Skip to main content

Showing 1–26 of 26 results for author: Ziller, A

Searching in archive cs. Search in all archives.
.
  1. arXiv:2403.07588  [pdf, other

    cs.LG cs.CR

    Visual Privacy Auditing with Diffusion Models

    Authors: Kristian Schwethelm, Johannes Kaiser, Moritz Knolle, Daniel Rueckert, Georgios Kaissis, Alexander Ziller

    Abstract: Image reconstruction attacks on machine learning models pose a significant risk to privacy by potentially leaking sensitive information. Although defending against such attacks using differential privacy (DP) has proven effective, determining appropriate DP parameters remains challenging. Current formal guarantees on data reconstruction success suffer from overly theoretical assumptions regarding… ▽ More

    Submitted 12 March, 2024; originally announced March 2024.

  2. arXiv:2402.12861  [pdf, other

    cs.LG cs.CR

    Bounding Reconstruction Attack Success of Adversaries Without Data Priors

    Authors: Alexander Ziller, Anneliese Riess, Kristian Schwethelm, Tamara T. Mueller, Daniel Rueckert, Georgios Kaissis

    Abstract: Reconstruction attacks on machine learning (ML) models pose a strong risk of leakage of sensitive data. In specific contexts, an adversary can (almost) perfectly reconstruct training data samples from a trained model using the model's gradients. When training ML models with differential privacy (DP), formal upper bounds on the success of such reconstruction attacks can be provided. So far, these b… ▽ More

    Submitted 20 February, 2024; originally announced February 2024.

  3. arXiv:2312.04590  [pdf, other

    cs.CR cs.AI cs.CV cs.LG

    Reconciling AI Performance and Data Reconstruction Resilience for Medical Imaging

    Authors: Alexander Ziller, Tamara T. Mueller, Simon Stieger, Leonhard Feiner, Johannes Brandt, Rickmer Braren, Daniel Rueckert, Georgios Kaissis

    Abstract: Artificial Intelligence (AI) models are vulnerable to information leakage of their training data, which can be highly sensitive, for example in medical imaging. Privacy Enhancing Technologies (PETs), such as Differential Privacy (DP), aim to circumvent these susceptibilities. DP is the strongest possible protection for training models while bounding the risks of inferring the inclusion of training… ▽ More

    Submitted 5 December, 2023; originally announced December 2023.

  4. arXiv:2312.03804  [pdf, other

    cs.CV

    How Low Can You Go? Surfacing Prototypical In-Distribution Samples for Unsupervised Anomaly Detection

    Authors: Felix Meissen, Johannes Getzner, Alexander Ziller, Georgios Kaissis, Daniel Rueckert

    Abstract: Unsupervised anomaly detection (UAD) alleviates large labeling efforts by training exclusively on unlabeled in-distribution data and detecting outliers as anomalies. Generally, the assumption prevails that large training datasets allow the training of higher-performing UAD models. However, in this work, we show that using only very few training samples can already match - and in some cases even im… ▽ More

    Submitted 6 December, 2023; originally announced December 2023.

  5. arXiv:2308.12018  [pdf, other

    cs.LG cs.CR

    Bias-Aware Minimisation: Understanding and Mitigating Estimator Bias in Private SGD

    Authors: Moritz Knolle, Robert Dorfman, Alexander Ziller, Daniel Rueckert, Georgios Kaissis

    Abstract: Differentially private SGD (DP-SGD) holds the promise of enabling the safe and responsible application of machine learning to sensitive datasets. However, DP-SGD only provides a biased, noisy estimate of a mini-batch gradient. This renders optimisation steps less effective and limits model utility as a result. With this work, we show a connection between per-sample gradient norms and the estimatio… ▽ More

    Submitted 23 August, 2023; originally announced August 2023.

