Skip to main content

Showing 1–50 of 68 results for author: Kaissis, G

Searching in archive cs. Search in all archives.
.
  1. arXiv:2407.02191  [pdf, other

    cs.LG cs.AI cs.CR math.ST stat.ML

    Attack-Aware Noise Calibration for Differential Privacy

    Authors: Bogdan Kulynych, Juan Felipe Gomez, Georgios Kaissis, Flavio du Pin Calmon, Carmela Troncoso

    Abstract: Differential privacy (DP) is a widely used approach for mitigating privacy risks when training machine learning models on sensitive data. DP mechanisms add noise during training to limit the risk of information leakage. The scale of the added noise is critical, as it determines the trade-off between privacy and utility. The standard practice is to select the noise scale in terms of a privacy budge… ▽ More

    Submitted 2 July, 2024; originally announced July 2024.

  2. arXiv:2406.08918  [pdf, other

    cs.CR cs.AI cs.LG math.ST stat.ML

    Beyond the Calibration Point: Mechanism Comparison in Differential Privacy

    Authors: Georgios Kaissis, Stefan Kolek, Borja Balle, Jamie Hayes, Daniel Rueckert

    Abstract: In differentially private (DP) machine learning, the privacy guarantees of DP mechanisms are often reported and compared on the basis of a single $(\varepsilon, δ)$-pair. This practice overlooks that DP guarantees can vary substantially \emph{even between mechanisms sharing a given $(\varepsilon, δ)$}, and potentially introduces privacy vulnerabilities which can remain undetected. This motivates t… ▽ More

    Submitted 13 June, 2024; originally announced June 2024.

    Comments: ICML 2024

  3. arXiv:2404.15770  [pdf, other

    cs.CV cs.CL cs.LG

    ChEX: Interactive Localization and Region Description in Chest X-rays

    Authors: Philip Müller, Georgios Kaissis, Daniel Rueckert

    Abstract: Report generation models offer fine-grained textual interpretations of medical images like chest X-rays, yet they often lack interactivity (i.e. the ability to steer the generation process through user queries) and localized interpretability (i.e. visually grounding their predictions), which we deem essential for future adoption in clinical practice. While there have been efforts to tackle these i… ▽ More

    Submitted 24 April, 2024; originally announced April 2024.

  4. arXiv:2403.07588  [pdf, other

    cs.LG cs.CR

    Visual Privacy Auditing with Diffusion Models

    Authors: Kristian Schwethelm, Johannes Kaiser, Moritz Knolle, Daniel Rueckert, Georgios Kaissis, Alexander Ziller

    Abstract: Image reconstruction attacks on machine learning models pose a significant risk to privacy by potentially leaking sensitive information. Although defending against such attacks using differential privacy (DP) has proven effective, determining appropriate DP parameters remains challenging. Current formal guarantees on data reconstruction success suffer from overly theoretical assumptions regarding… ▽ More

    Submitted 12 March, 2024; originally announced March 2024.

  5. arXiv:2403.06601  [pdf, other

    cs.CV cs.AI

    Cross-domain and Cross-dimension Learning for Image-to-Graph Transformers

    Authors: Alexander H. Berger, Laurin Lux, Suprosanna Shit, Ivan Ezhov, Georgios Kaissis, Martin J. Menten, Daniel Rueckert, Johannes C. Paetzold

    Abstract: Direct image-to-graph transformation is a challenging task that solves object detection and relationship prediction in a single model. Due to the complexity of this task, large training datasets are rare in many domains, which makes the training of large networks challenging. This data sparsity necessitates the establishment of pre-training strategies akin to the state-of-the-art in computer visio… ▽ More

    Submitted 11 March, 2024; originally announced March 2024.

  6. arXiv:2402.12861  [pdf, other

    cs.LG cs.CR

    Bounding Reconstruction Attack Success of Adversaries Without Data Priors

    Authors: Alexander Ziller, Anneliese Riess, Kristian Schwethelm, Tamara T. Mueller, Daniel Rueckert, Georgios Kaissis

    Abstract: Reconstruction attacks on machine learning (ML) models pose a strong risk of leakage of sensitive data. In specific contexts, an adversary can (almost) perfectly reconstruct training data samples from a trained model using the model's gradients. When training ML models with differential privacy (DP), formal upper bounds on the success of such reconstruction attacks can be provided. So far, these b… ▽ More

    Submitted 20 February, 2024; originally announced February 2024.

  7. arXiv:2402.11985  [pdf, other

    cs.CV cs.LG

    Weakly Supervised Object Detection in Chest X-Rays with Differentiable ROI Proposal Networks and Soft ROI Pooling

    Authors: Philip Müller, Felix Meissen, Georgios Kaissis, Daniel Rueckert

    Abstract: Weakly supervised object detection (WSup-OD) increases the usefulness and interpretability of image classification algorithms without requiring additional supervision. The successes of multiple instance learning in this task for natural images, however, do not translate well to medical images due to the very different characteristics of their objects (i.e. pathologies). In this work, we propose We… ▽ More

    Submitted 19 February, 2024; originally announced February 2024.

