning for Enhanced Model Fairness and Efficiency
abstract
Machine learning models have been instrumental in making decisions across domains, like mortgage lending and risk assessment in finance. However, these models have been found susceptible to biases, causing unfair decisions for a specific group of individuals. Such bias is generally based on some protected (or sensitive) attributes, such as age, sex, or race, and is still prevalent due to historical context or algorithmic bias. There have been several efforts to ensure equal opportunities for each individual/group, based on creditworthiness, rather than any social bias. Several pre-, in- and post-processing bias mitigation techniques have been proposed. However, these techniques perform data transformation or design new constraint/cost functions, which are task-specific, to achieve a fair prediction. Such techniques even require further access to the complete training/testing data. This paper proposes a novel post-processing bias mitigation technique that employs a model interpretation strategy to find the responsible model weights causing the bias. Pruning only a few model weights exhibits group fairness in model predictions while maintaining competitive accuracy levels, thus aligning with the goals of fairness and efficiency in decision-making. The proposed scheme requires access to only a few data samples representing the protected attributes, without exposing the complete training data. Through extensive experiments with multiple census datasets/methods, we demonstrate the efficacy of our approach, achieving up to a significant 50% reduction in bias while preserving the overall accuracy.
Harsh Kasyap, Ugur-Ilker Atmaca, Michela Iezzi, Toby Walsh, Carsten Maple
ECAI1
2024 Beyond data poisoning in federated learning
Harsh Kasyap, Somanath Tripathy
Expert Syst. Appl.1
2024 Privacy-preserving and Byzantine-robust Federated Learning Framework using Permissioned Blockchain
Harsh Kasyap, Somanath Tripathy
Expert Syst. Appl.1
2024 Sine: Similarity is Not Enough for Mitigating Local Model Poisoning Attacks in Federated Learning
abstract
Federated learning is a collaborative learning paradigm that brings the model to the edge for training over the participants' local data under the orchestration of a trusted server. Though this paradigm protects data privacy, the aggregator has no control over the local data or model at the edge. So, malicious participants could perturb their locally held data or model to post an insidious update, degrading global model accuracy. Recent Byzantine-robust aggregation rules could defend against data poisoning attacks. Also, model poisoning attacks have become more ingenious and adaptive to the existing defenses. But these attacks are crafted against specific aggregation rules. This work presents a generic model poisoning attack framework named Sine (Similarity is not enough), which harnesses vulnerabilities in cosine similarity to increase the impact of poisoning attacks by 20-30%. Sine makes convergence unachievable by maintaining the persistence of the attack. Further, we propose an effective defense technique called FLTC (FL Trusted Coordinates) to avoid such issues. FLTC selects the trusted coordinates and aggregates them based on the change in their direction and magnitude with respect to a trusted base model update. FLTC could successfully defend against poisoning attacks, including adaptive model poisoning attacks, by restricting the attack impact to 2-4%.
Harsh Kasyap, Somanath Tripathy
IEEE Trans. Dependable Secur. Comput.1
2023 HDFL: Private and Robust Federated Learning using Hyperdimensional Computing
abstract
Machine learning (ML) has seen widespread adoption across different domains and is used to make critical decisions. However, with profuse and diverse data available, collaboration is indispensable for ML. The traditional centralized ML for collaboration is susceptible to data theft and inference attacks. Federated learning (FL) promises secure collaborative machine learning by moving the model to the data. However, FL faces the challenge of data and model poisoning attacks. This is because FL provides autonomy to the participants. Many Byzantine-robust aggregation schemes exist to identify such poisoned model updates from participants. But, these schemes require raw access to the local model updates, which exposes them to inference attacks. Thus, the existing FL is still insecure to be adopted.This paper proposes the very first generic FL framework, which is both resistant to inference attacks and robust to poisoning attacks. The proposed framework uses hyperdimensional computing (HDC) coupled with FL, called HDFL. HDFL is compatible with different (ML) model architectures and existing Byzantine-robust defenses. HDFL restricts drop in accuracy to 1-2%. HDFL does not add any additional communication overheads and incurs negligible computational time in encoding and decoding raw local model updates. Empirical evaluation demonstrates the effectiveness of HDFL. HDFL performs secure aggregation and achieves no-attack accuracy, even in the presence of 40% attackers, in just 1.2s per iteration.
Harsh Kasyap, Somanath Tripathy, Mauro Conti
TrustCom1
2023 An Efficient Blockchain Assisted Reputation Aware Decentralized Federated Learning Framework
abstract
Because of the widespread presence and ease of access to the Internet, edge devices are the perfect candidates for providing quality training on a variety of applications. However, their participation is restrained due to potential leakage of sensitive and private data. Federated learning targets to address these issues by bringing the model to the device and keeping the data in place. Still, it suffers from inherent security issues such as malicious participation and unfair contribution. The central server may become a bottleneck as well as induce biased aggregation and incentives. This article proposes a blockchain assisted federated learning framework, which fosters honest participation with reduced overheads, facilitating fair contribution-based weighted incentivization. A new consensus mechanism named PoIS (Proof of Interpretation and Selection) is proposed based on honest clients’ contributions. PoIS uses model interpretation techniques for evaluating and calculating individual contributions. The aggregation of feature attributions in PoIS, is able to detect the adversaries, and the label-wise aggregation of attributions across the participants helps to define the prominent contributors. Further, we devise a credit function based on the contribution, relevance as well as the past performance for calculating incentives. Extensive experiments have been carried out for the proposed architecture with different settings, models, and datasets, to verify our claim. It successfully restricts the attack to less than 5%, and selects the prominent (top-${k}$) contributors. Theoretical analysis provides the guarantee for byzantine-robust aggregation, in a malicious setting.
Harsh Kasyap, Arpan Manna, Somanath Tripathy
IEEE Trans. Netw. Serv. Manag.1
2021 Moat: Model Agnostic Defense against Targeted Poisoning Attacks in Federated Learning
Arpan Manna, Harsh Kasyap, Somanath Tripathy
ICICS (1)2
2021 Privacy-preserving Decentralized Learning Framework for Healthcare System
abstract
Clinical trials and drug discovery would not be effective without the collaboration of institutions. Earlier, it has been at the cost of individual’s privacy. Several pacts and compliances have been enforced to avoid data breaches. The existing schemes collect the participant’s data to a central repository for learning predictions as the collaboration is indispensable for research advances. The current COVID pandemic has put a question mark on our existing setup where the existing data repository has proved to be obsolete. There is a need for contemporary data collection, processing, and learning. The smartphones and devices held by the last person of the society have also made them a potential contributor. It demands to design a distributed and decentralized Collaborative Learning system that would make the knowledge inference from every data point. Federated Learning [21], proposed by Google, brings the concept of in-place model training by keeping the data intact to the device. Though it is privacy-preserving in nature, however, it is susceptible to inference, poisoning, and Sybil attacks. Blockchain is a decentralized programming paradigm that provides a broader control of the system, making it attack resistant. It poses challenges of high computing power, storage, and latency. These emerging technologies can contribute to the desired learning system and motivate them to address their security and efficiency issues. This article systematizes the security issues in Federated Learning, its corresponding mitigation strategies, and Blockchain’s challenges. Further, a Blockchain-based Federated Learning architecture with two layers of participation is presented, which improves the global model accuracy and guarantees participant’s privacy. It leverages the channel mechanism of Blockchain for parallel model training and distribution. It facilitates establishing decentralized trust between the participants and the gateways using the Blockchain, which helps to have only honest participants.
Harsh Kasyap, Somanath Tripathy
ACM Trans. Multim. Comput. Commun. Appl.1