Study on adversarial examples and defenses for malware classification.
problem Vulnerability of neural networks to adversarial examples in malware classification.
method Analysis of different approaches for crafting adversarial examples and defense techniques in malware domain.
result Comparison of effectiveness of different approaches on multiple datasets.
Aligns uncertainty predictions for domain adaptation using pre-trained deep networks.
problem Domain adaptation with unlabelled target data.
method Adversarial learning to align uncertainty predictions between source and target domains.
result Class prediction uncertainty on target domain matches source domain.
Adversarial domain adaptation reduces sample bias in high energy physics classifier.
problem Sample bias in high energy physics classifier training.
method Adversarial domain adaptation using neural networks with gradient reversal layer.
result Successful bias removal on simulated events at the LHC.
NTK neural networks are robust to adversarial attacks in nonparametric regression.
problem Adversarial robustness of neural networks in nonparametric regression.
method Gradient flow with early stopping for NTK neural networks, proving robustness in Sobolev spaces.
result NTK neural networks achieve optimal adversarial robustness rates in Sobolev spaces.
This work formalizes and solves GNN extraction, a new type of attack.
problem Extracting the underlying model from a black-box GNN with API access.
method Formalizes GNN extraction, presents a solution with preliminary results.
result Preliminary results show the feasibility of GNN extraction.
Local convolutions bias neural networks towards high-frequency adversarial examples.
problem High-frequency adversarial examples in neural networks.
method Analysis of different linear and nonlinear architectures, focusing on the impact of local convolution operations.
result Local convolutions induce an implicit bias towards high frequency features, leading to high-frequency adversarial examples.
Study reveals adversarially robust domain adaptation is harder to generalize across domains.
problem Hardness of transferring adversarial robustness across different domains.
method Analysis of adversarial Rademacher complexity over symmetric difference hypothesis space.
result Adversarial Rademacher complexity is always greater than non-adversarial, indicating intrinsic hardness.
Efficient approach improves prediction calibration for domain shifts.
problem Improving uncertainty-aware predictions for domain shifts.
method Combining entropy-encouraging and adversarial calibration losses.
result Substantially outperforms existing approaches in domain drift calibration.
Study shows adversarial attacks can fool speech-to-text models, and PCA is ineffective as a defense.
problem Adversarial attacks can mislead speech-to-text neural networks.
method Crafted adversarial waveforms, used PCA for defense, tested under black-box setting.
result PCA is ineffective as a defense mechanism against adversarial attacks in audio domain.
AFD learns features resistant to adversarial attacks.
problem Vulnerability of neural networks to adversarial attacks.
method AFD learns features invariant to adversarial perturbations through a game of predictive and robust features.
result AFD effectively resists a wide range of attack types and strengths.
Modern automatic speech recognition (ASR) systems need to be robust under acoustic variability arising from environmental, speaker, channel, and recording conditions. Ensuring such robustness to variability is a challenge in modern day neural network-based ASR systems, especially when all types of variability are not s…
Research evaluates adversarial attacks and defenses on 3D point cloud classifiers.
problem Robustness of 3D object classifiers against adversarial attacks.
method Extending 2D adversarial attacks to 3D point clouds and proposing new defenses.
result 3D point cloud classifiers are weak to adversarial attacks but more defensible.
New methods protect malware classification networks from adversarial attacks.
problem Adversarial perturbations compromise malware classification networks.
method Training restricted networks with non-negative weight restrictions and relaxing constraints.
result Improved classifier accuracy while maintaining resistance to adversarial attacks.
Domain-Adversarial Neural Networks improve fault diagnosis models across different machines.
problem Improving fault diagnosis models on new machines with limited labeled data.
method Domain-Adversarial Neural Networks (DANN) and other methods for domain adaptation.
result Unified experimental protocol for fair comparison of domain adaptation methods.
Study on deep learning IDS resistance against adversarial attacks.
problem Vulnerabilities in deep learning-based IDS against adversarial attacks.
method Apply min-max optimization to train IDS against adversarial samples.
result Adversarial attack methods can be used in continuous domains and boost IDS robustness.
Paper tackles policy optimization from observational data, overcoming missing counterfactuals and selection bias.
problem Optimizing policies from observational data in the absence of controlled experiments.
method Theoretical bounds on estimation errors of counterfactuals, domain adversarial neural networks.
result Effective domain adversarial training for choosing optimal policies.
