Paper shows attacks on transfer learning models without target-specific info.
problem Security vulnerability in transfer learning models.
method Brute force attack on pre-trained models without target-specific data.
result Demonstrates effective and efficient attacks on transfer learning models.
Paper proposes protecting DNN models with secret key preprocessing.
problem Protecting deep learning models from unauthorized access.
method Block-wise pixel shuffling with secret key for preprocessing.
result Protected models maintain close performance to non-protected models with correct key, but accuracy drops significantly with incorrect key.
Computational method finds examples of extremal hyperbolic surfaces.
problem Constructing explicit examples of extremal hyperbolic surfaces is complicated.
method Brute force computational procedure.
result Examples of extremal hyperbolic surfaces constructed in all cases.
Sparse linear regression is hard to solve efficiently, even with k-sparse solutions.
problem Sparse linear regression problem with k-sparse solutions.
method Fine-grained complexity and hardness assumptions.
result No better-than-brute-force algorithms exist for sparse linear regression.
A cardinality-constrained portfolio caps the number of stocks to be traded across and within groups or sectors. These limitations arise from real-world scenarios faced by fund managers, who are constrained by transaction costs and client preferences as they seek to maximize return and limit risk. We develop a new appro…
Recently proposed models which learn to write computer programs from data use either input/output examples or rich execution traces. Instead, we argue that a novel alternative is to use a glass-box loss function, given as a program itself that can be directly inspected. Glass-box optimization covers a wide range of pro…
Proof of theorem for 7D manifolds with boundary using Witten deformation.
problem Proving a theorem for 7-dimensional manifolds with boundary.
method Brute-force proof using Witten deformation.
result Proof of Kastler-Kalau-Walze type theorem for 7D manifolds with boundary.
An important task in structural design is to quantify the structural performance of an object under the external forces it may experience during its use. The problem proves to be computationally very challenging as the external forces' contact locations and magnitudes may exhibit significant variations. We present an e…
Efficiently calibrates volatility models using Chebyshev Tensors.
problem Calibrating pricing models efficiently.
method Used Chebyshev Tensors to speed up calibration of the rough Bergomi volatility model.
result Chebyshev Tensors can calibrate the rough Bergomi volatility model 40,000 times more efficiently than brute-force methods.
On certain manifolds, the phase which appears in the scalar product of two coherent state vectors is twice the symplectic area of the geodesic triangle determined by the corresponding points on the manifold and the origin of the system of coordinates. This result is proved for compact Hermitian symmetric spaces using t…
The scientific method relies on the iterated processes of inference and inquiry. The inference phase consists of selecting the most probable models based on the available data; whereas the inquiry phase consists of using what is known about the models to select the most relevant experiment. Optimizing inquiry involves …
Isometry pursuit identifies orthonormal submatrices from wide matrices.
problem Identifying isometric embeddings from wide matrices.
method A convex algorithm combining normalization and multitask basis pursuit.
result The method identifies isometric embeddings from interpretable dictionaries.
The purpose of this paper is to design an algorithm for the computation of the counterparty risk which is competitive in regards of a brute force "Monte-Carlo of Monte-Carlo" method (with nested simulations). This is achieved using marked branching diffusions describing a Galton-Watson random tree. Such an algorithm le…
This paper optimizes UAV and FeICIC locations in a three-tier LTE-Advanced network.
problem Optimizing UAV and FeICIC locations in a three-tier LTE-Advanced network.
method Integrates UAVs as both UE and BS in LTE-Advanced HetNet, uses CRE, ICIC, 3D beamforming, and genetic algorithms for optimization.
result Heuristic algorithms outperform brute-force techniques in achieving better 5pSE and coverage probability.
Classifies uncolored bonded knots with up to 7 singularity points.
problem Classifying uncolored bonded knots with up to 7 singularity points.
method Generation of planar graphs, conversion into bonded knot diagrams, use of Yamada polynomial, and brute-force Reidemeister moves.
result Systematic classification of uncolored bonded knots with singularity number at most seven.
New theorem disproves Angle Defect for super triangles.
problem Angle Defect Theorem for N=1 super hyperbolic geometry.
method Action of OSp(1|2) on real super Minkowski space and brute-force computation.
result Disproves Angle Defect Theorem and provides novel additive function.
Deep models store facts in geometric embeddings, not just associative memory.
problem Understanding how deep models store and utilize atomic facts.
method Identified geometric memory, contrasting with associative lookup.
result Geometric memory transforms hard reasoning into easy tasks.
