Machine Learning Research Logo
  • MLDM Group
  • Search
Navigation bar avatar
✕

    Privacy & Security in ML


    A research blog by the Machine Learning and Data Management (MLDM) group.
    • Explainable Vision Transformer Malware Classification

      A systematic comparison of malware-to-image encodings, explainability methods, and reverse traceability

      By Luzia Klauser
      Posted on July 15, 2026

      Malware continues to pose a significant threat to individuals, organizations, and critical infrastructure. As the number and complexity of malware samples continue to grow, automated malware family classification has become an important tool for supporting malware analysis, reverse engineering, and incident response. Visualization-based malware classification has become a widely studied... [Read More]
      Tags:
      • malware
      • vision-transformers
      • explainability
      • reverse-engineering
      • cybersecurity
    • FedMIA against DP-SGD

      An Attack Performance Review

      By Clara Pichler
      Posted on March 13, 2026

      Federated learning (FL) has emerged as a promising paradigm for training machine learning models in privacy-sensitive domains such as healthcare, finance, and cross-institutional collaborations. Instead of centralizing data, multiple clients collaboratively train a shared model while keeping their raw data local. At each communication round, clients compute updates based on... [Read More]
      Tags:
      • membership inference attack
      • differential privacy
      • federated learning
    • A Mathematical Proof of Parallel Composition for Approximate Differential Privacy

      By Clara E. Pichler
      Posted on February 26, 2026

      Data privacy is a subfield of data management concerned with answering queries over sensitive datasets while protecting the privacy of the individuals they contain. One influential definition addressing this challenge is differential privacy [3][6]. Differential privacy is a mathematical notion guaranteeing that the distribution of a randomized algorithm’s output changes... [Read More]
      Tags:
      • differential privacy
      • parallel composition
      • group differential privacy
    • Architectural Backdoors

      By Beril Yilgur Vidakovic
      Posted on February 20, 2026

      Training a deep neural network (DNN) from scratch is expensive and time consuming. It requires large datasets, powerful GPUs, and significant computational resources. To reduce cost, training is often outsourced through Machine Learning as a Service (MLaaS)[1], or developers rely on pretrained models from public repositories such as Hugging Face... [Read More]
    • Intellectual Property Protection of Speaker Recognition ML Models

      By Yelyzaveta Klysa
      Posted on December 17, 2025

      Problem Statement In recent years, research has increased on model protection techniques, especially in the image domain. On the other hand, the audio domain, specifically speaker recognition (SR) models and ways to protect them from being stolen, is still rather unexplored. Speaker recognition models are designed to identify and verify... [Read More]
      Tags:
      • intellectual property protection
      • ml security
      • watermarking
    • Older Posts →
    • GitHub

    SBA Research - MLDM  •  2026  •  Imprint  •  Contact

    Powered by Beautiful Jekyll