← Search

Yuval Elovici

17 accepted papers

2026

AntiStyler: Defending Object Detection Models Against Adversarial Patch Attacks Using Style Removal

CVPR 2026

Adversarial patch attacks pose a significant threat to the reliability of object detection (OD) models, particularly in real-time security applications. Although several defenses have been proposed, they often suffer from two limitations: 1) reduced performance on benign images, and 2) impractical p

Cited by 0SourcecodeScholar
2026

Tab-MIA: A Benchmark Dataset for Membership Inference Attacks on Tabular Data in LLMs

ICLR 2026poster

Large language models (LLMs) are increasingly trained on tabular data, which, unlike unstructured text, often contains personally identifiable information (PII) in a highly structured and explicit format. As a result, privacy risks arise, since sensitive records can be inadvertently retained by the…

Cited by 0SourceScholar
2025

DIESEL: A Lightweight Inference-Time Safety Enhancement for Language Models

ACL 2025finding

Large language models (LLMs) have demonstrated impressive performance across a wide range of tasks, including open-ended dialogue, driving advancements in virtual assistants and other interactive systems. However, these models often generate outputs misaligned with human values, such as ethical norm…

Cited by 0SourcePDFScholar
2025

DOMBA: Double Model Balancing for Access-Controlled Language Models via Minimum-Bounded Aggregation

AAAI 2025technical

The utility of large language models (LLMs) depends heavily on the quality and quantity of their training data. Many organizations possess large data corpora that could be leveraged to train or fine-tune LLMs tailored to their specific needs. However, these datasets often come with access restrict…

2025

Gradient Inversion of Multimodal Models

ICML 2025poster

Federated learning (FL) enables privacy-preserving distributed machine learning by sharing gradients instead of raw data. However, FL remains vulnerable to gradient inversion attacks, in which shared gradients can reveal sensitive training data. Prior research has mainly concentrated on unimodal tas…

Cited by 0SourcePDFScholar
2025

KDAT: Inherent Adversarial Robustness via Knowledge Distillation with Adversarial Tuning for Object Detection Models

AAAI 2025technical

Adversarial patches pose a significant threat to computer vision models' integrity, decreasing the accuracy of various tasks, including object detection (OD). Most existing OD defenses exhibit a trade-off between enhancing the model's adversarial robustness and maintaining its performance on benign…

2025

Tag&Tab: Pretraining Data Detection in Large Language Models Using Keyword-Based Membership Inference Attack

EMNLP 2025

Large language models (LLMs) have become essential tools for digital task assistance. Their training relies heavily on the collection of vast amounts of data, which may include copyright-protected or sensitive information. Recent studies on detecting pretraining data in LLMs have primarily focused o

2025

Variance-Based Membership Inference Attacks Against Large-Scale Image Captioning Models

CVPR 2025poster

The proliferation of multi-modal generative models has introduced new privacy and security challenges, especially due to the risks of memorization and unintentional disclosure of sensitive information. This paper focuses on the vulnerability of multi-modal image captioning models to membership infer…

Cited by 0SourcePDFScholar
2024

AdversariaLeak: External Information Leakage Attack Using Adversarial Samples on Face Recognition Systems

ECCV 2024poster

"Face recognition (FR) systems are vulnerable to external information leakage (EIL) attacks, which can reveal sensitive information about the training data, thus compromising the confidentiality of the company’s proprietary and the privacy of the individuals concerned. Existing EIL attacks mainly re…

Cited by 2SourcePDFScholar
2024

DeSparsify: Adversarial Attack Against Token Sparsification Mechanisms

NeurIPS 2024spotlight

Vision transformers have shown remarkable advancements in the computer vision domain, demonstrating state-of-the-art performance in diverse tasks (e.g., image classification, object detection). However, their high computational requirements grow quadratically with the number of tokens used. Token sp…

Cited by 0SourcePDFScholar
2024

Universal Adversarial Attack Against Speaker Recognition Models

ICASSP 2024accepted

In recent years, deep learning-based speaker recognition (SR) models have received a large amount of attention from the machine learning (ML) community. Their increasing popularity derives in large part from their effectiveness in identifying speakers in many security-sensitive applications. Researc…

Cited by 0SourceScholar
2024

Visual Riddles: a Commonsense and World Knowledge Challenge for Large Vision and Language Models

NeurIPS 2024poster

Imagine observing someone scratching their arm; to understand why, additional context would be necessary. However, spotting a mosquito nearby would immediately offer a likely explanation for the person’s discomfort, thereby alleviating the need for further information. This example illustrates how s…

2024

YolOOD: Utilizing Object Detection Concepts for Multi-Label Out-of-Distribution Detection

CVPR 2024poster

Out-of-distribution (OOD) detection has attracted a large amount of attention from the machine learning research community in recent years due to its importance in deployed systems. Most of the previous studies focused on the detection of OOD samples in the multi-class classification task. However O…

2023

Breaking Common Sense: WHOOPS! A Vision-and-Language Benchmark of Synthetic and Compositional Images

ICCV 2023poster

Weird, unusual, and uncanny images pique the curiosity of observers because they challenge commonsense. For example, an image released during the 2022 world cup depicts the famous soccer stars Lionel Messi and Cristiano Ronaldo playing chess, which playfully violates our expectation that their compe…

Cited by 71PDFScholar
2022

WinoGAViL: Gamified Association Benchmark to Challenge Vision-and-Language Models

NeurIPS 2022accept

While vision-and-language models perform well on tasks such as visual question answering, they struggle when it comes to basic human commonsense reasoning skills. In this work, we introduce WinoGAViL: an online game of vision-and-language associations (e.g., between werewolves and a full moon), used…

2021

The Translucent Patch: A Physical and Universal Attack on Object Detectors

CVPR 2021poster

Physical adversarial attacks against object detectors have seen increasing success in recent years. However, these attacks require direct access to the object of interest in order to apply a physical patch. Furthermore, to hide multiple objects, an adversarial patch must be applied to each object. I…

Cited by 129PDFScholar