This paper tackles adversarial reinforcement learning in cyber defence with partial observability.
problem Adversarial manipulation of reinforcement learning agents in autonomous cyber defence.
method Proposes an inversion defence method to counteract causative attacks under partial observability.
result The proposed inversion defence method effectively reduces the impact of adversarial attacks without affecting non-attack training scenarios.
Deep Latent Defence combines adversarial training with a detection system to protect neural networks.
problem Vulnerability of neural networks to adversarial attacks, especially those that cause misclassification.
method Adversarial training combined with a k-NN classifier in a latent space. result Deep Latent Defence effectively detects and mitigates adversarial attacks, even under strong attack models.
New defence against data-poisoning attacks in neural networks.
problem Data-poisoning attacks can evade existing defences and increase model efficacy.
method Proved geometric mechanism and identified near clone regime in input space.
result Regularisation and data augmentation reduce data fitting capacity and prevent poisoning.
In the last decade, deep learning algorithms have become very popular thanks to the achieved performance in many machine learning and computer vision tasks. However, most of the deep learning architectures are vulnerable to so called adversarial examples. This questions the security of deep neural networks (DNN) for ma…
The paper uses a simulator and optimisation to defend against cyber threats.
problem Defending against cyber threats in simulated networks.
method Dynamic causal Bayesian optimisation (DCBO) integrated with a cyber security simulator.
result DCBO optimally reduces the cost of intrusions in simulated networks.
We prove, under two sufficient conditions, that idealised models can have no adversarial examples. We discuss which idealised models satisfy our conditions, and show that idealised Bayesian neural networks (BNNs) satisfy these. We continue by studying near-idealised BNNs using HMC inference, demonstrating the theoretic…
This study evaluates the robustness of transformation-based ensemble defense against evasion attacks.
problem Understanding the reasons behind the robustness improvement in transformation-based ensemble defense.
method Designing two adaptive attacks to evaluate transformation-based ensemble defense, conducting experiments to analyze robustness.
result The robustness improvement is mainly from irreversible transformations rather than the ensemble of models.
Despite the successful application of machine learning (ML) in a wide range of domains, adaptability---the very property that makes machine learning desirable---can be exploited by adversaries to contaminate training and evade classification. In this paper, we investigate the feasibility of applying a specific class of…
Machine learning algorithms can be fooled by small well-designed adversarial perturbations. This is reminiscent of cellular decision-making where ligands (called antagonists) prevent correct signalling, like in early immune recognition. We draw a formal analogy between neural networks used in machine learning and model…
New attack strategy circumvents CC framework's defences in federated learning.
problem Vulnerabilities in Byzantine attacks in federated learning.
method Introducing a novel attack strategy and proposing a new robust defence mechanism.
result Reduces test accuracy of robust aggregators up to 33% in image classification tasks.
Dual quality assessment method tackles adversarial robustness issues across various metrics.
problem Varying robustness levels and bias in adversarial attacks and defenses.
method Model agnostic dual quality assessment method, including robustness levels.
result Current networks and defenses are vulnerable at all robustness levels, highlighting the need for a dual approach.
Adversarial perturbations are more effective in Y-channel of YCbCr color space.
problem Vulnerability of deep models to adversarial perturbations in images.
method Proposed ResUpNet defense that removes perturbations only from the Y-channel of YCbCr color space.
result ResUpNet achieves the best balance between defense and maintaining original image accuracy.
Enhances neural networks' robustness against adversarial samples without sacrificing clean sample generalization.
problem Limited generalization and time complexity of adversarial training.
method Feature Pyramid Decoder (FPD) framework that integrates denoising and image restoration modules into CNNs and constrains the Lipschitz constant.
result FPD-enhanced CNNs achieve sufficient robustness against general adversarial samples on various datasets.
Empirical study on adversarial robustness in transfer learning from CIFAR 100 to CIFAR 10.
problem Evaluating adversarial robustness in transfer learning from CIFAR 100 to CIFAR 10.
method Study of adversarial robustness under transfer learning from a source trained on CIFAR 100 to a target network trained on CIFAR 10, using robust optimisation.
result Using PGD examples during training on the source task leads to more general robust features that are easier to transfer and achieve 5.2% more accuracy against white-box PGD attacks.
To accelerate research on adversarial examples and robustness of machine learning classifiers, Google Brain organized a NIPS 2017 competition that encouraged researchers to develop new methods to generate adversarial examples as well as to develop new ways to defend against them. In this chapter, we describe the struct…
Multiplayer Online Battle Arena (MOBA) games are among the most played digital games in the world. In these games, teams of players fight against each other in arena environments, and the gameplay is focused on tactical combat. Mastering MOBAs requires extensive practice, as is exemplified in the popular MOBA Defence o…
A new method detects and corrects adversarial attacks on classifiers.
problem Detecting and correcting adversarial attacks on machine learning models.
method Unsupervised autoencoder trained with KL divergence loss to match predictions.
result Almost completely neutralizes powerful attacks on MNIST and Fashion-MNIST.
Paper proposes SDS for 5G security using machine learning.
problem Cybersecurity threats and expanding IoT in 5G networks.
method SDS uses machine learning, specifically a CNN with NAS, to detect anomalies.
result CNN achieved 100% accuracy in identifying benign traffic and 96.4% in detecting anomalies.
