Improved algorithm speeds up generation of universal adversarial perturbations.
problem Slow generation of universal adversarial perturbations.
method Optimized algorithm based on orientation of perturbation vectors.
result Significantly faster generation of universal perturbations with higher fooling rates.
This paper presents a new approach, called perturb-max, for high-dimensional statistical inference that is based on applying random perturbations followed by optimization. This framework injects randomness to maximum a-posteriori (MAP) predictors by randomly perturbing the potential function for the input. A classic re…
The paper tackles extrapolation of gene knockouts effects on RNA counts.
problem Modeling effects of gene knockouts on RNA counts for new perturbations.
method Formulated as a latent variable model with additive perturbation effects, proved identifiability, proposed PDAE for estimation.
result PDAE can accurately predict effects of unseen but identifiable perturbations.
Novel geometry-informed irreversible perturbation accelerates Langevin dynamics convergence.
problem Accelerating convergence of Langevin dynamics for Bayesian computation.
method Geometry-informed irreversible perturbation of Riemannian manifold Langevin dynamics.
result Improves estimation performance over irreversible perturbations that ignore geometry.
Study linear perturbations in Schwarzschild black hole spacetime.
problem Linear perturbations of Schwarzschild black hole spacetime.
method Investigate linearised perturbation of constant mass aspect function foliation at null infinity.
result Linearised perturbations of Bondi energy and mass vanish, and all linear momentum can be achieved.
New research evaluates various perturbation methods for improving neural network robustness.
problem Understanding and improving robustness of Convolutional Neural Networks (CNNs) against adversarial attacks.
method Detailed evaluation of five main perturbation-based defenses, comparing random and deterministic approaches.
result Perturbation-based defenses are equivalent in efficacy, and attacks transfer between them.
We study the transfer of adversarial robustness of deep neural networks between different perturbation types. While most work on adversarial examples has focused on L ∞ L_\infty L ∞ and L 2 L_2 L 2 -bounded perturbations, these do not capture all types of perturbations available to an adversary. The present work evaluates 32 attack…
EVILL uses randomised perturbations to improve exploration in bandit problems.
problem Improving exploration in structured stochastic bandit problems.
method Solves for the minimiser of a linearly perturbed regularised negative log-likelihood function.
result EVILL matches the performance of Thompson-sampling-style methods in theory and practice.
New bifurcation found in perturbations of non-generic closed self-shrinkers.
problem Understanding the behavior of perturbations in non-generic closed self-shrinkers.
method Analyzing the mean curvature flow singularity transitions.
result Different types of singularity transitions based on perturbation direction.
Adversarial perturbations fool deepfake detectors with high accuracy.
problem Improving deepfake detection accuracy against adversarial attacks.
method Used adversarial perturbations and two defenses: Lipschitz regularization and Deep Image Prior (DIP).
result Deepfake detectors achieved 27% accuracy on perturbed images, compared to 95% on unperturbed.
Advances FTPL results for bandit problems with unbounded perturbations.
problem Improving analytical foundations of FTPL in bandit problems.
method Revisiting classical FTRL-FTPL duality for unbounded perturbations.
result Establishes Best-of-Both-Worlds (BOBW) results for FTPL under a broad family of asymmetric unbounded perturbations.
Generative Intervention Models predict perturbation effects without knowing the underlying mechanisms.
problem Predicting perturbation effects when the mechanisms are unknown.
method Generative Intervention Models (GIM) that map perturbation features to distributions over atomic interventions in a causal model.
result GIMs achieve robust out-of-distribution predictions and infer underlying perturbation mechanisms.
Identifies all perturbative vacua in bosonic string theory.
problem Identifying all perturbative vacua in bosonic string theory.
method Completely identified perturbative vacua through string fluctuations.
result Derivation of path-integrals up to any order from fluctuations.
Develops new methods to create imperceptible image changes that fool classifiers.
problem Improving the robustness of image classifiers by creating subtle changes undetectable to humans.
method Two methods: Edge-Aware and Color-Aware, designed to reduce detectability of image perturbations.
result Demonstrated that the new methods effectively cause misclassification and are computationally efficient.
Charge measurements for instantons and gravitational perturbations.
problem Evaluating charges in Hermitian non-Kähler Einstein 4-manifolds and their perturbations.
method Evaluation of charges via Killing spinors and perturbation analysis of gravitational instantons.
result Generic gravitational perturbations admit a closed 2-form measuring the charge change.
Eigenvalues of Steklov eigenproblems change predictably with boundary tweaks.
problem Understanding how Steklov eigenvalues respond to boundary changes.
method Analyzing smooth boundary perturbations of Steklov eigenvalues.
result Steklov eigenvalues are generically simple under such perturbations.
