AAT separates robust and non-robust features without supervision.
arXiv research
A locally-built, LLM-digested index of recent arXiv papers in quant finance, geometry/topology, and statistical ML — keyword search served straight from SQLite on this machine.
Trend · papers per month
Batch normalization shifts models to rely more on non-robust features.
The vulnerability to slight input perturbations is a worrying yet intriguing property of deep neural networks (DNNs). Despite many previous works studying the reason behind such adversarial behavior, the relationship between the generalization performance and adversarial behavior of DNNs is still little understood. In …
Recent works show that Graph Neural Networks (GNNs) are highly non-robust with respect to adversarial attacks on both the graph structure and the node attributes, making their outcomes unreliable. We propose the first method for certifiable (non-)robustness of graph convolutional networks with respect to perturbations …
Graph Random Neural Network improves semi-supervised learning on graphs.
Gradient descent biases neural networks to use an average of features, leading to non-robustness.
Defense against user shilling attacks in collaborative filtering using edge reweighting.
Study uses RL to hedge financial derivatives, showing robust strategies outperform non-robust ones.
Bayesian investor learns unknown asset drift, trades mean-variance optimal portfolio, but policy is robust to observation model distortion.
Federated learning is the centralized training of statistical models from decentralized data on mobile devices while preserving the privacy of each device. We present a robust aggregation approach to make federated learning robust to settings when a fraction of the devices may be sending corrupted updates to the server…
New datasets reveal neural networks can rely on simple features, leading to poor generalization.
Detects adversarial directions to make reinforcement learning policies more robust.
Study analyzes and enhances robustness of neural networks for classification and regression.
New algorithm improves RL performance across different environments.
It has been shown that instead of learning actual object features, deep networks tend to exploit non-robust (spurious) discriminative features that are shared between training and test sets. Therefore, while they achieve state of the art performance on such test sets, they achieve poor generalization on out of distribu…
Improves robust transfer learning with side information.
DVERGE diversifies adversarial vulnerabilities to enhance robust ensemble models.
DRO-REBEL improves LLM alignment by robustly updating models online.
The paper tackles robust classification trees for distribution shifts, improving accuracy in public health and social work.
This paper provides a non-robust interpretation of the distributionally robust optimization (DRO) problem by relating the distributional uncertainties to the chance probabilities. Our analysis allows a decision-maker to interpret the size of the ambiguity set, which is often lack of business meaning, through the chance…
We investigate the possibility of statistical evaluation of the market completeness for discrete time stock market models. It is known that the market completeness is not a robust property: small random deviations of the coefficients convert a complete market model into a incomplete one. The paper shows that market inc…
Adversarial examples have attracted significant attention in machine learning, but the reasons for their existence and pervasiveness remain unclear. We demonstrate that adversarial examples can be directly attributed to the presence of non-robust features: features derived from patterns in the data distribution that ar…
Recent studies on the adversarial vulnerability of neural networks have shown that models trained to be more robust to adversarial attacks exhibit more interpretable saliency maps than their non-robust counterparts. We aim to quantify this behavior by considering the alignment between input image and saliency map. We h…
Framework for robust control under model uncertainty, improving financial derivatives hedging.
Generative adversarial networks (GANs) are designed with the help of min-max optimization problems that are solved with stochastic gradient-type algorithms which are known to be non-robust. In this work we revisit a non-adversarial method based on kernels which relies on a pure minimization problem and propose a simple…
In recent years several adversarial attacks and defenses have been proposed. Often seemingly robust models turn out to be non-robust when more sophisticated attacks are used. One way out of this dilemma are provable robustness guarantees. While provably robust models for specific -perturbation models have been dev…
We continue the study of statistical/computational tradeoffs in learning robust classifiers, following the recent work of Bubeck, Lee, Price and Razenshteyn who showed examples of classification tasks where (a) an efficient robust classifier exists, in the small-perturbation regime; (b) a non-robust classifier can be l…
Variational inference is a powerful tool for approximate inference. However, it mainly focuses on the evidence lower bound as variational objective and the development of other measures for variational inference is a promising area of research. This paper proposes a robust modification of evidence and a lower bound for…
Despite the exploding interest in graph neural networks there has been little effort to verify and improve their robustness. This is even more alarming given recent findings showing that they are extremely vulnerable to adversarial attacks on both the graph structure and the node attributes. We propose the first method…
We solve robust optimization problems using Wasserstein balls and apply it to mean-CVaR optimization.
Social Security and other public policies can be viewed as a series of cash in and outflows that depend on parameters such as the age distribution of the population and the retirement age. Given forecasts of these parameters, policies can be designed to be financially stable, i.e., to terminate with a zero balance. If …
Study examines noise sensitivity of DNNs for binary classification.
New algorithm estimates eigenspace with faulty nodes, matching performance of existing methods.
Recently, interpretable models called self-explaining models (SEMs) have been proposed with the goal of providing interpretability robustness. We evaluate the interpretability robustness of SEMs and show that explanations provided by SEMs as currently proposed are not robust to adversarial inputs. Specifically, we succ…
The possibility of statistical evaluation of the market completeness and incompleteness is investigated for continuous time diffusion stock market models. It is known that the market completeness is not a robust property: small random deviations of the coefficients convert a complete market model into a incomplete one.…
RATIO improves neural network robustness and explainability.
Paper improves sample complexity for robust reinforcement learning.
Proposes a new VAE framework for anomaly detection in time series data.
Two-layer networks trained on low-dimensional subspaces are vulnerable to adversarial examples.
Synthesizes robust estimators for domain adaptation.
We study issues of robustness in the context of Quantitative Risk Management and Optimization. We develop a general methodology for determining whether a given risk measurement related optimization problem is robust, which we call "robustness against optimization". The new notion is studied for various classes of risk …
Improves natural accuracy of deep learning models by combining robust predictions and features.
Study quantifies model risk in dynamic portfolio selection using KL divergence.
Robust reinforcement learning aims to produce policies that have strong guarantees even in the face of environments/transition models whose parameters have strong uncertainty. Existing work uses value-based methods and the usual primitive action setting. In this paper, we propose robust methods for learning temporally …
Gradient flow in ReLU networks biases towards generalization but makes them vulnerable to adversarial attacks.
Study shows semi-supervised learning can be more robust with fewer labeled examples.
Deep RL policies share adversarial features across different MDPs.
Paper proposes an algorithm for robust estimation using Huber's criterion.