Research
On-device research index

arXiv research

A locally-built, LLM-digested index of recent arXiv papers in quant finance, geometry/topology, and statistical ML — keyword search served straight from SQLite on this machine.

169,051 papers · 148 categories

Trend · papers per month

4080119159 · Jun 202019922001200920182026
48 results for Universal Perturbations

Improved algorithm speeds up generation of universal adversarial perturbations.

problem Slow generation of universal adversarial perturbations.
method Optimized algorithm based on orientation of perturbation vectors.
result Significantly faster generation of universal perturbations with higher fooling rates.

Paper finds universal speech command perturbations that fool models.

problem Existence of universal adversarial examples in speech command classification.
method Proposed a novel analytical framework for evaluating universal perturbations and a detailed distortion measurement method.
result Universal perturbations can fool speech command classification models across different models.

Given a state-of-the-art deep neural network classifier, we show the existence of a universal (image-agnostic) and very small perturbation vector that causes natural images to be misclassified with high probability. We propose a systematic algorithm for computing universal perturbations, and show that state-of-the-art …

2016-10-26abs ↗pdf ↗

This paper finds universal perturbations to fool black-box ML classifiers.

problem Breaking security through obscurity in black-box ML settings.
method Zeroth-order optimization for finding universal adversarial perturbations in a black-box setting.
result State-of-the-art ML classifiers can be fooled with a single imperceptible image perturbation.

Neural networks are known to be vulnerable to adversarial examples, inputs that have been intentionally perturbed to remain visually similar to the source input, but cause a misclassification. It was recently shown that given a dataset and classifier, there exists so called universal adversarial perturbations, a single…

2017-08-17abs ↗pdf ↗

While deep learning is remarkably successful on perceptual tasks, it was also shown to be vulnerable to adversarial perturbations of the input. These perturbations denote noise added to the input that was generated specifically to fool the system while being quasi-imperceptible for humans. More severely, there even exi…

2017-04-19abs ↗pdf ↗

A new game-theoretic approach to training robust classifiers against universal adversarial perturbations.

problem Learning classifiers robust to universal adversarial perturbations.
method Formulated as a two-player zero-sum game, where one player optimizes the classifier and the other creates adversarial perturbations.
result Empirically demonstrated robustness and versatility in multiple image classification datasets.

Simple technique turns any adversarial attack into a universal one using few test examples.

problem Creating universal adversarial attacks with minimal data.
method Universalization technique using few adversarial test examples and spectral properties.
result Simple universalization technique achieves comparable fooling rates to state-of-the-art methods.

New method generates universal adversarial perturbations across different image sources.

problem Certifying robustness of deep learning models with universal adversarial perturbations across various image sources.
method Few-shot learning approach using bilevel optimization and learning-to-optimize techniques.
result Improved attack success rate and faster performance compared to existing methods.

DEceit constructs effective universal pixel-restricted perturbations for deep image classifiers.

problem Creating effective universal pixel-restricted perturbations for deep neural networks.
method DEceit algorithm for black-box feedback, targeting 10% of pixels in images.
result Perturbing only 10% of pixels achieves high Fooling Rate and visual similarity.

New method creates universal perturbations to fool neural network interpretations.

problem Vulnerability of gradient-based saliency maps to adversarial perturbations.
method Gradient-based optimization and PCA-based approach to create UPI.
result Existence and successful application of Universal Perturbation for Interpretation (UPI).

Paper introduces procedural noise for generating adversarial examples that fool deep networks.

problem Vulnerability of deep convolutional networks to adversarial examples.
method Structured approach for generating Universal Adversarial Perturbations (UAPs) with procedural noise.
result Single noise patterns can fool up to 90% of a dataset, with high universal evasion rates.

New approach to quantum knot invariants using perturbed Gaussian generating functions.

problem Developing universal quantum knot invariants.
method Introducing generating functions of the form PeGPe^G where GG is quadratic and PP is a perturbation, and developing a calculus for such functions.
result The rank one invariant ZD\mathbf{Z}_\mathbb{D} dominates sl2\mathfrak{sl}_2-colored Jones polynomials and relates to knot genus and Whitehead doubling.

