Paper defends iris recognition from adversarial examples using wavelet decomposition.
problem Adversarial examples threaten deep neural networks in biometric applications.
method Wavelet domain denoising of input examples to detect and mitigate adversarial attacks.
result Proposed defense strategies improve recognition accuracy against adversarial attacks.
New strategy uses interpretability to improve adversarial learning.
problem Improving adversarial learning speed and effectiveness.
method Spatially constrained one-pixel adversarial perturbations guided by gradient-based interpretability.
result Spatially constrained one-pixel adversarial perturbations noticeably improve convergence and attack success.
Study on robustness of subspace learning from adversarial modifications.
problem Adversarial robustness of subspace learning problems.
method Characterization of optimal rank-one attack strategies and generalization to non-rank-constrained scenarios.
result Optimal attack strategies depend on singular values and adversary's energy budget.
Neural networks are known to be vulnerable to adversarial examples. Carefully chosen perturbations to real images, while imperceptible to humans, induce misclassification and threaten the reliability of deep learning systems in the wild. To guard against adversarial examples, we take inspiration from game theory and ca…
New algorithm tackles adversarial bandits with arbitrary strategies.
problem Adversarial bandit problem against arbitrary strategies.
method Adopted master-base framework using online mirror descent method (OMD). Proposed adaptive learning rates for OMD.
result Achieved improved regret bounds compared to previous methods.
Generative Adversarial Networks improve trading strategy performance.
problem Optimizing trading strategies in a competitive market.
method Conditional Generative Adversarial Networks (cGANs) for strategy calibration and combination.
result cGANs provide outperformance over traditional techniques in generating alpha.
Study on learning strategies in adaptive Markov games with policy regret as metric.
problem Learning in dynamic Markov games with adaptive opponents is challenging.
method Introduced policy regret as a new learning metric and developed algorithms for consistent adaptive adversaries.
result Achieved T \sqrt{T} T policy regret against certain adaptive adversaries. New approach optimizes policies in adversarial MDPs using adversarial learning.
problem Optimizing policies in adversarial Markov decision processes.
method Adversarial learning on advantage functions, extending previous reductions.
result Stronger regret criteria and performance guarantees for policy optimization.
This paper proposes multi-view attack strategies for deep models.
problem Vulnerability of multi-view deep models to adversarial attacks.
method Two multi-view attack strategies: two-stage attack (TSA) and end-to-end attack (ETEA).
result Proposed multi-view attack strategies are effective on multi-view deep models.
Deep learning has become the state of the art approach in many machine learning problems such as classification. It has recently been shown that deep learning is highly vulnerable to adversarial perturbations. Taking the camera systems of self-driving cars as an example, small adversarial perturbations can cause the sy…
Random Gaussian noise and pixel discretization improve image classifier robustness.
problem Whitebox adversarial attacks decrease classifier accuracy.
method Inject random Gaussian noise, discretize pixels, and use any classifier.
result Reduces KL divergence and lower bound on classifier accuracy.
No universal trading strategy exists due to mathematical impossibilities.
problem The impossibility of universally winning trading strategies in competitive markets.
method Three mathematical paradigms: measure-theoretic, No-Free-Lunch theorem, and adversarial Cantor diagonalization.
result No-arbitrage and free-lunch principles are mathematically precluded in competitive markets.
The paper introduces a method to make neural networks more robust to adversarial attacks.
problem Vulnerability of deep neural networks to small, adversarially designed perturbations.
method A bottom-up strategy using a nonlinear front end that polarizes and quantizes data.
result The approach can completely eliminate adversarial perturbations on MNIST and Fashion MNIST datasets.
New method defends deep learning models against adversarial attacks.
problem Robustness of deep learning models against adversarial attacks is compromised.
method Adversarial samples are relaxed onto the target class distribution manifold using MALA.
result MALADE outperformed state-of-the-art methods in various attacks.
Generative Adversarial Networks create realistic financial correlation matrices.
problem Creating realistic financial correlation matrices for practical applications.
method Generative Adversarial Networks (GANs) to model correlation matrices.
result GANs can recover known stylized facts about empirical correlation matrices.
Proposes a defense method against multiple adversarial video types.
problem Lack of multi-perturbation robustness in existing defense approaches.
method Adversarial training with multiple independent BN layers and a BN selection module.
result Demonstrates stronger multi-perturbation robustness against different adversarial video types.
New findings suggest both robust and accurate models are possible.
problem Clarifying the relationship between adversarial robustness and generalization.
method Assumed a low-dimensional data manifold and analyzed adversarial examples.
result On-manifold adversarial examples are generalization errors, and on-manifold adversarial training boosts generalization.