    Comments: Accepted to the 2023 Theory and Practice of Differential Privacy (TPDP) Workshop

  6. arXiv:2308.02493  [pdf, other

    eess.IV cs.CV

    Body Fat Estimation from Surface Meshes using Graph Neural Networks

    Authors: Tamara T. Mueller, Siyu Zhou, Sophie Starck, Friederike Jungmann, Alexander Ziller, Orhun Aksoy, Danylo Movchan, Rickmer Braren, Georgios Kaissis, Daniel Rueckert

    Abstract: Body fat volume and distribution can be a strong indication for a person's overall health and the risk for develo** diseases like type 2 diabetes and cardiovascular diseases. Frequently used measures for fat estimation are the body mass index (BMI), waist circumference, or the waist-hip-ratio. However, those are rather imprecise measures that do not allow for a discrimination between different t… ▽ More

    Submitted 31 October, 2023; v1 submitted 13 July, 2023; originally announced August 2023.

  7. arXiv:2307.06614  [pdf, other

    eess.IV cs.CV

    Interpretable 2D Vision Models for 3D Medical Images

    Authors: Alexander Ziller, Ayhan Can Erdur, Marwa Trigui, Alp Güvenir, Tamara T. Mueller, Philip Müller, Friederike Jungmann, Johannes Brandt, Jan Peeken, Rickmer Braren, Daniel Rueckert, Georgios Kaissis

    Abstract: Training Artificial Intelligence (AI) models on 3D images presents unique challenges compared to the 2D case: Firstly, the demand for computational resources is significantly higher, and secondly, the availability of large datasets for pre-training is often limited, impeding training success. This study proposes a simple approach of adapting 2D networks with an intermediate feature representation… ▽ More

    Submitted 5 December, 2023; v1 submitted 13 July, 2023; originally announced July 2023.

  8. arXiv:2307.03928  [pdf, other

    cs.CR cs.AI

    Bounding data reconstruction attacks with the hypothesis testing interpretation of differential privacy

    Authors: Georgios Kaissis, Jamie Hayes, Alexander Ziller, Daniel Rueckert

    Abstract: We explore Reconstruction Robustness (ReRo), which was recently proposed as an upper bound on the success of data reconstruction attacks against machine learning models. Previous research has demonstrated that differential privacy (DP) mechanisms also provide ReRo, but so far, only asymptotic Monte Carlo estimates of a tight ReRo bound have been shown. Directly computable ReRo bounds for general D… ▽ More

    Submitted 8 July, 2023; originally announced July 2023.

  9. arXiv:2302.01622  [pdf, other

    eess.IV cs.AI cs.CR cs.CV cs.LG

    Private, fair and accurate: Training large-scale, privacy-preserving AI models in medical imaging

    Authors: Soroosh Tayebi Arasteh, Alexander Ziller, Christiane Kuhl, Marcus Makowski, Sven Nebelung, Rickmer Braren, Daniel Rueckert, Daniel Truhn, Georgios Kaissis

    Abstract: Artificial intelligence (AI) models are increasingly used in the medical domain. However, as medical data is highly sensitive, special precautions to ensure its protection are required. The gold standard for privacy preservation is the introduction of differential privacy (DP) to model training. Prior work indicates that DP has negative implications on model accuracy and fairness, which are unacce… ▽ More

    Submitted 16 March, 2024; v1 submitted 3 February, 2023; originally announced February 2023.

    Comments: Published in Communications Medicine. Nature Portfolio

    Journal ref: Commun Med 4(1), 46 (2024)

  10. arXiv:2211.10173  [pdf, other

    cs.CR cs.LG

    How Do Input Attributes Impact the Privacy Loss in Differential Privacy?

    Authors: Tamara T. Mueller, Stefan Kolek, Friederike Jungmann, Alexander Ziller, Dmitrii Usynin, Moritz Knolle, Daniel Rueckert, Georgios Kaissis

    Abstract: Differential privacy (DP) is typically formulated as a worst-case privacy guarantee over all individuals in a database. More recently, extensions to individual subjects or their attributes, have been introduced. Under the individual/per-instance DP interpretation, we study the connection between the per-subject gradient norm in DP neural networks and individual privacy loss and introduce a novel m… ▽ More

    Submitted 18 November, 2022; originally announced November 2022.

