Scanning of museum specimens has taken off. Using 3-D computed tomography (CT), specimens are scanned and, along with underlying digital data, are stored in online repositories, such as Digimorph, MorphoSource, iDigBio, and others. The material is made publicly available. But a host of legal questions have emerged, including ownership of scans, data, and the ability (or lack thereof) to copyright them. Do the people in possession of the specimen own it, and do they have permission to distribute the specimen for scanning? Who claims the rights to the digital data? Does a contract between the owning institution and the source of the specimen affect its digital reproduction and distribution? Tim White, director of collections and research, Yale Peabody Museum of Natural History, notes: ââŠresearchers will borrow something and then realize [they] want to have these specimens scannedâŠoften at a third-party institution and the museum may only find out after the fact.â Does Yale own the specimen or is it on loan? Is there shared ownership by a written agreement? Who scanned the specimenâthe borrowing institution or another organization that owns scanning equipment? According to David Bloom of VertNet, a National Science Foundation funded project, the loaning institution owns or manages the specimen, although the scan belongs to the borrower. Intellectual property attorney and former museum curator Amanda Nelson warns that it is not so simple. In the Yale example, much depends on the paperwork between the loaner and borrower. To avoid misunderstandings, Dirk Neumann of the Bavarian Natural History Collection, suggests the owner add âa specific section on the loan form that the borrower cannot get copyright ownership in his imaging but may use the images for his research purpose, so that there is a written proof of the borrower that he is author of the images but waives his copyright.â Doug Boyer, of Duke University and founder of the MorphoSource 3-D data and imagery repository, explains that museums have release forms that state what can be done with the specimen and may include a third-party clause that limits rights to distribute the data. In the United States, unlike in most European countries, medical scans cannot be copyrighted, as the copyright office does not judge them to have creative input. But Boyer suggests organizations assert copyright for their 3-D scans, many of which are derivative, posted in online repositories. Prepping and scanning a specimen for research involves value judgments and creativity to emphasize certain parts of its anatomy. Boyer thinks copyright should be applicable to research scans: âThere's no question that at least the derivative images are copyrightable.â As attorney Nelson notes, âThe bar for creativity has been set so low, sometimes just merely changing [or adding] colorsâŠis a creative choice.â Patent attorney Sarita Pickett, of Mesmer & Deleault, explains that technology has changed so quickly âthe laws have not always had time to catch upâŠ.â Copyright âclerks are unlikely to have the experience necessary to recognize when additional design elements are involved in activities that were previously entirely technological,â says Pickett. Part of the problem is how scientists describe their scans. Scientists put creative thought into designing and coloring a scan, âbut when they describe what they did, they donât use creative terms, leaning too heavily on the functionality aspect [showing frog bones]âas might be appreciated by another scientist.â To Boyer's knowledge, no scientists have registered copyright of their CT scans, but the MorphoSource group encourages researchers to assert copyright and ownership of their scans. The copyright issue will likely be determined in the courts, he added. A network of US-based museums and working groups is devising best practices and guidelines for archiving and sharing 3D data, and Boyer is optimistic that this will help museums share their collections globally. Data, too, are an issue. Nelson says, generally âdata canât be copyrighted.â Identifying tags on a specimen âcannot be copyrighted because that's information; that's fact.â The basis for this policy is that sharing the data is âfor the benefit of society [as] a wholeâ for research and study. Some institutions want to maintain the open availability of data, although others want to limit what can be done with the data. The Creative Commons licensing mechanism can leave data or scans open to all, limit use, or claim copyright worldwide. Most data put online are for noncommercial use. But, warns Nelson Rios of Yale Peabody, âThere's absolutely zero enforcement behind any of thatâŠit's too complicated to pursue; also it's too expensive.â No matter what, Amanda Nelson points to the value of paperwork: âAt the end of the day, it's who signed what and what does it say.â Myrna E. Watanabe (mewatanabeconsulting@gmail.com) is a science and grant writer in Patterson, New York.
