Skip to main content

Showing 1–14 of 14 results for author: Knolle, M

Searching in archive cs. Search in all archives.
.
  1. arXiv:2403.07588  [pdf, other

    cs.LG cs.CR

    Visual Privacy Auditing with Diffusion Models

    Authors: Kristian Schwethelm, Johannes Kaiser, Moritz Knolle, Daniel Rueckert, Georgios Kaissis, Alexander Ziller

    Abstract: Image reconstruction attacks on machine learning models pose a significant risk to privacy by potentially leaking sensitive information. Although defending against such attacks using differential privacy (DP) has proven effective, determining appropriate DP parameters remains challenging. Current formal guarantees on data reconstruction success suffer from overly theoretical assumptions regarding… ▽ More

    Submitted 12 March, 2024; originally announced March 2024.

  2. arXiv:2311.03075  [pdf, other

    cs.LG cs.CR cs.IT

    SoK: Memorisation in machine learning

    Authors: Dmitrii Usynin, Moritz Knolle, Georgios Kaissis

    Abstract: Quantifying the impact of individual data samples on machine learning models is an open research problem. This is particularly relevant when complex and high-dimensional relationships have to be learned from a limited sample of the data generating distribution, such as in deep learning. It was previously shown that, in these cases, models rely not only on extracting patterns which are helpful for… ▽ More

    Submitted 6 November, 2023; originally announced November 2023.

  3. arXiv:2309.14198  [pdf, other

    cs.LG cs.CV cs.CY eess.IV

    (Predictable) Performance Bias in Unsupervised Anomaly Detection

    Authors: Felix Meissen, Svenja Breuer, Moritz Knolle, Alena Buyx, Ruth Müller, Georgios Kaissis, Benedikt Wiestler, Daniel Rückert

    Abstract: Background: With the ever-increasing amount of medical imaging data, the demand for algorithms to assist clinicians has amplified. Unsupervised anomaly detection (UAD) models promise to aid in the crucial first step of disease detection. While previous studies have thoroughly explored fairness in supervised models in healthcare, for UAD, this has so far been unexplored. Methods: In this study, w… ▽ More

    Submitted 25 September, 2023; originally announced September 2023.

    Comments: 11 pages, 5 Figures, 1 panel

  4. arXiv:2308.12018  [pdf, other

    cs.LG cs.CR

    Bias-Aware Minimisation: Understanding and Mitigating Estimator Bias in Private SGD

    Authors: Moritz Knolle, Robert Dorfman, Alexander Ziller, Daniel Rueckert, Georgios Kaissis

    Abstract: Differentially private SGD (DP-SGD) holds the promise of enabling the safe and responsible application of machine learning to sensitive datasets. However, DP-SGD only provides a biased, noisy estimate of a mini-batch gradient. This renders optimisation steps less effective and limits model utility as a result. With this work, we show a connection between per-sample gradient norms and the estimatio… ▽ More

    Submitted 23 August, 2023; originally announced August 2023.

    Comments: Accepted to the 2023 Theory and Practice of Differential Privacy (TPDP) Workshop

  5. arXiv:2211.10173  [pdf, other

    cs.CR cs.LG

    How Do Input Attributes Impact the Privacy Loss in Differential Privacy?

    Authors: Tamara T. Mueller, Stefan Kolek, Friederike Jungmann, Alexander Ziller, Dmitrii Usynin, Moritz Knolle, Daniel Rueckert, Georgios Kaissis

    Abstract: Differential privacy (DP) is typically formulated as a worst-case privacy guarantee over all individuals in a database. More recently, extensions to individual subjects or their attributes, have been introduced. Under the individual/per-instance DP interpretation, we study the connection between the per-subject gradient norm in DP neural networks and individual privacy loss and introduce a novel m… ▽ More

    Submitted 18 November, 2022; originally announced November 2022.

  6. arXiv:2110.03478  [pdf, other

    cs.CR cs.LG

    Complex-valued deep learning with differential privacy

    Authors: Alexander Ziller, Dmitrii Usynin, Moritz Knolle, Kerstin Hammernik, Daniel Rueckert, Georgios Kaissis

    Abstract: We present $ζ$-DP, an extension of differential privacy (DP) to complex-valued functions. After introducing the complex Gaussian mechanism, whose properties we characterise in terms of $(\varepsilon, δ)$-DP and Rényi-DP, we present $ζ$-DP stochastic gradient descent ($ζ$-DP-SGD), a variant of DP-SGD for training complex-valued neural networks. We experimentally evaluate $ζ$-DP-SGD on three complex… ▽ More

    Submitted 7 October, 2021; originally announced October 2021.

    Comments: Submitted as conference paper to ICLR 2022

  7. arXiv:2109.10582  [pdf, other

    cs.CR cs.AI

    Partial sensitivity analysis in differential privacy

    Authors: Tamara T. Mueller, Alexander Ziller, Dmitrii Usynin, Moritz Knolle, Friederike Jungmann, Daniel Rueckert, Georgios Kaissis

    Abstract: Differential privacy (DP) allows the quantification of privacy loss when the data of individuals is subjected to algorithmic processing such as machine learning, as well as the provision of objective privacy guarantees. However, while techniques such as individual Rényi DP (RDP) allow for granular, per-person privacy accounting, few works have investigated the impact of each input feature on the i… ▽ More

    Submitted 28 November, 2021; v1 submitted 22 September, 2021; originally announced September 2021.