  8. arXiv:2312.04590  [pdf, other

    cs.CR cs.AI cs.CV cs.LG

    Reconciling AI Performance and Data Reconstruction Resilience for Medical Imaging

    Authors: Alexander Ziller, Tamara T. Mueller, Simon Stieger, Leonhard Feiner, Johannes Brandt, Rickmer Braren, Daniel Rueckert, Georgios Kaissis

    Abstract: Artificial Intelligence (AI) models are vulnerable to information leakage of their training data, which can be highly sensitive, for example in medical imaging. Privacy Enhancing Technologies (PETs), such as Differential Privacy (DP), aim to circumvent these susceptibilities. DP is the strongest possible protection for training models while bounding the risks of inferring the inclusion of training… ▽ More

    Submitted 5 December, 2023; originally announced December 2023.

  9. arXiv:2312.03804  [pdf, other

    cs.CV

    How Low Can You Go? Surfacing Prototypical In-Distribution Samples for Unsupervised Anomaly Detection

    Authors: Felix Meissen, Johannes Getzner, Alexander Ziller, Georgios Kaissis, Daniel Rueckert

    Abstract: Unsupervised anomaly detection (UAD) alleviates large labeling efforts by training exclusively on unlabeled in-distribution data and detecting outliers as anomalies. Generally, the assumption prevails that large training datasets allow the training of higher-performing UAD models. However, in this work, we show that using only very few training samples can already match - and in some cases even im… ▽ More

    Submitted 6 December, 2023; originally announced December 2023.

  10. arXiv:2311.03075  [pdf, other

    cs.LG cs.CR cs.IT

    SoK: Memorisation in machine learning

    Authors: Dmitrii Usynin, Moritz Knolle, Georgios Kaissis

    Abstract: Quantifying the impact of individual data samples on machine learning models is an open research problem. This is particularly relevant when complex and high-dimensional relationships have to be learned from a limited sample of the data generating distribution, such as in deep learning. It was previously shown that, in these cases, models rely not only on extracting patterns which are helpful for… ▽ More

    Submitted 6 November, 2023; originally announced November 2023.

  11. Propagation and Attribution of Uncertainty in Medical Imaging Pipelines

    Authors: Leonhard F. Feiner, Martin J. Menten, Kerstin Hammernik, Paul Hager, Wenqi Huang, Daniel Rueckert, Rickmer F. Braren, Georgios Kaissis

    Abstract: Uncertainty estimation, which provides a means of building explainable neural networks for medical imaging applications, have mostly been studied for single deep learning models that focus on a specific task. In this paper, we propose a method to propagate uncertainty through cascades of deep learning models in medical imaging pipelines. This allows us to aggregate the uncertainty in later stages… ▽ More

    Submitted 28 September, 2023; originally announced September 2023.

  12. arXiv:2309.14198  [pdf, other

    cs.LG cs.CV cs.CY eess.IV

    (Predictable) Performance Bias in Unsupervised Anomaly Detection

    Authors: Felix Meissen, Svenja Breuer, Moritz Knolle, Alena Buyx, Ruth Müller, Georgios Kaissis, Benedikt Wiestler, Daniel Rückert

    Abstract: Background: With the ever-increasing amount of medical imaging data, the demand for algorithms to assist clinicians has amplified. Unsupervised anomaly detection (UAD) models promise to aid in the crucial first step of disease detection. While previous studies have thoroughly explored fairness in supervised models in healthcare, for UAD, this has so far been unexplored. Methods: In this study, w… ▽ More

    Submitted 25 September, 2023; originally announced September 2023.

    Comments: 11 pages, 5 Figures, 1 panel

  13. arXiv:2309.12325  [pdf, other

    cs.CY cs.AI cs.CV cs.LG

    FUTURE-AI: International consensus guideline for trustworthy and deployable artificial intelligence in healthcare

    Authors: Karim Lekadir, Aasa Feragen, Abdul Joseph Fofanah, Alejandro F Frangi, Alena Buyx, Anais Emelie, Andrea Lara, Antonio R Porras, An-Wen Chan, Arcadi Navarro, Ben Glocker, Benard O Botwe, Bishesh Khanal, Brigit Beger, Carol C Wu, Celia Cintas, Curtis P Langlotz, Daniel Rueckert, Deogratias Mzurikwao, Dimitrios I Fotiadis, Doszhan Zhussupov, Enzo Ferrante, Erik Meijering, Eva Weicken, Fabio A González , et al. (93 additional authors not shown)

    Abstract: Despite major advances in artificial intelligence (AI) for medicine and healthcare, the deployment and adoption of AI technologies remain limited in real-world clinical practice. In recent years, concerns have been raised about the technical, clinical, ethical and legal risks associated with medical AI. To increase real world adoption, it is essential that medical AI tools are trusted and accepted… ▽ More

    Submitted 11 August, 2023; originally announced September 2023.