We consider zero-knowledge proofs, a class of cryptographic protocols by which an agent (a Prover) can prove to another agent (a Verifier) that a statement is true without revealing any additional information. For example, a zero-knowledge proof allows one to prove knowledge of a password to somebody at the other end of the communication without actually revealing the password. \nWe present an introduction to and survey literature on zero-knowledge proofs, covering the history, formal definition, and classical applications of zero-knowledge proofs. In addition, we consider connections to complexity, demonstrating that all problems in the complexity class NP have zero-knowledge proofs, and also discuss more exotic applications of zero-knowledge, namely in electronic voting and nuclear disarmament. \nWe then consider applications of zero-knowledge to financial regulation, specifically in balancing transparency and confidentiality in financial reporting. Namely, we polled professionals in the financial industry to identify three major classes of regulatory problems. We then utilize zero-knowledge proofs to develop and present cryptographic protocols/mechanisms and solutions to these regulatory problems: (1) An employer verifying an employee has no financial holdings on a blacklist without revealing the other (allowed) holdings of the employee, (2) A fund convincing its investors that its holdings subscribe to particular risk constraints, without disclosing the actual holdings, (3) A collection of investors of a fund verifying aggregate information provided by the fund, while preserving pairwise anonymity. Applications (1) and (3) are novel applications developed in this paper, while (2) is drawn from [47].
Fadhel Ayed, Marco Battiston, Federico Camerlenghi, Stefano Favaro
Given $n$ samples from a population of individuals belonging to different types with unknown proportions, how do we estimate the probability of discovering a new type at the $(n+1)$-th draw? This is a classical problem in statistics, commonly referred to as the missing mass estimation problem. Recent results by Ohannessian and Dahleh \citet{Oha12} and Mossel and Ohannessian \citet{Mos15} showed: i) the impossibility of estimating (learning) the missing mass without imposing further structural assumptions on the type proportions; ii) the consistency of the Good-Turing estimator for the missing mass under the assumption that the tail of the type proportions decays to zero as a regularly varying function with parameter $α\in(0,1)$. In this paper we rely on tools from Bayesian nonparametrics to provide an alternative, and simpler, proof of the impossibility of a distribution-free estimation of the missing mass. Up to our knowledge, the use of Bayesian ideas to study large sample asymptotics for the missing mass is new, and it could be of independent interest. Still relying on Bayesian nonparametric tools, we then show that under regularly varying type proportions the convergence rate of the Good-Turing estimator is the best rate that any estimator can achieve, up to a slowly varying function, and that minimax rate must be at least $n^{-α/2}$. We conclude with a discussion of our results, and by conjecturing that the Good-Turing estimator is an rate optimal minimax estimator under regularly varying type proportions.
We propose definitions and implementations of "S-money" - virtual tokens designed for high value fast transactions on networks with relativistic or other trusted signalling constraints, defined by inputs that in general are made at many network points, some or all of which may be space-like separated. We argue that one significant way of characterising types of money in space-time is via the "summoning" tasks they can solve: that is, how flexibly the money can be propagated to a desired space-time point in response to relevant information received at various space-time points. We show that S-money is more flexible than standard quantum or classical money in the sense that it can solve deterministic summoning tasks that they cannot. It requires the issuer and user to have networks of agents with classical data storage and communication, but no long term quantum state storage, and is feasible with current technology. User privacy can be incorporated by secure bit commitment and zero knowledge proof protocols. The level of privacy feasible in given scenarios depends on efficiency and composable security questions that remain to be systematically addressed.
