Improved algorithm speeds up generation of universal adversarial perturbations.
problem Slow generation of universal adversarial perturbations.
method Optimized algorithm based on orientation of perturbation vectors.
result Significantly faster generation of universal perturbations with higher fooling rates.
Adversarial training helps classifiers resist universal perturbations.
problem Vulnerability of classifiers to universal perturbations.
method Adversarial training with shared adversarial examples.
result Adversarial training reduces sensitivity to universal perturbations.
Deep networks have recently been shown to be vulnerable to universal perturbations: there exist very small image-agnostic perturbations that cause most natural images to be misclassified by such classifiers. In this paper, we propose the first quantitative analysis of the robustness of classifiers to universal perturba…
Universal perturbations misclassify text with high accuracy.
problem Vulnerability of text classifiers to small perturbations.
method Algorithm to compute universal adversarial perturbations.
result Deep neural networks are highly vulnerable to universal adversarial perturbations.
Paper finds universal speech command perturbations that fool models.
problem Existence of universal adversarial examples in speech command classification.
method Proposed a novel analytical framework for evaluating universal perturbations and a detailed distortion measurement method.
result Universal perturbations can fool speech command classification models across different models.
Universal audio perturbations fool ASR systems.
problem Speech recognition systems are vulnerable to adversarial attacks.
method Developed an algorithm to create universal perturbations that fool ASR models.
result Universal perturbations can fool ASR systems across different models.
A fast method computes class-specific adversarial perturbations for deep networks.
problem Computing robust adversarial perturbations for deep networks.
method Linear function of weights, no training data, no hyper-parameters.
result Obtains 34% to 51% fooling rate on ImageNet, transfers across models.
Given a state-of-the-art deep neural network classifier, we show the existence of a universal (image-agnostic) and very small perturbation vector that causes natural images to be misclassified with high probability. We propose a systematic algorithm for computing universal perturbations, and show that state-of-the-art …
This paper finds universal perturbations to fool black-box ML classifiers.
problem Breaking security through obscurity in black-box ML settings.
method Zeroth-order optimization for finding universal adversarial perturbations in a black-box setting.
result State-of-the-art ML classifiers can be fooled with a single imperceptible image perturbation.
Universal audio perturbations fool multiple classification models.
problem Creating audio adversarial perturbations that work across different models.
method Two methods: greedy iterative approach and novel penalty formulation.
result The penalty method produces more successful attacks with limited training data.
Neural networks are known to be vulnerable to adversarial examples, inputs that have been intentionally perturbed to remain visually similar to the source input, but cause a misclassification. It was recently shown that given a dataset and classifier, there exists so called universal adversarial perturbations, a single…
New method UADs improves transferability of adversarial perturbations.
problem Transferability of adversarial perturbations across different DNN architectures.
method Proposes Universal Adversarial Directions (UADs) to improve transferability.
result UADs can achieve a Nash equilibrium, indicating potential transferability.
While deep learning is remarkably successful on perceptual tasks, it was also shown to be vulnerable to adversarial perturbations of the input. These perturbations denote noise added to the input that was generated specifically to fool the system while being quasi-imperceptible for humans. More severely, there even exi…
A new game-theoretic approach to training robust classifiers against universal adversarial perturbations.
problem Learning classifiers robust to universal adversarial perturbations.
method Formulated as a two-player zero-sum game, where one player optimizes the classifier and the other creates adversarial perturbations.
result Empirically demonstrated robustness and versatility in multiple image classification datasets.
Simple technique turns any adversarial attack into a universal one using few test examples.
problem Creating universal adversarial attacks with minimal data.
method Universalization technique using few adversarial test examples and spectral properties.
result Simple universalization technique achieves comparable fooling rates to state-of-the-art methods.
GCNNs gain rotation invariance with more training augmentation, making SVD-Universal more effective.
problem Improving robustness of GCNNs to adversarial attacks.
method SVD-Universal technique applied to GCNNs trained with larger rotations.
result SVD-Universal becomes more effective as GCNNs gain rotation invariance.