  8. arXiv:2109.10573  [pdf, other

    cs.LG cs.CR

    An automatic differentiation system for the age of differential privacy

    Authors: Dmitrii Usynin, Alexander Ziller, Moritz Knolle, Andrew Trask, Kritika Prakash, Daniel Rueckert, Georgios Kaissis

    Abstract: We introduce Tritium, an automatic differentiation-based sensitivity analysis framework for differentially private (DP) machine learning (ML). Optimal noise calibration in this setting requires efficient Jacobian matrix computations and tight bounds on the L2-sensitivity. Our framework achieves these objectives by relying on a functional analysis-based method for sensitivity tracking, which we bri… ▽ More

    Submitted 5 April, 2022; v1 submitted 22 September, 2021; originally announced September 2021.

    Comments: 8 pages, Accepted to the NEURIPS 2021 Privacy Preserving Machine Learning Workshop

  9. arXiv:2109.10528  [pdf, other

    cs.CR cs.IT cs.LG

    A unified interpretation of the Gaussian mechanism for differential privacy through the sensitivity index

    Authors: Georgios Kaissis, Moritz Knolle, Friederike Jungmann, Alexander Ziller, Dmitrii Usynin, Daniel Rueckert

    Abstract: The Gaussian mechanism (GM) represents a universally employed tool for achieving differential privacy (DP), and a large body of work has been devoted to its analysis. We argue that the three prevailing interpretations of the GM, namely $(\varepsilon, δ)$-DP, f-DP and Rényi DP can be expressed by using a single parameter $ψ$, which we term the sensitivity index. $ψ$ uniquely characterises the GM an… ▽ More

    Submitted 22 September, 2021; originally announced September 2021.

    Comments: Under review at PETS 2022

  10. arXiv:2107.14582   

    cs.LG cs.CR

    NeuralDP Differentially private neural networks by design

    Authors: Moritz Knolle, Dmitrii Usynin, Alexander Ziller, Marcus R. Makowski, Daniel Rueckert, Georgios Kaissis

    Abstract: The application of differential privacy to the training of deep neural networks holds the promise of allowing large-scale (decentralized) use of sensitive data while providing rigorous privacy guarantees to the individual. The predominant approach to differentially private training of neural networks is DP-SGD, which relies on norm-based gradient clip** as a method for bounding sensitivity, foll… ▽ More

    Submitted 10 August, 2021; v1 submitted 30 July, 2021; originally announced July 2021.

    Comments: Paper withdrawn. The paper contains a factual error

  11. arXiv:2107.04296  [pdf, other

    cs.LG cs.CR cs.CV

    Differentially private training of neural networks with Langevin dynamics for calibrated predictive uncertainty

    Authors: Moritz Knolle, Alexander Ziller, Dmitrii Usynin, Rickmer Braren, Marcus R. Makowski, Daniel Rueckert, Georgios Kaissis

    Abstract: We show that differentially private stochastic gradient descent (DP-SGD) can yield poorly calibrated, overconfident deep learning models. This represents a serious issue for safety-critical applications, e.g. in medical diagnosis. We highlight and exploit parallels between stochastic gradient Langevin dynamics, a scalable Bayesian inference technique for training deep neural networks, and DP-SGD,… ▽ More

    Submitted 4 August, 2021; v1 submitted 9 July, 2021; originally announced July 2021.

    Comments: Accepted to the ICML 2021 Theory and Practice of Differential Privacy Workshop

  12. arXiv:2107.04265  [pdf, ps, other

    cs.LG cs.CR cs.SC

    Sensitivity analysis in differentially private machine learning using hybrid automatic differentiation

    Authors: Alexander Ziller, Dmitrii Usynin, Moritz Knolle, Kritika Prakash, Andrew Trask, Rickmer Braren, Marcus Makowski, Daniel Rueckert, Georgios Kaissis

    Abstract: In recent years, formal methods of privacy protection such as differential privacy (DP), capable of deployment to data-driven tasks such as machine learning (ML), have emerged. Reconciling large-scale ML with the closed-form reasoning required for the principled analysis of individual privacy loss requires the introduction of new tools for automatic sensitivity analysis and for tracking an individ… ▽ More

    Submitted 17 August, 2021; v1 submitted 9 July, 2021; originally announced July 2021.

    Comments: Accepted to the ICML 2021 Theory and Practice of Differential Privacy Workshop

  13. arXiv:2107.02586  [pdf, other

    eess.IV cs.CV cs.LG

    Differentially private federated deep learning for multi-site medical image segmentation

    Authors: Alexander Ziller, Dmitrii Usynin, Nicolas Remerscheid, Moritz Knolle, Marcus Makowski, Rickmer Braren, Daniel Rueckert, Georgios Kaissis

    Abstract: Collaborative machine learning techniques such as federated learning (FL) enable the training of models on effectively larger datasets without data transfer. Recent initiatives have demonstrated that segmentation models trained with FL can achieve performance similar to locally trained models. However, FL is not a fully privacy-preserving technique and privacy-centred attacks can disclose confiden… ▽ More

    Submitted 6 July, 2021; originally announced July 2021.

    Comments: Submitted to the Journal of Machine Learning in Biomedical Imaging (MELBA)

  14. Efficient, high-performance pancreatic segmentation using multi-scale feature extraction

    Authors: Moritz Knolle, Georgios Kaissis, Friederike Jungmann, Sebastian Ziegelmayer, Daniel Sasse, Marcus Makowski, Daniel Rueckert, Rickmer Braren

    Abstract: For artificial intelligence-based image analysis methods to reach clinical applicability, the development of high-performance algorithms is crucial. For example, existent segmentation algorithms based on natural images are neither efficient in their parameter use nor optimized for medical imaging. Here we present MoNet, a highly optimized neural-network-based pancreatic segmentation algorithm focu… ▽ More

    Submitted 12 January, 2021; v1 submitted 2 September, 2020; originally announced September 2020.

    ACM Class: I.4.6; J.3