Proposed cryptographic protocol with zero-knowledge proof on elliptic curves using one-way hash function, allowing to establish the truth of allegation and does not convey any additional information about the approval. Cryptographic protocols based on zero-knowledge proof allow identification, key exchange and other cryptographic operations to be performed without leakage of sensitive information during the information exchange. The implementation of the cryptographic protocol of the zero-knowledge proof on the basis of the mathematical apparatus of elliptic curves allows to significantly reduce the size of the protocol parameters and increase the cryptographic stability (computational complexity of the hacking problem). The security of cryptosystems on elliptic curves is based on the difficulty of solving the elliptic curve discrete logarithm problem. The completeness and correctness of the protocol is determined in the work, an example of calculation is given, the cryptographic protocol is modeled on the High-Level Protocol Specification Language, the model validation and verification of the protocol are performed. Software verification of the cryptographic protocol was performed using the software modules On the Fly Model Checker and Constraint Logic based Attack Searcher. To validation the cryptographic protocol for resistance to intruder attacks was used the Security Protocol Animator package for Automated Validation of Internet Security Protocols and Applications. The security of the proposed cryptographic protocol is based on the difficulty of solving the elliptic curve discrete logarithm problem and the cryptographic stability of the hash function. To implement the cryptographic protocol, you can use the recommended elliptical curves according to DSTU 4145-2000 and the hash function GOST 34.311-95.
We propose building a new PKC in a ring structure, the classification of rings being an open problem. The difficulty of the scheme is based on retrieving the eigenvalues of endomorphism on a finite type module over a non-commutative ring. It is resistant to a chosen cipher text attack. Working in the fraction ring of a non-commutative ring makes our scheme a zero-knowledge proof of knowledge, result indistinguishable, in the Naor-Yung model. Finally, a dramatic improvement in security is obtained through the drawing with uniform probability of the working ring at high frequency.
The prevalence of IoT devices makes them an ideal target for attackers. To\nreduce the risk of attacks vendors routinely deliver security updates (patches)\nfor their devices. The delivery of security updates becomes challenging due to\nthe issue of scalability as the number of devices may grow much quicker than\nvendors' distribution systems. Previous studies have suggested a permissionless\nand decentralized blockchain-based network in which nodes can host and deliver\nsecurity updates, thus the addition of new nodes scales out the network.\nHowever, these studies do not provide an incentive for nodes to join the\nnetwork, making it unlikely for nodes to freely contribute their hosting space,\nbandwidth, and computation resources. In this paper, we propose a novel\ndecentralized IoT software update delivery network in which participating nodes\nreferred to as distributors) are compensated by vendors with digital currency\nfor delivering updates to devices. Upon the release of a new security update, a\nvendor will make a commitment to provide digital currency to distributors that\ndeliver the update; the commitment will be made with the use of smart\ncontracts, and hence will be public, binding, and irreversible. The smart\ncontract promises compensation to any distributor that provides\nproof-of-distribution, which is unforgeable proof that a single update was\ndelivered to a single device. A distributor acquires the proof-of-distribution\nby exchanging a security update for a device signature using the Zero-Knowledge\nContingent Payment (ZKCP) trustless data exchange protocol. Eliminating the\nneed for trust between the security update distributor and the security\nconsumer (IoT device) by providing fair compensation, can significantly\nincrease the number of distributors, thus facilitating rapid scale out.\n
Fergus Dall, Gabrielle De Micheli, Thomas Eisenbarth, Daniel Genkin · 7 authors
Intel Software Guard Extensions (SGX) allows users to perform secure computation on platforms that run untrusted software. To validate that the computation is correctly initialized and that it executes on trusted hardware, SGX supports attestation providers that can vouch for the userâs computation. Communication with these attestation providers is based on the Extended Privacy ID (EPID) protocol, which not only validates the computation but is also designed to maintain the userâs privacy. In particular, EPID is designed to ensure that the attestation provider is unable to identify the host on which the computation executes. In this work we investigate the security of the Intel implementation of the EPID protocol. We identify an implementation weakness that leaks information via a cache side channel. We show that a malicious attestation provider can use the leaked information to break the unlinkability guarantees of EPID. We analyze the leaked information using a lattice-based approach for solving the hidden number problem, which we adapt to the zero-knowledge proof in the EPID scheme, extending prior attacks on signature schemes.