While domain adaptation has been actively researched in recent years, most theoretical results and algorithms focus on the single-source-single-target adaptation setting. Naive application of such algorithms on multiple source domain adaptation problem may lead to suboptimal solutions. As a step toward bridging the gap…
Detects adversarial examples using SHAP values from neural networks.
problem Vulnerability of deep neural networks to adversarial attacks.
method Uses SHAP values from internal layers to distinguish normal from adversarial inputs.
result Demonstrates high detection accuracy and strong generalization to various attack methods.
GPDNNs inherit robustness from GPs and DNNs, outputting high entropy for adversarial examples.
problem Robustness of deep neural networks in real-world scenarios.
method GP hybrid deep networks (GPDNNs) combining GPs and DNNs.
result GPDNNs output high entropy for adversarial examples, indicating uncertainty.
Develops Triangle GAN for semi-supervised cross-domain learning.
problem Semi-supervised cross-domain joint distribution matching with limited labeled data.
method Triangle GAN architecture with two generators and two discriminators trained adversarially.
result Generators learn conditional distributions between domains, discriminators define ternary function.
Deep neural networks are vulnerable to adversarial attacks in time series classification.
problem Vulnerability of deep learning models to adversarial time series examples.
method Proposed adversarial attack mechanisms to add noise to input time series.
result Current state-of-the-art deep learning time series classifiers are vulnerable to adversarial attacks.
HAGAN uses hierarchical attention to improve cross-domain sentiment classification.
problem Cross-domain sentiment classification with domain discrepancy.
method Hierarchical attention in GANs to produce domain-indistinguishable document representations.
result HAGAN outperforms existing methods on Amazon review dataset.
This research evaluates neural network robustness through loss visualization and a new metric.
problem Neural networks' robustness property is insufficiently investigated compared to adversarial attacks and defenses.
method Loss visualization and a new robustness metric to evaluate model stability.
result The proposed robustness metric provides a more reliable evaluation of model stability, uniformed across different models and settings.
A new method makes adversarial domain adaptation aware of class relationships.
problem Ignoring inter-class semantic relationships in domain adaptation.
method RADA algorithm that aligns inter-class dependencies learned from domain discriminator with those from label predictor.
result Improves performance on benchmark datasets by incorporating class relationships.
Generative adversarial network improves signal reconstruction from magnitude spectrograms.
problem Reconstructing a time-domain signal from a magnitude spectrogram.
method Deep neural network and generative adversarial network approach.
result Our method reconstructs signals faster with higher quality than the Griffin-Lim method.
WM layer improves CNN robustness to noise and adversarial attacks.
problem CNNs' susceptibility to noise and adversarial attacks.
method WM layer as a generic architectural addition to CNNs.
result WM variants enhance robustness to noise and adversarial attacks.
DA-RNN predicts driving maneuvers up to 3 seconds ahead.
problem Adapting driving model to new drivers and vehicles.
method Domain-Adversarial Recurrent Neural Network (DA-RNN) for robust predictions.
result DA-RNN improves performance by 30% in real drivers and 114% in simulations.
TAnoGan detects anomalies in time series data using GANs.
problem Anomaly detection in time series data.
method Generative Adversarial Networks (GAN) for unsupervised anomaly detection.
result TAnoGan outperforms traditional and neural network models in anomaly detection.
This work generates diverse adversarial attacks for different domains using latent variable perturbation.
problem Adversarial attacks on deep neural networks are limited to a single perturbation.
method Frame adversarial attacks as learning a distribution of perturbations, enabling generation of diverse attacks.
result Framework generates competitive or superior adversarial attacks across diverse domains (images, text, graphs).
Improves deep learning robustness by enforcing local and global compactness.
problem Deep neural networks' vulnerability to adversarial attacks.
method Proposes Adversary Divergence Reduction Network (ADRN) that enforces local/global compactness and clustering assumption.
result Augmenting adversarial training with ADRN components improves robustness.
We introduce a new representation learning algorithm suited to the context of domain adaptation, in which data at training and test time come from similar but different distributions. Our algorithm is directly inspired by theory on domain adaptation suggesting that, for effective domain transfer to be achieved, predict…
Adversarially-trained models transfer better in limited data scenarios.
problem Improving transfer learning performance with limited data.
method Adversarially-train deep nets, freeze early layers, fine-tune last layers, observe shape vs texture bias.
result Adversarially-trained models transfer better than non-adversarially-trained models, especially with limited data.
Study of adversarial attacks on neural networks for graph data.
problem Robustness of neural networks for graph data to adversarial attacks.
method Introduced first study of adversarial attacks on attributed graphs, focusing on graph convolutions. Developed efficient algorithm Nettack for generating unnoticeable perturbations.
result Significant drop in accuracy of node classification even with few perturbations, and attacks are transferable.
