A new method uses adversarial attacks to detect other adversarial attacks.
arXiv research
A locally-built, LLM-digested index of recent arXiv papers in quant finance, geometry/topology, and statistical ML — keyword search served straight from SQLite on this machine.
Trend · papers per month
It has recently been shown that neural networks but also other classifiers are vulnerable to so called adversarial attacks e.g. in object recognition an almost non-perceivable change of the image changes the decision of the classifier. Relatively fast heuristics have been proposed to produce these adversarial inputs bu…
This paper analyzes adversarial attacks methods and their effectiveness.
In this paper, we analyze efficacy of the fast gradient sign method (FGSM) and the Carlini-Wagner's L2 (CW-L2) attack. We prove that, within a certain regime, the untargeted FGSM can fool any convolutional neural nets (CNNs) with ReLU activation; the targeted FGSM can mislead any CNNs with ReLU activation to classify a…
Adversarial examples are of wide concern due to their impact on the reliability of contemporary machine learning systems. Effective adversarial examples are mostly found via white-box attacks. However, in some cases they can be transferred across models, thus enabling them to attack black-box models. In this work we ev…
MARGINATTACK improves zero-confidence adversarial attacks' accuracy and efficiency.
Modern neural networks are highly non-robust against adversarial manipulation. A significant amount of work has been invested in techniques to compute lower bounds on robustness through formal guarantees and to build provably robust models. However, it is still difficult to get guarantees for larger networks or robustn…
We give a new algorithm for approximating the Discrete Fourier transform of an approximately sparse signal that has been corrupted by worst-case noise, namely a bounded number of coordinates of the signal have been corrupted arbitrarily. Our techniques generalize to a wide range of linear transformations that are…
Recent advances show that deep neural networks are not robust to deliberately crafted adversarial examples which many are generated by adding human imperceptible perturbation to clear input. Consider norms attacks, Project Gradient Descent (PGD) and the Carlini and Wagner (C\&W) attacks are the two main methods, …
A new method detects and corrects adversarial attacks on classifiers.
In this paper, we address a problem of machine learning system vulnerability to adversarial attacks. We propose and investigate a Key based Diversified Aggregation (KDA) mechanism as a defense strategy. The KDA assumes that the attacker (i) knows the architecture of classifier and the used defense strategy, (ii) has an…
Deep Neural Networks are quite vulnerable to adversarial perturbations. Current state-of-the-art adversarial attack methods typically require very time consuming hyper-parameter tuning, or require many iterations to solve an optimization based adversarial attack. To address this problem, we present a new family of trus…
We study Label-Smoothing as a means for improving adversarial robustness of supervised deep-learning models. After establishing a thorough and unified framework, we propose several variations to this general method: adversarial, Boltzmann and second-best Label-Smoothing methods, and we explain how to construct your own…
In recent years, defending adversarial perturbations to natural examples in order to build robust machine learning models trained by deep neural networks (DNNs) has become an emerging research field in the conjunction of deep learning and security. In particular, MagNet consisting of an adversary detector and a data re…
Understanding and characterizing the subspaces of adversarial examples aid in studying the robustness of deep neural networks (DNNs) to adversarial perturbations. Very recently, Ma et al. (ICLR 2018) proposed to use local intrinsic dimensionality (LID) in layer-wise hidden representations of DNNs to study adversarial s…
Minimax defense improves neural network security against gradient-based attacks.
Deep Neural Networks (DNNs) are vulnerable to adversarial attacks, especially white-box targeted attacks. One scheme of learning attacks is to design a proper adversarial objective function that leads to the imperceptible perturbation for any test image (e.g., the Carlini-Wagner (C&W) method). Most methods address targ…
Adversarial perturbations fool deepfake detectors with high accuracy.
EdgeFool generates adversarial images to mislead classifiers.
We study the problem of finding a universal (image-agnostic) perturbation to fool machine learning (ML) classifiers (e.g., neural nets, decision tress) in the hard-label black-box setting. Recent work in adversarial ML in the white-box setting (model parameters are known) has shown that many state-of-the-art image clas…
We propose an efficient gradient-based attack on kNN and kNN-based models.