We show that the perturbative g invariant of rational homology 3-spheres can be recovered from the LMO invariant for any simple Lie algebra g, i.e, the LMO invariant is universal among the perturbative invariants. This universality was conjectured in [25]. Since the perturbative invariants dominate …
New method generates universal adversarial perturbations across different image sources.
problem Certifying robustness of deep learning models with universal adversarial perturbations across various image sources.
method Few-shot learning approach using bilevel optimization and learning-to-optimize techniques.
result Improved attack success rate and faster performance compared to existing methods.
DEceit constructs effective universal pixel-restricted perturbations for deep image classifiers.
problem Creating effective universal pixel-restricted perturbations for deep neural networks.
method DEceit algorithm for black-box feedback, targeting 10% of pixels in images.
result Perturbing only 10% of pixels achieves high Fooling Rate and visual similarity.
New method creates universal perturbations to fool neural network interpretations.
problem Vulnerability of gradient-based saliency maps to adversarial perturbations.
method Gradient-based optimization and PCA-based approach to create UPI.
result Existence and successful application of Universal Perturbation for Interpretation (UPI).
DCNs are fooled by Gabor noise patterns similar to adversarial perturbations.
problem Sensitivity of DCNs to Gabor noise patterns.
method Examined different DCN architectures and their sensitivity to Gabor noise.
result DCNs are fooled by Gabor noise patterns similar to adversarial perturbations.
Paper introduces procedural noise for generating adversarial examples that fool deep networks.
problem Vulnerability of deep convolutional networks to adversarial examples.
method Structured approach for generating Universal Adversarial Perturbations (UAPs) with procedural noise.
result Single noise patterns can fool up to 90% of a dataset, with high universal evasion rates.
The integrality of the Kontsevich integral and perturbative invariants is discussed. We show that the denominator of the degree n part of the Kontsevich integral of any knot or link is a divisor of (2!3!...n!)4(n+1)!. We also show that the denominator of of the degree n part of the universal perturbative invari…
New approach to quantum knot invariants using perturbed Gaussian generating functions.
problem Developing universal quantum knot invariants.
method Introducing generating functions of the form PeG where G is quadratic and P is a perturbation, and developing a calculus for such functions. result The rank one invariant ZD dominates sl2-colored Jones polynomials and relates to knot genus and Whitehead doubling. The universal perturbative invariants of rational homology spheres can be extracted from the Chern-Simons partition function by combining perturbative and nonperturbative results. We spell out the general procedure to compute these invariants, and we work out in detail the case of Seifert spaces. By extending some prev…
New invariant counts graph configurations in 3D manifolds.
problem Counting graph configurations in 3D manifolds.
method Using combings instead of parallelizations for a more flexible definition.
result Universal finite type invariant of three-manifolds.
We give a complete proof of the fact that a contact structure that is sufficiently close to a Reebless foliation is universally tight.
The paper shows instability in Minkowski spacetime for a quantum system.
problem Linear instability of the semiclassical Einstein-Klein-Gordon system in Minkowski spacetime.
method Formulated a forcing problem for metric and state perturbations, used tensor decomposition and quantum Møller operator.
result Metric perturbations grow exponentially, bounded by a universal scale H, indicating quantum backreaction.
Researchers create a flickering attack to fool video recognition networks.
problem Adversarial manipulation of video classification networks.
method Introducing a flickering temporal perturbation to fool video classifiers.
result Achieved high fooling ratio and temporal-invariant perturbation.
Study on low-dimensional adversarial perturbations in classification models.
problem Understanding and quantifying the effectiveness of low-dimensional adversarial perturbations.
method Analytical lower-bounds for fooling rate, considering binary classifiers under generic regularity conditions.
result Rigorous explanation for the success of heuristic methods in generating low-dimensional adversarial perturbations.
We present a project of classification of a certain class of bihamiltonian 1+1 PDEs depending on a small parameter. Our aim is to embed the theory of Gromov - Witten invariants of all genera into the theory of integrable systems. The project is focused at describing normal forms of the PDEs and their local bihamiltonia…
Based on a general (1+3) threading of the spacetime (M,g), we obtain a new and simple splitting of a both the Einstein field equations (EFE) and the conservation laws in (M,g). As an application we obtain the splitting of (EFE) in an almost FLRW universe with energy-momentum tensor of a perfect fluid. In particul…
New method makes neural networks robust to various adversarial attacks.
problem Neural networks are vulnerable to specific adversarial attacks.
method Proposed MMR-Universal regularization scheme for ReLU networks.
result First provably robust models against any lp-norm for p≥1. We give a purely topological definition of the perturbative quantum invariants of links and 3-manifolds associated with Chern-Simons field theory. Our definition is as close as possible to one given by Kontsevich. We will also establish some basic properties of these invariants, in particular that they are universally …
New insights into model robustness for random features and NTK models.
problem Understanding and distinguishing robustness in machine learning models.
method Analyzing empirical risk minimization in random features and NTK models.
result Random features models are not robust under any degree of over-parameterization, even when satisfying the universal law of robustness.