The paper shows instability in Minkowski spacetime for a quantum system.

problem Linear instability of the semiclassical Einstein-Klein-Gordon system in Minkowski spacetime.
method Formulated a forcing problem for metric and state perturbations, used tensor decomposition and quantum Møller operator.
result Metric perturbations grow exponentially, bounded by a universal scale H, indicating quantum backreaction.

Study on low-dimensional adversarial perturbations in classification models.

problem Understanding and quantifying the effectiveness of low-dimensional adversarial perturbations.
method Analytical lower-bounds for fooling rate, considering binary classifiers under generic regularity conditions.
result Rigorous explanation for the success of heuristic methods in generating low-dimensional adversarial perturbations.

We give a purely topological definition of the perturbative quantum invariants of links and 3-manifolds associated with Chern-Simons field theory. Our definition is as close as possible to one given by Kontsevich. We will also establish some basic properties of these invariants, in particular that they are universally …

1999-12-21abs ↗pdf ↗

New insights into model robustness for random features and NTK models.

problem Understanding and distinguishing robustness in machine learning models.
method Analyzing empirical risk minimization in random features and NTK models.
result Random features models are not robust under any degree of over-parameterization, even when satisfying the universal law of robustness.

This work analyzes how different forms of compressibility affect adversarial robustness in neural networks.

problem Understanding the interaction between compressibility and adversarial robustness in neural networks.
method Developed a principled framework to analyze the effects of neuron-level sparsity and spectral compressibility on adversarial robustness.
result Identified that different forms of compression can induce highly sensitive directions in the representation space that adversaries can exploit.

Adversarial attacks can fool algorithmic trading systems.

problem Adversarial perturbations can manipulate algorithmic trading models.
method Real-time adversarial attacks on trading algorithms using universal perturbations.
result Perturbations can fool trading algorithms at unseen data points.

Let MM a compact connected orientable 4-manifold. We study the space ΞΞ of SpincSpin^c-structures of fixed fundamental class, as an infinite dimensional principal bundle on the manifold of riemannian metrics on MM. In order to study perturbations of the metric in Seiberg-Witten equations, we study the transversality of…

2009-02-26abs ↗pdf ↗

Adversarial weight perturbations can inject backdoors into trained neural models.

problem Security risk of using publicly available trained models due to backdoors.
method Extended adversarial perturbations to model weights, using a composite loss and projected gradient descent.
result Adversarial weight perturbations can be successfully injected with very small changes, exposing security risks across various tasks.

I sketch what it is supposed to mean to quantize gauge theory, and how this can be made more concrete in perturbation theory and also by starting with a finite-dimensional lattice approximation. Based on real experiments and computer simulations, quantum gauge theory in four dimensions is believed to have a mass gap. T…

2008-12-24abs ↗pdf ↗

New rules found to fool deep neural networks in text classification.

problem Vulnerabilities of deep neural networks in text classification.
method Coevolutionary optimization algorithm to create imperceptible adversarial samples.
result Universal rules for fooling deep neural networks in text classification exist and are sample and method agnostic.

New approach makes adversarial examples less suspicious without changing perceptual salience.

problem Robustness of deep neural networks to unsuspicious adversarial examples.
method Splitting images into foreground and background, allowing larger perturbations in background while maintaining low cognitive salience.
result Dual-perturbation attacks are effective against classifiers robust to conventional attacks and adversarial training yields more robust classifiers.

The study identifies conditions under which algorithmic stability explains generalization in interpolating learning systems.

problem Understanding when algorithmic stability explains generalization in interpolating learning systems.
method Modeling training as a function-space trajectory and measuring sensitivity to single-sample perturbations.
result There exist interpolating regimes with small risk where contractive sensitivity cannot hold, showing that stability is not a universal explanation.