Wednesday, August 31, 2022

Burrows–Abadi–Needham BAG logic

 

Burrows–Abadi–Needham (BAN) logic

https://en.wikipedia.org/wiki/Burrows%E2%80%93Abadi%E2%80%93Needham_logic#:~:text=Burrows%E2%80%93Abadi%E2%80%93Needham%20logic%20(,secured%20against%20eavesdropping%2C%20or%20both.







PET privacy enhancing techniques

Referecne:  https://www.drivendata.org/competitions/98/nist-federated-learning-1/rules/

privacy-preserving federated learning (PPFL) solutions

 democracy-affirming technologies.

 the global federated model is trained, the parameters related to the local models could be used to learn about the sensitive information contained in the training data of each client. Similarly, the released global model could also be used to infer sensitive information about the training datasets used.

1.4 GOALS AND OBJECTIVES:

  • Drive innovation in the technological development and application of novel privacy enhancing technologies;
  • Deliver strong privacy guarantees against a set of common threats and privacy attacks; and
  • Generate effective models to accomplish a set of predictive or analytical tasks that support the use cases.

Organizers seek to mature federated learning approaches and build trust in adoption by accelerating the development of efficient PPFL solutions that leverage a combination of input and output privacy techniques to:

Phase 1: Concept Paper. Blue Team Participants will produce a technical white paper (“Concept Paper” or “White Paper”) setting out their proposed solution approach. Technical papers will be evaluated by a panel of judges across a set of weighted criteria. Participants will be eligible to win prizes awarded to the top technical papers, ranked by points awarded.

As you propose your technical solutions, be prepared to clearly describe the technical approaches and sketch out proof of or justification for privacy guarantees. Participants should consider a broad range of privacy threats during the model training and model use phases and consider technical and process aspects including but not limited to cryptographic and non-cryptographic methods, and protection needed within the deployment environment.

Successful technical approaches and proofs of privacy guarantees will include the design of any algorithms, protocols, etc. utilized, as well as formal or informal arguments of how the solution will provide privacy guarantees. Participants will clearly list any additional privacy issues specific to the technological approaches used and justify initial enhancements or novelties compared to the current state-of-the-art. Participant submissions must describe how the solution will cater to the types of data provided to participants and how generalizable the solution is to multiple domains. Expected efficiency/scalability of improvements, privacy vs. utility trade off should be articulated, if possible, at this conceptual stage.

Q: what is the definition of privacy guarantee? 

a one-page abstract and a Concept Paper.

Abstract: The one-page abstract must include a title and a brief description of the proposed solution, including the proposed privacy mechanisms and architecture of the federated model. The description should also describe the proposed machine learning model and expected results with regard to accuracy. Successful abstracts will outline how solutions will achieve privacy while minimizing loss to accuracy, a proposed solution, and the anticipated results, as more fully described on the Challenge Website. Abstracts must be submitted by following the instructions on the Challenge Website. Abstracts will be screened by the DrivenData and Organizers’ staff for contest eligibility and used to ensure the composition of the judging panel’s expertise aligns to proposed solutions that will be evaluated throughout the course of the Challenge. Feedback will not be provided.
Concept Paper: The Concept Paper should conceptualize solutions that describe the technical approaches and lay out the proof of privacy guarantees that solve a set of predictive or analytic tasks that support the use cases. Successful Concept Papers will incorporate the originally submitted abstract and be no more than ten pages in length. References will not count towards page length. Participant submissions shall:

  • Include a title and abstract for the solution
  • Clearly articulate the selected track(s) the solution addresses, understanding of the problem, and opportunities for privacy technology within the current state-of-the-art.
  • Clearly describe the technical approaches and proof of privacy guarantees based on their described threat model, including:
  • The design of any algorithms, protocols, etc. utilized,
  • The formal or informal arguments of how the solution will provide privacy guarantees.
  • Clearly list any additional privacy issues specific to the technological approaches used.
  • Justify initial enhancement or novelty compared to the state-of-the-art.
  • Articulate:
  • The expected efficiency and scalability of the privacy solution,
  • The expected accuracy and performance of the model,
  • The expected tradeoffs between privacy and accuracy/utility,
  • How the explainability of model outputs may be impacted by your privacy solution,
  • The feasibility of implementing the solution within the competition timeframe.
  • Describe how the solution will cater to the types of data provided to participants and articulate what additional work may be needed to generalize the solution to other types of data.
  • Articulate the anticipated use and purpose of licensed software.
  • Be free from typographical and grammatical errors.
Participants should refer to Section 7 on general submission requirements for additional guidance and style guidelines.
Judges will score the Concept Papers against the weighted criteria outlined in the table below. Solutions will need to carefully consider trade-offs between criteria such as privacy, accuracy, and efficiency, and should take the weightings of the criteria into account when considering these trade-offs. Concept Papers must also demonstrate how acceptable levels of both privacy and accuracy will be achieved – one must not be completely traded off for the other (a fully privacy-preserving but totally inaccurate model is not of use to anyone). Proposals that do not sufficiently demonstrate how both privacy and accuracy will be achieved will not be eligible to score points in the remaining criteria.
















