News

Grades for Presentation and Report

Written on 19.02.24 by Xiao Zhang

Hello everyone,

The feedback and grades of the oral presentation and the final report are available on CMS. Kudos to every team's accomplishments in the course project.

If you have any questions about the grades (i.e., homework assignments, paper review, course project), please reach out to us… Read more

Hello everyone,

The feedback and grades of the oral presentation and the final report are available on CMS. Kudos to every team's accomplishments in the course project.

If you have any questions about the grades (i.e., homework assignments, paper review, course project), please reach out to us by email no later than this Thursday, Feb. 22

Cheers,

Xiao

The Feedback of HW3, HW4 and Paper Review

Written on 15.02.24 by Minxing Zhang

Hi everyone,

The feedback of hw3, hw4, and paper review has been released.

If you have any issue or question regarding the feedback, please feel free to contact the corresponding TA within this week.

 

Best,

Minxing

Oral Presentation

Written on 08.02.24 by Xiao Zhang

Hi everyone,

Congratulations to every team who presented your course project this afternoon! All of you did a fantastic job. I enjoyed learning from your project.

For the remaining three teams who have schedule conflicts, I booked Room 0.07 at CISPA Main Building from 3:00 pm to 4:00 pm on Feb.… Read more

Hi everyone,

Congratulations to every team who presented your course project this afternoon! All of you did a fantastic job. I enjoyed learning from your project.

For the remaining three teams who have schedule conflicts, I booked Room 0.07 at CISPA Main Building from 3:00 pm to 4:00 pm on Feb. 15, 2024. You can find the schedule here on the same Google spreadsheet. I am also looking forward to your presentations.

Best regards,

Xiao

Finalizing Presentation Schedule

Written on 05.02.24 by Xiao Zhang

Hi everyone,

I am finalizing the oral presentation schedule (check this Google form). Please put the title of your team's presentation in the corresponding place in the form. I look forward to your presentation on Thursday ;)

Each presentation consists of 12 minutes: a 10-minute presentation and… Read more

Hi everyone,

I am finalizing the oral presentation schedule (check this Google form). Please put the title of your team's presentation in the corresponding place in the form. I look forward to your presentation on Thursday ;)

Each presentation consists of 12 minutes: a 10-minute presentation and a 2-minute Q&A. Please ensure your team's presentation follows this time limit since we have a tight schedule. 

For the teams that can not make it to the event on Feb. 08, we will have an additional presentation event organized in the early afternoon of Feb.15. The location will be announced later.

Best regards,

Xiao

Homework Assignment 4 Released

Written on 19.01.24 by Xiao Zhang

Hi everyone,

For your information, homework assignment 4 has been released on CMS, with the submission deadline extended by a week. Good luck and enjoy the weekend.

Best regards,

Xiao

Class Online due to Heavy Snow

Written on 18.01.24 by Xiao Zhang

Good Morning Everyone,

Due to the heavy snow this morning, we will have an online class today over Zoom (link: https://cispa-de.zoom-x.de/j/65081098332?pwd=eFBYdzUzYUkwQnlOT2RnNmtOTSswZz09). The whole invitation is attached at the end of this email. In addition, homework assignment 4 will be… Read more

Good Morning Everyone,

Due to the heavy snow this morning, we will have an online class today over Zoom (link: https://cispa-de.zoom-x.de/j/65081098332?pwd=eFBYdzUzYUkwQnlOT2RnNmtOTSswZz09). The whole invitation is attached at the end of this email. In addition, homework assignment 4 will be released later tomorrow. I apologize for the delay. No worries; the submission deadline of HW4 will be postponed accordingly.

Be safe, and hope to see you in the afternoon on Zoom

Xiao

 

Xiao Zhang is inviting you to a scheduled Zoom meeting.

Topic: [Advanced Lecture] Robustness in Machine Learning
Time: Jan 18, 2024, 02:00 PM Amsterdam, Berlin, Rome, Stockholm, Vienna

Join Zoom Meeting
https://cispa-de.zoom-x.de/j/65081098332?pwd=eFBYdzUzYUkwQnlOT2RnNmtOTSswZz09

Meeting ID: 650 8109 8332
Passcode: qQL4!D
One tap mobile
+496938980596,,65081098332# Germany

Dial by your location
        +49 69 389 805 96 Germany
Meeting ID: 650 8109 8332
Find your local number: https://cispa-de.zoom-x.de/u/cb8FpEGLNT


Privacy Notice:
Please refer to https://cispa.de/en/data-privacy-policy-zoom for our privacy notice regarding the use of Zoom at CISPA

Schedule for Oral Presentation

Written on 05.01.24 by Xiao Zhang

Hi everyone,

Happy New Year, and I hope this email finds you well.

