The Experts below are selected from a list of 2919 Experts worldwide ranked by ideXlab platform

Thomas Ristenpart - One of the best experts on this subject based on the ideXlab platform.

  • stealing machine learning models via prediction apis
    USENIX Security Symposium, 2016
    Co-Authors: Florian Tramer, Fan Zhang, Ari Juels, Michael K Reiter, Thomas Ristenpart
    Abstract:

    Machine learning (ML) models may be deemed confidential due to their sensitive training data, commercial value, or use in security applications. Increasingly often, confidential ML models are being deployed with publicly accessible query interfaces. ML-as-a-service ("predictive analytics") systems are an example: Some allow users to train models on potentially sensitive data and charge others for access on a pay-per-query basis. The tension between model confidentiality and public access motivates our investigation of model extraction attacks. In such attacks, an adversary with black-box access, but no prior knowledge of an ML model's parameters or training data, aims to duplicate the functionality of (i.e., "steal") the model. Unlike in classical learning theory settings, ML-as-a-service offerings may accept partial feature vectors as inputs and include confidence values with predictions. Given these practices, we show simple, efficient attacks that extract target ML models with near-Perfect Fidelity for popular model classes including logistic regression, neural networks, and decision trees. We demonstrate these attacks against the online services of BigML and Amazon Machine Learning. We further show that the natural countermeasure of omitting confidence values from model outputs still admits potentially harmful model extraction attacks. Our results highlight the need for careful ML model deployment and new model extraction countermeasures.

  • USENIX Security Symposium - Stealing machine learning models via prediction APIs
    2016
    Co-Authors: Florian Tramer, Fan Zhang, Ari Juels, Michael K Reiter, Thomas Ristenpart
    Abstract:

    Machine learning (ML) models may be deemed confidential due to their sensitive training data, commercial value, or use in security applications. Increasingly often, confidential ML models are being deployed with publicly accessible query interfaces. ML-as-a-service ("predictive analytics") systems are an example: Some allow users to train models on potentially sensitive data and charge others for access on a pay-per-query basis. The tension between model confidentiality and public access motivates our investigation of model extraction attacks. In such attacks, an adversary with black-box access, but no prior knowledge of an ML model's parameters or training data, aims to duplicate the functionality of (i.e., "steal") the model. Unlike in classical learning theory settings, ML-as-a-service offerings may accept partial feature vectors as inputs and include confidence values with predictions. Given these practices, we show simple, efficient attacks that extract target ML models with near-Perfect Fidelity for popular model classes including logistic regression, neural networks, and decision trees. We demonstrate these attacks against the online services of BigML and Amazon Machine Learning. We further show that the natural countermeasure of omitting confidence values from model outputs still admits potentially harmful model extraction attacks. Our results highlight the need for careful ML model deployment and new model extraction countermeasures.

Christian Weedbrook - One of the best experts on this subject based on the ideXlab platform.

  • Production of photonic universal quantum gates enhanced by machine learning
    Physical Review A, 2019
    Co-Authors: Krishna Kumar Sabapathy, Josh Izaac, Christian Weedbrook
    Abstract:

    We introduce photonic architectures for universal quantum computation. The first step is to produce a resource state which is a superposition of the first four Fock states with a probability $\geq 10^{-2}$, an increase by a factor of $10^4$ over standard sequential photon-subtraction techniques. The resource state is produced with near-Perfect Fidelity from a quantum gadget that uses displaced squeezed vacuum states, interferometers and photon-number resolving detectors. The parameters of this gadget are trained using machine learning algorithms for variational circuits. We discuss in detail various aspects of the non-Gaussian state preparation resulting from the numerical experiments. We then propose a notion of resource farms where these gadgets are stacked in parallel, to increase the success probability further. We find a trade-off between the success probability of the farm, the error tolerance, and the number of gadgets. Using the resource states in conventional gate teleportation techniques we can then implement weak tuneable cubic phase gates. The numerical tools that have been developed could potentially be useful for other applications in photonics as well.

Timothy H Hsieh - One of the best experts on this subject based on the ideXlab platform.

  • variational thermal quantum simulation via thermofield double states
    Physical Review Letters, 2019
    Co-Authors: Timothy H Hsieh
    Abstract:

    We present a variational approach for quantum simulators to realize finite temperature Gibbs states by preparing thermofield double (TFD) states. Our protocol is motivated by the quantum approximate optimization algorithm and involves alternating time evolution between the Hamiltonian of interest and interactions which entangle the system and its auxiliary counterpart. As a simple example, we demonstrate that thermal states of the 1D classical Ising model at any temperature can be prepared with Perfect Fidelity using L/2 iterations, where L is system size. We also show that a free fermion TFD can be prepared with nearly optimal efficiency. Given the simplicity and efficiency of the protocol, our approach enables near-term quantum platforms to access finite temperature phenomena via preparation of thermofield double states.

