Latest papers

7 papers
defense arXiv Mar 5, 2026 · 4w ago

Identifying Adversary Characteristics from an Observed Attack

Soyon Choi, Scott Alfeld, Meiyi Ma · Vanderbilt University · Amherst College

Reverse-engineers attacker capabilities and objectives from observed adversarial attacks to improve tailored ML defenses

Input Manipulation Attack tabular
PDF
defense arXiv Dec 1, 2025 · Dec 2025

Ensemble Privacy Defense for Knowledge-Intensive LLMs against Membership Inference Attacks

Haowei Fu, Bo Ni, Han Xu et al. · Vanderbilt University · University of Arizona +1 more

Defends RAG and SFT-based LLMs against membership inference attacks using an ensemble of base, fine-tuned, and judge models

Membership Inference Attack nlp
PDF
attack arXiv Nov 25, 2025 · Nov 2025

Latent Diffusion Inversion Requires Understanding the Latent Space

Mingxing Rao, Bowen Qu, Daniel Moyer · Vanderbilt University

Improves membership inference on latent diffusion models by exploiting decoder pullback geometry to identify memorization-prone latent dimensions

Membership Inference Attack Model Inversion Attack visiongenerative
PDF
benchmark arXiv Oct 8, 2025 · Oct 2025

Benchmarking Fake Voice Detection in the Fake Voice Generation Arms Race

Xutao Mao, Ke Li, Cameron Baird et al. · Vanderbilt University

Benchmarks 17 fake voice generators against 8 detectors via one-to-one protocol, revealing universal robustness gaps in audio deepfake detection

Output Integrity Attack audiogenerative
PDF
attack arXiv Sep 29, 2025 · Sep 2025

Score-based Membership Inference on Diffusion Models

Mingxing Rao, Bowen Qu, Daniel Moyer · Vanderbilt University

Proposes SimA, a single-query membership inference attack on diffusion models grounded in score-function theory

Membership Inference Attack generative
1 citations 1 influentialPDF
defense arXiv Sep 15, 2025 · Sep 2025

Probabilistic Robustness Analysis in High Dimensional Space: Application to Semantic Segmentation Network

Navid Hashemi, Samuel Sasaki, Diego Manzanas Lopez et al. · Vanderbilt University · ETH Zürich

Certifies probabilistic robustness of semantic segmentation networks against ℓ_p perturbations using conformal inference and a novel clipping block technique

Input Manipulation Attack vision
PDF Code
defense DCAI Jan 8, 2025 · Jan 2025

Resilient Peer-to-peer Learning based on Adaptive Aggregation

Chandreyee Bhowmick, Xenofon Koutsoukos · Vanderbilt University

Defends peer-to-peer distributed learning against Byzantine adversarial workers via adaptive loss-similarity-based aggregation

Data Poisoning Attack federated-learning
PDF