    ACM Class: I.2.0; I.4.0; I.5.0

  14. arXiv:2309.02875  [pdf, other

    cs.CV cs.AI

    MAD: Modality Agnostic Distance Measure for Image Registration

    Authors: Vasiliki Sideri-Lampretsa, Veronika A. Zimmer, Huaqi Qiu, Georgios Kaissis, Daniel Rueckert

    Abstract: Multi-modal image registration is a crucial pre-processing step in many medical applications. However, it is a challenging task due to the complex intensity relationships between different imaging modalities, which can result in large discrepancy in image appearance. The success of multi-modal image registration, whether it is conventional or learning based, is predicated upon the choice of an app… ▽ More

    Submitted 6 September, 2023; originally announced September 2023.

  15. arXiv:2309.02578  [pdf, other

    cs.CV cs.LG

    Anatomy-Driven Pathology Detection on Chest X-rays

    Authors: Philip Müller, Felix Meissen, Johannes Brandt, Georgios Kaissis, Daniel Rueckert

    Abstract: Pathology detection and delineation enables the automatic interpretation of medical scans such as chest X-rays while providing a high level of explainability to support radiologists in making informed decisions. However, annotating pathology bounding boxes is a time-consuming task such that large public datasets for this purpose are scarce. Current approaches thus use weakly supervised object dete… ▽ More

    Submitted 5 September, 2023; originally announced September 2023.

    Comments: Accepted at MICCAI 2023

  16. arXiv:2308.12018  [pdf, other

    cs.LG cs.CR

    Bias-Aware Minimisation: Understanding and Mitigating Estimator Bias in Private SGD

    Authors: Moritz Knolle, Robert Dorfman, Alexander Ziller, Daniel Rueckert, Georgios Kaissis

    Abstract: Differentially private SGD (DP-SGD) holds the promise of enabling the safe and responsible application of machine learning to sensitive datasets. However, DP-SGD only provides a biased, noisy estimate of a mini-batch gradient. This renders optimisation steps less effective and limits model utility as a result. With this work, we show a connection between per-sample gradient norms and the estimatio… ▽ More

    Submitted 23 August, 2023; originally announced August 2023.

    Comments: Accepted to the 2023 Theory and Practice of Differential Privacy (TPDP) Workshop

  17. arXiv:2308.02493  [pdf, other

    eess.IV cs.CV

    Body Fat Estimation from Surface Meshes using Graph Neural Networks

    Authors: Tamara T. Mueller, Siyu Zhou, Sophie Starck, Friederike Jungmann, Alexander Ziller, Orhun Aksoy, Danylo Movchan, Rickmer Braren, Georgios Kaissis, Daniel Rueckert

    Abstract: Body fat volume and distribution can be a strong indication for a person's overall health and the risk for develo** diseases like type 2 diabetes and cardiovascular diseases. Frequently used measures for fat estimation are the body mass index (BMI), waist circumference, or the waist-hip-ratio. However, those are rather imprecise measures that do not allow for a discrimination between different t… ▽ More

    Submitted 31 October, 2023; v1 submitted 13 July, 2023; originally announced August 2023.

  18. arXiv:2307.10112  [pdf, other

    cs.SI cs.AI cs.LG

    Extended Graph Assessment Metrics for Graph Neural Networks

    Authors: Tamara T. Mueller, Sophie Starck, Leonhard F. Feiner, Kyriaki-Margarita Bintsi, Daniel Rueckert, Georgios Kaissis

    Abstract: When re-structuring patient cohorts into so-called population graphs, initially independent data points can be incorporated into one interconnected graph structure. This population graph can then be used for medical downstream tasks using graph neural networks (GNNs). The construction of a suitable graph structure is a challenging step in the learning pipeline that can have severe impact on model… ▽ More

    Submitted 19 September, 2023; v1 submitted 13 July, 2023; originally announced July 2023.

  19. arXiv:2307.06760  [pdf, other

    cs.LG cs.CR

    Privacy-Utility Trade-offs in Neural Networks for Medical Population Graphs: Insights from Differential Privacy and Graph Structure

    Authors: Tamara T. Mueller, Maulik Chevli, Ameya Daigavane, Daniel Rueckert, Georgios Kaissis

    Abstract: We initiate an empirical investigation into differentially private graph neural networks on population graphs from the medical domain by examining privacy-utility trade-offs at different privacy levels on both real-world and synthetic datasets and performing auditing through membership inference attacks. Our findings highlight the potential and the challenges of this specific DP application area.… ▽ More

    Submitted 13 July, 2023; originally announced July 2023.

