DIP-FAT improves adversarial training by diversifying perturbations.
arXiv research
A locally-built, LLM-digested index of recent arXiv papers in quant finance, geometry/topology, and statistical ML — keyword search served straight from SQLite on this machine.
Trend · papers per month
State-of-the-art machine learning models frequently misclassify inputs that have been perturbed in an adversarial manner. Adversarial perturbations generated for a given input and a specific classifier often seem to be effective on other inputs and even different classifiers. In other words, adversarial perturbations s…
This work improves structured prediction by learning the balance between signal and random noise.
New method UADs improves transferability of adversarial perturbations.
Improved DOA estimation with distributed sensors across multiple frequencies.
The goal of this paper is to analyze the geometric properties of deep neural network classifiers in the input space. We specifically study the topology of classification regions created by deep networks, as well as their associated decision boundary. Through a systematic empirical investigation, we show that state-of-t…
A new pruning method reduces neural network computation without retraining.
New method GSAT improves robustness against structured perturbations.
Generating high-quality and interpretable adversarial examples in the text domain is a much more daunting task than it is in the image domain. This is due partly to the discrete nature of text, partly to the problem of ensuring that the adversarial examples are still probable and interpretable, and partly to the proble…
We show that over the binary field , the Bar-Natan perturbation of Khovanov homology splits as the direct sum of its two reduced theories, which we also prove are isomorphic. This extends Shumakovitch's analogous result for ordinary Khovanov homology, without the perturbation.
In this paper we prove a global existence theorem, in the direction of cosmological expansion, for sufficiently small perturbations of a family of -dimensional, , spatially compact spacetimes which generalizes the Friedmann--Robertson--Walker vacuum spacetime. Our results demonstrate causal geodes…
DEceit constructs effective universal pixel-restricted perturbations for deep image classifiers.
Adversarial training is a principled approach for training robust neural networks. Despite of tremendous successes in practice, its theoretical properties still remain largely unexplored. In this paper, we provide new theoretical insights of gradient descent based adversarial training by studying its computational prop…
Given a state-of-the-art deep neural network classifier, we show the existence of a universal (image-agnostic) and very small perturbation vector that causes natural images to be misclassified with high probability. We propose a systematic algorithm for computing universal perturbations, and show that state-of-the-art …
Deep networks have recently been shown to be vulnerable to universal perturbations: there exist very small image-agnostic perturbations that cause most natural images to be misclassified by such classifiers. In this paper, we propose the first quantitative analysis of the robustness of classifiers to universal perturba…
We examine the issue of sensitivity with respect to model parameters for the problem of utility maximization from final wealth in an incomplete Samuelson model and mainly, but not exclusively, for utility functions of positive power-type. The method consists in moving the parameters through change of measure, which we …
Adversarial training, in which a network is trained on both adversarial and clean examples, is one of the most trusted defense methods against adversarial attacks. However, there are three major practical difficulties in implementing and deploying this method - expensive in terms of extra memory and computation costs; …
The study finds regular null hypersurfaces in a perturbed Schwarzschild black hole exterior.
The paper proves the existence and uniqueness of certain spacelike hypersurfaces with specific curvature and boundary conditions.
The inverse statistical problem of finding direct interactions in complex networks is difficult. In the natural sciences, well-controlled perturbation experiments are widely used to probe the structure of complex networks. However, our understanding of how and why perturbations aid inference remains heuristic, and we l…
Following great success in the image processing field, the idea of adversarial training has been applied to tasks in the natural language processing (NLP) field. One promising approach directly applies adversarial training developed in the image processing field to the input word embedding space instead of the discrete…
We consider the Zermelo navigation problem on the ellipsoid of revolution (spheroid) in the presence of a perturbation determined by a mild velocity vector field, , with application of Finsler metric of Randers type in the context of the corresponding optimal control represented by a time-efficient ship's he…
Study examines how body segments respond to random vibrations.
