Talent.com
INRIA
Post-Doctoral Research Visit F/M From AI audits to AI security: an information gain hierarchyINRIA • Rennes, FR
Post-Doctoral Research Visit F/M From AI audits to AI security: an information gain hierarchy

Post-Doctoral Research Visit F/M From AI audits to AI security: an information gain hierarchy

INRIA • Rennes, FR
Il y a plus de 30 jours
Type de contrat
  • Temps plein
Description de poste

Contexte et atouts du poste

AI-based models are now core to a wide range of applications,
including highly critical ones. The stakes are considerable for
companies or institutions deploying them, as their training amounts to
up to a billion dollars (e.g. for the training of ChatGPT). This
clearly calls for defending them against attacks, like
copy/extraction. In parallel, institutions such as state regulators
have to ensure that these models operate according to law, in
particular with regards to possible discrimination [1]. Researchers
are then tasked to provide algorithms to auditors for assessing
important metrics regarding deployed AI-based models. In such
black-box audits, where an auditor has no access to the remotely
operated model's internals, the goal is to stealthily (i.e. with a few
queries only) estimate some metrics, such as fairness [6].
Interestingly, and this has not yet been mentioned in the literature,
this audit setup is very close to offensive information gain, from a
conceptual standpoint. Indeed, potential attackers are incentivized to
try and leak information out of deployed models [4,10]. Motivations
range from economic intelligence, obtaining implementation details, to
simply avoiding development costs by copying deployed models. An
auditor is interested in stealthy model observation [3], to avoid
disrupting the audited model by using too many queries. Identically,
an attacker also desire stealthiness, here to avoid being detected and
cut off. In particular, auditors generally want to obtain precise
property estimation, yet confined to a single feature
(e.g. male/female fairness), while attackers aim at having a global
picture of the model (for basic copy, or evading some parameter
set). Thus, there is an avenue to devise offensive methods in between
stealthy audits and global attacks, to try and leak novel model
characteristics. The ambition of our group is to bridge the gap
between these two critical setups: legal auditing and offensive
security, in the domain of modern deployed AI models. From this unique
standpoint, and from the body of work in the field of AI auditing, we
expect to find new insights for attacking and defending deployed AI
models, by finding novel angles. For instance, we proposed a unified
way to approach model fingerprinting [2] that is of interest for an
auditor to guess which model she is observing on a platform; we
conjecture that leveraging such an approach to measure the evolution
in time of such a model (does the model changes due to updates?) is of
core interest for an attacker, as she can derive what is at play at
the company hosting this model. This could provide ground for the
attacker for economic intelligence, while leaking some precious
information that has to be defended by the attacked company.

Mission confiée

  • Research
  • Working with Ph.D. students from the group

Principales activités

A striking remark when looking at the current types of attacks on AI
models is their quantity and apparent independence (see [10] Fig. 3):
each is treated as a separate domain. In addition to this list of
attacks, we claim that an audit may be viewed as the leak of a feature
from a production model, and must be considered as a potential threat.
In that light, clarifications in the relation between these attacks
might come from a systematic study of how they relate with regards to
the setup they operate in, versus the information gain they permit. We
propose to work on a hierarchy of attacks, that will uncover the
smallest attacks (in terms of assumptions and scope) and how they
might be composed into larger attacks, and so on. This hierarchy will
reveal unexplored configurations, where several simple attacks will be
combined to build richer attacks. This hierarchy will provide the
missing link between audits and AI security, bridging the two in a
formal way. The postdoc candidate will leverage algorithmic
background, to devise a hierarchy, in a parallel to the Herlihy
hierarchy in algorithms. We intend to use the notion of
"distinguishability" [14] as a hierarchy backbone (to assess if an
attack leaks data permitting strong or weak distinguishability of
models). In particular, the field of "property testing" will be
related to this hierarchy.