Reward-poisoning attacks can force RL agents to learn bad policies, and we categorize and quantify their feasibility.
problem Reward-poisoning attacks can manipulate RL agents to learn undesirable policies.
method Categorize attacks by infinity-norm constraint, provide thresholds for feasibility, and develop adaptive attack strategies.
result Adaptive reward-poisoning attacks can achieve the nefarious policy in polynomial steps, while non-adaptive attacks require exponential steps.
Attackers can poison environments to force RL agents to follow target policies.
problem Security threat to reinforcement learning where attackers manipulate environments to force agents into following target policies.
method Optimization framework for finding optimal stealthy attacks under different measures of attack cost.
result Attackers can easily succeed in teaching any target policy to RL agents under mild conditions.
New algorithms tackle adversarial multi-player bandits with forced-collision communication.
problem No-sensing adversarial multi-player multi-armed bandits (MP-MAB) problem.
method Adversary-Adaptive Collision-Communication (A2C2) algorithms, attackability-aware and unaware settings, information-theoretic tools, error-correction coding.
result Asymptotic attackability-dependent sublinear regret achieved, with or without knowing attackability.
Solve arc diagrams on surfaces via branched covers.
problem Computing arc diagrams on surfaces via branched covers.
method Represent branched covers combinatorially and solve membership problem.
result Efficient solution for triangulated arc diagrams.
We study offline data poisoning attacks in contextual bandits, a class of reinforcement learning problems with important applications in online recommendation and adaptive medical treatment, among others. We provide a general attack framework based on convex optimization and show that by slightly manipulating rewards i…
Two statistical tasks are shown to have equivalent sample complexity.
problem Determining if a function depends on only a few variables and identifying those variables.
method Proved statistical equivalence of feature selection and junta testing through sample complexity analysis.
result Brute-force algorithm is sample-optimal for both tasks with optimal sample size.
We adopt data structure in the form of cover trees and iteratively apply approximate nearest neighbour (ANN) searches for fast compressed sensing reconstruction of signals living on discrete smooth manifolds. Levering on the recent stability results for the inexact Iterative Projected Gradient (IPG) algorithm and by us…
Optimal attack against autoregressive models by manipulating environment states.
problem Manipulating autoregressive forecasts to track a target trajectory.
method Linear Quadratic Regulator (LQR) for linear models, Model Predictive Control (MPC) for nonlinear models.
result Optimal attack formulations for both white-box and black-box settings.
A new framework for mobile authentication using deep metric learning.
problem Challenges in mobile authentication using behavioral biometrics.
method Deep metric learning, private data protection, flexible training scheduling.
result 95% authentication accuracy on public datasets, robust against attacks.
Efficiently finds diverse coherent counterfactual explanations.
problem Finding coherent counterfactual explanations for complex data.
method Mixed integer programming with mixed polytope constraints.
result Efficiently generates diverse coherent counterfactual explanations.
New action poisoning attacks improve LinUCB's performance by changing action signals.
problem Improving understanding of adversarial attacks on contextual bandit algorithms.
method Proposed action poisoning attacks in white-box and black-box settings.
result Action poisoning attacks can force LinUCB to pull a target arm frequently with low cost.
New algorithm approximates conditional expectations with fast convergence.
problem Approximating conditional expectations in stochastic derivative weights.
method Least-squares Monte Carlo with brute-force SVD truncation.
result Convergence rate is arbitrarily fast polynomial in number of samples.
We propose a fast algorithm for computing the economic capital, Value at Risk and Greeks in the Gaussian factor model. The algorithm proposed here is much faster than brute force Monte Carlo simulations or Fourier transform based methods \cite{MD}. While the algorithm of Hull-White \cite{HW} is comparably fast, it assu…
Partial soft-matching distance improves neural representation comparison by allowing some neurons to remain unmatched.
problem Neural representations are noisy and contain outliers, making traditional matching methods unreliable.
method Extends soft-matching distance to a partial optimal transport setting, allowing some neurons to remain unmatched.
result Partial soft-matching provides robust correspondences that are more reliable under noise and outliers.
This paper studies adversarial attacks on Gaussian process bandits.
problem Adversarial attacks on Gaussian process bandits to manipulate optimal function regions.
method Proposes various adversarial attack methods on GP bandits, including white-box and black-box attacks.
result Adversarial attacks can force GP bandits to optima in target regions even with low attack budgets.
