SearcharxivSearch

arXiv subjects

Nuria

Publications and source records attributed to Nuria.

2 recordsLinked to original sources

Can we infer the presence of Differential Privacy in Deep Learning models' weights? Towards more secure Deep Learning

Differential Privacy (DP) is a key property to protect data and models from integrity attacks. In the Deep Learning (DL) field, it is commonly implemented through the Differentially Private Stochastic Gradient Descent (DP-SGD). However, when a model is shared or released, there is no way to check whether it is differentially private, that is, it required to trust the model provider. This situation poses a problem when data privacy is mandatory, specially with current data regulations, as the presence of DP can not be certificated consistently by any third party. Thus, we face the challenge of determining whether a DL model has been trained with DP, according to the title question: Can we infer the presence of Differential Privacy in Deep Learning models' weights? Since the DP-SGD significantly changes the training process of a DL model, we hypothesize that DP leaves an imprint in the weights of a DL model, which can be used to predict whether a model has been trained with DP regardless of its architecture and the training dataset. In this paper, we propose to employ the imprint in model weights of using DP to infer the presence of DP training in a DL model. To substantiate our hypothesis, we developed an experimental methodology based on two datasets of weights of DL models, each with models with and without DP training and a meta-classifier to infer whether DP was used in the training process of a DL model, by accessing its weights. We accomplish both, the removal of the requirement of a trusted model provider and a strong foundation for this interesting line of research. Thus, our contribution is an additional layer of security on top of the strict private requirements of DP training in DL models, towards to DL models.

cs.LG

CAIXA: a catalogue of AGN in the XMM-Newton archive III. Excess Variance Analysis

We report on the results of the first XMM systematic "excess variance" study of all the radio quiet, X-ray un-obscured AGN. The entire sample consist of 161 sources observed by XMM for more than 10 ks in pointed observations which is the largest sample used so far to study AGN X-ray variability on time scales less than a day. We compute the excess variance for all AGN, on different time-scales (10, 20, 40 and 80 ks) and in different energy bands (0.3-0.7, 0.7-2 and 2-10 keV). We observe a highly significant and tight (~0.7 dex) correlation between excess variance and MBH. The subsample of reverberation mapped AGN shows an even smaller scatter (~0.45 dex) comparable to the one induced by the MBH uncertainties. This implies that X-ray variability can be used as an accurate tool to measure MBH and this method is more accurate than the ones based on single epoch optical spectra. The excess variance vs. accretion rate dependence is weaker than expected based on the PSD break frequency scaling, suggesting that both the PSD high frequency break and the normalisation depend on accretion rate in such a way that they almost completely counterbalance each other. A highly significant correlation between excess variance and 2-10 keV spectral index is observed. Both the variability vs. LBol and FWHM_Hbeta correlations are consistent with being just by-products of the correlation with MBH. The soft and medium variability is very well correlated with the hard variability, suggesting that the additional soft components (i.e. soft excess, warm absorber) add a minor contribution to the total variability. Once the variability is rescaled for MBH and mdot, no significant difference between narrow-line and broad-line Seyfert 1 is observed. The results are in agreement with a picture where, to first approximation, all local AGN have the same variability properties once rescaled for MBH and accretion rate.

astro-ph.HE