Edgar GonzĂĄlez FernĂĄndez, Guillermo Morales-Luna, FeliĂș Sagols Troncoso
Zero-Knowledge Proofs ZKP provide a reliable option to verify that a claim is true without giving detailed information other than the answer. A classical example is provided by the ZKP based in the Graph Isomorphism problem (GI), where a prover must convince the verifier that he knows an isomorphism between two isomorphic graphs without publishing the bijection. We design a novel ZKP exploiting the NP-hard problem of finding the algebraic ideal of a multivariate polynomial set, and consequently resistant to quantum computer attacks. Since this polynomial set is obtained considering instances of GI, we guarantee that the protocol is at least as secure as the GI based protocol.
The Internet of Things (IoT) network of connected devices currently contains more than 11 billion devices and is estimated to double in size within the next four years. The prevalence of these devices makes them an ideal target for attackers. To reduce the risk of attacks vendors routinely deliver security updates (patches) for their devices. The delivery of security updates becomes challenging due to the issue of scalability as the number of devices may grow much quicker than vendors' distribution systems. Previous studies have suggested a permissionless and decentralized blockchainbased network in which nodes can host and deliver security updates, thus the addition of new nodes scales out the network. However, these studies do not provide an incentive for nodes to join the network, making it unlikely for nodes to freely contribute their hosting space, bandwidth, and computation resources. In this paper, we propose a novel decentralized IoT software update delivery network in which participating nodes (referred to as distributors) are compensated by vendors with digital currency for delivering updates to devices. Upon the release of a new security update, a vendor will make a commitment to provide digital currency to distributors that deliver the update; the commitment will be made with the use of smart contracts, and hence will be public, binding, and irreversible. The smart contract promises compensation to any distributor that provides proof-of-distribution, which is unforgeable proof that a single update was delivered to a single device. A distributor acquires the proof-of-distribution by exchanging a security update for a device signature using the Zero-Knowledge Contingent Payment (ZKCP) trustless data exchange protocol. Eliminating the need for trust between the security update distributor and the security consumer (IoT device) by providing fair compensation, can significantly increase the number of distributors, thus facilitating rapid scale out.
Authentication over insecure public networks or with untrusted servers raises more concerns in privacy and security.Modern algebra is one of the significantfields of mathematics. It is a combination of techniques used for a variety of applications including the process of the manipulation of the mathematical categories. In addition,modern algebra deals in depth with the study of abstractions such as groups, rings and fields,the main objective of this article is to provide a novel algebraic verification protocol using ring theory. The protocol is blind, meaning that it detects only the identity, and no additional information will be known anything about the prover (the biometric) to the authenticating server or vice-versa. More officially a blind authentication scheme is a cryptographic protocol that comprises of two parties, a user (the prover) that wants to achieve having signs on her messages, and a signer (the verifier) that is in ownership of his secret signing key. In this paper, we employ the algebraic structure called central Armendariz rings to design a neoteric algorithm for zero knowledge proof. The proposed protocol is established and illustrated through numerical example, and its soundness and completeness are proved.This method gave two important properties for the central Armendariz zero knowledge protocol compared with other known protocols.
Peng Jiang, Fuchun Guo, Willy Susilo, Man Ho Au · 6 authors
A procurement protocol is a protocol for a buyer to purchase digital goods at their prices from a vendor. A procurement protocol with privacy preservation can be achieved by priced oblivious transfer (POT). POT allows the buyer to obliviously procure items one by one. An adaptive POT protocol only consumes O(1) communication cost in each transaction, where all items are committed and encrypted before transactions. However, we found that the state-of-the-art adaptive POT protocol proposed by Rial et al. is less practical and does not meet real-world needs. It has to restrict to the one-buyer setting where all items are encrypted associated with one buyer's public key. For multiple buyers, the vendor must respectively encrypt all the same items for each buyer. Besides, it has to employ computationally expensive primitives such as zero-knowledge proof which imply inefficient computation operations. It is therefore unscalable and unsuitable in large-scale applications. In this paper, we propose an efficient adaptive priced oblivious transfer protocol to address the aforementioned problems. The proposed adaptive POT is built on top of a new cryptographic primitive, namely, adaptive set membership encryption (ASME). In our proposed protocol, all items are encrypted without the use of buyers' public keys and hence they can be used for universal buyers. Our protocol significantly reduces the transaction cost compared to existing schemes. For example, the communication in each transaction costs only 6 group elements compared to at least 141 group elements in Rial et al.'s protocol. The implementation shows that our protocol is efficient in terms of bandwidth and computational cost.
