Paper bounds convergence rate of adversarial surrogate risk.
arXiv research
A locally-built, LLM-digested index of recent arXiv papers in quant finance, geometry/topology, and statistical ML — keyword search served straight from SQLite on this machine.
Trend · papers per month
Modern machine learning algorithms perform poorly on adversarially manipulated data. Adversarial risk quantifies the error of classifiers in adversarial settings; adversarial classifiers minimize adversarial risk. In this paper, we analyze adversarial risk and adversarial classifiers from an optimal transport perspecti…
Study non-asymptotic bounds for robust estimators under misspecified models.
This paper examines various definitions of adversarial risk and their implications.
Generative Adversarial Regression (GAR) learns risk scenarios robustly across policies.
We derive bounds for a notion of adversarial risk, designed to characterize the robustness of linear and neural network classifiers to adversarial perturbations. Specifically, we introduce a new class of function transformations with the property that the risk of the transformed functions upper-bounds the adversarial r…
Adversarial consistency depends on the uniqueness of adversarial Bayes classifiers.
SVAT reduces investment risks by making stock models sensitive to adversarial perturbations.
This paper investigates recently proposed approaches for defending against adversarial examples and evaluating adversarial robustness. We motivate 'adversarial risk' as an objective for achieving models robust to worst-case inputs. We then frame commonly used attacks and evaluation metrics as defining a tractable surro…
This paper explores tradeoffs between standard and adversarial risks in distributionally adversarial training.
Despite their numerous successes, there are many scenarios where adversarial risk metrics do not provide an appropriate measure of robustness. For example, test-time perturbations may occur in a probabilistic manner rather than being generated by an explicit adversary, while the poor train--test generalization of adver…
Data augmentation impacts adversarial risk; careful application recommended.
The paper sets lower bounds for adversarial robustness in multiclass classification.
FE-GAN improves VaR and ES estimation in financial risk management.
Classification problems in security settings are usually contemplated as confrontations in which one or more adversaries try to fool a classifier to obtain a benefit. Most approaches to such adversarial classification problems have focused on game theoretical ideas with strong underlying common knowledge assumptions, w…
Adversarial training can lead to overfitting without compromising robustness.
Interpolating label noise makes models vulnerable to adversarial attacks.
Here we propose a general theoretical method for analyzing the risk bound in the presence of adversaries. Specifically, we try to fit the adversarial learning problem into the minimax framework. We first show that the original adversarial learning problem can be reduced to a minimax statistical learning problem by intr…
We study risk-sensitive imitation learning where the agent's goal is to perform at least as well as the expert in terms of a risk profile. We first formulate our risk-sensitive imitation learning setting. We consider the generative adversarial approach to imitation learning (GAIL) and derive an optimization problem for…
This study connects Jacobian regularization to adversarial robustness and improves generalization.
Paper provides optimal statistical guarantees for adversarial robustness in Gaussian classification.
Robust risk minimisation has several advantages: it has been studied with regards to improving the generalisation properties of models and robustness to adversarial perturbation. We bound the distributionally robust risk for a model class rich enough to include deep neural networks by a regularised empirical risk invol…
ADGAN improves risk tolerance prediction by aligning cross-domain data.
New geometric insights reveal properties of adversarial training problems.
Ensemble of diverse CNNs detects and mitigates adversarial attacks.
In this work we consider adversarial contextual bandits with risk constraints. At each round, nature prepares a context, a cost for each arm, and additionally a risk for each arm. The learner leverages the context to pull an arm and then receives the corresponding cost and risk associated with the pulled arm. In additi…
Study on adversarial training dynamics in high dimensions using SGD.
ACL improves robustness with unlabeled data, and we analyze its generalization using Rademacher complexity.
New method improves adversarial robustness of neural networks.
Recent works on adversarial perturbations show that there is an inherent trade-off between standard test accuracy and adversarial accuracy. Specifically, they show that no classifier can simultaneously be robust to adversarial perturbations and achieve high standard test accuracy. However, this is contrary to the stand…
Study on robustness in linear regression models, focusing on adversarial perturbations.
Malware constitutes a major global risk affecting millions of users each year. Standard algorithms in detection systems perform insufficiently when dealing with malware passed through obfuscation tools. We illustrate this studying in detail an open source metamorphic software, making use of a hybrid framework to obtain…
This paper improves adversarial robustness of deep learning models.
We study adversarial perturbations when the instances are uniformly distributed over . We study both "inherent" bounds that apply to any problem and any classifier for such a problem as well as bounds that apply to specific problems and specific hypothesis classes. As the current literature contains multiple…
Overfitting can make models vulnerable to adversarial attacks even if they are robust to standard risks.
New algorithm improves robustness by more regularization on less robust samples.
New method improves privacy risk evaluation of machine learning models.
The paper proposes a new approach to model risk measurement based on the Wasserstein distance between two probability measures. It formulates the theoretical motivation resulting from the interpretation of fictitious adversary of robust risk management. The proposed approach accounts for equivalent and non-equivalent p…
Neural networks have been shown to be vulnerable against minor adversarial perturbations of their inputs, especially for high dimensional data under attacks. To combat this problem, techniques like adversarial training have been employed to obtain models which are robust on the training set. However, the …
Paper analyzes adversarial training's performance in binary classification.
Adversarial training is a technique for training robust machine learning models. To encourage robustness, it iteratively computes adversarial examples for the model, and then re-trains on these examples via some update rule. This work analyzes the performance of adversarial training on linearly separable data, and prov…
Survey finds many adversarial machine learning threats are not critical for most entities.
Recent work on adversarial attack has shown that Projected Gradient Descent (PGD) Adversary is a universal first-order adversary, and the classifier adversarially trained by PGD is robust against a wide range of first-order attacks. It is worth noting that the original objective of an attack/defense model relies on a d…
Traditional classification algorithms assume that training and test data come from similar distributions. This assumption is violated in adversarial settings, where malicious actors modify instances to evade detection. A number of custom methods have been developed for both adversarial evasion attacks and robust learni…
PAC-Bayesian bounds estimate adversarial robustness.
Unified framework analyzes privacy risks from gradients in distributed learning.
With the deployment of online monitoring systems in distribution networks, massive amounts of data collected through them contains rich information on the operating states of the networks. By leveraging the data, an unsupervised approach based on bidirectional generative adversarial networks (BiGANs) is proposed for op…
This research analyzes the consistency of convex and nonconvex surrogate losses for adversarially robust classification.