Study linear perturbations of Spin(7) metrics, finding only rank one nilpotent matrices.
problem Linear perturbations of Spin(7) metrics.
method Applying the method of linear perturbations to Spin(7)-structures.
result Only rank one nilpotent matrices determine nontrivial perturbations.
Simple perturbation of Vafa-Witten equations leads to transversality.
problem Transversality of Vafa-Witten moduli space.
method Simple perturbation of Vafa-Witten equations, proving transversality for S U ( 2 ) SU(2) S U ( 2 ) or S O ( 3 ) SO(3) S O ( 3 ) structure groups. result For generic perturbation parameter, the full rank part of the moduli space satisfies transversality.
We developed a perturbation model for affine gravity theories.
problem Cosmological perturbations in theories without metric.
method Segregated perturbations into symmetric and antisymmetric components, decomposing into irreducible elements.
result Fully addressed gauge freedom in affine gravity theories.
Classifiers such as deep neural networks have been shown to be vulnerable against adversarial perturbations on problems with high-dimensional input space. While adversarial training improves the robustness of image classifiers against such adversarial perturbations, it leaves them sensitive to perturbations on a non-ne…
DBPA assesses LLM perturbations using frequentist hypothesis testing.
problem Quantifying input perturbation impacts on LLM outputs.
method DBPA reformulates perturbation analysis as frequentist hypothesis testing, using Monte Carlo sampling for empirical null and alternative distributions.
result DBPA provides interpretable p-values and scalar effect sizes for LLM perturbations.
The paper learns perturbation sets from data to improve robustness in machine learning.
problem Real-world perturbations are not well characterized in adversarial defenses.
method A conditional generator defines perturbation sets over latent space, with properties for quality measured.
result Learned perturbation sets generate diverse, meaningful perturbations and improve model robustness.
Adversarial training, in which a network is trained on both adversarial and clean examples, is one of the most trusted defense methods against adversarial attacks. However, there are three major practical difficulties in implementing and deploying this method - expensive in terms of extra memory and computation costs; …
A fast method computes class-specific adversarial perturbations for deep networks.
problem Computing robust adversarial perturbations for deep networks.
method Linear function of weights, no training data, no hyper-parameters.
result Obtains 34% to 51% fooling rate on ImageNet, transfers across models.
Study metric perturbations to make degenerate harmonic forms non-degenerate.
problem Dealing with degenerate harmonic 1-forms in Riemannian geometry.
method Combining analysis of local expansions with Nash-Moser implicit function theorem.
result Proves deformation to nearby non-degenerate Z/2-harmonic 1-forms.
In this paper we investigate the usage of adversarial perturbations for the purpose of privacy from human perception and model (machine) based detection. We employ adversarial perturbations for obfuscating certain variables in raw data while preserving the rest. Current adversarial perturbation methods are used for dat…
Given a state-of-the-art deep neural network text classifier, we show the existence of a universal and very small perturbation vector (in the embedding space) that causes natural text to be misclassified with high probability. Unlike images on which a single fixed-size adversarial perturbation can be found, text is of …
The paper proves new theorems about specific types of operator perturbations.
problem Analyzing conformal perturbations of Dirac and signature operators.
method Developed Kastler-Kalau-Walze type theorems for specific operator types.
result Established new theorems for six-dimensional manifolds with boundary.
The study reveals how adversarial perturbations can include class features for generalization.
problem Understanding why adversarial examples deceive neural networks and transfer between networks.
method A one-hidden-layer network trained on mutually orthogonal samples.
result Adversarial perturbations, even of a few pixels, contain sufficient class features for generalization.
Deep networks have recently been shown to be vulnerable to universal perturbations: there exist very small image-agnostic perturbations that cause most natural images to be misclassified by such classifiers. In this paper, we propose the first quantitative analysis of the robustness of classifiers to universal perturba…
Improved online Lasso reduces regret in sparse linear contextual bandits.
problem Sparse linear contextual bandit problem with inefficient sampling.
method Perturbed adversary approach to alleviate sampling inefficiency.
result Online Lasso achieves O ( k T log d ) \mathcal{O}(\sqrt{kT\log d}) O ( k T log d ) regret bound. New method μ P 2 μP^2 μ P 2 improves neural network training by scaling perturbations layerwise.
problem Improving neural network performance as models scale up.
method Layerwise perturbation scaling in the infinite-width limit of neural networks.
result Layerwise perturbation scaling ensures all layers are effectively perturbed in the limit.
Paper proposes a method to generate adversarial perturbations for black-box attacks without accessing inner states.
problem Generating adversarial perturbations for black-box attacks without accessing inner states of a DNN.
method Matrix-free generation method that requires fewer query trials.
result The proposed method successfully deceives a DNN for semantic segmentation more effectively than random noise.