  11. arXiv:2211.04180  [pdf, other

    eess.IV cs.CV

    Exploiting segmentation labels and representation learning to forecast therapy response of PDAC patients

    Authors: Alexander Ziller, Ayhan Can Erdur, Friederike Jungmann, Daniel Rueckert, Rickmer Braren, Georgios Kaissis

    Abstract: The prediction of pancreatic ductal adenocarcinoma therapy response is a clinically challenging and important task in this high-mortality tumour entity. The training of neural networks able to tackle this challenge is impeded by a lack of large datasets and the difficult anatomical localisation of the pancreas. Here, we propose a hybrid deep neural network pipeline to predict tumour response to in… ▽ More

    Submitted 30 March, 2023; v1 submitted 8 November, 2022; originally announced November 2022.

  12. arXiv:2210.13028  [pdf, other

    cs.CR cs.AI stat.AP

    Generalised Likelihood Ratio Testing Adversaries through the Differential Privacy Lens

    Authors: Georgios Kaissis, Alexander Ziller, Stefan Kolek Martinez de Azagra, Daniel Rueckert

    Abstract: Differential Privacy (DP) provides tight upper bounds on the capabilities of optimal adversaries, but such adversaries are rarely encountered in practice. Under the hypothesis testing/membership inference interpretation of DP, we examine the Gaussian mechanism and relax the usual assumption of a Neyman-Pearson-Optimal (NPO) adversary to a Generalized Likelihood Test (GLRT) adversary. This mild rel… ▽ More

    Submitted 24 October, 2022; originally announced October 2022.

  13. arXiv:2205.04095  [pdf, other

    cs.CV cs.LG

    SmoothNets: Optimizing CNN architecture design for differentially private deep learning

    Authors: Nicolas W. Remerscheid, Alexander Ziller, Daniel Rueckert, Georgios Kaissis

    Abstract: The arguably most widely employed algorithm to train deep neural networks with Differential Privacy is DPSGD, which requires clip** and noising of per-sample gradients. This introduces a reduction in model utility compared to non-private training. Empirically, it can be observed that this accuracy degradation is strongly dependent on the model architecture. We investigated this phenomenon and, b… ▽ More

    Submitted 9 May, 2022; originally announced May 2022.

  14. Privacy: An axiomatic approach

    Authors: Alexander Ziller, Tamara Mueller, Rickmer Braren, Daniel Rueckert, Georgios Kaissis

    Abstract: The increasing prevalence of large-scale data collection in modern society represents a potential threat to individual privacy. Addressing this threat, for example through privacy-enhancing technologies (PETs), requires a rigorous definition of what exactly is being protected, that is, of privacy itself. In this work, we formulate an axiomatic definition of privacy based on quantifiable and irredu… ▽ More

    Submitted 22 March, 2022; originally announced March 2022.

  15. arXiv:2203.00324  [pdf, other

    cs.LG cs.CR

    Differentially private training of residual networks with scale normalisation

    Authors: Helena Klause, Alexander Ziller, Daniel Rueckert, Kerstin Hammernik, Georgios Kaissis

    Abstract: The training of neural networks with Differentially Private Stochastic Gradient Descent offers formal Differential Privacy guarantees but introduces accuracy trade-offs. In this work, we propose to alleviate these trade-offs in residual networks with Group Normalisation through a simple architectural modification termed ScaleNorm by which an additional normalisation layer is introduced after the r… ▽ More

    Submitted 6 May, 2022; v1 submitted 1 March, 2022; originally announced March 2022.

    Comments: Submitted as paper to TPDP at ICML 2022

  16. arXiv:2112.11040  [pdf, ps, other

    cs.LG cs.CR

    Distributed Machine Learning and the Semblance of Trust

    Authors: Dmitrii Usynin, Alexander Ziller, Daniel Rueckert, Jonathan Passerat-Palmbach, Georgios Kaissis

    Abstract: The utilisation of large and diverse datasets for machine learning (ML) at scale is required to promote scientific insight into many meaningful problems. However, due to data governance regulations such as GDPR as well as ethical concerns, the aggregation of personal and sensitive data is problematic, which prompted the development of alternative strategies such as distributed ML (DML). Techniques… ▽ More

    Submitted 21 December, 2021; originally announced December 2021.

