We demonstrate the existence of universal adversarial perturbations, which can fool a family of audio classification architectures, for both targeted and untargeted attack scenarios. We propose two methods for finding such perturbations. The first method is based on an iterative, greedy approach that is well-known in c…
arXiv research
A locally-built, LLM-digested index of recent arXiv papers in quant finance, geometry/topology, and statistical ML — keyword search served straight from SQLite on this machine.
Trend · papers per month
In this paper, we propose novel generative models for creating adversarial examples, slightly perturbed images resembling natural images but maliciously crafted to fool pre-trained models. We present trainable deep neural networks for transforming images to adversarial perturbations. Our proposed models can produce ima…
Deep neural networks improve free energy calculations for peptide conformations.
The paper examines how gradient descent stabilizes low-rank matrix factorization in noisy conditions.
New method improves blackbox attack transferability by perturbing feature hierarchy.
The paper proposes a neural network architecture inspired by Langevin Monte Carlo for sampling from target distributions.
Based on the Hamiltonian dimensional reduction of axially symmetric, Ricci-flat Lorentzian spacetimes to a Einstein-wave map system with the (negatively curved) hyperbolic 2-plane target, we construct a positive-definite, (spacetime) gauge-invariant energy functional for linear axially symmetric perturbatio…
This paper proposes a new algorithm for controlling classification results by generating a small additive perturbation without changing the classifier network. Our work is inspired by existing works generating adversarial perturbation that worsens classification performance. In contrast to the existing methods, our wor…
While deep learning is remarkably successful on perceptual tasks, it was also shown to be vulnerable to adversarial perturbations of the input. These perturbations denote noise added to the input that was generated specifically to fool the system while being quasi-imperceptible for humans. More severely, there even exi…
GNNs robustness in community detection is studied with various perturbations.
Improved KSD test for better detection of differences in distributions.
Tricks adversarial attacks to target specific classes, improving classifier accuracy.
Despite their accuracy, neural network-based classifiers are still prone to manipulation through adversarial perturbations. Those perturbations are designed to be misclassified by the neural network, while being perceptually identical to some valid input. The vast majority of attack methods rely on white-box conditions…
Machine learning models are vulnerable to adversarial examples. An adversary modifies the input data such that humans still assign the same label, however, machine learning models misclassify it. Previous approaches in the literature demonstrated that adversarial examples can even be generated for the remotely hosted m…
We explore the nonperturbative aspects of the chiral algebras of N = (0,2) sigma models, which perturbatively are intimately related to the theory of chiral differential operators (CDOs). The grading by charge and scaling dimension is anomalous if the first Chern class of the target space is nonzero. This has some nont…
Adversarial examples are delicately perturbed inputs, which aim to mislead machine learning models towards incorrect outputs. While most of the existing work focuses on generating adversarial perturbations in multi-class classification problems, many real-world applications fall into the multi-label setting in which on…
New methods use transport maps to improve Langevin dynamics for sampling.
Classifiers such as deep neural networks have been shown to be vulnerable against adversarial perturbations on problems with high-dimensional input space. While adversarial training improves the robustness of image classifiers against such adversarial perturbations, it leaves them sensitive to perturbations on a non-ne…
This study tackles offline RL with perturbed data sources, deriving a lower bound and proposing an optimal algorithm.
Localized uncertainty attacks target uncertain regions to create imperceptible adversarial examples.
BOBYQA optimizes deep networks with fewer queries than other methods.
Adversarial examples are inputs to machine learning models designed by an adversary to cause an incorrect output. So far, adversarial examples have been studied most extensively in the image domain. In this domain, adversarial examples can be constructed by imperceptibly modifying images to cause misclassification, and…
Neural networks are known to be vulnerable to adversarial examples, inputs that have been intentionally perturbed to remain visually similar to the source input, but cause a misclassification. It was recently shown that given a dataset and classifier, there exists so called universal adversarial perturbations, a single…
Researchers found a way to measure energy in black hole perturbations.
Cellina uses supervised disentanglement to predict cell behavior in tissues.
Indirect attacks can fool graph classifiers even with poisoned neighbors.
In machine learning, the domain adaptation problem arrives when the test (target) and the train (source) data are generated from different distributions. A key applied issue is thus the design of algorithms able to generalize on a new distribution, for which we have no label information. We focus on learning classifica…
Adversarial examples in machine learning for images are widely publicized and explored. Illustrations of misclassifications caused by slightly perturbed inputs are abundant and commonly known (e.g., a picture of panda imperceptibly perturbed to fool the classifier into incorrectly labeling it as a gibbon). Similar atta…
We tackle the PAC-Bayesian Domain Adaptation (DA) problem. This arrives when one desires to learn, from a source distribution, a good weighted majority vote (over a set of classifiers) on a different target distribution. In this context, the disagreement between classifiers is known crucial to control. In non-DA superv…
SOOTT framework optimizes target tracking with robust and learning-augmented algorithms.
The paper strengthens a theorem on crossings under linear perturbations with Hausdorff measure estimates.
Adversarial examples are intentionally perturbed images that mislead classifiers. These images can, however, be easily detected using denoising algorithms, when high-frequency spatial perturbations are used, or can be noticed by humans, when perturbations are large. In this paper, we propose EdgeFool, an adversarial im…
ViTaX provides formal guarantees for targeted explanations in safety-critical systems.
Deep neural networks have become widely used, obtaining remarkable results in domains such as computer vision, speech recognition, natural language processing, audio recognition, social network filtering, machine translation, and bio-informatics, where they have produced results comparable to human experts. However, th…
Neural networks are vulnerable to adversarial examples, malicious inputs crafted to fool trained models. Adversarial examples often exhibit black-box transfer, meaning that adversarial examples for one model can fool another model. However, adversarial examples may be overfit to exploit the particular architecture and …
Optimal reinsurance strategy found to minimize financial risk.
Deep neural networks (DNNs) are known for their vulnerability to adversarial examples. These are examples that have undergone small, carefully crafted perturbations, and which can easily fool a DNN into making misclassifications at test time. Thus far, the field of adversarial research has mainly focused on image model…
Paper examines adversarial attacks on weather forecasting models, focusing on TC trajectory prediction.
New DA method CIRM outperforms existing methods under structural causal model assumptions.
Accelerates DNN robustness verification with target labels.
BioBO optimizes gene perturbation design using Bayesian optimization with biological priors.
Recent advances show that deep neural networks are not robust to deliberately crafted adversarial examples which many are generated by adding human imperceptible perturbation to clear input. Consider norms attacks, Project Gradient Descent (PGD) and the Carlini and Wagner (C\&W) attacks are the two main methods, …
DIP-FAT improves adversarial training by diversifying perturbations.
Co-Diffusion predicts drug-target affinity by learning latent manifolds and diffusion, improving generalization.
Adversarial attacks can fool algorithmic trading systems.
The application of deep recurrent networks to audio transcription has led to impressive gains in automatic speech recognition (ASR) systems. Many have demonstrated that small adversarial perturbations can fool deep neural networks into incorrectly predicting a specified target with high confidence. Current work on fool…
Researchers create a flickering attack to fool video recognition networks.
A key problem in research on adversarial examples is that vulnerability to adversarial examples is usually measured by running attack algorithms. Because the attack algorithms are not optimal, the attack algorithms are prone to overestimating the size of perturbation needed to fool the target model. In other words, the…