Paper proposes detecting video manipulation using stream descriptors.
problem Misuse of manipulated video content.
method Binary classifiers on multimedia stream descriptors.
result Scalable approach can detect high-quality manipulations.
New framework reduces strategic manipulation cost for minority groups in fair classification.
problem Strategic manipulation disparities in fair classification.
method Constrained optimization framework that constructs classifiers to reduce strategic manipulation cost for minority groups.
result Empirically, the approach reduces strategic manipulation cost for minority groups over multiple real-world datasets.
Modified Perceptron handles strategic agents with limited position changes.
problem Learning linear classifiers in the presence of strategic agents that can manipulate their positions.
method Developed a modified Perceptron algorithm with bounded mistakes under various manipulation costs.
result The modified Perceptron achieves bounded mistakes even when manipulation costs are unknown.
This work generates training-time adversarial data using auto-encoders to manipulate classifiers.
problem Manipulating the behavior of trained classifiers during test time with bounded perturbation.
method An auto-encoder-like network generates perturbations, learning to update weights to produce harmful noise.
result The method can manipulate classifiers effectively, showing good transferability.
Camera stickers can fool deep learning systems by manipulating the lens, achieving 49.6% misclassification rate.
problem The vulnerability of deep learning systems to physical adversarial attacks.
method Iterative procedure to update attack perturbation and threat model for physical realizability.
result Achieved 49.6% misclassification rate for targeted attacks on ImageNet classifiers.
Recent work has shown that state-of-the-art classifiers are quite brittle, in the sense that a small adversarial change of an originally with high confidence correctly classified input leads to a wrong classification again with high confidence. This raises concerns that such classifiers are vulnerable to attacks and ca…
FaceSigns embeds a secret watermark in images to authenticate and detect deepfakes.
problem Realistic image and video manipulation threats, especially deepfakes.
method Semi-fragile watermarking using neural networks, robust to face-swapping but fragile to deepfake manipulations.
result FaceSigns can reliably detect deepfake content with high accuracy.
Researchers create a flickering attack to fool video recognition networks.
problem Adversarial manipulation of video classification networks.
method Introducing a flickering temporal perturbation to fool video classifiers.
result Achieved high fooling ratio and temporal-invariant perturbation.
Paper proposes structured semantic perturbations to improve adversarial attacks.
problem Vulnerability of deep neural networks to adversarial attacks.
method Manipulates semantic attributes via disentangled latent codes.
result Demonstrates the effectiveness of structured semantic perturbations.
This work introduces a framework to detect unintended bias in facial analysis models.
problem Detecting unintended biases in facial analysis models used in critical applications.
method Image counterfactual sensitivity analysis using generative adversarial networks.
result Identifies factors affecting facial classifier predictions, revealing unintended biases.
Can we manipulate multiple deep neural networks simultaneously?
problem Selective fooling of multiple machine learning systems.
method Formulated as a novel optimization problem.
result It is easy to selectively manipulate multiple MNIST classifiers simultaneously.
New model improves classifier security against evasion attacks by selecting features.
problem Security of machine learning classifiers against evasion attacks.
method Adversary-aware feature selection model incorporating specific adversary assumptions.
result Classifier security worsens with feature selection, but new model improves it.
New method makes machine learning models robust to label flipping attacks.
problem Machine learning models are vulnerable to label flipping attacks.
method Randomized smoothing over arbitrary functions to build certifiably robust classifiers.
result Linear classifiers are robust to label flipping attacks with deterministic bounds.
Data poisoning is an attack on machine learning models wherein the attacker adds examples to the training set to manipulate the behavior of the model at test time. This paper explores poisoning attacks on neural nets. The proposed attacks use "clean-labels"; they don't require the attacker to have any control over the …
Randomized classifiers improve strategic classification efficiency.
problem Designing optimal classifiers in strategic classification games.
method Investigation of randomized classifiers and their efficiency in strategic classification.
result Randomized classifiers are necessary for maximizing classification efficiency.
The paper examines how social inequality affects algorithmic classification outcomes.
problem Social inequality impacts algorithmic classification outcomes.
method Adapting models of strategic manipulation to account for social inequality and subsidy effects.
result Subsidizing disadvantaged groups can paradoxically harm both groups and the learner.
