EVILL uses randomised perturbations to improve exploration in bandit problems.
arXiv research
A locally-built, LLM-digested index of recent arXiv papers in quant finance, geometry/topology, and statistical ML — keyword search served straight from SQLite on this machine.
Trend · papers per month
Develops new methods to create imperceptible image changes that fool classifiers.
We present an algorithm for computing class-specific universal adversarial perturbations for deep neural networks. Such perturbations can induce misclassification in a large fraction of images of a specific class. Unlike previous methods that use iterative optimization for computing a universal perturbation, the propos…
Perturbation theory improves nonparametric instrumental variable estimation accuracy.
This work improves explanation quality for time series predictions by learning perturbations.
In this paper, we propose novel generative models for creating adversarial examples, slightly perturbed images resembling natural images but maliciously crafted to fool pre-trained models. We present trainable deep neural networks for transforming images to adversarial perturbations. Our proposed models can produce ima…
Adversarial training, in which a network is trained on both adversarial and clean examples, is one of the most trusted defense methods against adversarial attacks. However, there are three major practical difficulties in implementing and deploying this method - expensive in terms of extra memory and computation costs; …
New method proves inequalities for self-shrinkers using perturbation.
Study linear perturbations of Spin(7) metrics, finding only rank one nilpotent matrices.
Simple regional perturbations maintain model transferability while reducing adversarial example distortion.
DIP-FAT improves adversarial training by diversifying perturbations.
Meta framework generates noise to improve multi-attack robustness.
The paper tackles extrapolation of gene knockouts effects on RNA counts.
We demonstrate the existence of universal adversarial perturbations, which can fool a family of audio classification architectures, for both targeted and untargeted attack scenarios. We propose two methods for finding such perturbations. The first method is based on an iterative, greedy approach that is well-known in c…
Differentiable clustering method using perturbed spanning forests.
Adversarial perturbations fool deepfake detectors with high accuracy.
New method GSAT improves robustness against structured perturbations.
ContrastiveVI+ models CRISPR screens with noisy guide efficiency.
Saliency methods can make deep neural network predictions more interpretable by identifying a set of critical features in an input sample, such as pixels that contribute most strongly to a prediction made by an image classifier. Unfortunately, recent evidence suggests that many saliency methods poorly perform, especial…
While several feature scoring methods are proposed to explain the output of complex machine learning models, most of them lack formal mathematical definitions. In this study, we propose a novel definition of the feature score using the maximally invariant data perturbation, which is inspired from the idea of adversaria…
Recent advances show that deep neural networks are not robust to deliberately crafted adversarial examples which many are generated by adding human imperceptible perturbation to clear input. Consider norms attacks, Project Gradient Descent (PGD) and the Carlini and Wagner (C\&W) attacks are the two main methods, …
In this paper, we propose a perturbation framework to measure the robustness of graph properties. Although there are already perturbation methods proposed to tackle this problem, they are limited by the fact that the strength of the perturbation cannot be well controlled. We firstly provide a perturbation framework on …
Gradient perturbation, widely used for differentially private optimization, injects noise at every iterative update to guarantee differential privacy. Previous work first determines the noise level that can satisfy the privacy requirement and then analyzes the utility of noisy gradient updates as in the non-private cas…
Study of free particle's geometry and its perturbations using complex projective structures.
A new approach to maximum likelihood learning of discrete graphical models and RBM in particular is introduced. Our method, Perturb and Descend (PD) is inspired by two ideas (I) perturb and MAP method for sampling (II) learning by Contrastive Divergence minimization. In contrast to perturb and MAP, PD leverages trainin…
Generative Intervention Models predict perturbation effects without knowing the underlying mechanisms.
The paper constructs new bimetric conformal invariants using metric perturbations.
In general, adversarial perturbations superimposed on inputs are realistic threats for a deep neural network (DNN). In this paper, we propose a practical generation method of such adversarial perturbation to be applied to black-box attacks that demand access to an input-output relationship only. Thus, the attackers gen…
A new method for generating SPX and VIX risk scenarios using perturbed optimal transport.
A new method speeds up sampling of Boltzmann distribution in high-dimensional systems.
PRoA assesses deep learning robustness against practical functional perturbations.
Improved generalization with semantic perturbations using normalizing flows.
This paper proposes a new algorithm for controlling classification results by generating a small additive perturbation without changing the classifier network. Our work is inspired by existing works generating adversarial perturbation that worsens classification performance. In contrast to the existing methods, our wor…
Beyond existing multi-view clustering, this paper studies a more realistic clustering scenario, referred to as incomplete multi-view clustering, where a number of data instances are missing in certain views. To tackle this problem, we explore spectral perturbation theory. In this work, we show a strong link between per…
This paper introduces metrics to evaluate robustness of neural networks to natural adversarial examples.
Deep networks have recently been shown to be vulnerable to universal perturbations: there exist very small image-agnostic perturbations that cause most natural images to be misclassified by such classifiers. In this paper, we propose the first quantitative analysis of the robustness of classifiers to universal perturba…
In this paper we investigate the usage of adversarial perturbations for the purpose of privacy from human perception and model (machine) based detection. We employ adversarial perturbations for obfuscating certain variables in raw data while preserving the rest. Current adversarial perturbation methods are used for dat…
Deep learning has become the state of the art approach in many machine learning problems such as classification. It has recently been shown that deep learning is highly vulnerable to adversarial perturbations. Taking the camera systems of self-driving cars as an example, small adversarial perturbations can cause the sy…
Machine learning models have been shown vulnerable to adversarial attacks launched by adversarial examples which are carefully crafted by attacker to defeat classifiers. Deep learning models cannot escape the attack either. Most of adversarial attack methods are focused on success rate or perturbations size, while we a…
Improved online Lasso reduces regret in sparse linear contextual bandits.
Deep neural networks are susceptible to adversarial manipulations in the input domain. The extent of vulnerability has been explored intensively in cases of -bounded and -minimal adversarial perturbations. However, the vulnerability of DNNs to adversarial perturbations with specific statistical properti…
Study reveals class-dependent effects in perturbation-based feature attribution metrics for time series classification.
Adversarial examples are intentionally perturbed images that mislead classifiers. These images can, however, be easily detected using denoising algorithms, when high-frequency spatial perturbations are used, or can be noticed by humans, when perturbations are large. In this paper, we propose EdgeFool, an adversarial im…
New method proves instability of naked singularity and censors it.
New method improves neural network training by scaling perturbations layerwise.
New method identifies latent variables with sparse perturbations.
The paper develops new methods to approximate ruin probabilities in a perturbed risk model.
In this work we prove the fact that, for a short time, it is possible to construct a smooth parametrized family of isometric embeddings of an arbitrary smooth parametrized family of Riemannian metrics on a smooth closed manifold into an Euclidean space. In order to prove this statement we work out stability estimates w…