Researchers develop methods to protect reinforcement learning and control systems from policy poisoning attacks.
problem Attacks on reinforcement learning and control systems that manipulate learned policies.
method Unified framework for solving policy poisoning attacks, demonstrating global optimality and feasibility.
result Policy poisoning attacks are feasible and can be defended with a convex optimization approach.
Paper studies attacks on bandit algorithms and shows how attackers can manipulate data to hijack behavior.
problem Potential attacks on bandit algorithms can cause catastrophic loss in real-world applications.
method Proposes a framework of offline and online attacks on bandit algorithms using convex optimization and adaptive strategies.
result Attackers can force bandit algorithms to pull target arms with high probability by manipulating data.
Improved symbolic regression finds optimal formulas robust to noise.
problem Finding accurate formulas for noisy data.
method Exploits graph modularity, uses normalizing flows, and statistical hypothesis testing.
result Discoveres many formulas previously unattainable.
A new method speeds up sampling of Boltzmann distribution in high-dimensional systems.
problem High computational cost of obtaining Jacobian of flow-based models in high dimensions.
method Flow perturbation method that incorporates stochastic perturbations and reweighting.
result Achieves unbiased sampling of Boltzmann distribution with orders of magnitude speedup.
We study the problem of the optimal execution of a large trade in the presence of nonlinear transient impact. We propose an approach based on homotopy analysis, whereby a well behaved initial strategy is continuously deformed to lower the expected execution cost. We find that the optimal solution is front loaded for co…
AI detects LDDoS attacks by analyzing TCP connection parameters.
problem Detecting low-rate LDDoS attacks that overwhelm server connections.
method AI algorithms trained on simulated and real-world datasets using TCP flow features.
result Decision trees and k-NN achieved high accuracy in classifying attacks, with low false positives and negatives.
Paper introduces class-oriented poisoning attacks to improve adversarial availability attacks.
problem Improving adversarial availability attacks on neural networks.
method Gradient-based framework for crafting poisoned images at the class level.
result Demonstrated effectiveness of class-oriented poisoning attacks on various models and datasets.
Algorithm finds causal effects from observational data using auxiliary variables.
problem Estimating causal effects from observational data with confounders.
method Gradient-based optimization using auxiliary variables.
result Algorithm outperforms alternatives in estimating true causal effect.
The paper certifies decision trees against evasion attacks using program analysis.
problem Vulnerability of decision tree models to evasion attacks by maliciously crafted perturbations.
method Transform decision trees into imperative programs for program analysis, leveraging abstract interpretation.
result Soundly verifies security guarantees of decision tree models, yielding minimal false positives.
Consider two networks on overlapping, non-identical vertex sets. Given vertices of interest in the first network, we seek to identify the corresponding vertices, if any exist, in the second network. While in moderately sized networks graph matching methods can be applied directly to recover the missing correspondences,…
Initial margin requirements are becoming an increasingly common feature of derivative markets. However, while the valuation of derivatives under collateralisation (Piterbarg 2010, Piterbarg2012), under counterparty risk with unsecured funding costs (FVA) (Burgard2011, Burgard2011, Burgard2013) and in the presence of re…
Empowerment quantifies the influence an agent has on its environment. This is formally achieved by the maximum of the expected KL-divergence between the distribution of the successor state conditioned on a specific action and a distribution where the actions are marginalised out. This is a natural candidate for an intr…
Study defenses against data poisoning attacks in online learning.
problem Data poisoning attacks on machine learning models.
method Rigorous study of four standard defenses in both a powerful and a realistic threat model.
result The effectiveness of defenses depends on the ease of the learning problem.
Paper detects adversarial speech inputs with high accuracy.
problem Adversarial attacks on ASR systems.
method Uncertainty quantification using neural networks.
result Detection accuracy of adversarial inputs over 0.99.
New method finds local anomalies in time series by considering context information.
problem Finding anomalous subsequence in long time series is difficult.
method Introduces semantic discord, an approach that incorporates context information.
result Significantly outperforms state-of-the-art methods in locating anomalies.
Develops active learning for scale-bridging simulations.
problem Quantitative predictions in nanoporous media and inertial confinement fusion.
method Active learning approach to optimize fine-scale simulations for coarse-scale hydrodynamics.
result Optimizes use of fine-scale simulations for coarse-scale predictions.