This work analyzes how different forms of compressibility affect adversarial robustness in neural networks.
problem Understanding the interaction between compressibility and adversarial robustness in neural networks.
method Developed a principled framework to analyze the effects of neuron-level sparsity and spectral compressibility on adversarial robustness.
result Identified that different forms of compression can induce highly sensitive directions in the representation space that adversaries can exploit.
Adversarial attacks can fool algorithmic trading systems.
problem Adversarial perturbations can manipulate algorithmic trading models.
method Real-time adversarial attacks on trading algorithms using universal perturbations.
result Perturbations can fool trading algorithms at unseen data points.
New high-order universal portfolios outperform standard ones.
problem Improving upon the Cover universal portfolio.
method Constructing higher order universal portfolios by recurrence and analyzing their properties.
result Second high-order UP outperforms standard UP under perturbation.
New method GSAT improves robustness against structured perturbations.
problem Structured perturbations in biological data.
method Formulates GSAT as a non-convex concave minimax optimization problem and solves it with GDADMM.
result Improves robustness against group-sparse and rank-constrained perturbations.
We give a new and simple proof for the computation of the oriented and the unoriented fold cobordism groups of Morse functions on surfaces. We also compute similar cobordism groups of Morse functions based on simple stable maps of 3-manifolds into the plane. Furthermore, we show that certain cohomology classes associat…
Let M a compact connected orientable 4-manifold. We study the space Ξ of Spinc-structures of fixed fundamental class, as an infinite dimensional principal bundle on the manifold of riemannian metrics on M. In order to study perturbations of the metric in Seiberg-Witten equations, we study the transversality of…
Adversarial weight perturbations can inject backdoors into trained neural models.
problem Security risk of using publicly available trained models due to backdoors.
method Extended adversarial perturbations to model weights, using a composite loss and projected gradient descent.
result Adversarial weight perturbations can be successfully injected with very small changes, exposing security risks across various tasks.
I sketch what it is supposed to mean to quantize gauge theory, and how this can be made more concrete in perturbation theory and also by starting with a finite-dimensional lattice approximation. Based on real experiments and computer simulations, quantum gauge theory in four dimensions is believed to have a mass gap. T…
Paper proposes structured semantic perturbations to improve adversarial attacks.
problem Vulnerability of deep neural networks to adversarial attacks.
method Manipulates semantic attributes via disentangled latent codes.
result Demonstrates the effectiveness of structured semantic perturbations.
Reviews g-theorem and hard Lefschetz theorem for face rings.
problem Understanding and proving the g-theorem and hard Lefschetz theorem for face rings.
method Perturbations of maps, biased Poincaré pairings, cobordism argument, edge-contractions.
result Alternative and alternative arguments for the Lefschetz property.
New rules found to fool deep neural networks in text classification.
problem Vulnerabilities of deep neural networks in text classification.
method Coevolutionary optimization algorithm to create imperceptible adversarial samples.
result Universal rules for fooling deep neural networks in text classification exist and are sample and method agnostic.
New approach makes adversarial examples less suspicious without changing perceptual salience.
problem Robustness of deep neural networks to unsuspicious adversarial examples.
method Splitting images into foreground and background, allowing larger perturbations in background while maintaining low cognitive salience.
result Dual-perturbation attacks are effective against classifiers robust to conventional attacks and adversarial training yields more robust classifiers.
The study identifies conditions under which algorithmic stability explains generalization in interpolating learning systems.
problem Understanding when algorithmic stability explains generalization in interpolating learning systems.
method Modeling training as a function-space trajectory and measuring sensitivity to single-sample perturbations.
result There exist interpolating regimes with small risk where contractive sensitivity cannot hold, showing that stability is not a universal explanation.