In the present work we construct a lift of a metric on a 2-dimensional oriented Riemannian manifold to a metric on the total space of the orthonormal frame bundle of . We call this lift the \textit {Wagner lift}. Viktor Vladimirovich Wagner (1908 -1981) proposed a technique to extend a metric d…
We present the classical Wagner construction from 1935 of the curvature tensor for completely nonholonomic manifolds in both invariant and coordinate way. The starting point is the Shouten curvature tensor for nonholonomic connection introduced by Vranceanu and Shouten. We illustrate the construction on two mechanical …
The aim of this text is to provide an elementary and self-contained exposition of Gromov's argument on topological overlap (the presentation is based on Gromov's work, as well as two follow-up papers of Matousek and Wagner, and of Dotterrer, Kaufman and Wagner). We also discuss a simple generalization in which the vert…
ManiGen generates adversarial examples without classifier knowledge.
The notions of the interior and truncated connections of a nonholonomic manifold are introduced. A class of extended truncated connections is distinguished. For the case of a contact space with a Finsler metric, it is shown that there exists a unique extended truncated connection that satisfies additional properties. T…
Diversification increases systemic risk, contrary to belief.
We characterise the embeddability of simply connected locally 3-connected 2-dimensional simplicial complexes in 3-space in a way analogous to Kuratowski's characterisation of graph planarity, by excluded minors. This answers questions of Lovász, Pardon and Wagner.
This paper operationalizes the Exponential Mechanism using Normalizing Flows for private optimization.
We generalize the Morton-Franks-Williams inequality to the colored link homology defined in arXiv:0907.0695, which gives infinitely many new bounds for the braid index and the self linking number. A key ingredient of our proof is a composition product for the general MOY graph polynomial, which gener…
In this paper we construct a functor from the category of two-dimensional Riemannian manifolds to the category of three-dimensional manifolds with generalized metric tensors. For each two-dimensional oriented Riemannian manifold we construct a metric tensor (in general, with singularities) on the total…
We give asymptotically tight estimates of tangent space variation on Riemannian submanifolds of Euclidean space with respect to the local feature size of the submanifolds. We show that the result follows directly from structural properties of local feature size of the Riemannian submanifold and some elementary Euclidea…
Taking advantage of the recent litterature on exact simulation algorithms (Beskos, Papaspiliopoulos and Roberts) and unbiased estimation of the expectation of certain fonctional integrals (Wagner, Beskos et al. and Fearnhead et al.), we apply an exact simulation based technique for pricing continuous arithmetic average…
Triple-point Whitney trick classifies ornaments of 3-manifolds.
Witt algebra acts on categorified quantum groups in type A.
Lectures introduce evaluation of SL(3) foams and link homology.
The lattice of integer flows of a graph is known to determine the graph up to 2-isomorphism (work of Su--Wagner and Caporaso--Viviani). In this paper we give an algorithmic construction of the graphic matroid $\calM(G)$ of a graph , given its lattice of integer flows $\calF(G)$. The algorithm can then be applied to …
The study characterizes embeddable 2-complexes in 3-space.
In this paper we study the tensor powers of the standard representation of the quantum super-algebra , focusing on the rings of its algebra endomorphisms, called centraliser algebras and denoted by . Their dimensions were conjectured by I. Marin and E. Wagner \cite{MW}. We prove this conjecture, desc…
In graph theory there are intimate connections between the expansion properties of a graph and the spectrum of its Laplacian. In this paper we define a notion of combinatorial expansion for simplicial complexes of general dimension, and prove that similar connections exist between the combinatorial expansion of a compl…
"Feint Attack", as a new type of APT attack, has become the focus of attention. It adopts a multi-stage attacks mode which can be concluded as a combination of virtual attacks and real attacks. Under the cover of virtual attacks, real attacks can achieve the real purpose of the attacker, as a result, it often caused hu…
This paper studies adversarial attacks on Gaussian process bandits.
Subpopulation attacks poison data to misclassify naturally distributed points.
Reward-poisoning attacks can force RL agents to learn bad policies, and we categorize and quantify their feasibility.
Spanning attack improves black-box attacks with unlabeled data.
Simplified computation of symmetric gl_1 homology for links.
Headless attacks bypass classification heads to fool transfer learning models.
New attack manipulates UCB algorithm, new defense algorithm reduces pseudo-regret.