SearcharxivSearch

arXiv subjects

Thomas Michel

Publications and source records attributed to Thomas Michel.

8 recordsLinked to original sources

Sequential Membership Inference Attacks

Modern AI models are not static. They go through multiple updates in their lifecycles. We propose to design Sequential Membership Inference (SeMI) attacks leading to tighter privacy audits by exploiting the sequence of models and injecting a target canary at a controlled insertion time. First, for empirical mean computation, we develop SeMI*, an {optimal SeMI attack to identify the presence of a target inserted at a specific insertion step}. We derive the power of SeMI* to show that accessing the model sequence yields more powerful MI attacks than scrutinising only the final model. SeMI* exhibits an isolation property -- its power depends on the statistics obtained right before and after insertion of the target. Leveraging this insight, we develop practical white-box (accessing model gradients) and black-box (accessing loss) SeMI attacks against models trained with (DP-)SGD. Across datasets and models trained with (DP-)SGD, our experiments show that SeMI attacks achieve higher powers than snapshot-independent baselines, and yield tighter privacy audits thanks to (a) control over the insertion time and (b) observations across the model sequence.

cs.LG

Octax: Accelerated CHIP-8 Arcade Environments for Reinforcement Learning in JAX

Reinforcement learning (RL) research requires diverse, challenging environments that are both tractable and scalable. While modern video games may offer rich dynamics, they are computationally expensive and poorly suited for large-scale experimentation due to their CPU-bound execution. We introduce Octax, a high-performance suite of classic arcade game environments implemented in JAX, based on CHIP-8 emulation, a predecessor to Atari, which is widely adopted as a benchmark in RL research. Octax provides the JAX community with a long-awaited end-to-end GPU alternative to Atari games, offering image-based environments, spanning puzzle, action, and strategy genres, all executable at massive scale on modern GPUs. Our JAX-based implementation achieves orders-of-magnitude speedups over traditional CPU emulators. We demonstrate Octax's capabilities by training RL agents across multiple games, showing significant improvements in training speed and scalability compared to existing solutions. The environment's modular design enables researchers to easily extend the suite with new games or generate novel environments using large language models, making it an ideal platform for large-scale RL experimentation. Our open-source framework is available at https://github.com/riiswa/octax/.

cs.LG

DP-SPRT: Differentially Private Sequential Probability Ratio Tests

We revisit Wald's celebrated Sequential Probability Ratio Test for sequential tests of two simple hypotheses, under privacy constraints. We propose DP-SPRT, a wrapper that can be calibrated to achieve desired error probabilities and privacy constraints, addressing a significant gap in previous work. DP-SPRT relies on a private mechanism that processes a sequence of queries and stops after privately determining when the query results fall outside a predefined interval. This OutsideInterval mechanism improves upon naive composition of existing techniques like AboveThreshold, achieving a factor-of-2 privacy improvement and thus potentially benefiting other continual monitoring procedures. We prove generic upper bounds on the error and sample complexity of DP-SPRT that can accommodate various noise distributions based on the practitioner's privacy needs. We exemplify them in two settings: Laplace noise (pure Differential Privacy) and Gaussian noise (R\'enyi differential privacy). In the former setting, by providing a lower bound on the sample complexity of any $\varepsilon$-DP test with prescribed type I and type II errors, we show that DP-SPRT is near optimal when both errors are small and the two hypotheses are close. Moreover, we conduct an experimental study revealing its good practical performance.

stat.ML

Exploring Flow-Lenia Universes with a Curiosity-driven AI Scientist: Discovering Diverse Ecosystem Dynamics

We present a curiosity-driven AI scientist method for discovering system-level dynamics in Flow-Lenia, a continuous cellular automaton (CA) with mass conservation and parameter localization. Building on prior work that uses diversity search in Lenia to find individual self-organized patterns, we adapt Intrinsically Motivated Goal Exploration Processes (IMGEPs) to large environments of interacting patterns, using simulation-wide metrics such as evolutionary activity, compression ratio, and multi-scale matter distribution. We apply IMGEP in two exploration experiments: one targeting ecosystem-level dynamics, the other matter movement through obstacle-laden environments. In both, IMGEP illuminates significantly more of the metric space than random search and reveals self-organized behaviors qualitatively resembling many biological phenomena. Leveraging the resulting archive, we then run a scaling study across six spatial scales and seven time horizons, uncovering macro-scale organization with no analogue at the base scale and characterizing how goal-space metrics behave at scale. This illustrates a strength of our approach: a relatively cheap large-scale diversity search can act as a principled scaffold for designing subsequent, more expensive experiments, enabling an iterative loop of experiment design, inspection, and redesign, supported by an interactive exploration tool that keeps scientists in the loop. Though demonstrated with Flow-Lenia, this approach potentially applies to other parameterizable complex systems where studying bottom-up collective behavior is of interest.

