This paper presents a new approach, called perturb-max, for high-dimensional statistical inference that is based on applying random perturbations followed by optimization. This framework injects randomness to maximum a-posteriori (MAP) predictors by randomly perturbing the potential function for the input. A classic re…
arXiv research
A locally-built, LLM-digested index of recent arXiv papers in quant finance, geometry/topology, and statistical ML — keyword search served straight from SQLite on this machine.
Trend · papers per month
This work improves structured prediction by learning the balance between signal and random noise.
Recent work has extensively shown that randomized perturbations of neural networks can improve robustness to adversarial attacks. The literature is, however, lacking a detailed compare-and-contrast of the latest proposals to understand what classes of perturbations work, when they work, and why they work. We contribute…
EVILL uses randomised perturbations to improve exploration in bandit problems.
MAP perturbation models have emerged as a powerful framework for inference in structured prediction. Such models provide a way to efficiently sample from the Gibbs distribution and facilitate predictions that are robust to random noise. In this paper, we propose a provably polynomial time randomized algorithm for learn…
Study analyzes perturbations in singular subspaces under random noise.
Improved perturbation reduces matrix condition number to O(n) with minimal storage.
Adding node feature kernels improves GCN robustness to graph perturbations.
We introduce an efficient message passing scheme for solving Constraint Satisfaction Problems (CSPs), which uses stochastic perturbation of Belief Propagation (BP) and Survey Propagation (SP) messages to bypass decimation and directly produce a single satisfying assignment. Our first CSP solver, called Perturbed Blief …
Most random ReLU networks are vulnerable to small, Euclidean adversarial perturbations.
The paper introduces a method to improve adversarial robustness in neural networks using randomized perturbations.
As most natural resources, fisheries are affected by random disturbances. The evolution of such resources may be modelled by a succession of deterministic process and random perturbations on biomass and/or growth rate at random times. We analyze the impact of the characteristics of the perturbations on the management o…
Short proof shows how ridge regression works with random data.
Introduces RPU to explain randomization preference in dynamic settings.
A perturbative approach is used to derive approximations of arbitrary order to estimate high percentiles of sums of positive independent random variables that exhibit heavy tails. Closed-form expressions for the successive approximations are obtained both when the number of terms in the sum is deterministic and when it…
We propose a novel framework for the differentially private ERM, input perturbation. Existing differentially private ERM implicitly assumed that the data contributors submit their private data to a database expecting that the database invokes a differentially private mechanism for publication of the learned model. In i…
A new exploration strategy for contextual bandits reduces regret and is computationally efficient.
Extends randomized smoothing to certify robustness against various threat models and adversarial perturbations.
New method enhances neural network robustness against adversarial attacks.
We investigate two perturbation approaches to overcome conservatism that optimism based algorithms chronically suffer from in practice. The first approach replaces optimism with a simple randomization when using confidence sets. The second one adds random perturbations to its current estimate before maximizing the expe…
It is well-known that classifiers are vulnerable to adversarial perturbations. To defend against adversarial perturbations, various certified robustness results have been derived. However, existing certified robustnesses are limited to top-1 predictions. In many real-world applications, top- predictions are more rel…
Study privacy and accuracy in high-dimensional LASSO with perturbation mechanisms.
Study efficient learning of robust halfspaces with noise.
DIP-FAT improves adversarial training by diversifying perturbations.
Gaussian copulas are widely used in the industry to correlate two random variables when there is no prior knowledge about the co-dependence between them. The perturbed Gaussian copula approach allows introducing the skew information of both random variables into the co-dependence structure. The analytical expression of…
LMC improves sampling from complex distributions using quasi-random sequences.
Paper shows robustness of gradient descent in matrix sensing despite perturbations.
The paper analyzes how random perturbations affect RSVD and its applications.
In this paper we relate the partition function to the max-statistics of random variables. In particular, we provide a novel framework for approximating and bounding the partition function using MAP inference on randomly perturbed models. As a result, we can use efficient MAP solvers such as graph-cuts to evaluate the c…
In general, adversarial perturbations superimposed on inputs are realistic threats for a deep neural network (DNN). In this paper, we propose a practical generation method of such adversarial perturbation to be applied to black-box attacks that demand access to an input-output relationship only. Thus, the attackers gen…
The paper addresses uncertainties in spectral clustering of corrupted data.
The universal perturbative invariants of rational homology spheres can be extracted from the Chern-Simons partition function by combining perturbative and nonperturbative results. We spell out the general procedure to compute these invariants, and we work out in detail the case of Seifert spaces. By extending some prev…
The Davis-Kahan-Wedin theorem describes how the singular subspaces of a matrix change when subjected to a small perturbation. This classic result is sharp in the worst case scenario. In this paper, we prove a stochastic version of the Davis-Kahan-Wedin theorem when the perturbation is a Gaussian rando…
Study of knot invariant growth for twisted knots.
We first analyze the integrated density of states (IDS) of periodic Schrödinger operators on an amenable covering manifold. A criterion for the continuity of the IDS at a prescribed energy is given along with examples of operators with both continuous and discontinuous IDS'. Subsequently, alloy-type perturbations of th…
We study two randomized algorithms for generalized linear bandits. The first, GLM-TSL, samples a generalized linear model (GLM) from the Laplace approximation to the posterior distribution. The second, GLM-FPL, fits a GLM to a randomly perturbed history of past rewards. We analyze both algorithms and derive $\tilde{O}(…
We consider a neural network architecture with randomized features, a sign-splitter, followed by rectified linear units (ReLU). We prove that our architecture exhibits robustness to the input perturbation: the output feature of the neural network exhibits a Lipschitz continuity in terms of the input perturbation. We fu…
Improved online Lasso reduces regret in sparse linear contextual bandits.
New method improves matrix completion accuracy, especially in noisy data.
Classical matrix perturbation results, such as Weyl's theorem for eigenvalues and the Davis-Kahan theorem for eigenvectors, are general purpose. These classical bounds are tight in the worst case, but in many settings sub-optimal in the typical case. In this paper, we present perturbation bounds which consider the natu…
We show how to turn any classifier that classifies well under Gaussian noise into a new classifier that is certifiably robust to adversarial perturbations under the norm. This "randomized smoothing" technique has been proposed recently in the literature, but existing guarantees are loose. We prove a tight robu…
Paper defends deep learning classifiers against channel-aware adversarial attacks.
Wide networks learn from adversarial perturbations effectively.
We regard pre-trained residual networks (ResNets) as nonlinear systems and use linearization, a common method used in the qualitative analysis of nonlinear systems, to understand the behavior of the networks under small perturbations of the input images. We work with ResNet-56 and ResNet-110 trained on the CIFAR-10 dat…
Overparametrized models are vulnerable to adversarial perturbations, affecting robust generalization.
Randomized smoothing is the current state-of-the-art defense with provable robustness against adversarial attacks. Many works have devised new randomized smoothing schemes for other metrics, such as or ; however, substantial effort was needed to derive such new guarantees. This begs the q…
Exact simulation method for market impact estimation under various execution strategies.
Hierarchical randomized smoothing improves model robustness for complex data.