New method learns optimal prediction strategies in adversarial games.
problem Learning optimal prediction procedures in uncertain data environments.
method Adversarial Monte Carlo approach with neural network architecture.
result Optimal strategy is equivariant and invariant to various transformations.
Generative Adversarial Networks simulate realistic market interactions.
problem Lack of agent-level historical data limits market simulation realism.
method Conditional Generative Adversarial Networks (CGANs) trained on real data.
result CGAN-based synthetic market generator outperforms previous methods in market responsiveness and realism.
Develops a strategy to minimize loss in both stochastic and adversarial environments for linear contextual bandits.
problem Linear contextual bandits with adversarial corruption.
method Proposes a novel strategy called Best-of-Both-Worlds (BoBW) RealFTRL, extending RealLinExp3 and FTRL.
result Regret upper bound of $O\left(\min\left\{\frac{(\log(T))^3}{Δ_{*}} + \sqrt{\frac{C(\log(T))^3}{Δ_{*}}},\ \ \sqrt{T}(\log(T))^2
ight\}
ight)$ , showing effectiveness in both stochastic and adversarial environments.
Meta learning can adapt fast but is vulnerable to adversarial attacks.
problem Vulnerability of meta learning to adversarial attacks.
method Formal definition of adversarial attacks unique to meta learning, proposing an attacking algorithm.
result Meta learning is vulnerable to adversarial attacks.
New method improves adversarial training efficiency and robustness.
problem High computational costs and lack of stability in adversarial training.
method Backward smoothing for randomized smoothing of random initialization.
result Our method achieves similar model robustness as state-of-the-art methods but with significantly less training time.
A new method for estimating adversarial strategies in nonlinear systems.
problem Inferring an intelligent adversarial agent's strategy in highly nonlinear systems.
method Formulated inverse cognition as a nonlinear Gaussian state-space model and developed an inverse UKF (IUKF) system.
result The estimation error of IUKF converges and closely follows the recursive Cramér-Rao lower bound.
Framework uses RL to design robust observers for cyber-attacks.
problem Robustness of autonomous systems under cyber-attacks and sensor failures.
method Adversarial deep reinforcement learning for observer design.
result Learned observer strategies perform well under bounded adversarial errors.
OpenAlpha validates decentralized capital strategies using game theory and market aggregation.
problem Decentralized capital management's lack of trust-minimised, adaptive deployment.
method Game-theoretic validation, adversarial auditing, market-based belief aggregation.
result Confidence scores from validation phases inform capital allocation rules.
New algorithm optimally identifies best arm in both stochastic and adversarial settings.
problem Best arm identification in stochastic and adversarial reward scenarios.
method Parameter-free algorithm designed to be robust to adversarial rewards and optimal in stochastic problems.
result Algorithm's error rate matches optimal bounds in stochastic problems and is robust to adversarial rewards.
Generative adversarial networks create realistic equity option market simulations.
problem Limited real-world data for training and evaluating option trading strategies.
method Recurrent and temporal convolutional architectures with state compression.
result GANs outperform classical methods on benchmark metrics.
Optimal adversarial noise algorithms for multiple classifiers using game theory.
problem Designing robust attacks against multiple classifiers.
method Formulating the problem as a two-player, zero-sum game and using Multiplicative Weights Update framework with best response oracles.
result Demonstrated the effectiveness of randomization in adversarial attacks and optimal mixed strategies.
This work proposes a robust ensemble method for decision trees that resists adversarial attacks.
problem Adversarial attacks on machine learning models, especially decision trees.
method Feature partitioning to train robust ensembles and approximate certification methods.
result The proposed ensemble method can resist evasion attacks by a majority of its models.
Surveying strategies for making machine learning models robust against adversarial attacks.
problem Ensuring machine learning models are robust and reliable in real-world applications.
method Taxonomy of adversarial attacks and defenses, Robust Optimization problem formulation, and survey of methods.
result Surveyed recent results in adversarial example generation, defense mechanisms, and formal robustness certificates.
Enhances neural networks' robustness against adversarial samples without sacrificing clean sample generalization.
problem Limited generalization and time complexity of adversarial training.
method Feature Pyramid Decoder (FPD) framework that integrates denoising and image restoration modules into CNNs and constrains the Lipschitz constant.
result FPD-enhanced CNNs achieve sufficient robustness against general adversarial samples on various datasets.
SEAL improves AL on attributed graphs by combining deep learning and adversarial strategies.
problem Efficient AL on attributed graphs with label sparsity issues.
method SEAL framework using adversarial components for graph embedding and semi-supervised discriminator.
result Superior performance improvements over state-of-the-art baselines.
This project improves model robustness to affine transformations.
problem Vulnerability of models to affine transformations.
method Evolution strategies for finding worst affine transforms.
result Effective robust models against non-parametric adversarial perturbations.