  20. arXiv:2307.06614  [pdf, other

    eess.IV cs.CV

    Interpretable 2D Vision Models for 3D Medical Images

    Authors: Alexander Ziller, Ayhan Can Erdur, Marwa Trigui, Alp Güvenir, Tamara T. Mueller, Philip Müller, Friederike Jungmann, Johannes Brandt, Jan Peeken, Rickmer Braren, Daniel Rueckert, Georgios Kaissis

    Abstract: Training Artificial Intelligence (AI) models on 3D images presents unique challenges compared to the 2D case: Firstly, the demand for computational resources is significantly higher, and secondly, the availability of large datasets for pre-training is often limited, impeding training success. This study proposes a simple approach of adapting 2D networks with an intermediate feature representation… ▽ More

    Submitted 5 December, 2023; v1 submitted 13 July, 2023; originally announced July 2023.

  21. arXiv:2307.03928  [pdf, other

    cs.CR cs.AI

    Bounding data reconstruction attacks with the hypothesis testing interpretation of differential privacy

    Authors: Georgios Kaissis, Jamie Hayes, Alexander Ziller, Daniel Rueckert

    Abstract: We explore Reconstruction Robustness (ReRo), which was recently proposed as an upper bound on the success of data reconstruction attacks against machine learning models. Previous research has demonstrated that differential privacy (DP) mechanisms also provide ReRo, but so far, only asymptotic Monte Carlo estimates of a tight ReRo bound have been shown. Directly computable ReRo bounds for general D… ▽ More

    Submitted 8 July, 2023; originally announced July 2023.

  22. arXiv:2306.06503  [pdf

    cs.LG cs.AI cs.CR eess.IV

    Preserving privacy in domain transfer of medical AI models comes at no performance costs: The integral role of differential privacy

    Authors: Soroosh Tayebi Arasteh, Mahshad Lotfinia, Teresa Nolte, Marwin Saehn, Peter Isfort, Christiane Kuhl, Sven Nebelung, Georgios Kaissis, Daniel Truhn

    Abstract: Develo** robust and effective artificial intelligence (AI) models in medicine requires access to large amounts of patient data. The use of AI models solely trained on large multi-institutional datasets can help with this, yet the imperative to ensure data privacy remains, particularly as membership inference risks breaching patient confidentiality. As a proposed remedy, we advocate for the integ… ▽ More

    Submitted 7 December, 2023; v1 submitted 10 June, 2023; originally announced June 2023.

    Comments: Published in Radiology: Artificial Intelligence. RSNA

    Journal ref: Radiology: Artificial Intelligence, 2024, 6(1), e230212

  23. arXiv:2305.02942  [pdf, other

    cs.LG cs.AI cs.CR

    Incentivising the federation: gradient-based metrics for data selection and valuation in private decentralised training

    Authors: Dmitrii Usynin, Daniel Rueckert, Georgios Kaissis

    Abstract: Obtaining high-quality data for collaborative training of machine learning models can be a challenging task due to A) regulatory concerns and B) a lack of data owner incentives to participate. The first issue can be addressed through the combination of distributed machine learning techniques (e.g. federated learning) and privacy enhancing technologies (PET), such as the differentially private (DP)… ▽ More

    Submitted 16 April, 2024; v1 submitted 4 May, 2023; originally announced May 2023.

    Comments: Accepted at EICC 2024

  24. Interactive and Explainable Region-guided Radiology Report Generation

    Authors: Tim Tanida, Philip Müller, Georgios Kaissis, Daniel Rueckert

    Abstract: The automatic generation of radiology reports has the potential to assist radiologists in the time-consuming task of report writing. Existing methods generate the full report from image-level features, failing to explicitly focus on anatomical regions in the image. We propose a simple yet effective region-guided report generation model that detects anatomical regions and then describes individual,… ▽ More

    Submitted 17 April, 2023; originally announced April 2023.

    Comments: Accepted at CVPR 2023

    Journal ref: 2023 IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), pp. 7433-7442

  25. arXiv:2303.01920  [pdf, other

    cs.CV

    Robust Detection Outcome: A Metric for Pathology Detection in Medical Images

    Authors: Felix Meissen, Philip Müller, Georgios Kaissis, Daniel Rueckert

    Abstract: Detection of pathologies is a fundamental task in medical imaging and the evaluation of algorithms that can perform this task automatically is crucial. However, current object detection metrics for natural images do not reflect the specific clinical requirements in pathology detection sufficiently. To tackle this problem, we propose Robust Detection Outcome (RoDeO); a novel metric for evaluating a… ▽ More

    Submitted 3 March, 2023; originally announced March 2023.