Alessandro Chiesa, Michael A. Forbes, Tom Gur, Nicholas Spooner
Zero knowledge plays a central role in cryptography and complexity. The seminal work of Ben-Or et al. (STOC 1988) shows that zero knowledge can be achieved unconditionally for any language in NEXP , as long as one is willing to make a suitable physical assumption : if the provers are spatially isolated, then they can be assumed to be playing independent strategies. Quantum mechanics, however, tells us that this assumption is unrealistic, because spatially-isolated provers could share a quantum entangled state and realize a non-local correlated strategy. The MIP * model captures this setting. In this work, we study the following question: Does spatial isolation still suffice to unconditionally achieve zero knowledge even in the presence of quantum entanglement? We answer this question in the affirmative: we prove that every language in NEXP has a 2-prover zero knowledge interactive proof that is sound against entangled provers; that is, NEXP â ZK-MIP * . Our proof consists of constructing a zero knowledge interactive probabilistically checkable proof with a strong algebraic structure, and then lifting it to the MIP * model. This lifting relies on a new framework that builds on recent advances in low-degree testing against entangled strategies, and clearly separates classical and quantum tools. Our main technical contribution is the development of new algebraic techniques for obtaining unconditional zero knowledge; this includes a zero knowledge variant of the celebrated sumcheck protocol, a key building block in many probabilistic proof systems. A core component of our sumcheck protocol is a new algebraic commitment scheme, whose analysis relies on algebraic complexity theory.
Although the problems identified in the statement have been known for several decades, previous expressions of concern and calls for action have not fostered broad improvements in practice.2 A P value of 0.05 carries a 5% risk of a false positive result (i.e. there is no true difference between treatments). If a trial is meant to provide proof of a genuine treatment difference beyond reasonable doubt, a much smaller P value â say p < 0. 001 â is required.5 We disagree âŠ.that our statement⊠is erroneous. According to the null hypothesis, P < 0.05 will occur 5% of the time.6 No editorial corrigendum has appeared. A P-value is the area under the curve of a probability distribution defined by a mathematical model. The model, usually presented graphically, describes the expected distribution of a sample statistic around a central measure, the parameter or theoretical âtrueâ value, for example the population mean, ÎŒ. Under the central limit theorem, this would be the standard normal distribution of sample means generated by repeat sampling of a population variable of interest. The mean of the sample means would equal the âtrueâ population mean, ÎŒ. In medicine, it is rare for us ever to know the true value of the variable of interest. However, we can usefully assign a value in the special case of a difference statistic, for example the difference in mean outcome variables in a placebo-controlled drug trial. In this case, the sampling distribution would represent that of the difference statistic. In this case, if the value we assign ÎŒ is zero then the mathematical model becomes the null hypothesis used in NHST. By way of contrast, non-inferiority drug trials require a non-zero value to be assigned. The cumulative AUC of the sampling distribution of a continuous variable is represented by a mathematical function called the cumulative density function. In medical science, most study variables are continuous or, if categorical, are transformed using the logit model. As the P-value is a mathematical integral, that is the cumulative AUC, it cannot take on a precise value as there is no AUC defined by a single point on the curve, for example the P-value †0.05, but not P = 0.05. While this may seem pedantic, the semantics of statistical inference are influential in thinking and decision-making yet misinterpretation and misuse of terminology are commonplace. Under the null hypothesis, one sample mean that happens to fall within an extreme region of the standard normal distribution may be expected to occur with a low frequency, say P †0.05 meaning such a sample mean or one more extreme would be expected to occur with a frequency of 5% or less. To be valid, the assumptions of independence and random selection of each sample mean selected from the normal distribution of sample means must be assumed. Another way of stating this is as a conditional probability: . Note: | means âgivenâ. It is important to understand that the P-value is a measure conditional on the assumption that the mathematical model describes the distribution of sample means and is not a measure