This paper optimizes attacks on stochastic bandits and proposes defenses against them.
problem Optimizing adversarial attacks on stochastic bandit algorithms.
method Designs optimal attack strategies and proposes defense algorithms.
result Optimal attack strategies and defense algorithms achieve near perfect performance.
A new method aggregates generative classifiers to resist adversarial attacks.
problem Adversarial attacks on deep neural networks.
method Rank-aggregating ensemble of generative classifiers trained on intermediate layer responses.
result The ensemble of generative classifiers shows robustness to adversarial attacks.
Paper defends machine learning models from adversarial attacks using GLRT.
problem Adversarial attacks on machine learning models leading to misclassification.
method Generalized likelihood ratio test (GLRT) for robust classification.
result GLRT yields performance competitive with minimax approach under worst-case attacks, and better trade-off under weaker attacks.
Defense strategy improves controller robustness against adversarial attacks.
problem Adversarial attacks on learning-enabled controllers in CPS.
method Two-stage defense strategy treating controller and environment as black-boxes with unknown dynamics.
result Defense strategy effectively improves controller robustness in realistic control domains.
Empirical study on adversarial robustness in transfer learning from CIFAR 100 to CIFAR 10.
problem Evaluating adversarial robustness in transfer learning from CIFAR 100 to CIFAR 10.
method Study of adversarial robustness under transfer learning from a source trained on CIFAR 100 to a target network trained on CIFAR 10, using robust optimisation.
result Using PGD examples during training on the source task leads to more general robust features that are easier to transfer and achieve 5.2% more accuracy against white-box PGD attacks.
This paper introduces defensive dropout to protect deep neural networks from adversarial attacks.
problem Vulnerability of deep neural networks to adversarial attacks.
method Proposes using dropout at test time to enhance robustness, modeling the problem as a game between attacker and defender.
result Defensive dropout reduces adversarial attack success rate significantly, from 100% to 13.89% on MNIST.
We present a new strategy for gap estimation in randomized algorithms for multiarmed bandits and combine it with the EXP3++ algorithm of Seldin and Slivkins (2014). In the stochastic regime the strategy reduces dependence of regret on a time horizon from ( ln t ) 3 (\ln t)^3 ( ln t ) 3 to ( ln t ) 2 (\ln t)^2 ( ln t ) 2 and eliminates an additive factor of o…
Federated learning is vulnerable to model poisoning attacks by a single malicious agent.
problem Vulnerability of federated learning to model poisoning attacks by a single non-colluding agent.
method Exploration of model poisoning attacks, including boosting, alternating minimization, and parameter estimation.
result Even a constrained adversary can successfully carry out model poisoning attacks while maintaining stealth.
Adversaries can poison online learning data to mislead models.
problem Adversarial attacks on online learning systems.
method Formalized problem into two settings, proposed optimization-based attack strategy, and three solution strategies.
result Demonstrated effectiveness of data poisoning attacks in online learning.
This research improves CNNs' resistance to adversarial examples.
problem Vulnerability of CNNs to adversarial examples.
method Intelligent hyperparameter selection for model resistance.
result Selection of model hyperparameters impacts resistance to adversarial examples.
With a large number of sensors and control units in networked systems, distributed support vector machines (DSVMs) play a fundamental role in scalable and efficient multi-sensor classification and prediction tasks. However, DSVMs are vulnerable to adversaries who can modify and generate data to deceive the system to mi…
The paper examines how to protect LASSO-based feature selection from adversarial attacks.
problem Adversarial attacks on LASSO-based feature selection.
method Formulated as a bi-level optimization problem, reformulated LASSO with linear inequality constraints, solved using interior-point method, and modified using projected gradient descent.
result Demonstrated the effectiveness of the proposed method in protecting LASSO-based feature selection from adversarial attacks.
We study the regret of optimal strategies for online convex optimization games. Using von Neumann's minimax theorem, we show that the optimal regret in this adversarial setting is closely related to the behavior of the empirical minimization algorithm in a stochastic process setting: it is equal to the maximum, over jo…
New betting strategy reduces regret to ln(ln n) with protection against adversarial data.
problem Tackles the problem of minimizing regret in betting against adversarial and stochastic data.
method Combines insights from Robbins and Cover, using a mixture strategy.
result Exhibits a regret of O(ln(ln n)) on almost all paths, with O(log n) regret on the complement.
New algorithm finds mixed Nash equilibria in GANs.
problem No provably convergent algorithm exists for general GANs.
method Developed a novel algorithmic framework via an infinite-dimensional two-player game.
result Proved rigorous convergence rates to the mixed Nash Equilibrium.