    Comments: Accepted at MIDL 2023

  26. Unsupervised Pathology Detection: A Deep Dive Into the State of the Art

    Authors: Ioannis Lagogiannis, Felix Meissen, Georgios Kaissis, Daniel Rueckert

    Abstract: Deep unsupervised approaches are gathering increased attention for applications such as pathology detection and segmentation in medical images since they promise to alleviate the need for large labeled datasets and are more generalizable than their supervised counterparts in detecting any kind of rare pathology. As the Unsupervised Anomaly Detection (UAD) literature continuously grows and new para… ▽ More

    Submitted 29 July, 2023; v1 submitted 1 March, 2023; originally announced March 2023.

    Comments: 12 pages, 4 figures, accepted for publication in IEEE Transactions on Medical Imaging (added copyright, DOI information)

  27. arXiv:2302.01622  [pdf, other

    eess.IV cs.AI cs.CR cs.CV cs.LG

    Private, fair and accurate: Training large-scale, privacy-preserving AI models in medical imaging

    Authors: Soroosh Tayebi Arasteh, Alexander Ziller, Christiane Kuhl, Marcus Makowski, Sven Nebelung, Rickmer Braren, Daniel Rueckert, Daniel Truhn, Georgios Kaissis

    Abstract: Artificial intelligence (AI) models are increasingly used in the medical domain. However, as medical data is highly sensitive, special precautions to ensure its protection are required. The gold standard for privacy preservation is the introduction of differential privacy (DP) to model training. Prior work indicates that DP has negative implications on model accuracy and fairness, which are unacce… ▽ More

    Submitted 16 March, 2024; v1 submitted 3 February, 2023; originally announced February 2023.

    Comments: Published in Communications Medicine. Nature Portfolio

    Journal ref: Commun Med 4(1), 46 (2024)

  28. arXiv:2301.13104  [pdf, other

    cs.CV cs.CR cs.LG

    Equivariant Differentially Private Deep Learning: Why DP-SGD Needs Sparser Models

    Authors: Florian A. Hölzl, Daniel Rueckert, Georgios Kaissis

    Abstract: Differentially Private Stochastic Gradient Descent (DP-SGD) limits the amount of private information deep learning models can memorize during training. This is achieved by clip** and adding noise to the model's gradients, and thus networks with more parameters require proportionally stronger perturbation. As a result, large models have difficulties learning useful information, rendering training… ▽ More

    Submitted 21 June, 2023; v1 submitted 30 January, 2023; originally announced January 2023.

  29. arXiv:2212.01082  [pdf, other

    cs.CR

    Membership Inference Attacks Against Semantic Segmentation Models

    Authors: Tomas Chobola, Dmitrii Usynin, Georgios Kaissis

    Abstract: Membership inference attacks aim to infer whether a data record has been used to train a target model by observing its predictions. In sensitive domains such as healthcare, this can constitute a severe privacy violation. In this work we attempt to address the existing knowledge gap by conducting an exhaustive study of membership inference attacks and defences in the domain of semantic image segmen… ▽ More

    Submitted 2 December, 2022; originally announced December 2022.

    Comments: Submitted as conference paper to PETS 2023

  30. arXiv:2211.10173  [pdf, other

    cs.CR cs.LG

    How Do Input Attributes Impact the Privacy Loss in Differential Privacy?

    Authors: Tamara T. Mueller, Stefan Kolek, Friederike Jungmann, Alexander Ziller, Dmitrii Usynin, Moritz Knolle, Daniel Rueckert, Georgios Kaissis

    Abstract: Differential privacy (DP) is typically formulated as a worst-case privacy guarantee over all individuals in a database. More recently, extensions to individual subjects or their attributes, have been introduced. Under the individual/per-instance DP interpretation, we study the connection between the per-subject gradient norm in DP neural networks and individual privacy loss and introduce a novel m… ▽ More

    Submitted 18 November, 2022; originally announced November 2022.

  31. arXiv:2211.07254  [pdf, other

    cs.CV cs.LG

    The Role of Local Alignment and Uniformity in Image-Text Contrastive Learning on Medical Images

    Authors: Philip Müller, Georgios Kaissis, Daniel Rueckert

    Abstract: Image-text contrastive learning has proven effective for pretraining medical image models. When targeting localized downstream tasks like semantic segmentation or object detection, additional local contrastive losses that align image regions with sentences have shown promising results. We study how local contrastive losses are related to global (per-sample) contrastive losses and which effects the… ▽ More

    Submitted 2 March, 2023; v1 submitted 14 November, 2022; originally announced November 2022.