Robotic grasp stability improved with fingertip slippage detection.
problem Improving grasp stability in robotic manipulation.
method Task-relevant feature extraction and efficient classifier design for fingertip slippage detection.
result The proposed method effectively detects object slippage with fingertips in an online fashion.
In this work we develop a fast saliency detection method that can be applied to any differentiable image classifier. We train a masking model to manipulate the scores of the classifier by masking salient parts of the input image. Our model generalises well to unseen images and requires a single forward pass to perform …
A single robust classifier handles complex image synthesis tasks.
problem Challenging image synthesis tasks.
method Adversarial robustness training of a single classifier.
result Direct manipulation of salient features in input images.
Paper examines adversarial attacks on event cause analysis in power grids.
problem Adversarial attacks manipulate data to mislead event classifiers.
method Investigated adversarial attacks on CNN-based event cause analysis.
result Demonstrated adversaries can misclassify events through stealthy data manipulations.
The paper develops classifiers that encourage positive adaptation in machine learning settings.
problem Strategic behavior by decision subjects leads to performance loss in machine learning models.
method Formulates a two-stage game to characterize optimal strategies for model designers and decision subjects.
result Trained classifiers maintain accuracy while inducing higher improvement and less manipulation.
Self-guidance controls image generation by extracting properties from diffusion model representations.
problem Generating images from text descriptions is challenging due to the complexity of visual details.
method Self-guidance uses internal representations of diffusion models to control image generation.
result Properties like object shape, location, and appearance can be extracted and used to steer image generation.
Research proposes classifiers to distinguish tweets with conflicting cashtags.
problem Cryptocurrency cashtags interfere with stock company cashtags on Twitter.
method Heuristic and supervised classifiers analyzed for distinguishing tweets.
result Independent Models perform best in distinguishing tweets with conflicting cashtags.
Ensembles of classifier models typically deliver superior performance and can outperform single classifier models given a dataset and classification task at hand. However, the gain in performance comes together with the lack in comprehensibility, posing a challenge to understand how each model affects the classificatio…
New method shows unfair explanations can be created for any classifier.
problem Fairness in black-box classifier explanations is not guaranteed.
method Constructs a new classifier with similar performance but altered explanations.
result Explanation methods can be manipulated to show unfair decisions.
Analyzes how learning algorithms affect and are affected by data manipulation.
problem Characterizing the closed-loop behavior of learning algorithms in the presence of decision-dependent data.
method Analyzes repeated risk minimization as perturbed gradient flows of performative risk minimization, considering multiple local minimizers.
result Characterizes the region of attraction for various equilibria and introduces performative alignment.
AI learns market manipulation through simulation, suggesting regulation.
problem Regulating AI to prevent market manipulation.
method Used a genetic algorithm in an artificial market simulation.
result AI discovered market manipulation as an optimal strategy.
Model manipulates facial expressions without affecting other attributes.
problem Manipulating specific visual attributes in real scenes without altering others.
method Trains model on nonphotorealistic 3D renders to manipulate facial expressions, preserving other attributes.
result Model can manipulate facial expressions without affecting other attributes like head orientation.
The paper analyzes how leverage affects manipulation in event-linked markets, offering new insights into regulation.
problem Manipulation and insider information in leveraged event-linked markets.
method Develops a two-axis manipulation taxonomy and analyzes leverage's effects on market-price and outcome manipulation.
result Leverage scales market-price manipulation linearly but shifts the cost-benefit threshold for outcome manipulation.
Paper analyzes adversarial risk using optimal transport.
problem Poor performance of machine learning on adversarial data.
method Optimal transport perspective, optimal transport plans (couplings), convexity, smoothness assumptions.
result Fundamental limits on adversarial risk calculated for various datasets.
New model improves neural network robustness against input manipulations.
problem Improving neural network robustness against input manipulations.
method Causal view and deep causal manipulation augmented model (deep CAMA) with data augmentation and test-time fine-tuning.
result Deep CAMA shows superior robustness against unseen manipulations compared to traditional models.
Localized adversarial training improves image classifiers' robustness.
problem State-of-the-art image classifiers fail on carefully manipulated adversarial images.
method Developed a localized adversarial attack and used it to train a robust classifier.
result Localized adversarial training increases robustness against adversarial inputs.
