New method improves adversarial training robustness.
problem Lack of tight upper bounds for adversarial training.
method Holistic expansion of the network for upper bound minimization.
result RUB and aRUB methods are more robust than state-of-the-art methods.
Proposes ETB for tighter bounds in robust training of deep networks.
problem Training robust deep neural networks to adversarial attacks.
method Proposes ETB, a provably tighter bound approach for interval bound propagation.
result Achieves orders of magnitudes tighter bounds compared to IBP.
New method certifies global robustness of neural networks efficiently.
problem Adversarial examples threaten certifiably robust neural networks.
method Formalized global robustness, adapted widely-used architectures with efficient global Lipschitz bounds.
result Certifiable robust models achieve state-of-the-art verifiable accuracy with negligible costs.
The paper shows robustness and generalization are closely connected via data-dependent bounds.
problem Connecting robustness and generalization in machine learning.
method Data-dependent generalization bounds that reduce dependence on covering number and hypothesis space.
result Proves robustness implies generalization, with near-exponential improvements in various situations.
The paper sets lower bounds for adversarial robustness in multiclass classification.
problem Adversarial robustness in multiclass classification with arbitrary loss functions.
method Dual and barycentric reformulations for robust risk minimization.
result Sharp lower bounds for adversarial risks are computed efficiently.
New measure of robustness for estimators, with tight bounds for Gaussian mean estimation.
problem Developing robust statistical estimators for datasets with noise or outliers.
method Introducing empirical sensitivity as a new robustness measure and proving lower bounds for Gaussian mean estimation.
result Empirical sensitivity bounds for optimal estimators are tight, showing obstructions on mean and variance.
Paper provides robustness bounds for GNNs against adversarial attacks.
problem Adversarial robustness of GNNs for graph-related tasks.
method PAC-Bayesian framework applied to GCN and MP-GNN.
result Spectral norms of diffusion matrix and weights govern robustness.
Study robust best-arm identification in linear bandits with lower bounds and algorithms.
problem Identify a near-optimal robust arm in linear bandits with adversarial actions.
method Propose instance-dependent lower bounds and both static and adaptive bandit algorithms.
result Sample complexity matches the lower bound and algorithms effectively identify robust arms.
This work proves MultiKrum is robust in mean estimation with adversaries.
problem Mean estimation in the presence of Byzantine adversaries.
method Introducing κ* and constructing upper and lower bounds on MultiKrum's robustness coefficient.
result MultiKrum is the first provably robust aggregation rule, with robustness coefficient bounds.
New method makes robust estimators work without knowing corruption levels.
problem Robust estimation algorithms struggle with unknown corruption levels.
method Abstracted geometric puzzle solution to universal meta technique.
result Converts any robust estimator to work without corruption bounds.
New regularizers tighten convex relaxation bounds for neural networks.
problem Large gap between certifiable and empirical robustness in neural networks.
method Two regularizers to train neural networks yielding tighter convex relaxation bounds.
result Higher certified accuracy with proposed regularizers.
IBP simplifies robust training for large networks.
problem Training robust neural networks with scalable methods.
method Interval Bound Propagation (IBP) for robust training.
result IBP enables training large provably robust networks.
Paper proposes robust generative models using VAEs.
problem Lack of robustness in generative models.
method Formally defined robust lower bound, optimized during training.
result Generative models become more robust to adversarial attacks.
New method CROWN-IBP combines IBP and CROWN for efficient verifiable robust neural networks.
problem Training verifiably robust neural networks is challenging and computationally expensive.
method CROWN-IBP combines interval bound propagation and linear relaxation for efficient training.
result CROWN-IBP achieves significant improvements in verifiable robustness on MNIST and CIFAR datasets.
PAC-Bayesian bounds estimate adversarial robustness.
problem Estimating robustness to imperceptible input perturbations.
method PAC-Bayesian framework for averaging over hypotheses.
result General bounds valid for any type of adversarial attacks.
New robust estimators achieve subgaussian bounds using VC-dimension.
problem Robust estimation of sparse and corrupted data.
method Use of VC-dimension to measure statistical complexity.
result First robust estimators for sparse estimation with subgaussian rate.
Lipschitz networks bound distributional robustness for deep neural networks.
problem Improving robustness of deep neural networks to adversarial perturbations.
method Bounding distributional robust risk with Lipschitz constant of the model.
result Distributional robustness upperbounds adversarial training risk.