Deep neural networks are susceptible to adversarial manipulations in the input domain. The extent of vulnerability has been explored intensively in cases of ℓ p \ell_p ℓ p -bounded and ℓ p \ell_p ℓ p -minimal adversarial perturbations. However, the vulnerability of DNNs to adversarial perturbations with specific statistical properti…
New metric scores perturbations across populations, not cells, improving model comparison.
problem Single-cell perturbation data overlaps, making per-cell accuracy unreliable.
method Average per-cell probability vectors over all cells of a perturbation to form a population profile and rank candidate perturbations.
result Classifier Discrimination Score (CDS) identifies true perturbation more reliably than pseudobulk-based scores.
In this paper, we propose a perturbation framework to measure the robustness of graph properties. Although there are already perturbation methods proposed to tackle this problem, they are limited by the fact that the strength of the perturbation cannot be well controlled. We firstly provide a perturbation framework on …
This work improves explanation quality for time series predictions by learning perturbations.
problem Explaining predictions on multivariate time series data with time dependencies.
method Learning both masks and associated perturbations to explain predictions.
result Learning perturbations significantly improves explanation quality on time series data.
The paper studies perturbations of de Rham Hodge operators on manifolds with or without boundaries.
problem Analyzing perturbations of de Rham Hodge operators on manifolds with boundaries.
method Lichnerowicz type formulas and Kastler-Kalau-Walze type theorems for 4D and 6D compact manifolds with or without boundaries.
result Proves Kastler-Kalau-Walze type theorems for perturbations of de Rham Hodge operators on 4D and 6D manifolds with or without boundaries.
This paper establishes transversality for perturbed Vafa-Witten moduli spaces on 4-manifolds.
problem Transversality of Vafa-Witten moduli spaces on 4-manifolds with C ≡ 0 C\equiv0 C ≡ 0 . method Constructing perturbation terms to ensure the moduli space is a smooth manifold of dimension zero.
result For generic perturbation terms, the moduli space of solutions is a smooth manifold of dimension zero.
New adversarial training methods generate multiplicative perturbations for robust DNN training.
problem Training Deep Neural Networks with adversarial examples to improve robustness.
method Proposes xAT and xVAT, generating multiplicative perturbations for robust training.
result xAT and xVAT match or outperform state-of-the-art classification accuracies and are faster.
ContrastiveVI+ models CRISPR screens with noisy guide efficiency.
problem Noisy guide efficiency in CRISPR screens.
method Generative modeling framework that disentangles perturbation-induced from shared variations.
result ContrastiveVI+ better recovers perturbation-induced variations and identifies cells without edits.
If we consider the moduli space of flat connections of a non trivial principal SO(3)-bundle over a surface, then we can define a map from the set of perturbed closed geodesics, below a given energy level, into families of perturbed Yang-Mills connections depending on a small parameter. In this paper we show that this m…
The paper examines how gradient descent stabilizes low-rank matrix factorization in noisy conditions.
problem Stability of low-rank implicit regularization in perturbed deep matrix factorization.
method Derives spectral conditions for gradient descent to exhibit a low-rank phase in noiseless settings and analyzes perturbed dynamics.
result Gradient descent converges to a low-rank solution under perturbation, with explicit dependence on perturbation size.
Constructs perturbations of a minimal surface with triple junctions.
problem Minimal surfaces with triple junctions in curved spaces.
method Constructs stationary perturbations with given boundary conditions.
result Constructs minimal surfaces with triple junctions in R 2 i m e s S 1 \mathbb{R}^2 imes \mathbb{S}^1 R 2 im es S 1 . In this paper, we take the first steps towards a novel unified framework for the analysis of perturbations in both the Time and Frequency domains. The identification of type and source of such perturbations is fundamental for monitoring reactor cores and guarantee safety while running at nominal conditions. A 3D Convol…
Investigates fluid flow perturbations using geometric theory.
problem Analyzing linear perturbations in non-equilibrium fluid flows.
method Uses second order variations of the action and Jacobi fields.
result Demonstrates numerical simulations of perturbation dynamics.
The paper proves two theorems for modified Novikov operators under conformal perturbations.
problem Proving theorems for modified Novikov operators under conformal perturbations.
method Two Kastler-Kalau-Walze type theorems for conformal perturbations of modified Novikov Operators on 4D and 6D compact manifolds.
result Obtained two Kastler-Kalau-Walze type theorems for conformal perturbations of modified Novikov Operators.
Perturbation theory improves nonparametric instrumental variable estimation accuracy.
problem Improving nonparametric instrumental variable estimation accuracy in high-dimensional settings.
method Perturbative approach based on physics perturbation theory, extending kernel ridge methods with higher-order corrections.
result First-order perturbative corrections reduce prediction error by up to 99% in high-dimensional ill-defined cases.