Reward-poisoning attacks can force RL agents to learn bad policies, and we categorize and quantify their feasibility.
arXiv research
A locally-built, LLM-digested index of recent arXiv papers in quant finance, geometry/topology, and statistical ML — keyword search served straight from SQLite on this machine.
Trend · papers per month
Automated discovery of adaptive attacks improves adversarial defense evaluation.
Adaptive attacks have (rightfully) become the de facto standard for evaluating defenses to adversarial examples. We find, however, that typical adaptive evaluations are incomplete. We demonstrate that thirteen defenses recently published at ICLR, ICML and NeurIPS---and chosen for illustrative and pedagogical purposes--…
Stochastic multi-armed bandits form a class of online learning problems that have important applications in online recommendation systems, adaptive medical treatment, and many others. Even though potential attacks against these learning algorithms may hijack their behavior, causing catastrophic loss in real-world appli…
The problem of spoofing attacks is increasingly relevant as digital systems are becoming more ubiquitous. Thus the detection of such attacks and the localisation of attackers have been objects of recent study. After an attack has been detected, various algorithms have been proposed in order to localise the attacker. In…
Simple adaptive attacks can jailbreak state-of-the-art safety-aligned language models.
Neural networks are vulnerable to adversarially-constructed perturbations of their inputs. Most research so far has considered perturbations of a fixed magnitude under some norm. Although studying these attacks is valuable, there has been increasing interest in the construction of (and robustness to) unrestricted…
ADAPT improves robustness of Vision Transformers without full model fine-tuning.
A new attack for probabilistic classifiers adapts to noise levels.
AFD learns features resistant to adversarial attacks.
Meta learning can adapt fast but is vulnerable to adversarial attacks.
Study robustness of early-stopping GD for linear regression attacks.
Backdoor attacks can poison federated meta-learning models, even with few examples.
Study membership inference under skewed priors and adaptive thresholds, improving attack accuracy.
We study offline data poisoning attacks in contextual bandits, a class of reinforcement learning problems with important applications in online recommendation and adaptive medical treatment, among others. We provide a general attack framework based on convex optimization and show that by slightly manipulating rewards i…
Deep Neural Networks (DNNs) are susceptible to model stealing attacks, which allows a data-limited adversary with no knowledge of the training dataset to clone the functionality of a target model, just by using black-box query access. Such attacks are typically carried out by querying the target model using inputs that…
This paper improves model robustness against adversarial attacks using optimal transport.
AdvMind detects adversary intent in black-box attacks with high accuracy.
Paper proposes a method to improve building extraction from aerial images by adapting CNN models.
Recent advances in smart cities applications enforce security threads such as node replication attacks. Such attack is take place when the attacker plants a replicated network node within the network. Vehicular Ad hoc networks are connecting sensors that have limited resources and required the response time to be as lo…
Deep neural networks are vulnerable to adversarial examples, i.e., carefully-perturbed inputs aimed to mislead classification. This work proposes a detection method based on combining non-linear dimensionality reduction and density estimation techniques. Our empirical findings show that the proposed approach is able to…
First robust bandit algorithm for contextual bandits with sub-linear regret.
New attacks inflate earnings while reducing fraud scores, potentially millions at stake.
In this appraisal paper, we evaluate the efficacy of SHIELD, a compression-based defense framework for countering adversarial attacks on image classification models, which was published at KDD 2018. Here, we consider alternative threat models not studied in the original work, where we assume that an adaptive adversary …
Deep learning classifiers are known to be vulnerable to adversarial examples. A recent paper presented at ICML 2019 proposed a statistical test detection method based on the observation that logits of noisy adversarial examples are biased toward the true class. The method is evaluated on CIFAR-10 dataset and is shown t…
New research shows many recent defenses against adversarial examples are ineffective against black-box attacks.
Recently, deep neural networks have significant progress and successful application in various fields, but they are found vulnerable to attack instances, e.g., adversarial examples. State-of-art attack methods can generate attack images by adding small perturbation to the source image. These attack images can fool the …
New attack reveals memorization patterns in pre-trained LLMs.
Recent studies show that Deep Reinforcement Learning (DRL) models are vulnerable to adversarial attacks, which attack DRL models by adding small perturbations to the observations. However, some attacks assume full availability of the victim model, and some require a huge amount of computation, making them less feasible…
Paper tackles adversarial attacks on nonparametric regression models.
New NIDS uses hypergraphs for real-time detection of evolving port scans.
Neural networks have been proven to be vulnerable to a variety of adversarial attacks. From a safety perspective, highly sparse adversarial attacks are particularly dangerous. On the other hand the pixelwise perturbations of sparse attacks are typically large and thus can be potentially detected. We propose a new black…
TAROT enhances robustness and domain adaptability with domain-invariant features.
Deep neural networks (DNN) are known to be vulnerable to adversarial attacks. Numerous efforts either try to patch weaknesses in trained models, or try to make it difficult or costly to compute adversarial examples that exploit them. In our work, we explore a new "honeypot" approach to protect DNN models. We intentiona…
VarDetect monitors API queries to detect model extraction attacks.
Deep learning models are vulnerable to adversarial examples crafted by applying human-imperceptible perturbations on benign inputs. However, under the black-box setting, most existing adversaries often have a poor transferability to attack other defense models. In this work, from the perspective of regarding the advers…
Convolutional neural networks (CNNs) are known for their good performance and generalization in vision-related tasks and have become state-of-the-art in both application and research-based domains. However, just like other neural network models, they suffer from a susceptibility to noise and adversarial attacks. An adv…
New method improves privacy risk evaluation of machine learning models.
New algorithms tackle adversarial multi-player bandits with forced-collision communication.
SmoothLLM defends LLMs from jailbreaking attacks by randomly perturbing inputs.
Adversarial examples pose a threat to deep neural network models in a variety of scenarios, from settings where the adversary has complete knowledge of the model and to the opposite "black box" setting. Black box attacks are particularly threatening as the adversary only needs access to the input and output of the mode…
The evaluation of robustness against adversarial manipulation of neural networks-based classifiers is mainly tested with empirical attacks as methods for the exact computation, even when available, do not scale to large networks. We propose in this paper a new white-box adversarial attack wrt the -norms for $p \in…
SAPAG attacks distributed learning by reconstructing true training data from gradients.
New defense method inspired by encryption improves visual classification accuracy.
Paper proposes a framework to detect adversarial concept drifts under poisoning attacks.
Efficiently poisons offline RLHF models by flipping preference labels.
P-BO reduces black-box adversarial attacks by 10x with Bayesian optimization and function prior.
Unify gradients to improve deep networks' robustness against black-box attacks.