    Comments: NeurIPS 2022 Workshop: Self-Supervised Learning - Theory and Practice (Reason for updated version: correction of a typo in Eq. (2) and (3))

  32. arXiv:2211.04180  [pdf, other

    eess.IV cs.CV

    Exploiting segmentation labels and representation learning to forecast therapy response of PDAC patients

    Authors: Alexander Ziller, Ayhan Can Erdur, Friederike Jungmann, Daniel Rueckert, Rickmer Braren, Georgios Kaissis

    Abstract: The prediction of pancreatic ductal adenocarcinoma therapy response is a clinically challenging and important task in this high-mortality tumour entity. The training of neural networks able to tackle this challenge is impeded by a lack of large datasets and the difficult anatomical localisation of the pancreas. Here, we propose a hybrid deep neural network pipeline to predict tumour response to in… ▽ More

    Submitted 30 March, 2023; v1 submitted 8 November, 2022; originally announced November 2022.

  33. arXiv:2210.13028  [pdf, other

    cs.CR cs.AI stat.AP

    Generalised Likelihood Ratio Testing Adversaries through the Differential Privacy Lens

    Authors: Georgios Kaissis, Alexander Ziller, Stefan Kolek Martinez de Azagra, Daniel Rueckert

    Abstract: Differential Privacy (DP) provides tight upper bounds on the capabilities of optimal adversaries, but such adversaries are rarely encountered in practice. Under the hypothesis testing/membership inference interpretation of DP, we examine the Gaussian mechanism and relax the usual assumption of a Neyman-Pearson-Optimal (NPO) adversary to a Generalized Likelihood Test (GLRT) adversary. This mild rel… ▽ More

    Submitted 24 October, 2022; originally announced October 2022.

  34. arXiv:2210.05330  [pdf, other

    cs.LG

    Label Noise-Robust Learning using a Confidence-Based Sieving Strategy

    Authors: Reihaneh Torkzadehmahani, Reza Nasirigerdeh, Daniel Rueckert, Georgios Kaissis

    Abstract: In learning tasks with label noise, improving model robustness against overfitting is a pivotal challenge because the model eventually memorizes labels, including the noisy ones. Identifying the samples with noisy labels and preventing the model from learning them is a promising approach to address this challenge. When training with noisy labels, the per-class confidence scores of the model, repre… ▽ More

    Submitted 27 September, 2023; v1 submitted 11 October, 2022; originally announced October 2022.

    Comments: https://openreview.net/forum?id=3taIQG4C7H

    Journal ref: Transactions on Machine Learning Research, 2835-8856, 2023

  35. arXiv:2210.00053  [pdf, other

    cs.LG cs.CR

    Kernel Normalized Convolutional Networks for Privacy-Preserving Machine Learning

    Authors: Reza Nasirigerdeh, Javad Torkzadehmahani, Daniel Rueckert, Georgios Kaissis

    Abstract: Normalization is an important but understudied challenge in privacy-related application domains such as federated learning (FL), differential privacy (DP), and differentially private federated learning (DP-FL). While the unsuitability of batch normalization for these domains has already been shown, the impact of other normalization methods on the performance of federated or differentially private… ▽ More

    Submitted 23 November, 2022; v1 submitted 30 September, 2022; originally announced October 2022.

    Comments: To appear in the IEEE Conference on Secure and Trustworthy Machine Learning (SaTML), February 2023

    Journal ref: 1st IEEE Conference on Secure and Trustworthy Machine Learning (SaTML), 2023

  36. arXiv:2209.04338  [pdf, other

    eess.IV cs.CR cs.CV cs.LG

    Bridging the Gap: Differentially Private Equivariant Deep Learning for Medical Image Analysis

    Authors: Florian A. Hölzl, Daniel Rueckert, Georgios Kaissis

    Abstract: Machine learning with formal privacy-preserving techniques like Differential Privacy (DP) allows one to derive valuable insights from sensitive medical imaging data while promising to protect patient privacy, but it usually comes at a sharp privacy-utility trade-off. In this work, we propose to use steerable equivariant convolutional networks for medical image analysis with DP. Their improved feat… ▽ More

    Submitted 20 June, 2023; v1 submitted 9 September, 2022; originally announced September 2022.

    Comments: Accepted as extended abstract at GeoMedIA Workshop 2022 (https://openreview.net/forum?id=rGYfMrMxI17)

  37. Unsupervised Anomaly Localization with Structural Feature-Autoencoders

    Authors: Felix Meissen, Johannes Paetzold, Georgios Kaissis, Daniel Rueckert

    Abstract: Unsupervised Anomaly Detection has become a popular method to detect pathologies in medical images as it does not require supervision or labels for training. Most commonly, the anomaly detection model generates a "normal" version of an input image, and the pixel-wise $l^p$-difference of the two is used to localize anomalies. However, large residuals often occur due to imperfect reconstruction of t… ▽ More

    Submitted 23 August, 2022; originally announced August 2022.

