Z. Zhao
Please Note
13 records found
1
Generative Adversarial Networks (GANs) are increasingly adopted by the industry to synthesize realistic images using competing generator and discriminator neural networks. Due to data not being centrally available, Multi-Discriminator (MD)-GANs training frameworks employ multiple discriminators that have direct access to the real data. Distributedly training a joint GAN model entails the risk of free-riders, i.e., participants that aim to benefit from the common model while only pretending to participate in the training process. In this paper, we first define a free-rider as a participant without training data and then identify three possible actions: not training, training on synthetic data, or using pre-trained models for similar but not identical tasks that are publicly available. We conduct experiments to explore the impact of these three types of free-riders on the ability of MD-GANs to produce images that are indistinguishable from real data. We consequently design a defense against free-riders, termed DFG, which compares the performance of client discriminators to reference discriminators at the server. The defense allows the server to evict clients whose behavior does not match that of a benign client. The result shows that even when 67% of the clients are free-riders, the proposed DFG can improve synthetic image quality by up to 70.96%, compared to the case of no defense.
The adaptive practical prescribed-time (PPT) neural control is studied for multi-input multi-output (MIMO) nonlinear systems with unknown nonlinear functions and unknown input gain matrices. Unlike existing PPT design schemes based on backstepping, this study proposes a novel PPT control framework using the dynamic surface control (DSC) approach. Firstly, a novel nonlinear filter (NLF) with an adaptive parameter estimator and a piece-wise function is constructed to effectively compensate for filter errors and facilitate prescribed-time convergence. Based on this, a unified DSC-based adaptive PPT control algorithm, augmented with a neural networks (NNs) approximator, is developed, where NNs are used to approximate unknown nonlinear system functions. This algorithm not only addresses the inherent computational complexity explosion associated with traditional backstepping methods but also reduces the constraints on filter design parameters compared to the DSC algorithm that relies on linear filters. The simulation showcases the effectiveness and superiority of the devised scheme by employing a two-degree-of-freedom robot manipulator.
CTAB-GAN+
Enhancing tabular data synthesis
The usage of synthetic data is gaining momentum in part due to the unavailability of original data due to privacy and legal considerations and in part due to its utility as an augmentation to the authentic data. Generative adversarial networks (GANs), a paragon of generative models, initially for images and subsequently for tabular data, has contributed many of the state-of-the-art synthesizers. As GANs improve, the synthesized data increasingly resemble the real data risking to leak privacy. Differential privacy (DP) provides theoretical guarantees on privacy loss but degrades data utility. Striking the best trade-off remains yet a challenging research question. In this study, we propose CTAB-GAN+ a novel conditional tabular GAN. CTAB-GAN+ improves upon state-of-the-art by (i) adding downstream losses to conditional GAN for higher utility synthetic data in both classification and regression domains; (ii) using Wasserstein loss with gradient penalty for better training convergence; (iii) introducing novel encoders targeting mixed continuous-categorical variables and variables with unbalanced or skewed data; and (iv) training with DP stochastic gradient descent to impose strict privacy guarantees. We extensively evaluate CTAB-GAN+ on statistical similarity and machine learning utility against state-of-the-art tabular GANs. The results show that CTAB-GAN+ synthesizes privacy-preserving data with at least 21.9% higher machine learning utility (i.e., F1-Score) across multiple datasets and learning tasks under given privacy budget.
FCT-GAN
Enhancing Global Correlation of Table Synthesis via Fourier Transform
In this paper, we focus on the French Macro-economic model. We use real economic data, available as time series, starting from 1980s and openly provided by the INSEE. Variables such as Gross Domestic Production, Exportation, Importation, Household Consumption, Gross Fixed Capital Formation and Public expenditure are included in the analysis. Our objective is to maintain a constant economic growth rate according to the available resources. We implement an optimal control policy via LQR to achieve that. Since we aim to maintain a constant growth rate, the control system is modified for this purpose. We prove the efficiency with three experiments based on real data, and we test the method robustness with respect to: (1) variation of LQR parameters, (2) realistic constraints on inputs, and (3) perturbations on outputs. Results show that our designed control system can guide the output to the desired growth rate.MIMO model, LQR, Optimal control, Macroeconomic data.