Tuesday, August 30, 2022

federated scope

 Alibaba federated learning

https://github.com/AI-in-Biomedical-Science/FederatedScope#quick-start


Concur travel reimbursement request

 

I submitted CONCUR Philadelphia ICIBM meeting travel reimbursement request. When I uploaded the hotel, there are errors for allowance. I then created Itinerary to add per diem, and the allowance error went away. 

So, next time, I should try create Itinerary first, and then upload hotel. 



To create a Travel Allowance Itinerary for an already created report:
  1. Log in to Concur.
  2. Click on Expense at the top of the screen.
  3. Open your existing expense report.
  4. Click Details.
  5. Under the Travel Allowance section, click New Itinerary.
  6. Populate all required fields (be accurate with dates and times).
  7. Click Save.

Monday, August 29, 2022

Active Presenter

 screencast, and video editing

https://atomisystems.com/download/ 

4180 day 3

 zoom, turn live caption on, record

review simple R

learning R with GISAID 

Running in RStudio
Next time, go through JHU data set. 




Thursday, August 25, 2022

CyptTen

 

https://ai.facebook.com/blog/crypten-a-new-research-tool-for-secure-machine-learning-with-pytorch/


https://crypten.readthedocs.io/en/latest/



hormophic encrption

 holomorphic encryption: 

Enc(m1) + Enc(m2) = Enc( m1 + m2) 

Enc(m1) x Enc(m2) = Enc( m1 x m2) 

So, an untrusted entity can compute addition or multiplication without decryption. 

https://en.wikipedia.org/wiki/Homomorphic_encryption

Fully homomorphic encryption (FHE)

From Wikipedia:

Fourth-generation FHE[edit]

In 2016, Cheon, Kim, Kim and Song (CKKS)[35] proposed an approximate homomorphic encryption scheme that supports a special kind of fixed-point arithmetic that is commonly referred to as block floating point arithmetic. The CKKS scheme includes an efficient rescaling operation that scales down an encrypted message after a multiplication. For comparison, such rescaling requires bootstrapping in the BGV and BFV schemes. The rescaling operation makes CKKS scheme the most efficient method for evaluating polynomial approximations, and is the preferred approach for implementing privacy-preserving machine learning applications. The scheme introduces several approximation errors, both nondeterministic and deterministic, that require special handling in practice.[36]

A 2020 article by Baiyu Li and Daniele Micciancio discusses passive attacks against CKKS, suggesting that the standard IND-CPA definition may not be sufficient in scenarios where decryption results are shared.[37] The authors apply the attack to four modern homomorphic encryption libraries (HEAAN, SEAL, HElib and PALISADE) and report that it is possible to recover the secret key from decryption results in several parameter configurations. The authors also propose mitigation strategies for these attacks, and include a Responsible Disclosure in the paper suggesting that the homomorphic encryption libraries already implemented mitigations for the attacks before the article became publicly available. Further information on the mitigation strategies implemented in the homomorphic encryption libraries has also been published.[38][39]


multiple aggregators in federated learning

 Leaf-aggregator, intermediate aggregator, master aggregator, in hierarchical tree based aggregation

https://arxiv.org/pdf/2203.12163.pdf

AdaFed takes associativity one step further. AdaFed mitigates issues with aggregation overlays by avoiding the construction of actual/physical tree topology.

Federated learning (book)

Book series

Federated Learning (FL) requires an aggregator and parties to exchange model updates. (Page 285)

vulnerable to the inference of private data

System entities of the FL system

the attack surface is used to refer to the exposed parameters and data

against data leak

FL-specific attacks often take advantage of the information transmission during FL. 

Differential privacy: differential privacy at the party side or the aggregator side. 

For healthcare data and personal information, there are regulation and compliance requirements [14, 63]


page 285: In FL, training data is not explicitly shared. 

$13.3.1 Secure Aggregation 

Wednesday, August 24, 2022

基于人工智能(AI)的蛋白结构预测工具合集

 

基于人工智能(AI)的蛋白结构预测工具合集

https://mp.weixin.qq.com/s/7fb4tx0sKXE26IX1nXw4qg


CPSC4180 day 2, Rstudio, Cloud, CoLab

zoom, turn live caption on, record
go over datacamp registration and assignment
R and R studio installation
RStudio Cloud; 
CoLab; Repit
simple R exercis: SimpleR.Rmd download directly form Canvas (GitHub link does not provide direct download as Rmd).   

Running in RStudio (1 hour, how to insert new R chunk, R pub) 
run simpleR in CoLab



Monday, August 22, 2022

cpsc4180, 5180 day 1

 

CPSC4180 day 1, orientation

zoom, turn live caption on, 

introduce myself 

syllabus

Socrative, Room HongQin, anonymous icebreaker, 

datacamp registration

participatory coding and video requirement

video submission with hyper-link. Examples of past student submissions. 

sample student videos, 

past student final report

why R and python

x Email list to calendar invitation

Unum Agile

agile at scale 

Rally BroadCom

Use IBM Z as the mainframe

according to the student intern, AGILE give employee work and life balance. Software engineers do not have to work in the weekends when AGILE replaced waterfall model. 

UNUM plan software engineering work one-year head, in order to request a budget.