Research
On-device research index

arXiv research

A locally-built, LLM-digested index of recent arXiv papers in quant finance, geometry/topology, and statistical ML — keyword search served straight from SQLite on this machine.

169,051 papers · 148 categories

Trend · papers per month

2.4%4.8%7.2%9.5% · May 201919922001200920182026
48 results for FGSM Adversary

This paper explains the theoretical regularization effect of FGSM and its generalization.

problem Understanding the theoretical properties of FGSM and its generalization.
method Developed asymptotic properties of Generalized FGSM in a simple neural network setting.
result Generalized FGSM estimation is root n-consistent and weakly oracle under proper conditions.

AutoGAN improves classifier robustness against adversarial attacks.

problem Classifiers fail to correctly classify perturbed images.
method AutoGAN uses a GAN with an autoencoder generator and a classifier discriminator to enhance the training data manifold and project perturbed data points onto it.
result AutoGAN can surpass FGSM method by up to 25% points on FGSM perturbed samples and achieves 89% accuracy without augmented training data.

DIP-FAT improves adversarial training by diversifying perturbations.

problem Adversarial examples fool deep neural networks, leading to overfitting and poor performance.
method DIP-FAT uses random directions to diversify perturbations in adversarial training.
result DIP-FAT reduces overfitting and improves clean data accuracy.

New methods improve adversarial attacks' transferability to other models.

problem Vulnerability of deep learning models to adversarial examples.
method Nesterov Iterative Fast Gradient Sign Method (NI-FGSM) and Scale-Invariant attack Method (SIM).
result NI-FGSM and SIM generate more transferable adversarial examples.

Paper assesses adversarial robustness of MCMC and BDK methods for deep Bayesian networks.

problem Assessing adversarial robustness of deep neural networks under MCMC and BDK approximations.
method Characterizes robustness of MCMC and BDK methods to FGSM and PGD attacks.
result Full MCMC-based inference shows excellent robustness, outperforming standard point estimation.

New method shows adversarial training can be as effective as traditional training without the high cost.

problem The high cost of adversarial training limits its practical application.
method Using FGSM with random initialization and efficient training techniques.
result Adversarial training with FGSM can achieve robust accuracy comparable to PGD-based training at a lower cost.

Empirical study on adversarial robustness in transfer learning from CIFAR 100 to CIFAR 10.

problem Evaluating adversarial robustness in transfer learning from CIFAR 100 to CIFAR 10.
method Study of adversarial robustness under transfer learning from a source trained on CIFAR 100 to a target network trained on CIFAR 10, using robust optimisation.
result Using PGD examples during training on the source task leads to more general robust features that are easier to transfer and achieve 5.2% more accuracy against white-box PGD attacks.

In recent years, it has been found that neural networks can be easily fooled by adversarial examples, which is a potential safety hazard in some safety-critical applications. Many researchers have proposed various method to make neural networks more robust to white-box adversarial attacks, but an effective method have …

2018-04-20abs ↗pdf ↗

Study reveals how neural network smoothness affects their vulnerability to adversarial attacks.

problem Understanding adversarial vulnerability in deep learning networks.
method Analysis of manifold smoothness and generalization capability of deep neural networks trained with local errors.
result High generalization accuracy requires a fast power-law decay of eigen-spectrum of hidden representations.

Minimax defense improves neural network security against gradient-based attacks.

problem Gradient-based adversarial attacks on neural networks.
method Minimax optimization in a GAN framework to create a discriminator that plays a minimax game with the generator.
result Minimax defense significantly reduces adversarial attack success rates compared to standard classifiers.

Simple technique turns any adversarial attack into a universal one using few test examples.

problem Creating universal adversarial attacks with minimal data.
method Universalization technique using few adversarial test examples and spectral properties.
result Simple universalization technique achieves comparable fooling rates to state-of-the-art methods.

This paper proposes a new method to improve adversarial robustness of DNNs by focusing on semantic information.

problem Vulnerability of deep neural networks to adversarial attacks.
method Region adversarial training (RAT) that generates a single adversarial perturbation carrying semantic information.
result RAT greatly improves adversarial robustness with a small dataset and defends against FGSM attacks.

Adversarial examples have been shown to exist for a variety of deep learning architectures. Deep reinforcement learning has shown promising results on training agent policies directly on raw inputs such as image pixels. In this paper we present a novel study into adversarial attacks on deep reinforcement learning polic…

2017-05-18abs ↗pdf ↗

Label-Smoothing improves adversarial robustness of deep learning models.

problem Improving the robustness of deep learning models against adversarial attacks.
method Label-Smoothing, including adversarial, Boltzmann, and second-best variants, applied to various models and datasets.
result Label-Smoothing enhances adversarial robustness across multiple attacks and datasets.

Detects adversarial examples using attribution methods.

problem Detecting adversarial examples in machine learning models.
method Integrated Gradient method for finding attributions and masking high attribution features to define causal neighborhoods.
result Adversarial inputs are not robust to masking high attribution features, while benign inputs are.

This study evaluates how adversarial examples transfer between different models.

problem Transferability of adversarial examples across models poses a threat to machine learning reliability.
method Evaluation of three adversarial attacks (FGSM, Basic Iterative Method, Carlini & Wagner) on two model classes (VGG and Inception). Use of specific parameters and metrics (L-Infinity clipping, SSIM) for assessment.
result Adversarial examples can be transferred between models, indicating a vulnerability in machine learning systems.

