Research
On-device research index

arXiv research

A locally-built, LLM-digested index of recent arXiv papers in quant finance, geometry/topology, and statistical ML — keyword search served straight from SQLite on this machine.

168,657 papers · 148 categories

Trend · papers per month

3774111148 · Jun 202019922001200920172026
48 results for Ell Infinity Perturbation

The paper studies the asymptotic behavior of adversarial training under \ell_\infty-perturbation.

problem Theoretical guarantees for sparsity-recovery in adversarial training.
method Investigation of the asymptotic distribution of the adversarial training estimator in generalized linear models.
result The asymptotic distribution of the adversarial training estimator under \ell_\infty-perturbation could have a positive probability mass at 0 when the true parameter is 0.

New neural network design resists small \ell_\infty-norm adversarial perturbations.

problem Vulnerability of neural networks to small \ell_\infty-norm adversarial perturbations.
method Designing \ell_\infty-dist neurons and constructing \ell_{\infty}-dist nets, proving their 1-Lipschitz property and expressive power.
result Certified robustness of \ell_{\infty}-dist nets with state-of-the-art performance on various datasets.

Enhances robustness of AT frameworks to multiple perturbations without increasing training complexity.

problem Defending against the union of multiple perturbations in adversarial training.
method SNAP technique that augments a network with shaped noise to enhance robustness.
result 14%-to-20% improvement in adversarial accuracy for ResNet-18 on CIFAR-10.

Defenses against adversarial examples, such as adversarial training, are typically tailored to a single perturbation type (e.g., small \ell_\infty-noise). For other perturbations, these defenses offer no guarantees and, at times, even increase the model's vulnerability. Our aim is to understand the reasons underlying…

2019-04-30abs ↗pdf ↗

This paper tackles robustness of ensemble stumps and trees under general ℓ_p norm perturbations.

problem The vulnerability of ensemble stumps and trees to small input perturbations under the ℓ_∞ norm.
method Developed dynamic programming algorithms for robustness verification and certified defense under general ℓ_p norm perturbations.
result First certified defense method for ensemble stumps and trees under ℓ_p norm perturbations.

Study linear perturbations in Schwarzschild black hole spacetime.

problem Linear perturbations of Schwarzschild black hole spacetime.
method Investigate linearised perturbation of constant mass aspect function foliation at null infinity.
result Linearised perturbations of Bondi energy and mass vanish, and all linear momentum can be achieved.

The paper improves ALO for 1\ell_1-regularized models.

problem Estimating out-of-sample error for 1\ell_1-regularized models.
method Developed a novel theory for 1\ell_1-regularized problems, bounding ALO error.
result For 1\ell_1-regularized problems, ALO error goes to zero as p goes to infinity.

An elementary family of local Hamiltonians H,¸,=1,2,3,ldotsH_{\c ,\ell}, \ell = 1,2,3, ldots, is described for a 22-dimensional quantum mechanical system of spin =1/2={1/2} particles. On the torus, the ground state space G,G_{\circ,\ell} is (log)(\log) extensively degenerate but should collapse under łłperturbation" to an anyonic syste…

2001-10-09abs ↗pdf ↗

This work improves robustness guarantees for neural networks using low rank representations.

problem Certified robustness to adversarial perturbations in neural networks.
method Low rank representations to provide improved robustness guarantees.
result Improved robustness guarantees for \ell_\infty perturbations using natural low rank representations.

Study analyzes perturbations in singular subspaces under random noise.

problem Understanding singular vector and subspace changes in signal-plus-noise models.
method Generalized Davis-Kahan-Wedin theorem for any unitarily invariant norm, considering \ell_\infty and 2,\ell_{2,\infty} bounds.
result Fine-grained insights into singular vector and subspace perturbations, including \ell_\infty and 2,\ell_{2,\infty} bounds.

Improved training boosts certified robustness of L-infinity distance nets.

problem Certified robustness of L-infinity distance nets is not as strong as conventional networks.
method Improved training process combining scaled cross-entropy and clipped hinge loss with a decaying mixing coefficient.
result Certified accuracy of L-infinity distance nets improved from 33.30% to 40.06% on CIFAR-10.

This paper explores adversarial training limits and improves model robustness against norm-bounded perturbations.

problem Understanding and improving adversarial robustness of deep neural networks.
method Systematic study of adversarial training with various factors, including model size, activation functions, and unlabeled data.
result Training robust models that go beyond state-of-the-art results by combining larger models, Swish/SiLU activations, and model weight averaging.

Let NN (resp., UU) be a manifold (resp., an open subset of Rm\mathbb{R}^m). Let f:NUf:N\to U and F:URF:U\to \mathbb{R}^\ell be an immersion and a CC^{\infty} mapping, respectively. Generally, the composition FfF\circ f does not necessarily yield a mapping transverse to a given subfiber-bundle of J1(N,R)J^1(N,\mathbb{R}^\ell)

2016-12-04abs ↗pdf ↗

New regularization techniques improve stability of deep neural networks.

problem Improving stability of deep neural networks in high-dimensional data.
method Apply manifold regularization to develop new regularizers based on graph Laplacian sparsification.
result Empirically, networks achieve high stability in various perturbation models, including adversarial attacks.

We improve image perturbation defenses using a better-defined Wasserstein threat model.

problem Real-world image perturbations are not pixel-independent, unlike p\ell_p threat models.
method We rectify flaws in the Wasserstein threat model and explore stronger attacks and defenses.
result Current Wasserstein-robust models are ineffective against real-world perturbations.

