← Search

Shengyuan Hu

5 accepted papers

2025

Unlearning or Obfuscating? Jogging the Memory of Unlearned LLMs via Benign Relearning

ICLR 2025poster

Machine unlearning is a promising approach to mitigate undesirable memorization of training data in ML models. However, in this work we show that existing approaches for unlearning in LLMs are surprisingly susceptible to a simple set of benign relearning attacks. With access to only a small and pote…

Cited by 1SourcePDFScholar
2024

No Free Lunch in LLM Watermarking: Trade-offs in Watermarking Design Choices

NeurIPS 2024poster

Advances in generative models have made it possible for AI-generated text, code, and images to mirror human-generated content in many applications. Watermarking, a technique that aims to embed information in the output of a model to verify its source, is useful for mitigating the misuse of such AI-g…

2022

On Privacy and Personalization in Cross-Silo Federated Learning

NeurIPS 2022accept

While the application of differential privacy (DP) has been well-studied in cross-device federated learning (FL), there is a lack of work considering DP and its implications for cross-silo FL, a setting characterized by a limited number of clients each containing many data subjects. In cross-silo FL…

2021

Ditto: Fair and Robust Federated Learning Through Personalization

ICML 2021spotlight

Fairness and robustness are two important concerns for federated learning systems. In this work, we identify that robustness to data and model poisoning attacks and fairness, measured as the uniformity of performance across devices, are competing constraints in statistically heterogeneous networks.…

2019

A New Defense Against Adversarial Images: Turning a Weakness into a Strength

NeurIPS 2019poster

Natural images are virtually surrounded by low-density misclassified regions that can be efficiently discovered by gradient-guided search --- enabling the generation of adversarial images. While many techniques for detecting these attacks have been proposed, they are easily bypassed when the adversa…