This paper shows excessive invariance in adversarial robust models can make them more vulnerable to certain types of attacks.
problem Excessive invariance in adversarial robust models can make them more vulnerable to certain types of attacks.
method Analytical constructions and empirical studies of vision classifiers with state-of-the-art robustness to perturbation-based adversaries constrained by an ℓp norm. result Robustness to perturbation-based adversarial examples does not guarantee general robustness and can increase vulnerability to invariance-based adversarial examples.
This paper explores tradeoffs between invariance and sensitivity in adversarial examples.
problem Understanding the limitations of existing adversarial defenses.
method Study of invariance-based adversarial examples and their impact on model accuracy.
result Adversarial defenses against sensitivity-based attacks can harm invariance-based attacks, necessitating new approaches.
Paper examines NMT robustness to nonsensical inputs.
problem NMT systems fail when source sentences are altered.
method Soft-attention technique to replace words in source sentences.
result Proposed technique achieves high success rate and outperforms existing methods.
We define the fundamental quandle of a spatial graph and several invariants derived from it. In the category of graph tangles, we define an invariant based on the walks in the graph and cocycles from nonabelian quandle cohomology.
Backdoors in deep neural networks are undetectable and enable invariance-based adversarial examples.
problem Statistically undetectable backdoors in deep neural networks.
method Adversarial model trainer method to plant backdoors, showing invariance-based adversarial examples.
result Backdoors are statistically undetectable and enable generation of adversarial examples for every input.
We propose a modification of the three-manifold invariant based on the use of Euclidean metric values ascribed to the elements of manifold triangulation. We thus obtain a nontrivial invariant that can, in particular, distinguish non-homeomorphic lens spaces.
This article is a continuation of work on construction and calculation various of modifications of invariant based on the use Euclidean metric values attributed to elements of manifold triangulation. We again address the well investigated lens spaces as a standard tool for checking the nontriviality of topological inva…
We observe that most known results of the form "v is not a finite-type invariant" follow from two basic theorems. Among those invariants which are not of finite type, we discuss examples which are "ft-independent" and examples which are not. We introduce (n,q)-finite invariants, which are generalizations of finite-type…
We define a graph algebra version of the stationary phase integration over the coadjoint orbits in the Reshetikhin formula for the colored Jones-HOMFLY polynomial. As a result, we obtain a `universal' U(1)-RCC invariant of links in rational homology spheres, which determines the U(1)-RCC invariants based on simple Lie …
Diagrammatic method calculates knot invariant from tangle decompositions.
problem Computing Rasmussen's invariant for knots.
method Diagrammatic approach using tangles and cobordisms.
result Computed s-invariants of all 3-strand pretzel knots. AFLAC improves domain generalization by balancing invariance and accuracy.
problem Balancing domain invariance and classification accuracy for domain generalization.
method Adversarial feature learning with accuracy constraint (AFLAC).
result AFLAC outperforms domain-invariance-based methods on synthetic and real-world datasets.
Mutation is an operation on 3-manifolds containing an embedded surface of genus 2. It is defined by cutting along the surface and regluing using the `hyperelliptic' involution, and is known to preserve many 3-manifold invariants. I show that mutation of a homology 3-sphere preserves its (instanton) Floer homology, and …
New formula for instantaneous frequency in unbalanced systems.
problem Estimating frequency in unbalanced electrical systems.
method Utilizes affine differential geometry to link frequency and voltage derivatives.
result Proposes a new formula for instantaneous frequency estimation.
Polynomial invariant derived from birack labelling of knots.
problem Developing a polynomial invariant for a broader class of knot theories.
method Generalizing biquandle colouring to birack labelling, reducing to biquandle invariant.
result Polynomial invariant for a class of knot theories.
We construct non-semisimple 2+1-TQFTs yielding mapping class group representations in Lyubashenko's spaces. In order to do this, we first generalize Beliakova, Blanchet and Geer's logarithmic Hennings invariants based on quantum sl2 to the setting of finite-dimensional non-degenerate unimodular ribbon H…
Optimizes atomic descriptors to reduce redundancy and improve machine learning models.
problem Redundant descriptors in atomistic machine learning models increase computational burden and limit model expressivity.
method Employing techniques from pattern recognition, we refine and augment existing atomistic representations to produce optimal sets of descriptors.
result New architectures recognize up to 5-body patterns with low computational cost and high accuracy.
New algebraic setup defines quantum link invariants.
problem Defining and controlling quantum link invariants.
method Quantum Schur--Weyl duality and variants.
result Global definitions of quantum polynomials.