New method improves robustness of smoothed classifiers against adversarial attacks.
problem Improving robustness of smoothed classifiers against adversarial attacks.
method Proposes worst-case adversarial loss over input distributions as a robustness certificate, and uses duality and smoothness properties to provide an easy-to-compute upper bound.
result Shows superior robustness performance over state-of-the-art certified or heuristic methods.
A robust method for off-policy evaluation in contextual bandits.
problem Evaluating policies when direct methods are unavailable.
method Robust regression approach to off-policy evaluation.
result Superior empirical performance across benchmarks.
New algorithm robust to outliers in Bayesian Optimization.
problem Vulnerability of Bayesian Optimization to extreme outliers.
method Introduces a new adversary with a frequency-bounded corruption budget and derives RCGP-UCB algorithm.
result Achieves sublinear regret in the presence of up to O(T1/4) and O(T1/7) corruptions with possibly infinite magnitude. New bounds for classifier robustness to adversarial attacks.
problem Characterizing robustness of classifiers to adversarial perturbations.
method Introducing function transformations to relate adversarial risk to standard learning-theoretic risk bounds.
result Error rates on the same order as generalization error of original function classes.
Proves a new law of robustness for interpolating arbitrary data distributions.
problem Understanding robust interpolation for arbitrary data distributions.
method Proves a Lipschitzness lower bound for robust interpolation.
result Demonstrates a two-fold law of robustness for interpolating functions.
This work improves adversarial robustness in sparse coding models.
problem The gap between theoretical models and practical deployment in adversarial robustness.
method Combining a sparsity-promoting encoder with a linear classifier, and providing a robustness certificate.
result Bounding the robust risk and providing a robustness certificate for end-to-end classification.
Improves adversarial robustness by constraining logits with a bounded function.
problem Improving adversarial robustness in deep learning models.
method Addition of a bounded function before softmax to constrain logits.
result Our method improves adversarial robustness without requiring adversarial training.
The paper explores the limits of tight PAC-Bayes bounds for cheap models in robust statistics.
problem The challenge of obtaining meaningful bounds on the error of learning algorithms without prior assumptions.
method Investigates tight PAC-Bayes bounds for robust models with minimal cost.
result Demonstrates the limits of obtaining tight PAC-Bayes bounds for cheap models.
Study bounds deepfake detection error probability using robust statistics.
problem Limiting error in deepfake detection.
method Formulated as hypothesis testing, uses robust statistics and Euclidean approximation.
result Established relationships between error probability and network thresholds.
This work certifies non-uniform bounds against adversarial attacks for neural networks.
problem Certifying robust regions around data points against non-uniform adversarial attacks.
method Formulated as an optimization problem with nonlinear constraints, using the augmented Lagrangian method for general feedforward neural networks.
result Non-uniform bounds have larger volumes and better interpretability compared to uniform bounds.
Develops first robustness verification for complex Transformers.
problem Certify prediction behavior of Transformers with complex self-attention layers.
method Resolves challenges of cross-nonlinearity and cross-position dependency in Transformers.
result Certified robustness bounds are significantly tighter than Interval Bound Propagation.
New parameterization of neural networks with Lipschitz bounds for robustness.
problem Developing robust neural networks with Lipschitz bounds.
method Introducing a new parameterization that admits a Lipschitz bound during training without requiring projections or barrier functions.
result The new parameterization improves robustness to adversarial attacks in image classification.
We propose a robust elastic net (REN) model for high-dimensional sparse regression and give its performance guarantees (both the statistical error bound and the optimization bound). A simple idea of trimming the inner product is applied to the elastic net model. Specifically, we robustify the covariance matrix by trimm…
Paper provides efficient robustness certificates for neural networks.
problem Ensuring neural networks are robust against adversarial attacks.
method Two-step approach: 1) Efficient convex optimization for robustness certificates with bounded Hessian eigenvalues, 2) Curvature-based regularization during training.
result Significantly higher certified robust accuracy achieved compared to existing methods.
New bounds show robust models can generalize well, contrary to prior theories.
problem Existing robustness-based error bounds are vacuous for the best classifier.
method Developed novel bounds that converge to the true error of the best classifier.
result New bounds converge to the true error of the best classifier, improving generalization.