of the probability of the âtruthâ of the mathematical model. To make this claim would invert the conditional probability statement and commit an error of reasoning called transposing the conditional7 aka the prosecutor's fallacy: . In reasoning from NHST, the commonly used definition of the P-value as âa measure of evidence against the null hypothesisâ is potentially misleading in that it seems to legitimise transposing the conditional as if it were a mathematically valid function rather than a matter of intuition. It was the intuitive interpretation that Fisher used in his a posteriori model of NHST.8, 9 His aim was to use the P-value as an aid in deciding which experiments to repeat. If on several repetitions, a consistent extreme P-value for the sample statistic was obtained then that would accumulate evidence for a true experimental effect. If no such effect was present, regression to the mean parameter (ÎŒ) would be expected (P â„ 0.05). In real-life scenarios, many factors inhibit repetition and replication of experiments; however, modelling can give us insight into the precision and reproducibility of extreme P-values10, 11 and hence the intuitive weight we place on the P-value âas a measure of evidence against the null hypothesisâ. Table 2 is a reproduction.10 It describes the results of simulating repeat experimentation and the probability of producing a P-value †0.05 under the prescribed conditions of the simulated experiment. It may be surprising to many how poorly reproducible the P-value is as a bright line test (a bright line test is a clearly defined rule or standard, the purpose of which is to produce consistent and predictable results). For example, if in the first experiment P †0.05 was produced there would be a 50% probability of reproducing P †0.05 in a repeat experiment; if P †0.01was produced in the first experiment the probability of producing P †0.05 in a repeat experiment, would be 73%; and if P †0.001 was produced in the first experiment the probability of P †0.05 in a repeat experiment would be 91%. The magnitudes of a number of these first experiment P-values are those commonly used in pharmaceutical trials and other medical analyses. The P-value is also sensitive to sample size. Irrespective of the effect size, with increasing sample size (n) the P-value can be made as small as you wish12 because the standard error is proportional to the inverse of n. If statistical significance is substituted for âclinical significanceâ even small irrelevant differences may be regarded as worthy of investment. Large sample sizes are often a feature of pharmaceutical trials of secondary and primary prevention interventions such as preventive therapies in atherosclerotic diseases and osteoporosis. The quoted extract from the article on clinical trials mistakenly promotes the P-value as a measure of error and further states that the error rate can legitimately be adjusted depending on the magnitude of the P-value thus providing âproof of a genuine treatment difference beyond reasonable doubtâ. This erroneous interpretation has arisen from the illusion of coherence resulting from the conflation of the dominant models of hypothesis testing.8, 9 The setting of theoretical type 1 (α) and type 2 (ÎČ) error rates in the Neyman and Pearson model envisions the frequency of error âin the long run of experienceâ (experimental repetition) given randomness and independence of sample means from two juxtaposed probability distributions. A priori two identical populations are imagined except that they differ in mean parameters, null ÎŒ0 and alternative ÎŒA. This model is valuable in providing a rationality to sample size selection. However, the conflation has resulted in confusion between Fisher's P-value and Neyman's α giving the P-value an apparent legitimacy as an a posteriori âslidingâ type 1 error rate. Even if this were logical, decreasing α would increase ÎČ, resulting in a decrease in power (1-ÎČ). Also the dichotomous approach of pitting null hypothesis against alternative hypothesis carries the risk of blinding the researcher or the consumer to other explanatory hypotheses. For those who think the use of confidence intervals (CI) overcomes the problems described, think again. Although it has greater intuitive value especially with respect to estimating effect size, the CI relies on the same premises as the P-value. For example the CI of juxtaposed probability distributions can be made as large or as small as can be paid for by increasing the sample size such that for any small difference the CI can be made not to overlap. Statistical analyses are very valuable tools for extracting information from data. However, the reliability of the knowledge generated is dependent on many more important factors inter alia, evidential justification of the experimental hypothesis, study