← Search

Yanjun Zhu

4 accepted papers

2023

Defending against Data-Free Model Extraction by Distributionally Robust Defensive Training

NeurIPS 2023poster

Data-Free Model Extraction (DFME) aims to clone a black-box model without knowing its original training data distribution, making it much easier for attackers to steal commercial models. Defense against DFME faces several challenges: (i) effectiveness; (ii) efficiency; (iii) no prior on the attacker…

Cited by 13SourcePDFScholar
2023

MetaMix: Towards Corruption-Robust Continual Learning With Temporally Self-Adaptive Data Transformation

CVPR 2023poster

Continual Learning (CL) has achieved rapid progress in recent years. However, it is still largely unknown how to determine whether a CL model is trustworthy and how to foster its trustworthiness. This work focuses on evaluating and improving the robustness to corruptions of existing CL models. Our e…

Cited by 15SourcePDFScholar
2020

CP-NAS: Child-Parent Neural Architecture Search for 1-bit CNNs

IJCAI 2020poster

Neural architecture search (NAS) proves to be among the best approaches for many tasks by generating an application-adaptive neural architectures, which are still challenged by high computational cost and memory consumption. At the same time, 1-bit convolutional neural networks (CNNs) with binarized…

Cited by 0SourcePDFScholar