The paper studies the asymptotic behavior of adversarial training under -perturbation.
arXiv research
A locally-built, LLM-digested index of recent arXiv papers in quant finance, geometry/topology, and statistical ML — keyword search served straight from SQLite on this machine.
Trend · papers per month
New neural network design resists small -norm adversarial perturbations.
Adversarial training is a principled approach for training robust neural networks. Despite of tremendous successes in practice, its theoretical properties still remain largely unexplored. In this paper, we provide new theoretical insights of gradient descent based adversarial training by studying its computational prop…
Enhances robustness of AT frameworks to multiple perturbations without increasing training complexity.
Defenses against adversarial examples, such as adversarial training, are typically tailored to a single perturbation type (e.g., small -noise). For other perturbations, these defenses offer no guarantees and, at times, even increase the model's vulnerability. Our aim is to understand the reasons underlying…
Owing to the susceptibility of deep learning systems to adversarial attacks, there has been a great deal of work in developing (both empirically and certifiably) robust classifiers. While most work has defended against a single type of attack, recent work has looked at defending against multiple perturbation models usi…
Deep neural networks perform well on real world data but are prone to adversarial perturbations: small changes in the input easily lead to misclassification. In this work, we propose an attack methodology not only for cases where the perturbations are measured by norms, but in fact any adversarial dissimilarit…
This paper tackles robustness of ensemble stumps and trees under general ℓ_p norm perturbations.
Verifying robustness of neural networks given a specified threat model is a fundamental yet challenging task. While current verification methods mainly focus on the -norm threat model of the input instances, robustness verification against semantic adversarial attacks inducing large -norm perturbations,…
Study linear perturbations in Schwarzschild black hole spacetime.
The paper improves ALO for -regularized models.
An elementary family of local Hamiltonians , is described for a dimensional quantum mechanical system of spin particles. On the torus, the ground state space is extensively degenerate but should collapse under perturbation" to an anyonic syste…
This work improves robustness guarantees for neural networks using low rank representations.
In a vacuum spacetime equipped with the Bondi's radiating metric which is asymptotically flat at spatial infinity including gravitational radiation ({\bf Condition D}), we establish the relation between the ADM total energy-momentum and the Bondi energy-momentum for perturbed radiative spatial infinity. The perturbatio…
Study analyzes perturbations in singular subspaces under random noise.
Improved training boosts certified robustness of L-infinity distance nets.
This paper explores adversarial training limits and improves model robustness against norm-bounded perturbations.
Let (resp., ) be a manifold (resp., an open subset of ). Let and be an immersion and a mapping, respectively. Generally, the composition does not necessarily yield a mapping transverse to a given subfiber-bundle of …
New regularization techniques improve stability of deep neural networks.
We improve image perturbation defenses using a better-defined Wasserstein threat model.
Deep neural networks are susceptible to adversarial manipulations in the input domain. The extent of vulnerability has been explored intensively in cases of -bounded and -minimal adversarial perturbations. However, the vulnerability of DNNs to adversarial perturbations with specific statistical properti…
New surfaces near a sphere violate Minkowski inequality.
Adversarial examples are carefully perturbed in-puts for fooling machine learning models. A well-acknowledged defense method against such examples is adversarial training, where adversarial examples are injected into training data to increase robustness. In this paper, we propose a new attack to unveil an undesired pro…
We show how to turn any classifier that classifies well under Gaussian noise into a new classifier that is certifiably robust to adversarial perturbations under the norm. This "randomized smoothing" technique has been proposed recently in the literature, but existing guarantees are loose. We prove a tight robu…
LSDAT reduces query efficiency for decision-based adversarial attacks.
Adversarial examples are malicious inputs crafted to cause a model to misclassify them. Their most common instantiation, "perturbation-based" adversarial examples introduce changes to the input that leave its true label unchanged, yet result in a different model prediction. Conversely, "invariance-based" adversarial ex…
Generative models improve adversarial robustness by adding synthetic data.
The study generalizes cohomology results for hyperbolic groups.
We demonstrate that model-based derivative free optimisation algorithms can generate adversarial targeted misclassification of deep networks using fewer network queries than non-model-based methods. Specifically, we consider the black-box setting, and show that the number of networks queries is less impacted by making …
We prove boundedness and polynomial decay statements for solutions to the spin Teukolsky-type equation projected to the spherical harmonic on Reissner-Nordström spacetime. The equation is verified by a gauge-invariant quantity which we identify and which involves the electromagnetic and curvature tensor…
Recent work has developed methods for learning deep network classifiers that are provably robust to norm-bounded adversarial perturbation; however, these methods are currently only possible for relatively small feedforward networks. In this paper, in an effort to scale these approaches to substantially larger models, w…
Neural networks have been shown to be vulnerable against minor adversarial perturbations of their inputs, especially for high dimensional data under attacks. To combat this problem, techniques like adversarial training have been employed to obtain models which are robust on the training set. However, the …
The paper analyzes how random perturbations affect RSVD and its applications.
Unified algorithm for linear bandits with improved regret bound.
The study finds regular null hypersurfaces in a perturbed Schwarzschild black hole exterior.
ScoreAG generates unrestricted adversarial images maintaining semantic integrity.
Extending work of Kapouleas and Yang, for any integers , , and sufficiently large, we apply gluing methods to construct in the round -sphere a closed embedded minimal surface that has genus and is invariant under a subgroup of , where …
Randomized smoothing is the current state-of-the-art defense with provable robustness against adversarial attacks. Many works have devised new randomized smoothing schemes for other metrics, such as or ; however, substantial effort was needed to derive such new guarantees. This begs the q…
We show that it is possible to perturb arbitrary vacuum asymptotically flat spacetimes to new ones having exactly the same energy and linear momentum, but with center of mass and angular momentum equal to any preassigned values measured with respect to a fixed affine frame at infinity. This is in contrast to the axisym…
Randomized classifiers have been shown to provide a promising approach for achieving certified robustness against adversarial attacks in deep learning. However, most existing methods only leverage Gaussian smoothing noise and only work for perturbation. We propose a general framework of adversarial certificati…
Carefully crafted, often imperceptible, adversarial perturbations have been shown to cause state-of-the-art models to yield extremely inaccurate outputs, rendering them unsuitable for safety-critical application domains. In addition, recent work has shown that constraining the attack space to a low frequency regime is …
Adversarial testing methods based on Projected Gradient Descent (PGD) are widely used for searching norm-bounded perturbations that cause the inputs of neural networks to be misclassified. This paper takes a deeper look at these methods and explains the effect of different hyperparameters (i.e., optimizer, step size an…
Study enhances robustness of In-CVaR based regression models under perturbation and contamination.
The paper proves the existence and uniqueness of certain spacelike hypersurfaces with specific curvature and boundary conditions.
Many recent works have shown that adversarial examples that fool classifiers can be found by minimally perturbing a normal input. Recent theoretical results, starting with Gilmer et al. (2018b), show that if the inputs are drawn from a concentrated metric probability space, then adversarial examples with small perturba…
This paper proves a canonical foliation on null infinity for Kerr-like black holes.
Paper develops a robust classifier for Gaussian mixture models under sparse adversarial perturbations.
Study robust estimation of principal components under adversarial perturbations.