design, study conduct and data collection and cleansing, competence in choice of statistical model, valid reasoning, reviewer bias, publication bias and replication. Much of the criticism of medical science centres on its overemphasis on the importance of the P-value, NHST and statistically defined effect sizes. A better understanding of how sound statistical inferences are made and how they influence decision making will be key elements to improving all aspects of healthcare. This is critically important in acknowledgement of individuals as complex adaptive systems with characteristics of emergence, adaptability, non-linearity and unpredictability13 rather than as static population averages. Surveys suggest statistical literacy amongst doctors is low.14, 15 Teaching and assessing knowledge and application of statistical inference, critical appraisal and decision-making skills should be a primary focus of medical schools and specialist colleges. Difficult concepts underpinning statistical inference may be more effectively and efficiently taught using computer simulation whereby the learner can manipulate effect sizes, sample sizes and other statistics in order to see how parameter estimates, P-values and CI change with reproduction and replication.16 This will foster a more in-depth understanding of the limits of statistical inference, making clinicians better able to choose wisely amongst the myriad of investigations and treatment options on offer. Subsequent to article submission and review the author attended the referenced ASA conference.2 A special issue of the ASA journal reporting the conference proceedings is planned for 2018. In the opening addresses, the 400 participants were encouraged to devote their energies to developing proposals and goals to address the long standing yet stubbornly persistent errors in statistical inference described in this article. While concrete proposals are yet to be endorsed by the ASA, many speakers emphasised the need to place greater emphasis on teaching the conceptual framework of the different philosophical approaches to science (mastering the concepts as a priority rather than the mechanics of statistical inference). The need for better understanding of statistical semantics on the part of non-statistician scientists was also highlighted. Further that the best way to achieve understanding would be to develop context-specific learning modules. An aspect of the conference that resonated with the author with respect to prediction in medical science was the idea that science defines degrees of uncertainty (not certainty) apropos caution must be applied to the use of prediction models in medical practice lest they be over-extended.
Jayakrishnan Unnikrishnan, Saeid Haghighatshoar, Martin Vetterli
We study the problem of solving a linear sensing system when the observations are unlabeled. Specifically we seek a solution to a linear system of equations y = Ax when the order of the observations in the vector y is unknown. Focusing on the setting in which A is a random matrix with i.i.d. entries, we show that if the sensing matrix A admits an oversampling ratio of 2 or higher, then, with probability 1, it is possible to recover x exactly without the knowledge of the order of the observations in y. Furthermore, if x is of dimension K, then any 2K entries of y are sufficient to recover x. This result implies the existence of deterministic unlabeled sensing matrices with an oversampling factor of 2 that admit perfect reconstruction. The result is universal in that conditioned on the realization of matrix A, recovery is guaranteed for all possible choices of x. While the proof is constructive, it uses a combinatorial algorithm which is not practical, leaving the question of complexity open. We also analyze a noisy version of the problem and show that local stability is guaranteed by the solution. In particular, for every x, the recovery error tends to zero as the signal-to-noise ratio tends to infinity. The question of universal stability is unclear. In addition, we obtain a converse of the result in the noiseless case: If the number of observations in y is less than 2K, then with probability 1, universal recovery fails, i.e., with probability 1, there exist distinct choices of x which lead to the same unordered list of observations in y. We also present extensions of the result of the noiseless case to special cases with non-i.i.d. entries in A, and to a different setting in which the labels of a portion of the observations y are known. In terms of applications, the unlabeled sensing problem is related to data association problems encountered in different domains including robotics where it is appears in a method called âsimultaneous localization and mappingâ, multi-target tracking applications, and in sampling signals in the presence of jitter.