We are currently trying to finalize the oral presentation schedule, but we need your input. The oral presentation is scheduled for 13:00 - 17:00 on Feb. 08. In principle; every student is expected to attend the oral presentation… Read more

Hi everyone,

Happy New Year, and I hope this email finds you well.

We are currently trying to finalize the oral presentation schedule, but we need your input. The oral presentation is scheduled for 13:00 - 17:00 on Feb. 08. In principle; every student is expected to attend the oral presentation event as much as possible to support others' presentations and learn from them. If your team has schedule conflicts for the period, please notify us (me and the TAs) by email as soon as possible. In the email, you should specify which period between 13:00 and 17:00 on Feb. 08 works for your team and which does not. If your team can not be present at any time during the period, please provide us with at least three time slots that work for you in the following week (Feb. 12 - Feb. 16). In addition, I have updated the instructions for paper review, oral presentation, and final report on the course website. Please remember to take a look and let us know if you have any questions.

Have a nice weekend,

Xiao

The Feedback of Proposals

Written on 02.01.24 (last change on 02.01.24) by Minxing Zhang

Happy New Year, everyone!

We have released our feedback on your submitted proposals. Each proposal should receive two feedback (one from a TA and one from the instructor).

We hope the feedback is useful to improve your projects. 

Please carefully check the assignment and project requirements,… Read more

Happy New Year, everyone!

We have released our feedback on your submitted proposals. Each proposal should receive two feedback (one from a TA and one from the instructor).

We hope the feedback is useful to improve your projects. 

Please carefully check the assignment and project requirements, including but not limited to the template requirement.

Another noteworthy thing is to submit the correct file(s); otherwise, we cannot understand the content.

 

Additional clarification:

- For each paper, the review is limited to 2 pages.

 

Best,

Minxing

Regarding Assignment 2

Written on 14.12.23 (last change on 14.12.23) by Minxing Zhang

Hi everyone,

All your submissions have been scored, please feel free to contact the TA who scored your submission if you have any questions.

- If you find my name (i.e., Minxing) in your feedback, that means I scored your submission.

 

Here are some submission suggestions.

For the… Read more

Hi everyone,

All your submissions have been scored, please feel free to contact the TA who scored your submission if you have any questions.

- If you find my name (i.e., Minxing) in your feedback, that means I scored your submission.

 

Here are some submission suggestions.

For the following submissions, please only submit the necessary files.

For example, regarding homework assignments, please submit and only submit 2 files, i.e., .pdf and .ipynb (the have-run version), which correspond to the theoretical and the programming questions.

Regarding the programming part,

- please read the questions and instructions carefully, and make sure that the submission contains all required outputs;

- please do NOT print non-required output.

Thanks for your understanding in advance!

 

Best,

Minxing

Regarding Q&A session

Written on 14.12.23 (last change on 14.12.23) by Minxing Zhang

Hi everyone,

today, Yuan and I will host the Q&A session at the same time (14:15 - 15:45) and in the same room (Bernd Therre Lecture Hall).

Please feel free to attend this session if you are interested.

Best,

Minxing

The Scores of Homework Assignment 1

Written on 06.12.23 (last change on 06.12.23) by Minxing Zhang

Hi everyone,

The scores of your homework assignment 1 can be checked on our CMS website now.

Please feel free to contact the teaching assistant who scores your assignment if you have questions.

- If you find my name (i.e., Minxing) on the feedback, it means I scored your assignment.

By the… Read more

Hi everyone,

The scores of your homework assignment 1 can be checked on our CMS website now.

Please feel free to contact the teaching assistant who scores your assignment if you have questions.

- If you find my name (i.e., Minxing) on the feedback, it means I scored your assignment.

By the way, the deadline for homework assignment 2 is closed, do not miss it.