# References

[1] Le Merrer, E., Pons, R., & Tredan, G. . Algorithmic audits of algorithms, and the law. AI and Ethics, 4,
1365-1375.
[2] Godinot, A., Le Merrer, E., Penzo, C., Taïani, F., & Tredan, G. . Queries, Representation & Detection: The
Next 100 Model Fingerprinting Schemes. In AAAI.
[3] Le Merrer, E., & Tredan, G. Remote explainability faces the bouncer problem. Nature machine intelligence,
2, 529-539.
[4] Maho, T., Furon, T., & Le Merrer, E. . Surfree: a fast surrogate-free black-box attack. In CVPR.
[5] Godinot, A., Le Merrer, E., Tredan, G., Penzo, C., & Taïani, F. . Under manipulations, are some AI models
harder to audit?. In IEEE Conference on Secure and Trustworthy Machine Learning.
[6] de Vos, M., Dhasade, A., Garcia Bourrée, J., Kermarrec, A. M., Le Merrer, E., Rottembourg, B., & Tredan, G. .
Fairness auditing with multi-agent collaboration. In ECAI.
[7] Le Merrer, E., Perez, P., & Tredan, G. . Adversarial frontier stitching for remote neural network
watermarking. Neural Computing and Applications, 32, 9233-9244.
[8] Le Merrer, E., Morgan, B., & Tredan, G. . Setting the record straighter on shadow banning. In INFOCOM.
[9] Maho, T., Furon, T., & Le Merrer, E. . Randomized smoothing under attack: How good is it in practice?. In
ICASSP.
[10]Ma et al., « Safety at Scale: A Comprehensive Survey of Large Model Safety». arXiv:2502.05206v3
[11]Yan, T., & Zhang, C. . Active fairness auditing. In ICML.
[12]Apruzzese, G., Anderson, H. S., Dambra, S., Freeman, D., Pierazzi, F., & Roundy, K. . “Real attackers don't
compute gradients”: bridging the gap between adversarial ml research and practice. In 2023 IEEE conference on
secure and trustworthy machine learning.
[13]Fukuchi, K., Hara, S., & Maehara, T. . Faking fairness via stealthily biased sampling. In AAAI.
[14]Attiya, H., & Rajsbaum, S. . Indistinguishability. Communications of the ACM, 63, 90-99.
[15]ANSSI . Security recommandations for a generative AI system. ANSSI-PA-102.

Compétences

  • Advanced machine learning background, and theory of machine learning
  • Python coding skills for experiments (if required)
  • A good publication track record is mandatory
  • Fluency in English is mandatory

Avantages

  • Subsidized meals
  • Partial reimbursement of public transport costs
  • Leave: 7 weeks of annual leave + 10 extra days off due to RTT (statutory reduction in working hours) + possibility of exceptional leave (sick children, moving home, etc.)
  • Possibility of teleworking (after 6 months of employment) and flexible organization of working hours
  • Professional equipment available (videoconferencing, loan of computer equipment, etc.)
  • Social, cultural and sports events and activities
  • Access to vocational training
  • Social security coverage

Rémunération

Monthly gross salary amounting to 2788 euros

Créer une alerte emploi pour cette recherche

Post-Doctoral Research Visit F/M From AI audits to AI security: an information gain hierarchy • Rennes, FR

Offres similaires

French Content Moderator in Porto, Portugal (Relocation Provided)

NordicrecruitersRennes, France
Temps plein
Quick Apply

Europes most charming, historic, and scenic coastal cities? Join our international team in.French-speaking Content Moderators.You will apply platform policies, take action on flagged posts, and hel... Voir plus

Ai Governance & Data Trust Lead

KeyrusBetton, France, FR
Temps plein

Data Trust & AI Governance Manager Le Data Trust & AI Governance Manager garantit la conformité, la fiabilité et la traçabilité des systèmes d'intelligence artificielle déployés chez no... Voir plus

 • Offre sponsorisée

Engineering Manager - Cross-Platform C++ (Remote) - Remote

CanonicalSaint-Jacques-De-La-Lande, France, FR
Temps plein

Canonical is seeking an Engineering Manager for Sustaining Engineering in Rennes, France.You will manage a distributed team, ensure team growth, and deliver high-quality solutions.The role offers a... Voir plus

 • Offre sponsorisée

Prof particulier de Chimie à Rennes pour étudiant

SuperProfRennes, FR
Temps partiel

Il met en relation ceux qui désirent apprendre et ceux qui souhaitent enseigner.Les professeurs peuvent choisir entre plus de.Gratuit, libre et sans aucun intermédiaire, Superprof vous propose de d... Voir plus

 • Offre sponsorisée

Active Directory & Iam Engineer - Cloud & Security - €38.000 - €55.000 Par An

METSYSRennes, France, FR
Temps plein

Recherche d'un ingénieur IAM à Rennes, avec compétences en Active Directory et scripting, et un bon niveau d'anglais. Voir plus

 • Offre sponsorisée

Architecte Cybersécurité (H/F)

AirbusRennes, France, FR
Temps plein

Job Description:Qui sommes-nous ? Airbus Defence and Space « Cyber Programmes » est un spécialiste européen de la cybersécurité pour les systèmes de défense et aérospatiaux.Notre mission est de con... Voir plus

 • Offre sponsorisée

Data Scientist H/F – Alternance Rennes - €486,5 - €1.801,8 Par Mois - Sans Expérience

CFA Sup de VinciRennes, France, FR

Le rôle principal est d'analyser les données, de créer des modèles prédictifs et d'améliorer les processus décisionnels.L'étudiant participera à l'évolution des outils. Voir plus