This is the second part of an article in two parts, which builds the foundation of a Floer-theoretic invariant, I_F. (See math.DG/0111313 for part I). Having constructed I_F and outlined a proof of its invariance based on bifurcation analysis in part I, in this part we prove a series of gluing theorems to confirm the b…
It is natural to try to place the new polynomial invariants of links in algebraic topology (e.g. to try to interpret them using homology or homotopy groups). However, one can think that these new polynomial invariants are byproducts of a new more delicate algebraic invariant of 3-manifolds which measures the obstructio…
This paper detects multi-stage Feint Attacks using Bi-RNN and few-shot learning.
problem Detecting multi-stage Feint Attacks due to lack of professional datasets and semantic relationships.
method Fuzzy clustering for attack chain mining, few-shot deep learning, Bi-RNN for feature extraction.
result Accurately detected Feint Attacks using Bi-RNN and few-shot learning.
This paper studies adversarial attacks on Gaussian process bandits.
problem Adversarial attacks on Gaussian process bandits to manipulate optimal function regions.
method Proposes various adversarial attack methods on GP bandits, including white-box and black-box attacks.
result Adversarial attacks can force GP bandits to optima in target regions even with low attack budgets.
In this paper, we begin constructing a new finite-dimensional topological quantum field theory (TQFT) for three-manifolds, based on group PSL(2,C) and its action on a complex variable by fractional-linear transformations, by providing its key ingredient -- a new type of chain complexes. As these complexes happen to be …
We study quantum invariant Z(M) for cusped hyperbolic 3-manifold M. We construct this invariant based on oriented ideal triangulation of M by assigning to each tetrahedron the quantum dilogarithm function, which is introduced by Faddeev in studies of the modular double of the quantum group. Following Thurston and Neuma…
Subpopulation attacks poison data to misclassify naturally distributed points.
problem Improving accuracy of machine learning predictions through adversarial data modification.
method Introducing a novel subpopulation attack framework, using influence functions and gradient optimization.
result Subpopulation attacks are effective and stealthy, making them difficult to defend against.
Efficient attacks on DRL models without model access and low computation.
problem Vulnerabilities of DRL models to adversarial attacks.
method Adapting black-box attacks, introducing efficient online sequential attacks, exploring perturbations in environment dynamics, and generating robust physical perturbations.
result Demonstrated the effectiveness of proposed attacks on real-world robots.
Reward-poisoning attacks can force RL agents to learn bad policies, and we categorize and quantify their feasibility.
problem Reward-poisoning attacks can manipulate RL agents to learn undesirable policies.
method Categorize attacks by infinity-norm constraint, provide thresholds for feasibility, and develop adaptive attack strategies.
result Adaptive reward-poisoning attacks can achieve the nefarious policy in polynomial steps, while non-adaptive attacks require exponential steps.
Spanning attack improves black-box attacks with unlabeled data.
problem Query inefficiency in black-box attacks due to high input space dimensionality.
method Proposes spanning attack by constraining adversarial perturbations in a low-dimensional subspace via an auxiliary unlabeled dataset.
result Significantly improves query efficiency of black-box attacks.
Headless attacks bypass classification heads to fool transfer learning models.
problem Adversarial attacks against transfer learning models without access to the classification head.
method Label-blind adversarial attacks that do not require class-label information.
result Transfer attack lowers ResNet18 accuracy on CIFAR10 by over 40%.
New attack manipulates UCB algorithm, new defense algorithm reduces pseudo-regret.
problem Adversarial attacks on stochastic bandit algorithms.
method Introducing action-manipulation attacks and proposing a robust defense algorithm.
result Proposed defense algorithm reduces pseudo-regret to O(max{log T, A}).
This paper explores evasion attacks against Bayesian models.
problem Bayesian predictive models are vulnerable to evasion attacks.
method Developed gradient-based attacks for specific point predictions and entire posterior distributions.
result Optimal evasion attacks can be designed against Bayesian models.
Adversarial attacks pose a threat to deep neural networks, especially in safety-critical applications.
problem Adversarial attacks can misclassify deep neural networks, leading to safety issues.
method Adversarial attacks are categorized into white-box and black-box attacks based on the attacker's knowledge. They can be targeted or non-targeted.
result Adversarial attacks are effective and can transfer between different models and real-world scenarios.
A new adversarial attack improves model perturbation efficiency.
problem Improving adversarial attacks to better perturb images.
method LogBarrier method for solving constrained minimization problem.
result LogBarrier attack performs better on challenging images.
Adversarial attacks hide cyber-physical attacks in ICS.
problem Hiding cyber-physical attacks in industrial control systems.
method Modeling an attacker compromising sensors, manipulating data, and evaluating attacks on both continuous and mixed data.
result Successfully hides cyber-physical attacks with 2.87 out of 12 sensors compromised on average.