Enjoy the winter time and take care,

Minxing

 

 

 

An Interesting Talk Tomorrow

Written on 15.11.23 by Xiao Zhang

Hi everyone,

There will be a very interesting talk from Lujo Bauer (Carnegie Mellon University) at 4:00 pm in Lecture Hall 0.05 right after tomorrow's lecture.

The talk is about "From pandas and gibbons to malware detection: Attacking and defending real-world uses of machine learning", which is… Read more

Hi everyone,

There will be a very interesting talk from Lujo Bauer (Carnegie Mellon University) at 4:00 pm in Lecture Hall 0.05 right after tomorrow's lecture.

The talk is about "From pandas and gibbons to malware detection: Attacking and defending real-world uses of machine learning", which is highly relevant to what we have learnt about adversarial robustness so far. You can find more details in the forwarded message below. I highly recommended you to attend the talk if you have time.

Best regards and see you tomorrow,

Xiao 

 

Dear all,

As part of CISPA's Distinguished Lecture Series, we are pleased to announce that

   Lujo Bauer (Carnegie Mellon University)

will give a talk on

   From pandas and gibbons to malware detection: Attacking and defending real-world uses of machine learning 

on Thursday, 16th of November, at 4pm. The talk will take place in a hybrid mode with a physical presentation in the Bernd Therre lecture hall at CISPA and via Zoom:


https://cispa-de.zoom-x.de/j/62011223528?pwd=TW9xWWE4ZnU1WHlHQ0w4ckV2aHFUdz09

Meeting ID: 620 1122 3528
Passcode: w%65qV

We encourage everyone on campus to attend the presentation. Should you want to meet with Lujo as well, please send me an email and I'll try to arrange a meeting.


Abstract:
A multitude of research results has shown that slightly changing the inputs given to an ML algorithm can trick the algorithm into producing "wrong" outputs. Such research typically assumes that an attacker has complete control over the input but also wants to change the input as little as possible. In this talk I'll argue that practical threat models are different: attackers work under constraints and toward goals that most research typically doesn't consider. Using face recognition and malware detection as examples, I'll show that under more realistic constraints, defeating ML requires creating new attack methods. I'll also show that even assessing the risk of real-world uses of ML may require new definitions of robustness, which in turn enable better defenses but also more efficient attacks.

Bio:
Lujo Bauer is a Professor of Electrical and Computer Engineering, and of  Computer Science, at Carnegie Mellon University. He is also a member of  CyLab, Carnegie Mellon's computer security and privacy institute. Lujo  received his Ph.D. in Computer Science from Princeton University in 2003. Lujo's research examines many aspects of computer security and  privacy, including building systems in which usability and security  co-exist and designing practical tools for identifying software  vulnerabilities. His recent work focuses on developing tools and  guidance to help users stay safer online and on examining how advances  in machine learning can (or might not) lead to a more secure future. Lujo served as program (co-)chair for the flagship computer security  conferences of the IEEE (S&P 2015) and the Internet Society (NDSS  2014), and is looking forward to doing so for USENIX in 2025.

Best regards,
Cris Staicu

 

Oral Exam & Registration on LSF

Written on 10.11.23 (last change on 13.11.23) by Xiao Zhang

Good morning everyone,

As announced in yesterday's lecture, the oral exam (oral presentation of your team's course project) will take place in Lecture Hall 0.05, CISPA Main Building between 13:00 - 17:00 on Feb 8, 2024. The date and location have been finalized. In addition, the exam registration… Read more

Good morning everyone,

As announced in yesterday's lecture, the oral exam (oral presentation of your team's course project) will take place in Lecture Hall 0.05, CISPA Main Building between 13:00 - 17:00 on Feb 8, 2024. The date and location have been finalized. In addition, the exam registration for this course should be open on LSF soon (until February 1, 2024). You need to register for the exam (before February 1) to receive your final grades. 

Best regards,

Xiao

 

 

Registration Limits for Paper Review

Written on 06.11.23 (last change on 06.11.23) by Xiao Zhang

Good Morning Everyone,

We decided to increase the student limits from 4 to 5 per paper for review, due to the large number of class attendees. You can now edit your preference if there are available slots on the spreadsheet.

Besides, I noticed that some students registered more than 2 papers on… Read more

Good Morning Everyone,

We decided to increase the student limits from 4 to 5 per paper for review, due to the large number of class attendees. You can now edit your preference if there are available slots on the spreadsheet.

