Skip to main content

Showing 1–3 of 3 results for author: Mura, R

Searching in archive cs. Search in all archives.
.
  1. arXiv:2409.12367  [pdf, other

    cs.LG cs.AI cs.CR

    Extracting Memorized Training Data via Decomposition

    Authors: Ellen Su, Anu Vellore, Amy Chang, Raffaele Mura, Blaine Nelson, Paul Kassianik, Amin Karbasi

    Abstract: The widespread use of Large Language Models (LLMs) in society creates new information security challenges for developers, organizations, and end-users alike. LLMs are trained on large volumes of data, and their susceptibility to reveal the exact contents of the source training datasets poses security and safety risks. Although current alignment procedures restrict common risky behaviors, they do n… ▽ More

    Submitted 1 October, 2024; v1 submitted 18 September, 2024; originally announced September 2024.

  2. HO-FMN: Hyperparameter Optimization for Fast Minimum-Norm Attacks

    Authors: Raffaele Mura, Giuseppe Floris, Luca Scionis, Giorgio Piras, Maura Pintor, Ambra Demontis, Giorgio Giacinto, Battista Biggio, Fabio Roli

    Abstract: Gradient-based attacks are a primary tool to evaluate robustness of machine-learning models. However, many attacks tend to provide overly-optimistic evaluations as they use fixed loss functions, optimizers, step-size schedulers, and default hyperparameters. In this work, we tackle these limitations by proposing a parametric variation of the well-known fast minimum-norm attack algorithm, whose loss… ▽ More

    Submitted 6 June, 2025; v1 submitted 11 July, 2024; originally announced July 2024.

    Comments: Accepted at Neurocomputing

  3. Improving Fast Minimum-Norm Attacks with Hyperparameter Optimization

    Authors: Giuseppe Floris, Raffaele Mura, Luca Scionis, Giorgio Piras, Maura Pintor, Ambra Demontis, Battista Biggio

    Abstract: Evaluating the adversarial robustness of machine learning models using gradient-based attacks is challenging. In this work, we show that hyperparameter optimization can improve fast minimum-norm attacks by automating the selection of the loss function, the optimizer and the step-size scheduler, along with the corresponding hyperparameters. Our extensive evaluation involving several robust models d… ▽ More

    Submitted 12 October, 2023; originally announced October 2023.

    Comments: Accepted at ESANN23