New method learns various data manipulation schemes for model training.
problem Improving model training with data manipulation.
method Adapts RL reward learning algorithm for data manipulation learning.
result Significant improvement in classification performance.
This paper studies poisoning attacks in episodic RL and discovers their effectiveness depends on reward bounds.
problem Understanding security threats to RL algorithms through poisoning attacks.
method Examined two types of poisoning attacks: reward and action manipulation, in bounded and unbounded reward settings.
result The effectiveness of poisoning attacks depends on reward bounds, with different attack costs and success rates.
Donors who defer their donations volunteer less in the future.
problem Volunteer labor can be less beneficial to charities than its costs.
method Regression discontinuity design with a procedure to handle manipulation.
result Donor manipulation invalidates standard regression discontinuity design, but a new method provides partial identification bounds.
Prediction markets can be manipulated by traders who can move contract settlements, harming price discovery.
problem Manipulation of settlement times in prediction markets leads to unfair wealth transfer and harms price discovery.
method Developed a model showing how settlement manipulation transfers wealth and harms price discovery, and observed real-world effects on Polymarket's Bitcoin contract.
result Manipulators capture significant profits from retail traders, especially when settlement times are short.
DIGIT is a low-cost tactile sensor for in-hand manipulation.
problem Difficulty in sensing contact forces limits robotic manipulation.
method DIGIT miniaturizes and improves a vision-based tactile sensor.
result DIGIT enables better control of interactions with the environment.
VarNet learns and manipulates high-level attributes from inputs.
problem Manipulating high-level attributes of inputs.
method Generative model that learns attributes from data and can handle predefined attributes.
result VarNet can learn and manipulate relevant attributes from datasets.
Paper presents a new port-Hamiltonian model for vehicle manipulators.
problem Complex mechanical systems' energy flow and conservation.
method Derives port-Hamiltonian dynamics from Hamiltonian reduction theory.
result Establishes mathematical equivalence with existing formulations.
PG-IM uses neural-symbolic programs to manipulate images.
problem Creating holistic image representations and manipulations.
method PG-IM detects patterns, induces symbolic programs, and manipulates images using a neural network.
result PG-IM learns from a single image and achieves superior performance.
Optimal benchmark design varies based on costs in financial manipulation.
problem Manipulation of price benchmarks in finance.
method Analyzes empirical pattern and cost structures to determine optimal benchmark design.
result The optimal benchmark depends on the relative sizes of fixed and variable costs.
Study examines reasons for Nutek India's share price drop.
problem Deep fall in Nutek India Limited's share price.
method Analyzed transactions and market forces to identify manipulation.
result Identified intentional interference in supply and demand.
The paper discusses decades of stock market manipulation and its benefits.
problem Manipulating public equity markets over 30 years.
method Quantitative analysis of market impact and price movement.
result Price manipulation is a valuable and profitable tool.
New method uses statistical physics to detect financial market manipulation.
problem Detecting financial market manipulation activities like spoofing and layering.
method Modeling order book dynamics as particle motion and using momentum measure.
result Method outperforms conventional Z-score-based anomaly detection.
Paper generalizes strategic classification framework and introduces SVC for PAC-learning.
problem Strategic manipulation of testing data to fool classifiers.
method Unified framework for strategic classification, strategic VC-dimension (SVC).
result Characterizes the learnability and computational tractability of linear classifiers.
Market manipulation is a strategy used by traders to alter the price of financial securities. One type of manipulation is based on the process of buying or selling assets by using several trading strategies, among them spoofing is a popular strategy and is considered illegal by market regulators. Some promising tools h…
Manipulated explanations can be made imperceptible to the naked eye.
problem The trustworthiness and interpretability of neural networks can be compromised by manipulable explanations.
method The paper demonstrates that explanations can be altered by applying small, imperceptible input changes that do not affect the network's output.
result An upper bound on the susceptibility of explanations to manipulation has been derived, and effective mechanisms to enhance explanation robustness have been proposed.
The paper classifies reversible and strongly reversible elements in Hermitian isometry groups.
problem Classifying reversible and strongly reversible elements in Hermitian isometry groups.
method Classification through group theory and algebraic manipulation.
result New classification of strongly reversible elements in Sp(n).