Besides, I noticed that some students registered more than 2 papers on the spreadsheet. This is not allowed - each student should register no more than 2 papers so that other students who also interested in the paper will have an opportunity to review it.

Best regards,

Xiao

Review registration open

Written on 02.11.23 by Xiao Zhang

Hi everyone,

The registration of paper review is now open. You can use this editable link to the Google spreadsheet and put your name to the two papers you would like to read and review. Note that each paper can be registered by at most 4 students (first come, first serve). The registration will be… Read more

Hi everyone,

The registration of paper review is now open. You can use this editable link to the Google spreadsheet and put your name to the two papers you would like to read and review. Note that each paper can be registered by at most 4 students (first come, first serve). The registration will be open until the end of this month.

Have a nice evening,

Xiao 

First Lecture Tomorrow at 14:15

Written on 25.10.23 (last change on 25.10.23) by Xiao Zhang

Dear students,

Thank you for registering for the advanced lecture course: Robustness in Machine Learning. We are going to have our first lecture this Thursday (26.10.2023) at 14:15. The meeting place is Bernd Therre Lecture Hall (0.05), CISPA Main Building (C0), Stuhlsatzenhaus 5.

Look forward… Read more

Dear students,

Thank you for registering for the advanced lecture course: Robustness in Machine Learning. We are going to have our first lecture this Thursday (26.10.2023) at 14:15. The meeting place is Bernd Therre Lecture Hall (0.05), CISPA Main Building (C0), Stuhlsatzenhaus 5.

Look forward to meeting you,

Xiao

Show all

Generally speaking, ML Robustness concerns how machine learners should react when the training and testing distributions are not identical, which can arise from any of the following situations:

  • The underlying data collection procedure is corrupted due to human labeling errors or measurement noise.
  • Test-time inputs are manipulated by malicious users, i.e., adversarial examples. 
  • Training data are manipulated by adversaries, i.e., poisoning and backdoor attacks.
  • Distribution shifts may exist whenever the model is deployed in a new environment.

In this advanced lecture, you will learn topics in adversarial machine learning, out-of-distribution generalization, and robust statistics. This course assumes that students have prior knowledge of machine learning and optimization.

Instructor: Xiao Zhang (xiao.zhang@cispa.de). Office hours: by appointment via email. My office is Room 3.12, C0. 

Teaching Assistants: Minxing Zhang (minxing.zhang@cispa.de) and Yuan Xin (yuan.xin@cispa.de)

Meeting Time: 14:15 - 15:45 on every Thursday, starting 26.10.2023

Meeting Room: Bernd Therre Lecture Hall (0.05), CISPA Main Building (C0), Stuhlsatzenhaus 5

Registration: You need to register for the course on CISPA CMS here. Registration will open on 01.10.2023. To receive the grades, you must also register for the course on LSF for the exam before 01.02.2024.

Piazza: Sign up for the lecture course using the link for online discussions

 

Lecture Plan


We plan to include the following topics in this advanced lecture course. However, the plan may be subject to changes.

2023-10-26:     Overview of Robust Machine Learning
2023-11-02:     Machine Learning & Deep Learning Basics
2023-11-09:     Introduction to Adversarial Examples
2023-11-16:     Empirical Defenses
2023-11-23:     Certification Methods
2023-11-30:     Understanding the Cause of Adversarial Vulnerability
2023-12-07:     Robust Generalization & Semi-Supervised Methods
2023-12-14:     Q&A session led by TAs
2023-12-21:     Robust Mean Estimation
2023-12-28:     No Lecture: Winter Break
2024-01-04:     Introduction to Data Poisoning
2024-01-11:     Indiscriminate Poisoning Attacks & Defenses
2024-01-18:     Model Debugging & Explainability
2024-01-25:     Robustness to Distribution Shifts
2024-02-01:     Robust Machine Learning in NLP

 

Grading


The final grades of this course will consist of the following components:

  • 4 mini homework, containing both theoretical and practical questions (20 pts)
  • 2 paper reviews (20 pts)
  • Course-long project that you can choose to work in a team (60 pts). The project will be graded based on an initial proposal + an oral presentation exam + a final report.
  • Challenging questions for bonus points (TBD)

 

 

Privacy Policy | Legal Notice
If you encounter technical problems, please contact the administrators.