Burrows–Abadi–Needham (BAN) logic
https://en.wikipedia.org/wiki/Burrows%E2%80%93Abadi%E2%80%93Needham_logic#:~:text=Burrows%E2%80%93Abadi%E2%80%93Needham%20logic%20(,secured%20against%20eavesdropping%2C%20or%20both.
This site is to serve as my note-book and to effectively communicate with my students and collaborators. Every now and then, a blog may be of interest to other researchers or teachers. Views in this blog are my own. All rights of research results and findings on this blog are reserved. See also http://youtube.com/c/hongqin @hongqin
https://en.wikipedia.org/wiki/Burrows%E2%80%93Abadi%E2%80%93Needham_logic#:~:text=Burrows%E2%80%93Abadi%E2%80%93Needham%20logic%20(,secured%20against%20eavesdropping%2C%20or%20both.
Referecne: https://www.drivendata.org/competitions/98/nist-federated-learning-1/rules/
privacy-preserving federated learning (PPFL) solutions
democracy-affirming technologies.
the global federated model is trained, the parameters related to the local models could be used to learn about the sensitive information contained in the training data of each client. Similarly, the released global model could also be used to infer sensitive information about the training datasets used.
1.4 GOALS AND OBJECTIVES:
Organizers seek to mature federated learning approaches and build trust in adoption by accelerating the development of efficient PPFL solutions that leverage a combination of input and output privacy techniques to:
Phase 1: Concept Paper. Blue Team Participants will produce a technical white paper (“Concept Paper” or “White Paper”) setting out their proposed solution approach. Technical papers will be evaluated by a panel of judges across a set of weighted criteria. Participants will be eligible to win prizes awarded to the top technical papers, ranked by points awarded.
As you propose your technical solutions, be prepared to clearly describe the technical approaches and sketch out proof of or justification for privacy guarantees. Participants should consider a broad range of privacy threats during the model training and model use phases and consider technical and process aspects including but not limited to cryptographic and non-cryptographic methods, and protection needed within the deployment environment.
Successful technical approaches and proofs of privacy guarantees will include the design of any algorithms, protocols, etc. utilized, as well as formal or informal arguments of how the solution will provide privacy guarantees. Participants will clearly list any additional privacy issues specific to the technological approaches used and justify initial enhancements or novelties compared to the current state-of-the-art. Participant submissions must describe how the solution will cater to the types of data provided to participants and how generalizable the solution is to multiple domains. Expected efficiency/scalability of improvements, privacy vs. utility trade off should be articulated, if possible, at this conceptual stage.
Q: what is the definition of privacy guarantee?
a one-page abstract and a Concept Paper.
Abstract: The one-page abstract must include a title and a brief description of the proposed solution, including the proposed privacy mechanisms and architecture of the federated model. The description should also describe the proposed machine learning model and expected results with regard to accuracy. Successful abstracts will outline how solutions will achieve privacy while minimizing loss to accuracy, a proposed solution, and the anticipated results, as more fully described on the Challenge Website. Abstracts must be submitted by following the instructions on the Challenge Website. Abstracts will be screened by the DrivenData and Organizers’ staff for contest eligibility and used to ensure the composition of the judging panel’s expertise aligns to proposed solutions that will be evaluated throughout the course of the Challenge. Feedback will not be provided.
Concept Paper: The Concept Paper should conceptualize solutions that describe the technical approaches and lay out the proof of privacy guarantees that solve a set of predictive or analytic tasks that support the use cases. Successful Concept Papers will incorporate the originally submitted abstract and be no more than ten pages in length. References will not count towards page length. Participant submissions shall:
I submitted CONCUR Philadelphia ICIBM meeting travel reimbursement request. When I uploaded the hotel, there are errors for allowance. I then created Itinerary to add per diem, and the allowance error went away.
So, next time, I should try create Itinerary first, and then upload hotel.
zoom, turn live caption on, record
https://ai.facebook.com/blog/crypten-a-new-research-tool-for-secure-machine-learning-with-pytorch/
https://crypten.readthedocs.io/en/latest/
holomorphic encryption:
Enc(m1) + Enc(m2) = Enc( m1 + m2)
Enc(m1) x Enc(m2) = Enc( m1 x m2)
So, an untrusted entity can compute addition or multiplication without decryption.
https://en.wikipedia.org/wiki/Homomorphic_encryption
Fully homomorphic encryption (FHE)
From Wikipedia:
In 2016, Cheon, Kim, Kim and Song (CKKS)[35] proposed an approximate homomorphic encryption scheme that supports a special kind of fixed-point arithmetic that is commonly referred to as block floating point arithmetic. The CKKS scheme includes an efficient rescaling operation that scales down an encrypted message after a multiplication. For comparison, such rescaling requires bootstrapping in the BGV and BFV schemes. The rescaling operation makes CKKS scheme the most efficient method for evaluating polynomial approximations, and is the preferred approach for implementing privacy-preserving machine learning applications. The scheme introduces several approximation errors, both nondeterministic and deterministic, that require special handling in practice.[36]
A 2020 article by Baiyu Li and Daniele Micciancio discusses passive attacks against CKKS, suggesting that the standard IND-CPA definition may not be sufficient in scenarios where decryption results are shared.[37] The authors apply the attack to four modern homomorphic encryption libraries (HEAAN, SEAL, HElib and PALISADE) and report that it is possible to recover the secret key from decryption results in several parameter configurations. The authors also propose mitigation strategies for these attacks, and include a Responsible Disclosure in the paper suggesting that the homomorphic encryption libraries already implemented mitigations for the attacks before the article became publicly available. Further information on the mitigation strategies implemented in the homomorphic encryption libraries has also been published.[38][39]
Leaf-aggregator, intermediate aggregator, master aggregator, in hierarchical tree based aggregation
https://arxiv.org/pdf/2203.12163.pdf
AdaFed takes associativity one step further. AdaFed mitigates issues with aggregation overlays by avoiding the construction of actual/physical tree topology.
Book series
Federated Learning (FL) requires an aggregator and parties to exchange model updates. (Page 285)
vulnerable to the inference of private data
System entities of the FL system
the attack surface is used to refer to the exposed parameters and data
against data leak
FL-specific attacks often take advantage of the information transmission during FL.
Differential privacy: differential privacy at the party side or the aggregator side.
For healthcare data and personal information, there are regulation and compliance requirements [14, 63]
page 285: In FL, training data is not explicitly shared.
https://mp.weixin.qq.com/s/7fb4tx0sKXE26IX1nXw4qg
zoom, turn live caption on,
introduce myself
syllabus
Socrative, Room HongQin, anonymous icebreaker,
datacamp registration
participatory coding and video requirement
video submission with hyper-link. Examples of past student submissions.
sample student videos,
past student final report
why R and python
x Email list to calendar invitation
agile at scale
Rally BroadCom
Use IBM Z as the mainframe
according to the student intern, AGILE give employee work and life balance. Software engineers do not have to work in the weekends when AGILE replaced waterfall model.
UNUM plan software engineering work one-year head, in order to request a budget.