cs.AI

Leveraging Model Interpretability and Stability to increase Model Robustness

State of the art Deep Neural Networks (DNN) can now achieve above human level accuracy on image classification tasks. However their outstanding performances come along with a complex inference mechanism making them arduously interpretable models. In order to understand the underlying prediction rules of DNNs, Dhamdhere et al. propose an interpretability method to break down a DNN prediction score as sum of its hidden unit contributions, in the form of a metric called conductance. Analyzing conductances of DNN hidden units, we find out there is a difference in how wrong and correct predictions are inferred. We identify distinguishable patterns of hidden unit activations for wrong and correct predictions. We then use an error detector in the form of a binary classifier on top of the DNN to automatically discriminate wrong and correct predictions of the DNN based on their hidden unit activations. Detected wrong predictions are discarded, increasing the model robustness. A different approach to distinguish wrong and correct predictions of DNNs is proposed by Wang et al. whose method is based on the premise that input samples leading a DNN into making wrong predictions are less stable to the DNN weight changes than correctly classified input samples. In our study, we compare both methods and find out by combining them that better detection of wrong predictions can be achieved.

cs.LG

Transmitter and Precoding Order Optimization for Nonlinear Downlink Beamforming

The downlink of a multiple-input multiple output (MIMO) broadcast channel (BC) is considered, where each receiver is equipped with a single antenna and the transmitter performs nonlinear Dirty-Paper Coding (DPC). We present an efficient algorithm that finds the optimum transmit filters and power allocation as well as the optimum precoding order(s) possibly affording time-sharing between individual DPC orders. Subsequently necessary and sufficient conditions for the optimality of an arbitrary precoding order are derived. Based on these we propose a suboptimal algorithm showing excellent performance and having low complexity.

cs.IT

The Delay-Limited Capacity Region of OFDM Broadcast Channels

In this work, the delay limited capacity (DLC) of orthogonal frequency division multiplexing (OFDM) systems is investigated. The analysis is organized into two parts. In the first part, the impact of system parameters on the OFDM DLC is analyzed in a general setting. The main results are that under weak assumptions the maximum achievable single user DLC is almost independent of the distribution of the path attenuations in the low signal-to-noise (SNR) region but depends strongly on the delay spread. In the high SNR region the roles are exchanged. Here, the impact of delay spread is negligible while the impact of the distribution becomes dominant. The relevant asymptotic quantities are derived without employing simplifying assumptions on the OFDM correlation structure. Moreover, for both cases it is shown that the DLC is maximized if the total channel energy is uniformly spread, i.e. the power delay profile is uniform. It is worth pointing out that since universal bounds are obtained the results can also be used for other classes of parallel channels with block fading characteristic. The second part extends the setting to the broadcast channel and studies the corresponding OFDM DLC BC region. An algorithm for computing the OFDM BC DLC region is presented. To derive simple but smart resource allocation strategies, the principle of rate water-filling employing order statistics is introduced. This yields analytical lower bounds on the OFDM DLC region based on orthogonal frequency division multiple access (OFDMA) and ordinal channel state information (CSI). Finally, the schemes are compared to an algorithm using full CSI.

cs.IT

Optimal resource allocation for OFDM multiuser channels

In this paper, a unifying framework for orthogonal frequency division multiplexing (OFDM) multiuser resource allocation is presented. The isolated seeming problems of maximizing a weighted sum of rates for a given power budget $\bar{P}$ and minimizing sum power for given rate requirements $\mathbf{\bar{R}}$ can be interpreted jointly in this framework. To this end we embed the problems in a higher dimensional space. Based on these results, we subsequently consider the combined problem of maximizing a weighted sum of rates under given rate requirements $\mathbf{\bar{R}}$ and a fixed power budget $\bar{P}$. This new problem is challenging, since the additional constraints do not allow to use the hitherto existing approaches. Interestingly, the optimal decoding orders turn out to be the ordering of the Lagrangian factors in all problems.

cs.IT