    Comments: 10 pages, 5 figures, one table, accepted to the MICCAI 2021 BrainLes Workshop

  38. arXiv:2205.10089  [pdf, other

    cs.LG cs.CV

    Kernel Normalized Convolutional Networks

    Authors: Reza Nasirigerdeh, Reihaneh Torkzadehmahani, Daniel Rueckert, Georgios Kaissis

    Abstract: Existing convolutional neural network architectures frequently rely upon batch normalization (BatchNorm) to effectively train the model. BatchNorm, however, performs poorly with small batch sizes, and is inapplicable to differential privacy. To address these limitations, we propose the kernel normalization (KernelNorm) and kernel normalized convolutional layers, and incorporate them into kernel no… ▽ More

    Submitted 4 March, 2024; v1 submitted 20 May, 2022; originally announced May 2022.

    Journal ref: Transactions on Machine Learning Research (TMLR), 2024

  39. arXiv:2205.04095  [pdf, other

    cs.CV cs.LG

    SmoothNets: Optimizing CNN architecture design for differentially private deep learning

    Authors: Nicolas W. Remerscheid, Alexander Ziller, Daniel Rueckert, Georgios Kaissis

    Abstract: The arguably most widely employed algorithm to train deep neural networks with Differential Privacy is DPSGD, which requires clip** and noising of per-sample gradients. This introduces a reduction in model utility compared to non-private training. Empirically, it can be observed that this accuracy degradation is strongly dependent on the model architecture. We investigated this phenomenon and, b… ▽ More

    Submitted 9 May, 2022; originally announced May 2022.

  40. arXiv:2205.02652  [pdf, other

    cs.LG cs.CR

    Can collaborative learning be private, robust and scalable?

    Authors: Dmitrii Usynin, Helena Klause, Johannes C. Paetzold, Daniel Rueckert, Georgios Kaissis

    Abstract: In federated learning for medical image analysis, the safety of the learning protocol is paramount. Such settings can often be compromised by adversaries that target either the private data used by the federation or the integrity of the model itself. This requires the medical imaging community to develop mechanisms to train collaborative models that are private and robust against adversarial data.… ▽ More

    Submitted 8 August, 2022; v1 submitted 5 May, 2022; originally announced May 2022.

    Comments: Accepted at MICCAI DeCaF 2022

  41. Privacy: An axiomatic approach

    Authors: Alexander Ziller, Tamara Mueller, Rickmer Braren, Daniel Rueckert, Georgios Kaissis

    Abstract: The increasing prevalence of large-scale data collection in modern society represents a potential threat to individual privacy. Addressing this threat, for example through privacy-enhancing technologies (PETs), requires a rigorous definition of what exactly is being protected, that is, of privacy itself. In this work, we formulate an axiomatic definition of privacy based on quantifiable and irredu… ▽ More

    Submitted 22 March, 2022; originally announced March 2022.

  42. arXiv:2203.10202  [pdf, other

    cs.CV

    Relationformer: A Unified Framework for Image-to-Graph Generation

    Authors: Suprosanna Shit, Rajat Koner, Bastian Wittmann, Johannes Paetzold, Ivan Ezhov, Hongwei Li, Jiazhen Pan, Sahand Sharifzadeh, Georgios Kaissis, Volker Tresp, Bjoern Menze

    Abstract: A comprehensive representation of an image requires understanding objects and their mutual relationship, especially in image-to-graph generation, e.g., road network extraction, blood-vessel network extraction, or scene graph generation. Traditionally, image-to-graph generation is addressed with a two-stage approach consisting of object detection followed by a separate relation prediction, which pr… ▽ More

    Submitted 18 March, 2022; originally announced March 2022.

  43. arXiv:2203.09205  [pdf, other

    cs.CR cs.AI cs.LG

    SoK: Differential Privacy on Graph-Structured Data

    Authors: Tamara T. Mueller, Dmitrii Usynin, Johannes C. Paetzold, Daniel Rueckert, Georgios Kaissis

    Abstract: In this work, we study the applications of differential privacy (DP) in the context of graph-structured data. We discuss the formulations of DP applicable to the publication of graphs and their associated statistics as well as machine learning on graph-based data, including graph neural networks (GNNs). The formulation of DP in the context of graph-structured data is difficult, as individual data… ▽ More

    Submitted 17 March, 2022; originally announced March 2022.

  44. arXiv:2203.00481  [pdf, other

    cs.LG cs.CR

    Beyond Gradients: Exploiting Adversarial Priors in Model Inversion Attacks

    Authors: Dmitrii Usynin, Daniel Rueckert, Georgios Kaissis

    Abstract: Collaborative machine learning settings like federated learning can be susceptible to adversarial interference and attacks. One class of such attacks is termed model inversion attacks, characterised by the adversary reverse-engineering the model to extract representations and thus disclose the training data. Prior implementations of this attack typically only rely on the captured data (i.e. the sh… ▽ More

    Submitted 1 March, 2022; originally announced March 2022.