Open access
Sparse and Compressive Sensing Techniques
Distributed Sensor Networks and Detection Algorithms
Abstract A functional credential allows a user to anonymously prove possession of a set of attributes that fulfills a certain policy. The policies are arbitrary polynomially computable predicates that are evaluated over arbitrary attributes. The key feature of this primitive is the delegation of verification to third parties, called designated verifiers. The delegation protects the privacy of the policy : A designated verifier can verify that a user satisfies a certain policy without learning anything about the policy itself. We illustrate the usefulness of this property in different applications, including outsourced databases with access control. We present a new framework to construct functional credentials that does not require (non-interactive) zero-knowledge proofs. This is important in settings where the statements are complex and thus the resulting zero-knowledge proofs are not efficient. Our construction is based on any predicate encryption scheme and the security relies on standard assumptions. A complexity analysis and an experimental evaluation confirm the practicality of our approach.
This paper investigates the power of quantum statistical zero knowledge interactive proof systems in the relativized setting. We prove the existence of an oracle relative to which quantum statistical zero-knowledge does not contain UP intersect coUP, and we prove that quantum statistical zero knowledge does not contain UP relative to a random oracle with probability 1. Our proofs of these statements rely on a bound on output state discrimination for relativized quantum circuits based on the quantum adversary method of Ambainis, following a technique similar to one used by Ben-David and Kothari to prove limitations on a query complexity variant of quantum statistical zero-knowledge.
Sepsis is a high mortality syndrome characterized by organ dysfunction due to a severe and dysregulated acute inflammatory response to infection. Research into therapies for this syndrome has historically ended in failure, which has largely been attributed to the elevated levels of subject heterogeneity. What may have been previously attributed to variability in sepsis may be due to mechanistic differences between patients. Endotypes are distinct subtypes of disease, where underlying causes such as mechanistic or pathway related differences manifest into phenotypes of disease. The lack of mechanistic understanding of immune mediator dynamics and the responses they trigger necessitates a mathematical modeling approach to analyze its complexities. A transfer function model is proposed to describe and cluster the dynamics of key inflammatory mediators. Five sepsis endotypes were discovered and revealed motifs of overwhelming inflammation, various levels of immunosuppression, sustained inflammation, and immunodeficiency. An accurate clinical tool was proposed to classify subjects into endotypes using six-hour trajectories of clinical data. A physiological ordinary differential equation model of sepsis is proposed that characterizes the interactions of inflammatory signaling molecules, neutrophils, and macrophages across the bone, blood, and tissue compartments of the body. This model used to generate individual subject fits against human sepsis data. Population-level parameter analysis implicated macrophage cell death and cytokine half- dynamics in endotype-level differences. Several proof-of-concept statistical models were introduced to demonstrate that it is possible to estimate the pre-hospital time of sepsis subjects and to quantify their sepsis-induced systemic tissue damage. A nearest-neighbor-based method was verified against animal and human data and revealed that identifying infection time-zero of sepsis patients can be quickly estimated with high accuracy using commonly measured clinical features. A logistic regression ensemble model demonstrated revealed early organ dysfunction were significant contributors to systemic damage and mortality. Knowledge of time-zero and systemic damage levels, in combination with an endotype classifier, provides clinicians with a clear depiction of where a subject is located on their sepsis trajectory. Such a decision support system enables therapy timing, early organ support, and targeted therapies to guide personalized treatment and shift patients towards better outcomes in sepsis.
This paper presents the implementation of an interactive Zero Knowledge Password authentication scheme for commercial Web sites. In this scheme, a legitimate prover (client) can exchange a secret code (password) with a remote skeptic (server), in order to reveal his/her identification. Based on the validity of the secret code the skeptic then allows the prover to login to the site and access the web services. This paper introduces a protocol that integrates the concepts of Discrete Logarithm Problem (DLP) and Zero-Knowledge Proofs (ZKP). The protocol consists of three entities, namely, the prover, the skeptic, and the facilitator who interact with one another to generate the secret code. When tested, the time to carry out various operations related to this protocol was reasonably small (under 4 seconds). Our scheme is resistant to man-in-the-middle attack and discourages replaying previously intercepted secret codes. We also propose two modifications to our basic scheme to make it resistant against the attack on Integrity and Denial of Service attack (DOS).