TensorShield defends images from adversarial attacks using tensor decomposition.

problem Adversarial attacks on images can fool deep neural networks.
method Tensor decomposition to find low-rank approximations of images, reducing high-frequency perturbations.
result TensorShield outperforms existing methods like SLQ by 14% against FGSM attacks.

Transfer learning improves model robustness against adversarial attacks.

problem Understanding how transfer learning affects model robustness against adversarial attacks.
method Extensive empirical evaluations of white-box and black-box attacks on fine-tuned transfer learning models.
result Adversarial examples are more transferable when fine-tuning is used than when networks are trained independently.

Deep neural networks (DNNs) are vulnerable to malicious inputs crafted by an adversary to produce erroneous outputs. Works on securing neural networks against adversarial examples achieve high empirical robustness on simple datasets such as MNIST. However, these techniques are inadequate when empirically tested on comp…

2018-02-02abs ↗pdf ↗

Paper introduces techniques to enhance time series data robustness against adversarial attacks.

problem Vulnerability of deep learning time series classifiers to adversarial attacks.
method Two local gradient based and one spectral density based data augmentation techniques.
result Trained models with augmented data achieve state-of-the-art classification accuracy and robustness.

Though CNNs have achieved the state-of-the-art performance on various vision tasks, they are vulnerable to adversarial examples --- crafted by adding human-imperceptible perturbations to clean images. However, most of the existing adversarial attacks only achieve relatively low success rates under the challenging black…

2018-03-19abs ↗pdf ↗

Mixup improves model robustness and generalization by convexly combining examples.

problem Improving model robustness and generalization.
method Using Mixup augmentation in training, which involves convex combinations of pairs of examples and their labels.
result Mixup training helps models exhibit robustness to adversarial attacks and reduces overfitting.

A two-step defense method generates strong adversarial examples at low cost.

problem Vulnerability of deep neural networks to adversarial attacks.
method Develops a two-step defense approach that generates strong adversarial examples using FGSM at a lower computational cost compared to traditional multi-step adversarial training.
result Demonstrates effectiveness of the two-step defense approach against various attack methods with comparable robustness to traditional multi-step adversarial training.

It is becoming increasingly clear that many machine learning classifiers are vulnerable to adversarial examples. In attempting to explain the origin of adversarial examples, previous studies have typically focused on the fact that neural networks operate on high dimensional data, they overfit, or they are too linear. H…

2017-11-08abs ↗pdf ↗

Paper tackles cyber threats to PHM systems using adversarial examples.

problem Vulnerability of IoT sensors and DL algorithms to cyber attacks.
method Adopted adversarial example crafting techniques from computer vision to PHM domain.
result PHM models are vulnerable to adversarial attacks, leading to inaccurate remaining useful life estimation.

We propose denoising dictionary learning (DDL), a simple yet effective technique as a protection measure against adversarial perturbations. We examined denoising dictionary learning on MNIST and CIFAR10 perturbed under two different perturbation techniques, fast gradient sign (FGSM) and jacobian saliency maps (JSMA). W…

2018-01-07abs ↗pdf ↗

Paper proposes a black-box technique to generate adversarial samples.

problem Robustness of Deep Neural Networks (DNNs) to adversarial samples.
method Black-box Momentum Iterative Fast Gradient Sign Method (BMI-FGSM) using Differential Evolution to approximate gradients.
result Achieves high success rates in generating adversarial samples and misclassification.

A bias classifier is introduced to resist adversarial attacks.

problem Resisting adversarial attacks on deep neural networks (DNNs).
method Introducing the bias part of a DNN with Relu as the activation function as a classifier, and adding a random first-degree part to make it information-theoretically safe.
result The bias classifier is more robust than DNNs of similar size against adversarial attacks.

Adversarial perturbations are more effective in Y-channel of YCbCr color space.

problem Vulnerability of deep models to adversarial perturbations in images.
method Proposed ResUpNet defense that removes perturbations only from the Y-channel of YCbCr color space.
result ResUpNet achieves the best balance between defense and maintaining original image accuracy.

Study tackles discretization problem in crafting adversarial examples for discrete integer domains.

problem Discretization problem in crafting adversarial examples for discrete integer domains.
method Proposes a black-box method to reduce adversarial example searching to a derivative-free optimization problem.
result Significantly higher success rate in crafting adversarial images in discrete integer domain compared to black-box methods.

A robust method for multiple kernel learning against adversarial inputs.

problem Certifiably robust learning against adversarial perturbations.
method Distributionally robust optimization with min-max formulation and debiasing techniques.
result The method achieves theoretical guarantees and generalization bounds.

Study fusion methods for financial image views to improve robustness against attacks.

problem Improving robustness of financial image views for next-day direction prediction.
method Same-source multi-view learning with early fusion and late fusion, using OHLCV and technical-indicator views, and evaluating pixel-space L-infinity attacks.
result Early fusion can suffer negative transfer under noisy settings, while late fusion is more reliable once labels stabilize.

Proposes a new adversarial model to avoid accuracy vs. adversarial accuracy tradeoff.

problem Inherent tradeoff between accuracy and adversarial accuracy in existing adversarial robustness definitions.
method Introduces Voronoi-epsilon adversary that balances perturbation constraints.
result Voronoi-epsilon adversary avoids accuracy vs. adversarial accuracy tradeoff even with large εε.

Adversarial consistency depends on the uniqueness of adversarial Bayes classifiers.

problem Consistency of adversarial surrogate losses is not guaranteed.
method Connected consistency of adversarial surrogate losses to the uniqueness of adversarial Bayes classifiers.
result A convex surrogate loss is statistically consistent for adversarial learning if and only if the adversarial Bayes classifier is unique.