  45. arXiv:2203.00324  [pdf, other

    cs.LG cs.CR

    Differentially private training of residual networks with scale normalisation

    Authors: Helena Klause, Alexander Ziller, Daniel Rueckert, Kerstin Hammernik, Georgios Kaissis

    Abstract: The training of neural networks with Differentially Private Stochastic Gradient Descent offers formal Differential Privacy guarantees but introduces accuracy trade-offs. In this work, we propose to alleviate these trade-offs in residual networks with Group Normalisation through a simple architectural modification termed ScaleNorm by which an additional normalisation layer is introduced after the r… ▽ More

    Submitted 6 May, 2022; v1 submitted 1 March, 2022; originally announced March 2022.

    Comments: Submitted as paper to TPDP at ICML 2022

  46. arXiv:2202.04647  [pdf, other

    eess.IV cs.AI cs.CV

    Multi-modal unsupervised brain image registration using edge maps

    Authors: Vasiliki Sideri-Lampretsa, Georgios Kaissis, Daniel Rueckert

    Abstract: Diffeomorphic deformable multi-modal image registration is a challenging task which aims to bring images acquired by different modalities to the same coordinate space and at the same time to preserve the topology and the invertibility of the transformation. Recent research has focused on leveraging deep learning approaches for this task as these have been shown to achieve competitive registration… ▽ More

    Submitted 15 March, 2022; v1 submitted 9 February, 2022; originally announced February 2022.

    Comments: Accepted to IEEE International Symposium on Biomedical Imaging (ISBI) 2022

  47. arXiv:2202.03826  [pdf, other

    eess.IV cs.CV

    On the Pitfalls of Using the Residual Error as Anomaly Score

    Authors: Felix Meissen, Benedikt Wiestler, Georgios Kaissis, Daniel Rueckert

    Abstract: Many current state-of-the-art methods for anomaly localization in medical images rely on calculating a residual image between a potentially anomalous input image and its "healthy" reconstruction. As the reconstruction of the unseen anomalous region should be erroneous, this yields large residuals as a score to detect anomalies in medical images. However, this assumption does not take into account… ▽ More

    Submitted 8 February, 2022; originally announced February 2022.

    Comments: 8 pages, 4 figures, under Review for MIDL 2022

    Journal ref: Proceedings of The 5th International Conference on Medical Imaging with Deep Learning 172 (2022) 914--928

  48. Differentially Private Graph Classification with GNNs

    Authors: Tamara T. Mueller, Johannes C. Paetzold, Chinmay Prabhakar, Dmitrii Usynin, Daniel Rueckert, Georgios Kaissis

    Abstract: Graph Neural Networks (GNNs) have established themselves as the state-of-the-art models for many machine learning applications such as the analysis of social networks, protein interactions and molecules. Several among these datasets contain privacy-sensitive data. Machine learning with differential privacy is a promising technique to allow deriving insight from sensitive data while offering formal… ▽ More

    Submitted 8 February, 2022; v1 submitted 5 February, 2022; originally announced February 2022.

  49. arXiv:2201.09579  [pdf, other

    eess.IV cs.CV

    AutoSeg -- Steering the Inductive Biases for Automatic Pathology Segmentation

    Authors: Felix Meissen, Georgios Kaissis, Daniel Rueckert

    Abstract: In medical imaging, un-, semi-, or self-supervised pathology detection is often approached with anomaly- or out-of-distribution detection methods, whose inductive biases are not intentionally directed towards detecting pathologies, and are therefore sub-optimal for this task. To tackle this problem, we propose AutoSeg, an engine that can generate diverse artificial anomalies that resemble the prop… ▽ More

    Submitted 24 January, 2022; originally announced January 2022.

    Comments: 8 pages, 3 figures, part of the MICCAI MOOD Challenge 2021

  50. arXiv:2112.11040  [pdf, ps, other

    cs.LG cs.CR

    Distributed Machine Learning and the Semblance of Trust

    Authors: Dmitrii Usynin, Alexander Ziller, Daniel Rueckert, Jonathan Passerat-Palmbach, Georgios Kaissis

    Abstract: The utilisation of large and diverse datasets for machine learning (ML) at scale is required to promote scientific insight into many meaningful problems. However, due to data governance regulations such as GDPR as well as ethical concerns, the aggregation of personal and sensitive data is problematic, which prompted the development of alternative strategies such as distributed ML (DML). Techniques… ▽ More

    Submitted 21 December, 2021; originally announced December 2021.

    Comments: Accepted at The Third AAAI Workshop on Privacy-Preserving Artificial Intelligence