New approach deflects adversarial attacks by causing them to resemble target classes.
problem Ongoing cycle of stronger defenses being broken by more advanced attacks.
method Combines three detection mechanisms in Capsule Networks to achieve state-of-the-art performance on both standard and defense-aware attacks. Uses human study to show attacks can no longer be called adversarial.
result Attack images can no longer be called adversarial because they are classified the same way as humans do.
This paper optimizes attacks on reinforcement learning policies, reducing their effectiveness.
problem Optimizing adversarial attacks on reinforcement learning policies to minimize rewards.
method Designing optimal attacks for both white-box and black-box scenarios using Markov Decision Processes and Reinforcement Learning.
result Optimal attacks can reduce the effectiveness of reinforcement learning policies, especially for smooth policies.
New defense method against physical attacks on image classification models.
problem Defending against physically realizable attacks on image classification models.
method Proposed a new abstract adversarial model, rectangular occlusion attacks, and developed two approaches for efficiently computing adversarial examples.
result Adversarial training using the new attack yields robust image classification models against physical attacks.
A structured approach to generating adversarial attacks for ML systems.
problem Vulnerability of ML systems to adversarial perturbations.
method Developed an 'attack generator' to systematically create adversarial attacks.
result Summarized and extended existing adversarial perturbation taxonomies.
RayS attack improves hard-label adversarial attacks by reducing query complexity and identifying false robust models.
problem Challenges in hard-label adversarial attacks, especially in terms of effectiveness and efficiency.
method Reformulates continuous problem into discrete problem without gradient estimation and uses a fast check step to eliminate unnecessary searches.
result Significantly reduces the number of queries needed for hard-label attacks and identifies false robust models.
New attacks on RL agents' action space improve understanding of cyber-physical systems vulnerabilities.
problem Understanding and improving the robustness of RL agents in CPS against action space attacks.
method Proposed white-box MAS and LAS attack algorithms to optimize and temporally couple attack budgets.
result LAS attacks cause significantly more performance degradation than MAS attacks.
Depending on how much information an adversary can access to, adversarial attacks can be classified as white-box attack and black-box attack. For white-box attack, optimization-based attack algorithms such as projected gradient descent (PGD) can achieve relatively high attack success rates within moderate iterates. How…
New method handles uncertainty in adversarial attacks using ensemble noise simulation.
problem Uncertainty in adversarial attacks on neural networks.
method Simulates attacker's noisy perturbation using various gradient-based attack algorithms and a pre-processing Denoising Autoencoder (DAE) defense.
result Significant improvements in post-attack accuracy with the proposed ensemble-trained defense.
New attacks reveal membership in label-only ML models.
problem Vulnerability of ML models to membership inference attacks.
method Developed decision-based membership inference attacks.
result Label-only exposures are vulnerable to membership leakage.
Paper creates universal adversarial attacks.
problem Creating universal, transferable, and targeted adversarial attacks.
method Learn a universal mapping to map sources to adversarial examples.
result Examples can fool networks into classifying all into one targeted class and have strong transferability.
Defends against ML inference attacks using adversarial examples.
problem Automated inference attacks using ML classifiers pose privacy and security threats.
method Turns ML classifier vulnerabilities into defenses by adding adversarial noise to public data.
result Adversarial examples can mislead ML classifiers and protect private data.
This paper proposes multi-view attack strategies for deep models.
problem Vulnerability of multi-view deep models to adversarial attacks.
method Two multi-view attack strategies: two-stage attack (TSA) and end-to-end attack (ETEA).
result Proposed multi-view attack strategies are effective on multi-view deep models.
New attacks can infer model training membership using only label predictions, not confidence.
problem Inferring whether a data point was used to train a machine learning model.
method Evaluate model's predicted labels under perturbations to infer membership.
result Label-only attacks perform as well as confidence-based attacks and break defenses that rely on confidence masking.
Paper studies attacks on bandit algorithms and shows how attackers can manipulate data to hijack behavior.
problem Potential attacks on bandit algorithms can cause catastrophic loss in real-world applications.
method Proposes a framework of offline and online attacks on bandit algorithms using convex optimization and adaptive strategies.
result Attackers can force bandit algorithms to pull target arms with high probability by manipulating data.
Efficiently attacks large-scale graphs without using the whole graph.
problem Vulnerability of graph neural networks to adversarial attacks.
method Simplified Gradient-based Attack (SGA) method for large-scale graphs.
result SGA achieves significant time and memory efficiency improvements.