  • efficient variational simulation of non trivial quantum states
    arXiv: Strongly Correlated Electrons, 2018
    Co-Authors: Timothy H Hsieh
    Abstract:

    We provide an efficient and general route for preparing non-trivial quantum states that are not adiabatically connected to unentangled product states. Our approach is a hybrid quantum-classical variational protocol that incorporates a feedback loop between a quantum simulator and a classical computer, and is experimentally realizable on near-term quantum devices of synthetic quantum systems. We find explicit protocols which prepare with Perfect fidelities (i) the Greenberger-Horne-Zeilinger (GHZ) state, (ii) a quantum critical state, and (iii) a topologically ordered state, with $L$ variational parameters and physical runtimes $T$ that scale linearly with the system size $L$. We furthermore conjecture and support numerically that our protocol can prepare, with Perfect Fidelity and similar operational costs, the ground state of every point in the one dimensional transverse field Ising model phase diagram. Besides being practically useful, our results also illustrate the utility of such variational ansatze as good descriptions of non-trivial states of matter.

Florian Tramer - One of the best experts on this subject based on the ideXlab platform.

  • stealing machine learning models via prediction apis
    USENIX Security Symposium, 2016
    Co-Authors: Florian Tramer, Fan Zhang, Ari Juels, Michael K Reiter, Thomas Ristenpart
    Abstract:

    Machine learning (ML) models may be deemed confidential due to their sensitive training data, commercial value, or use in security applications. Increasingly often, confidential ML models are being deployed with publicly accessible query interfaces. ML-as-a-service ("predictive analytics") systems are an example: Some allow users to train models on potentially sensitive data and charge others for access on a pay-per-query basis. The tension between model confidentiality and public access motivates our investigation of model extraction attacks. In such attacks, an adversary with black-box access, but no prior knowledge of an ML model's parameters or training data, aims to duplicate the functionality of (i.e., "steal") the model. Unlike in classical learning theory settings, ML-as-a-service offerings may accept partial feature vectors as inputs and include confidence values with predictions. Given these practices, we show simple, efficient attacks that extract target ML models with near-Perfect Fidelity for popular model classes including logistic regression, neural networks, and decision trees. We demonstrate these attacks against the online services of BigML and Amazon Machine Learning. We further show that the natural countermeasure of omitting confidence values from model outputs still admits potentially harmful model extraction attacks. Our results highlight the need for careful ML model deployment and new model extraction countermeasures.

  • USENIX Security Symposium - Stealing machine learning models via prediction APIs
    2016
    Co-Authors: Florian Tramer, Fan Zhang, Ari Juels, Michael K Reiter, Thomas Ristenpart
    Abstract:

    Machine learning (ML) models may be deemed confidential due to their sensitive training data, commercial value, or use in security applications. Increasingly often, confidential ML models are being deployed with publicly accessible query interfaces. ML-as-a-service ("predictive analytics") systems are an example: Some allow users to train models on potentially sensitive data and charge others for access on a pay-per-query basis. The tension between model confidentiality and public access motivates our investigation of model extraction attacks. In such attacks, an adversary with black-box access, but no prior knowledge of an ML model's parameters or training data, aims to duplicate the functionality of (i.e., "steal") the model. Unlike in classical learning theory settings, ML-as-a-service offerings may accept partial feature vectors as inputs and include confidence values with predictions. Given these practices, we show simple, efficient attacks that extract target ML models with near-Perfect Fidelity for popular model classes including logistic regression, neural networks, and decision trees. We demonstrate these attacks against the online services of BigML and Amazon Machine Learning. We further show that the natural countermeasure of omitting confidence values from model outputs still admits potentially harmful model extraction attacks. Our results highlight the need for careful ML model deployment and new model extraction countermeasures.

Krishna Kumar Sabapathy - One of the best experts on this subject based on the ideXlab platform.

  • Production of photonic universal quantum gates enhanced by machine learning
    Physical Review A, 2019
    Co-Authors: Krishna Kumar Sabapathy, Josh Izaac, Christian Weedbrook
    Abstract:

    We introduce photonic architectures for universal quantum computation. The first step is to produce a resource state which is a superposition of the first four Fock states with a probability $\geq 10^{-2}$, an increase by a factor of $10^4$ over standard sequential photon-subtraction techniques. The resource state is produced with near-Perfect Fidelity from a quantum gadget that uses displaced squeezed vacuum states, interferometers and photon-number resolving detectors. The parameters of this gadget are trained using machine learning algorithms for variational circuits. We discuss in detail various aspects of the non-Gaussian state preparation resulting from the numerical experiments. We then propose a notion of resource farms where these gadgets are stacked in parallel, to increase the success probability further. We find a trade-off between the success probability of the farm, the error tolerance, and the number of gadgets. Using the resource states in conventional gate teleportation techniques we can then implement weak tuneable cubic phase gates. The numerical tools that have been developed could potentially be useful for other applications in photonics as well.