New law establishes robustness for neural networks with bounded weights.
problem Ensuring robustness of neural networks against adversarial attacks.
method Deriving a lower bound on Lipschitz constant for arbitrary model classes with bounded Rademacher complexity.
result Established a law of robustness for weight-bounded neural networks, requiring log(n) layers for robust fitting.
The paper connects decision tree interpretability and robustness through separation.
problem Empirical observation of a connection between robustness and interpretability in decision trees.
method Investigation of the connection through decision trees and l∞-perturbation robustness, proving bounds on tree size. result First algorithm with guarantees on robustness, interpretability, and accuracy for decision trees.
The paper analyzes adversarial robustness of Gaussian processes.
problem Ensuring robustness of GP decisions to bounded perturbations.
method Compact subset analysis, branch-and-bound scheme, lower and upper bounds computation.
result Guarantees adversarial robustness of GPs with provable bounds.
Study finds adding more information to robust option pricing does not improve bounds.
problem Exploring robust pricing of financial claims using minimal assumptions.
method Empirical study of variance options, incorporating intermediate market data.
result Incorporating more information does not improve robust pricing bounds.
Paper quantifies label shift robustly.
problem Quantifying label shift in datasets.
method Robust estimators of label distribution.
result Maximum Likelihood Estimator is a robust estimator.
A new method optimizes robustness measures under input uncertainty using randomized Gaussian process upper confidence bound.
problem Optimizing robustness measures under input uncertainty.
method Randomized robustness measure GP-UCB (RRGP-UCB) that samples β from a chi-squared-based distribution.
result RRGP-UCB provides tight bounds on expected regret.
Certifiably robust VAEs are trained with bounds on input perturbations.
problem Ensuring VAEs are robust to adversarial attacks.
method Derive bounds on minimal perturbation size, control parameters, and train VAEs to meet criteria.
result Certifiably robust VAEs are more robust to attacks than standard VAEs.
Computational limitations require more model parameters for robust learning.
problem Computational constraints affect the number of parameters needed for robust learning.
method Analyzes computational limitations and their impact on model size for robust learning.
result Computational bounded learners need significantly more parameters for robust learning.
Robustly estimates linear regression coefficients with adversarial and noisy data.
problem Estimating robust linear regression coefficients with adversarial and noisy data.
method Adversarial robust weighted Huber regression with polynomial computational complexity.
result Derives an estimation error bound that depends on the stable rank and condition number of the covariance matrix.
New method provides tighter robustness guarantees for adversarial attacks.
problem Ensuring robustness against adversarial attacks in machine learning models.
method Developed a Second-order Smoothing (SoS) robustness certificate using Gaussian random smoothing.
result SoS certificates are tighter and provide improved robustness on high-dimensional datasets.
New bounds show neural networks can resist attacks better with sparse weights.
problem Neural networks are vulnerable to small adversarial perturbations.
method Compression based on effective sparsity and joint sparsity.
result Neural networks with approximately sparse weight matrices have better robustness and generalization.
We introduce a criterion, resilience, which allows properties of a dataset (such as its mean or best low rank approximation) to be robustly computed, even in the presence of a large fraction of arbitrary additional data. Resilience is a weaker condition than most other properties considered so far in the literature, an…
Adversarial robust learning improved for transductive setting.
problem Adversarial robust learning in transductive setting.
method Simple transductive learner for bounded VC dimension classes.
result Robust error rate linear in VC dimension, adaptive to perturbation complexity.
Improves robust transfer learning with side information.
problem Addressing environmental shift in MDPs with side information.
method Estimate-centered uncertainty sets with side information integration.
result Improved robust policy with reduced sub-optimality gap.
Generative models improve adversarial robustness by adding synthetic data.
problem Improving robustness in machine learning models trained on limited data.
method Using synthetic data generated from a large dataset to augment the original training set.
result Generative models can significantly reduce the robust-accuracy gap compared to models trained with additional real data.
Paper establishes lower bounds for Gaussian process bandit optimization under various perturbation models.
problem Lower bounds for Gaussian process bandit optimization in noisy and robust settings.
method Novel proof techniques for standard and robust settings, including deterministic strategies.
result Demonstrates inevitable joint dependence of cumulative regret on corruption level and time horizon in robust settings.