Adversarial examples are carefully perturbed in-puts for fooling machine learning models. A well-acknowledged defense method against such examples is adversarial training, where adversarial examples are injected into training data to increase robustness. In this paper, we propose a new attack to unveil an undesired pro…

2019-05-15abs ↗pdf ↗

We show how to turn any classifier that classifies well under Gaussian noise into a new classifier that is certifiably robust to adversarial perturbations under the 2\ell_2 norm. This "randomized smoothing" technique has been proposed recently in the literature, but existing guarantees are loose. We prove a tight robu…

2019-02-08abs ↗pdf ↗

Generative models improve adversarial robustness by adding synthetic data.

problem Improving robustness in machine learning models trained on limited data.
method Using synthetic data generated from a large dataset to augment the original training set.
result Generative models can significantly reduce the robust-accuracy gap compared to models trained with additional real data.

We prove boundedness and polynomial decay statements for solutions to the spin ±1\pm1 Teukolsky-type equation projected to the =1\ell=1 spherical harmonic on Reissner-Nordström spacetime. The equation is verified by a gauge-invariant quantity which we identify and which involves the electromagnetic and curvature tensor…

2018-12-06abs ↗pdf ↗

Recent work has developed methods for learning deep network classifiers that are provably robust to norm-bounded adversarial perturbation; however, these methods are currently only possible for relatively small feedforward networks. In this paper, in an effort to scale these approaches to substantially larger models, w…

2018-05-31abs ↗pdf ↗

The paper analyzes how random perturbations affect RSVD and its applications.

problem Analyzing the impact of random perturbations on RSVD.
method Derives bounds for distances between exact and approximated singular vectors using RSVD.
result Established nearly-optimal convergence rates and asymptotic normality for RSVD in various inference problems.

The study finds regular null hypersurfaces in a perturbed Schwarzschild black hole exterior.

problem Existence of regular null hypersurfaces in a perturbed Schwarzschild black hole.
method Proof of existence for null hypersurfaces in a perturbed Schwarzschild spacetime.
result Existence of many foliations by regular null hypersurfaces in the exterior region of a perturbed Schwarzschild black hole.

ScoreAG generates unrestricted adversarial images maintaining semantic integrity.

problem Limited robustness evaluations due to p\ell_p-norm constraints.
method Score-Based Adversarial Generation (ScoreAG) using score-based generative models.
result ScoreAG improves robustness assessments across multiple benchmarks.

Extending work of Kapouleas and Yang, for any integers N2N \geq 2, k,1k, \ell \geq 1, and mm sufficiently large, we apply gluing methods to construct in the round 33-sphere a closed embedded minimal surface that has genus km2(N1)+1k\ell m^2(N-1)+1 and is invariant under a Dkm×DmD_{km} \times D_{\ell m} subgroup of O(4)O(4), where …

2015-02-26abs ↗pdf ↗

Randomized smoothing is the current state-of-the-art defense with provable robustness against 2\ell_2 adversarial attacks. Many works have devised new randomized smoothing schemes for other metrics, such as 1\ell_1 or \ell_\infty; however, substantial effort was needed to derive such new guarantees. This begs the q…

2020-02-19abs ↗pdf ↗

Carefully crafted, often imperceptible, adversarial perturbations have been shown to cause state-of-the-art models to yield extremely inaccurate outputs, rendering them unsuitable for safety-critical application domains. In addition, recent work has shown that constraining the attack space to a low frequency regime is …

2019-02-28abs ↗pdf ↗

Adversarial testing methods based on Projected Gradient Descent (PGD) are widely used for searching norm-bounded perturbations that cause the inputs of neural networks to be misclassified. This paper takes a deeper look at these methods and explains the effect of different hyperparameters (i.e., optimizer, step size an…

2019-10-21abs ↗pdf ↗

Study enhances robustness of In-CVaR based regression models under perturbation and contamination.

problem Enhancing robustness of nonlinear regression models under perturbation and contamination.
method Introduces interval conditional value-at-risk (In-CVaR) and rigorously analyzes its robustness properties under both perturbation and contamination.
result The In-CVaR based estimator is qualitatively robust in terms of the Prokhorov metric if and only if the largest portion of losses is trimmed.

The paper proves the existence and uniqueness of certain spacelike hypersurfaces with specific curvature and boundary conditions.

problem Existence and uniqueness of convex, entire, spacelike hypersurfaces with constant σkσ_k curvature.
method Investigation of hypersurfaces with prescribed set of lightlike directions and perturbation on the ideal boundary at infinity.
result Existence and uniqueness of complete entire spacelike constant σkσ_k curvature hypersurfaces with prescribed lightlike directions and perturbation.

This paper proves a canonical foliation on null infinity for Kerr-like black holes.

problem Establishing well-defined physical quantities on null infinity for Kerr-like black holes.
method Existence and uniqueness results for GCM spheres by Klainerman-Szeftel.
result Existence of a canonical foliation on future null infinity with well-defined physical quantities.

Paper develops a robust classifier for Gaussian mixture models under sparse adversarial perturbations.

problem Classifying data under sparse adversarial perturbations for Gaussian mixture models.
method Develops FilTrun algorithm with filtration and truncation modules.
result Characterizes optimal robust classifier and robust classification error.

Study robust estimation of principal components under adversarial perturbations.

problem Estimating principal components in high-dimensional data under adversarial perturbations.
method Design of a computationally efficient algorithm for recovering the top-r principal subspace.
result The algorithm recovers an estimate of the top-r principal subspace with error depending on the robustness parameter κ.