Researcher profile

David Sánchez

David Sánchez contributes to research discovery and scholarly infrastructure.

ResearcherAffiliation not importedOpen to collaborate

Trust snapshot

Quick read

Trust 21 - EmergingVerification L1Unclaimed author
6works
0followers
7topics
4close collaborators

Actions

Decide how to stay connected

Follow researcher0

Identity and collaboration

How to connect with this researcher

Claiming links this public author record to a researcher profile and unlocks direct collaboration workflows.

Log in to claim

Direct collaboration

Open a focused conversation when the fit is right

Claim this author entity first to unlock direct invitations.

Research graph

See the researcher in context

Open full explorer

Inspect adjacent work, topics, institutions and collaborators without jumping out to a separate graph page.

Building this graph slice

BZPEER is loading the nearby papers, people, topics and institutions for this page.

Published work

6 published item(s)

preprint2022arXiv

Defending against the Label-flipping Attack in Federated Learning

Federated learning (FL) provides autonomy and privacy by design to participating peers, who cooperatively build a machine learning (ML) model while keeping their private data in their devices. However, that same autonomy opens the door for malicious peers to poison the model by conducting either untargeted or targeted poisoning attacks. The label-flipping (LF) attack is a targeted poisoning attack where the attackers poison their training data by flipping the labels of some examples from one class (i.e., the source class) to another (i.e., the target class). Unfortunately, this attack is easy to perform and hard to detect and it negatively impacts on the performance of the global model. Existing defenses against LF are limited by assumptions on the distribution of the peers' data and/or do not perform well with high-dimensional models. In this paper, we deeply investigate the LF attack behavior and find that the contradicting objectives of attackers and honest peers on the source class examples are reflected in the parameter gradients corresponding to the neurons of the source and target classes in the output layer, making those gradients good discriminative features for the attack detection. Accordingly, we propose a novel defense that first dynamically extracts those gradients from the peers' local updates, and then clusters the extracted gradients, analyzes the resulting clusters and filters out potential bad updates before model aggregation. Extensive empirical analysis on three data sets shows the proposed defense's effectiveness against the LF attack regardless of the data distribution or model dimensionality. Also, the proposed defense outperforms several state-of-the-art defenses by offering lower test error, higher overall accuracy, higher source class accuracy, lower attack success rate, and higher stability of the source class accuracy.

preprint2022arXiv

The Text Anonymization Benchmark (TAB): A Dedicated Corpus and Evaluation Framework for Text Anonymization

We present a novel benchmark and associated evaluation metrics for assessing the performance of text anonymization methods. Text anonymization, defined as the task of editing a text document to prevent the disclosure of personal information, currently suffers from a shortage of privacy-oriented annotated text resources, making it difficult to properly evaluate the level of privacy protection offered by various anonymization methods. This paper presents TAB (Text Anonymization Benchmark), a new, open-source annotated corpus developed to address this shortage. The corpus comprises 1,268 English-language court cases from the European Court of Human Rights (ECHR) enriched with comprehensive annotations about the personal information appearing in each document, including their semantic category, identifier type, confidential attributes, and co-reference relations. Compared to previous work, the TAB corpus is designed to go beyond traditional de-identification (which is limited to the detection of predefined semantic categories), and explicitly marks which text spans ought to be masked in order to conceal the identity of the person to be protected. Along with presenting the corpus and its annotation layers, we also propose a set of evaluation metrics that are specifically tailored towards measuring the performance of text anonymization, both in terms of privacy protection and utility preservation. We illustrate the use of the benchmark and the proposed metrics by assessing the empirical performance of several baseline text anonymization models. The full corpus along with its privacy-oriented annotation guidelines, evaluation scripts and baseline models are available on: https://github.com/NorskRegnesentral/text-anonymisation-benchmark

preprint2022arXiv

Trivial and topological bound states in bilayer graphene quantum dots and rings

We discuss and compare two different types of confinement in bilayer graphene by top and bottom gating with symmetrical microelectrodes. Trivial confinement corresponds to the same polarity of all top gates, which is opposed to that of all bottom ones. Topological confinement requires the polarity of part of the top-bottom pairs of gates to be reversed. We show that the main qualitative difference between trivial and topological bound states manifests itself in the magnetic field dependence. We illustrate our finding with an explicit calculation of the energy spectrum for quantum dots and rings. Trivial confinement shows bunching of levels into degenerate Landau bands, with a non-centered gap, while topological confinement shows no field-induced gap and a sequence of state branches always crossing zero-energy.

preprint2021arXiv

Geometry effects in topologically confined bilayer graphene loops

We investigate the electronic confinement in bilayer graphene by topological loops of different shapes. These loops are created by lateral gates acting via gap inversion on the two graphene sheets. For large-area loops the spectrum is well described by a quantization rule depending only on the loop perimeter. For small sizes, the spectrum depends on the loop shape. We find that zero-energy states exhibit a characteristic pattern that strongly depends on the spatial symmetry. We show this by considering loops of higher to lower symmetry (circle, square, rectangle and irregular polygon). Interestingly, magnetic field causes valley splittings of the states, an asymmetry between energy reversal states, flux periodicities and the emergence of persistent currents.

preprint2021arXiv

Scattering of topological kink-antikink states in bilayer graphene structures

Gapped bilayer graphene can support the presence of intragap states due to kink gate potentials applied to the graphene layers. Electrons in these states display valley-momentum locking, which makes them attractive for topological valleytronics. Here, we show that kink-antikink local potentials enable modulated scattering of topological currents. We find that the kink-antikink coupling leads to anomalous steps in the junction conductance. Further, when the constriction detaches from the propagating modes, forming a loop, the conductance reveals the system energy spectrum. Remarkably, these kink-antikink devices can also work as valley filters with tiny magnetic fields by tuning a central gate.

preprint2010arXiv

Mesoscopic Coulomb drag, broken detailed balance and fluctuation relations

When a biased conductor is put in proximity with an unbiased conductor a drag current can be induced in the absence of detailed balance. This is known as the Coulomb drag effect. However, even in this situation far away from equilibrium where detailed balance is explicitly broken, theory predicts that fluctuation relations are satisfied. This surprising effect has, to date, not been confirmed experimentally. Here we propose a system consisting of a capacitively coupled double quantum dot where the nonlinear fluctuation relations are verified in the absence of detailed balance.