    Comments: Accepted at The Third AAAI Workshop on Privacy-Preserving Artificial Intelligence

  17. arXiv:2110.03478  [pdf, other

    cs.CR cs.LG

    Complex-valued deep learning with differential privacy

    Authors: Alexander Ziller, Dmitrii Usynin, Moritz Knolle, Kerstin Hammernik, Daniel Rueckert, Georgios Kaissis

    Abstract: We present $ζ$-DP, an extension of differential privacy (DP) to complex-valued functions. After introducing the complex Gaussian mechanism, whose properties we characterise in terms of $(\varepsilon, δ)$-DP and Rényi-DP, we present $ζ$-DP stochastic gradient descent ($ζ$-DP-SGD), a variant of DP-SGD for training complex-valued neural networks. We experimentally evaluate $ζ$-DP-SGD on three complex… ▽ More

    Submitted 7 October, 2021; originally announced October 2021.

    Comments: Submitted as conference paper to ICLR 2022

  18. arXiv:2109.10582  [pdf, other

    cs.CR cs.AI

    Partial sensitivity analysis in differential privacy

    Authors: Tamara T. Mueller, Alexander Ziller, Dmitrii Usynin, Moritz Knolle, Friederike Jungmann, Daniel Rueckert, Georgios Kaissis

    Abstract: Differential privacy (DP) allows the quantification of privacy loss when the data of individuals is subjected to algorithmic processing such as machine learning, as well as the provision of objective privacy guarantees. However, while techniques such as individual Rényi DP (RDP) allow for granular, per-person privacy accounting, few works have investigated the impact of each input feature on the i… ▽ More

    Submitted 28 November, 2021; v1 submitted 22 September, 2021; originally announced September 2021.

  19. arXiv:2109.10573  [pdf, other

    cs.LG cs.CR

    An automatic differentiation system for the age of differential privacy

    Authors: Dmitrii Usynin, Alexander Ziller, Moritz Knolle, Andrew Trask, Kritika Prakash, Daniel Rueckert, Georgios Kaissis

    Abstract: We introduce Tritium, an automatic differentiation-based sensitivity analysis framework for differentially private (DP) machine learning (ML). Optimal noise calibration in this setting requires efficient Jacobian matrix computations and tight bounds on the L2-sensitivity. Our framework achieves these objectives by relying on a functional analysis-based method for sensitivity tracking, which we bri… ▽ More

    Submitted 5 April, 2022; v1 submitted 22 September, 2021; originally announced September 2021.

    Comments: 8 pages, Accepted to the NEURIPS 2021 Privacy Preserving Machine Learning Workshop

  20. arXiv:2109.10528  [pdf, other

    cs.CR cs.IT cs.LG

    A unified interpretation of the Gaussian mechanism for differential privacy through the sensitivity index

    Authors: Georgios Kaissis, Moritz Knolle, Friederike Jungmann, Alexander Ziller, Dmitrii Usynin, Daniel Rueckert

    Abstract: The Gaussian mechanism (GM) represents a universally employed tool for achieving differential privacy (DP), and a large body of work has been devoted to its analysis. We argue that the three prevailing interpretations of the GM, namely $(\varepsilon, δ)$-DP, f-DP and Rényi DP can be expressed by using a single parameter $ψ$, which we term the sensitivity index. $ψ$ uniquely characterises the GM an… ▽ More

    Submitted 22 September, 2021; originally announced September 2021.

    Comments: Under review at PETS 2022

  21. arXiv:2107.14582   

    cs.LG cs.CR

    NeuralDP Differentially private neural networks by design

    Authors: Moritz Knolle, Dmitrii Usynin, Alexander Ziller, Marcus R. Makowski, Daniel Rueckert, Georgios Kaissis

    Abstract: The application of differential privacy to the training of deep neural networks holds the promise of allowing large-scale (decentralized) use of sensitive data while providing rigorous privacy guarantees to the individual. The predominant approach to differentially private training of neural networks is DP-SGD, which relies on norm-based gradient clip** as a method for bounding sensitivity, foll… ▽ More

    Submitted 10 August, 2021; v1 submitted 30 July, 2021; originally announced July 2021.