Fabricated Flips
Poisoning Federated Learning without Data
Attacks on Federated Learning (FL) can severely reduce the quality of the generated models and limit the usefulness of this emerging learning paradigm that enables on-premise decentralized learning. However, existing untargeted attacks are not practical for many scenarios as they assume that i) the attacker knows every update of benign clients, or ii) the attacker has a large dataset to locally train updates imitating benign parties. In this paper, we propose a data-free untargeted attack (DFA) that synthesizes malicious data to craft adversarial models without eavesdropping on the transmission of benign clients at all or requiring a large quantity of task-specific training data. We design two variants of DFA, namely DFA-R and DFA-G, which differ in how they trade off stealthiness and effectiveness. Specifically, DFA-R iteratively optimizes a malicious data layer to minimize the prediction confidence of all outputs of the global model, whereas DFA-G interactively trains a malicious data generator network by steering the output of the global model toward a particular class. Experimental results on Fashion-MNIST, Cifar-10, and SVHN show that DFA, despite requiring fewer assumptions than existing attacks, achieves similar or even higher attack success rate than state-of-the-art untargeted attacks against various state-of-the-art defense mechanisms. Concretely, they can evade all considered defense mechanisms in at least 50% of the cases for CIFAR-10 and often reduce the accuracy by more than a factor of 2. Consequently, we design REFD, a defense specifically crafted to protect against data-free attacks. REFD leverages a reference dataset to detect updates that are biased or have a low confidence. It greatly improves upon existing defenses by filtering out the malicious updates and achieves high global model accuracy.
A new fixed-time fuzzy adaptive fault-tolerant control methodology is proposed for the longitudinal dynamics of hypersonic flight vehicles (HFVs) in the presence of actuator faults, uncertain dynamics, and external disturbances. In contrast with the conventional fixed-time control schemes that typically contain the fractional powers of errors in their designs, this work develops a low-complexity control structure in the sense of removing the dependence on the need of abovementioned fractional power terms by means of prescribed performance control (PPC) method. Different from the most existing PPC approaches where the initial conditions of tracking errors are required to be known, the newly proposed prescribed performance function (PPF) can relax such restrictions through choosing properly small initial values of PPF. Fuzzy logic systems (FLSs) are employed to handle unknown dynamics, and minimal learning parameter (MLP) technique is incorporated into the design for the purpose of alleviating computation burden. Closed-loop stability is rigorously proved via Lyapunov stability theory, and simulation results are eventually given to validate the effectiveness of the proposed control strategy.
Federated Learning for Tabular Data
Exploring Potential Risk to Privacy
This article proposes a fixed-time adaptive fault-tolerant control methodology for a larger class of high-order (powers are positive odd integers) nonlinear systems subject to asymmetric time-varying state constraints and actuator faults. In contrast with the state-of-the-art control methodologies, the distinguishing features of this study lie in that: (a) high-order asymmetric time-varying tan-type barrier Lyapunov function (BLF) is devised such that the state variables can be convergent to the preassigned compact sets all the time provided their initial values remain therein, which not only preserves the constraints satisfaction, but warrants the validity of the adopted neural network approximator; (b) the proposed control design ensures the tracking errors converge to specified residual sets within fixed time and makes the size of the convergence regions of tracking errors adjustable a priori by means of a new BLF-based tuning function and a projection operator; (c) a variable-separable lemma is delicately embedded into the control design to extract the control terms in a “linear-like” fashion which not only overcomes the difficulty that virtual control signals appear in a non-affine manner, but also solves the problem of actuator faults. Comparative simulations results finally validate the effectiveness of the proposed scheme.
Federated Learning is an emerging distributed collaborative learning paradigm adopted by many of today's applications, e.g., keyboard prediction and object recognition. Its core principle is to learn from large amount of users data while preserving data privacy by design as collaborative users only need to share the machine learning models and keep data locally. The main challenge for such systems is to provide incentives to users to contribute high-quality models trained from their local data. In this paper, we aim to answer how well incentives recognize (in)accurate local models from honest and malicious users, and perceive their impacts on the model accuracy of federated learning systems. We first present a thorough survey on two contrasting perspectives: incentive mechanisms to measure the contribution of local models by honest users, and malicious users to deliberately degrade the overall model. We conduct simulation experiments to empirically demonstrate if existing contribution measurement schemes can disclose low-quality models from malicious users. Our results show there exists a clear tradeoff among measurement schemes in terms of the computational efficiency and effectiveness to distill the impact of malicious participants. We conclude this paper by discussing the research directions to design resilient contribution incentives.