 • Offre sponsorisée

Médecin Praticien En Had - €7.900 Par Mois - Temps Partiel

Had 35Rennes, France, FR
Temps partiel

Le médecin praticien évalue les patients, coordonne les soins, participe aux astreintes et forme les équipes.Il assure la qualité des soins à domicile. Voir plus

 • Offre sponsorisée

Data Analyst Senior – Power Bi (H/F) - €40.000 - €50.000 Par An

CeladRennes, France, FR
Temps plein

Le Data Analyst Senior sera responsable de piloter la feuille de route Power BI, d'implémenter le socle BI, et d'accompagner les équipes dans l'adoption de l'outil. Voir plus

 • Offre sponsorisée

Work in Portugal: Video Content Analyst (Accomodation Support Available)!

Cross Border TalentsRennes, France
Temps plein
Quick Apply

Video Content Moderator (French) | Lisbon, Portugal.French (C1+) & English (B1+).Join a global social media project as a.You will review user-generated content to ensure it complies with commun... Voir plus

Technicien Métrologie H/F

3SP Technologies S.A.S.Nozay, France, FR
Temps plein

Filiale française du groupe O-Net Technologies (Group) Limited, 3SP Technologies est une PME en pleine croissance, qui conçoit et fabrique des puces et des modules optoélectroniques pour les réseau... Voir plus

 • Offre sponsorisée

Expert Data Gouvernance - Mdm (F/H) - €45.000 - €55.000 Par An

AsiRennes, France, FR
Temps plein

Description de l'entrepriseCabinet d'expertises numériques français, ASI compte 500 collaborateurs aux expertises complémentaires (Développement, Pilotage, Change, Architecture, Data, Proce... Voir plus

 • Offre sponsorisée

Data Analyst H/F – Alternance Rennes - €492,2 - €1.823,0 Par Mois - Sans Expérience

CFA Sup de VinciRennes, France, FR

Vous souhaitez vous former au métier de Data Analyst ?Cette alternance vous permettra de développer vos compétences en gestion d’équipe, coordination de projets et optimisation de la performance au... Voir plus

 • Offre sponsorisée

Stage Bd — Proptech & Projets Urbains (Rennes) - Sans Expérience

EdTechFranceBetton, France, FR
CDI

Stage Rémunéré Fin d'Études Business Developer (H/F) – 6 mois RennesHive, studio 3D spécialisé en rendus photoréalistes pour la promotion immobilière, recrute un(e) stagiaire en fin d'étude... Voir plus

 • Offre sponsorisée

Responsable Fonctionnel Projet Systèmes D’information

Armée de l’air et de l’espaceRennes, France, FR
Temps plein

Être militaire, c’est servir l’État, au sein des armées, en portant l’uniforme.Cela implique discipline, disponibilité et loyauté.Le sens de l’adaptation et le goût de l’effort sont des qualités in... Voir plus

 • Offre sponsorisée

Tech Business Developer – On The Ground & Remote - €55.000 - €58.000 Par An - Sans Expérience

EdTechFranceRennes, France, FR
Temps plein

Le Business Developer recherché à Rennes doit développer des relations et soutenir la croissance des start-ups, avec un salaire entre 55 000€ et 58 000€. Voir plus

 • Offre sponsorisée

Mid Market Customer Success Manager — Remote Options - €39.000 - €46.000 Par An

Entreprise De Technologie ÉducativeRennes, France, FR
Temps plein

Gestion et optimisation de l'expérience client pour une entreprise technologique, incluant l'onboarding et l'analyse d'usage.Relations clients et satisfaction sont au cœur du poste. Voir plus

 • Offre sponsorisée

Prof particulier de Physique - Chimie à Rennes pour étudiant

SuperProfRennes, FR
Temps partiel

Il met en relation ceux qui désirent apprendre et ceux qui souhaitent enseigner.Les professeurs peuvent choisir entre plus de.Gratuit, libre et sans aucun intermédiaire, Superprof vous propose de d... Voir plus

 • Offre sponsorisée

Job étudiant 2026 - Professeur particulier sans expérience - Télétravail possible - 12 à 28€/h

VoscoursSaint-Aubin-d'Aubigné, France
Télétravail
Temps plein

Vous êtes à la recherche d'un job étudiant ? Devenez professeur avec Voscours.Partagez vos connaissances avec nos élèves : soutien scolaire, musique, sports, langues, technologie.Nous recherchons d... Voir plus

 • Offre sponsorisée

Tech Lead Fullstack C.Net - F/H - €40.000 - €50.000 Par An

CoexyaRennes, France, FR
Temps plein

Net sera responsable de la conception et du développement de solutions web, de l'encadrement de l'équipe et de l'intégration des dernières technologies. Voir plus