    Comments: Paper withdrawn. The paper contains a factual error

  22. arXiv:2107.04296  [pdf, other

    cs.LG cs.CR cs.CV

    Differentially private training of neural networks with Langevin dynamics for calibrated predictive uncertainty

    Authors: Moritz Knolle, Alexander Ziller, Dmitrii Usynin, Rickmer Braren, Marcus R. Makowski, Daniel Rueckert, Georgios Kaissis

    Abstract: We show that differentially private stochastic gradient descent (DP-SGD) can yield poorly calibrated, overconfident deep learning models. This represents a serious issue for safety-critical applications, e.g. in medical diagnosis. We highlight and exploit parallels between stochastic gradient Langevin dynamics, a scalable Bayesian inference technique for training deep neural networks, and DP-SGD,… ▽ More

    Submitted 4 August, 2021; v1 submitted 9 July, 2021; originally announced July 2021.

    Comments: Accepted to the ICML 2021 Theory and Practice of Differential Privacy Workshop

  23. arXiv:2107.04265  [pdf, ps, other

    cs.LG cs.CR cs.SC

    Sensitivity analysis in differentially private machine learning using hybrid automatic differentiation

    Authors: Alexander Ziller, Dmitrii Usynin, Moritz Knolle, Kritika Prakash, Andrew Trask, Rickmer Braren, Marcus Makowski, Daniel Rueckert, Georgios Kaissis

    Abstract: In recent years, formal methods of privacy protection such as differential privacy (DP), capable of deployment to data-driven tasks such as machine learning (ML), have emerged. Reconciling large-scale ML with the closed-form reasoning required for the principled analysis of individual privacy loss requires the introduction of new tools for automatic sensitivity analysis and for tracking an individ… ▽ More

    Submitted 17 August, 2021; v1 submitted 9 July, 2021; originally announced July 2021.

    Comments: Accepted to the ICML 2021 Theory and Practice of Differential Privacy Workshop

  24. arXiv:2107.02586  [pdf, other

    eess.IV cs.CV cs.LG

    Differentially private federated deep learning for multi-site medical image segmentation

    Authors: Alexander Ziller, Dmitrii Usynin, Nicolas Remerscheid, Moritz Knolle, Marcus Makowski, Rickmer Braren, Daniel Rueckert, Georgios Kaissis

    Abstract: Collaborative machine learning techniques such as federated learning (FL) enable the training of models on effectively larger datasets without data transfer. Recent initiatives have demonstrated that segmentation models trained with FL can achieve performance similar to locally trained models. However, FL is not a fully privacy-preserving technique and privacy-centred attacks can disclose confiden… ▽ More

    Submitted 6 July, 2021; originally announced July 2021.

    Comments: Submitted to the Journal of Machine Learning in Biomedical Imaging (MELBA)

  25. arXiv:2012.06354  [pdf, other

    cs.CR cs.CV cs.LG

    Privacy-preserving medical image analysis

    Authors: Alexander Ziller, Jonathan Passerat-Palmbach, Théo Ryffel, Dmitrii Usynin, Andrew Trask, Ionésio Da Lima Costa Junior, Jason Mancuso, Marcus Makowski, Daniel Rueckert, Rickmer Braren, Georgios Kaissis

    Abstract: The utilisation of artificial intelligence in medicine and healthcare has led to successful clinical applications in several domains. The conflict between data usage and privacy protection requirements in such systems must be resolved for optimal results as well as ethical and legal compliance. This calls for innovative solutions such as privacy-preserving machine learning (PPML). We present PriMI… ▽ More

    Submitted 10 December, 2020; originally announced December 2020.

    Comments: Accepted at the workshop for Medical Imaging meets NeurIPS, 34th Conference on Neural Information Processing Systems (NeurIPS) December 11, 2020

  26. arXiv:1912.05007  [pdf, other

    cs.CV cs.LG stat.ML

    Oktoberfest Food Dataset

    Authors: Alexander Ziller, Julius Hansjakob, Vitalii Rusinov, Daniel Zügner, Peter Vogel, Stephan Günnemann

    Abstract: We release a realistic, diverse, and challenging dataset for object detection on images. The data was recorded at a beer tent in Germany and consists of 15 different categories of food and drink items. We created more than 2,500 object annotations by hand for 1,110 images captured by a video camera above the checkout. We further make available the remaining 600GB of (unlabeled) data containing day… ▽ More

    Submitted 22 November, 2019; originally announced December 2019.

    Comments: Dataset publication of Oktoberfest Food Dataset. 4 pages, 6 figures