← Search

Zahra Ghodsi

5 accepted papers

2023

zPROBE: Zero Peek Robustness Checks for Federated Learning

ICCV 2023poster

Privacy-preserving federated learning allows multiple users to jointly train a model with coordination of a central server. The server only learns the final aggregation result, thereby preventing leakage of the users' (private) training data from the individual model updates. However, keeping the in…

Cited by 19PDFScholar
2021

Circa: Stochastic ReLUs for Private Deep Learning

NeurIPS 2021poster

The simultaneous rise of machine learning as a service and concerns over user privacy have increasingly motivated the need for private inference (PI). While recent work demonstrates PI is possible using cryptographic primitives, the computational overheads render it impractical. State-of-art deep ne…

Cited by 41SourcePDFScholar
2021

DeepReDuce: ReLU Reduction for Fast Private Inference

ICML 2021spotlight

The recent rise of privacy concerns has led researchers to devise methods for private neural inference—where inferences are made directly on encrypted data, never seeing inputs. The primary challenge facing private inference is that computing on encrypted data levies an impractically-high latency pe…

Cited by 114SourcePDFScholar
2020

CryptoNAS: Private Inference on a ReLU Budget

NeurIPS 2020poster

Machine learning as a service has given raise to privacy concerns surrounding clients' data and providers' models and has catalyzed research in private inference (PI): methods to process inferences without disclosing inputs. Recently, researchers have adapted cryptographic techniques to show PI is p…

Cited by 106SourcePDFScholar
2017

SafetyNets: Verifiable Execution of Deep Neural Networks on an Untrusted Cloud

NeurIPS 2017poster

Inference using deep neural networks is often outsourced to the cloud since it is a computationally demanding task.  However, this raises a fundamental issue of trust. How can a client be sure that the cloud has performed inference correctly? A lazy cloud provider might use a simpler but less accura…

Cited by 237SourcePDFScholar