Two-layer networks trained on low-dimensional subspaces are vulnerable to adversarial examples.
Deep RL policies are vulnerable to adversarial perturbations, but vanilla training yields more robust policies.
In this paper, we address the issue of linear stability of Schwarzschild space- time subject to certain axisymmetric perturbations. In particular, we prove that associ- ated solutions to the linearized vacuum Einstein equations centered at a Schwarzschild metric, with suitably regular initial data, decay to a linearize…
GCNNs gain rotation invariance with more training augmentation, making SVD-Universal more effective.
Owing to the susceptibility of deep learning systems to adversarial attacks, there has been a great deal of work in developing (both empirically and certifiably) robust classifiers. While most work has defended against a single type of attack, recent work has looked at defending against multiple perturbation models usi…
This work introduces adversarial sparsity to measure robustness beyond adversarial accuracy.
BOBYQA optimizes deep networks with fewer queries than other methods.
Many machine learning image classifiers are vulnerable to adversarial attacks, inputs with perturbations designed to intentionally trigger misclassification. Current adversarial methods directly alter pixel colors and evaluate against pixel norm-balls: pixel perturbations smaller than a specified magnitude, according t…
Neural networks are part of many contemporary NLP systems, yet their empirical successes come at the price of vulnerability to adversarial attacks. Previous work has used adversarial training and data augmentation to partially mitigate such brittleness, but these are unlikely to find worst-case adversaries due to the c…
New example disproves complex contact theory for fat distributions with Reeb directions.
Improved neural network convergence with causal Bayesian modeling in retail performance.
PWGF escapes saddle points in nonconvex optimization.
We consider the problem of engineering robust direct perception neural networks with output being regression. Such networks take high dimensional input image data, and they produce affordances such as the curvature of the upcoming road segment or the distance to the front vehicle. Our proposal starts by allowing a neur…
State-of-art deep neural networks (DNN) are vulnerable to attacks by adversarial examples: a carefully designed small perturbation to the input, that is imperceptible to human, can mislead DNN. To understand the root cause of adversarial examples, we quantify the probability of adversarial example existence for linear …
When generating adversarial examples to attack deep neural networks (DNNs), Lp norm of the added perturbation is usually used to measure the similarity between original image and adversarial example. However, such adversarial attacks perturbing the raw input spaces may fail to capture structural information hidden in t…
Recent studies show that widely used deep neural networks (DNNs) are vulnerable to carefully crafted adversarial examples. Many advanced algorithms have been proposed to generate adversarial examples by leveraging the distance for penalizing perturbations. Researchers have explored different defense met…
We develop a technique based on Malliavin-Bismut calculus ideas, for asymptotic expansion of dual control problems arising in connection with exponential indifference valuation of claims, and with minimisation of relative entropy, in incomplete markets. The problems involve optimisation of a functional of Brownian path…
New methods help escape strict saddle points in nonsmooth optimization.
Variational Optimization forms a differentiable upper bound on an objective. We show that approaches such as Natural Evolution Strategies and Gaussian Perturbation, are special cases of Variational Optimization in which the expectations are approximated by Gaussian sampling. These approaches are of particular interest …
This paper examines how adversarial perturbations affect model performance and equilibrium learning.
Privacy subsidy found in market trading with noisy direction signals.
The paper analyzes how quantization affects the Fisher Information Matrix's dominant eigenvalue.
We show that, for odd , the bounds of Sogge and Xi for the Nikodym maximal function over manifolds of constant sectional curvature, are unstable with respect to metric perturbation, in the spirit of the work of Sogge and Minicozzi. A direct consequence is the instability of the bounds for the corre…
Recent work has developed methods for learning deep network classifiers that are provably robust to norm-bounded adversarial perturbation; however, these methods are currently only possible for relatively small feedforward networks. In this paper, in an effort to scale these approaches to substantially larger models, w…
DKMD is a fast signed statistic for comparing univariate distributions.