MetFA aligns source and target domains for cross-device image classification.
problem Learning discriminative class boundaries across different domains.
method Distance metric guided feature alignment (MetFA) for domain-invariant and discriminative feature extraction.
result MetFA outperforms state-of-the-art methods in cross-device image classification.
Speech recognition simplified by treating audio as images.
problem Identifying voice commands in noisy environments.
method Comparing neural network architectures (CNN, low-latency CNN, adversarially trained CNN) for keyword spotting.
result Demonstrated how to apply image classification techniques to audio recognition.
LIME outperforms other explainers in identifying adversarial attack regions.
problem Evaluating explainers for detecting adversarial attacks in neural networks.
method Quantitative and qualitative investigation of three explainers on adversarial examples.
result LIME outperforms classic salience and guided backpropagation in identifying adversarial attack regions.
SmoothFool efficiently computes smooth adversarial perturbations for deep networks.
problem Vulnerability of deep neural networks to adversarial attacks with specific statistical properties.
method SmoothFool: a general and computationally efficient framework for computing smooth adversarial perturbations.
result Smoothness significantly enhances robustness against adversarial attacks and improves transferability.
Paper improves neural network robustness certification with tighter radii estimates.
problem Certifying neural networks' robustness against adversarial attacks.
method Advanced algorithms for discrete and continuous domains, optimizing sample size, standard deviation, and temperature.
result Significant improvement in certified test-set accuracy with tighter certified radii bounds.
Study on adversarial training's impact on deep neural reinforcement learning policies.
problem Vulnerability of deep neural reinforcement learning policies to imperceptible adversarial perturbations.
method Two parallel approaches: Fourier spectrum analysis and feature sensitivity measurement.
result Adversarially trained policies are more sensitive to low frequency perturbations.
Improved neural networks resist adversarial attacks and explain decisions better.
problem Neural networks are vulnerable to adversarial examples that alter their outputs.
method Introduced a novel regularization technique inspired by the Lipschitz constraint.
result Demonstrated a neural network with an ARA of 0.0053, 2.4x better than previous state of the art.
Mathematical framework to understand neural network vulnerability.
problem Understanding and quantifying adversarial vulnerability in neural networks.
method Develops a geometric framework using Ricci curvature to measure decision boundaries and adversarial perturbations.
result Establishes a new theory linking adversarial attacks to Ricci curvature of decision boundaries.
Trapdoors in neural networks attract adversarial attacks, making them easier to detect.
problem Adversarial attacks on neural networks are difficult to detect and defend against.
method Intentionally inject trapdoors to attract adversarial attacks, then detect them based on feature similarity.
result Trapdoor-protected models can accurately detect adversarial examples with minimal impact on normal classification.
Adapts segmentation networks across synthetic and real domains using GANs.
problem Difficulty in learning informative representations across domain shift for semantic segmentation.
method Generative Adversarial Networks (GANs) to align embeddings in feature space.
result Achieves state-of-the-art results on synthetic to real domain adaptation scenarios.
TensorShield defends images from adversarial attacks using tensor decomposition.
problem Adversarial attacks on images can fool deep neural networks.
method Tensor decomposition to find low-rank approximations of images, reducing high-frequency perturbations.
result TensorShield outperforms existing methods like SLQ by 14% against FGSM attacks.
New framework detects adversarial inputs by contrasting human interpretation with classification.
problem Deep neural networks are vulnerable to adversarial inputs, especially in security-critical applications.
method Constructs a detection framework that compares human interpretation with classification results.
result Demonstrates the effectiveness of the new framework through experiments on benchmark datasets.
One pixel attack can fool deep neural networks, showing their vulnerability.
problem Vulnerability of deep neural networks to small perturbations in input.
method Proposes a novel method using differential evolution (DE) for generating one-pixel adversarial perturbations.
result 67.97% of natural images and 16.04% of ImageNet images can be fooled by modifying just one pixel.
Improved acoustic modeling with attentive adversarial learning.
problem Domain variability in acoustic modeling.
method Proposes an attentive ADIT method with an attention mechanism to improve domain-invariance of deep features.
result Improves deep feature domain-invariance and senone-discriminativity over ADIT.
Study stabilizes adversarial training in neural networks over infinite-dimensional spaces.
problem Stability issues in adversarial training of neural networks.
method Functional analysis of minimax optimization over infinite-dimensional spaces of continuous functions and probability measures.
result Convergence property of minimax problems under certain conditions, interpreted as stabilization techniques.