This paper quantifies how hard it is to identify specific data points in machine learning models.
problem Quantifying the difficulty of identifying specific data points in machine learning models.
method Characterizing optimal attacks and privacy defences, deriving impacts of noise and misspecification, and proposing a new covariance attack.
result The Mahalanobis distance explains the hardness of fixed-target membership inference attacks.
Paper models game theory for defending against data poisoning attacks.
problem Defending against data poisoning attacks using game theory.
method Modeling attacker-defender game, proving non-existence of pure Nash Equilibrium, proposing mixed strategy approach, and developing an algorithm to approximate Nash Equilibrium.
result Demonstrated effectiveness of mixed strategy defense in experiments.
Article evaluates AI security threats and proposes multiple measures.
problem Threats to AI integrity and security.
method Literature review, analysis of AI supply chain, discussion of mitigations.
result Multiple protective measures are necessary for AI security.
Deep models for financial transactions are vulnerable to adversarial attacks, especially when adding transaction tokens.
problem Vulnerability of deep models to adversarial attacks on financial transaction records.
method Examine adversarial attacks and defenses on transaction records data, considering black-box attacks and adding transaction tokens.
result A few generated transactions can fool a deep-learning model, highlighting the need for robustness improvements.
Efficient method defends privacy in federated learning without accuracy loss.
problem Privacy attacks on federated learning by reconstructing and identifying local data.
method Random noise perturbation method that allows recovery of true gradients.
result Strong privacy protection without sacrificing learning accuracy.
There is a rising interest in studying the robustness of deep neural network classifiers against adversaries, with both advanced attack and defence techniques being actively developed. However, most recent work focuses on discriminative classifiers, which only model the conditional distribution of the labels given the …
Model predicts credit portfolio losses with contagion effects.
problem Predicting credit portfolio losses with contagion effects.
method Introduced a model with a recursive algorithm and flexible distributions.
result Good fit for synthetic CDO tranches of the iTraxx index.
Simple aggregation of multiple methods defends against adversarial attacks on neural networks.
problem Manipulation of machine learning models to hide discriminating features.
method Aggregation of multiple explanation methods to make the model robust against adversarial attacks.
result The model remains robust even when the attacker has knowledge of the model weights and explanation methods.
Deep learning has enabled traditional reinforcement learning methods to deal with high-dimensional problems. However, one of the disadvantages of deep reinforcement learning methods is the limited exploration capacity of learning agents. In this paper, we introduce an approach that integrates human strategies to increa…
AI attacks threaten insurance systems, requiring new defenses.
problem Adversarial attacks on AI in insurance.
method Categorize and discuss various types of attacks and defense methods.
result Need for improved AI systems to resist attacks.
WM layer improves CNN robustness to noise and adversarial attacks.
problem CNNs' susceptibility to noise and adversarial attacks.
method WM layer as a generic architectural addition to CNNs.
result WM variants enhance robustness to noise and adversarial attacks.
BOBYQA optimizes deep networks with fewer queries than other methods.
problem Generating adversarial examples with fewer queries than non-model-based methods.
method Model-based derivative-free optimisation algorithm (BOBYQA).
result BOBYQA achieves state-of-the-art results with fewer queries than other methods.
A new game-theoretic approach to training robust classifiers against universal adversarial perturbations.
problem Learning classifiers robust to universal adversarial perturbations.
method Formulated as a two-player zero-sum game, where one player optimizes the classifier and the other creates adversarial perturbations.
result Empirically demonstrated robustness and versatility in multiple image classification datasets.
Margin system for margin loans using cash and stock as collateral is considered in this paper, which is the line of defence for brokers against risk associated with margin trading. The conditional probability of negative return is used as risk measure, and a recursive algorithm is proposed to realize this measure under…
New ELM algorithms reduce computation time and complexity.
problem Efficient computation of extreme learning machine (ELM) algorithms.
method Developed inverse-free ELM algorithms using recursive matrix inverse and inverse LDL' factorization.
result Proposed algorithms significantly reduce computational complexity.
Machine learning has become an important component for many systems and applications including computer vision, spam filtering, malware and network intrusion detection, among others. Despite the capabilities of machine learning algorithms to extract valuable information from data and produce accurate predictions, it ha…
Proof of convergence for multi-objective optimization using inverse reinforcement learning.
problem Proving convergence in multi-objective optimization problems.
method Wasserstein inverse reinforcement learning with projective subgradient method and gradient descent.
result Convergence of inverse reinforcement learning for multi-objective optimization.
AI detects LDDoS attacks by analyzing TCP connection parameters.
problem Detecting low-rate LDDoS attacks that overwhelm server connections.
method AI algorithms trained on simulated and real-world datasets using TCP flow features.
result Decision trees and k-NN achieved high accuracy in classifying attacks, with low false positives and negatives.
Two new inverse-free ELM algorithms for incremental and decremental learning are proposed.
problem Efficiently updating and removing multiple hidden nodes in ELM.
method Improved inverse-free recursive algorithms for Tikhonov regularization.
result Inverse-free algorithms for ELM with multiple hidden nodes and redundant nodes.
The notion of a generalized harmonic inverse mean curvature surface in the Euclidean four-space is introduced. A backward Bäcklund transform of a generalized harmonic inverse mean curvature surface is defined. A Darboux transform of a generalized harmonic inverse mean curvature surface is constructed by a backward Bäck…
New method for estimating parameters in inverse problems using double robustness.
problem Estimating parameters defined as linear functionals of solutions to linear inverse problems.
method Source condition double robust inference method that uses iterated Tikhonov regularized adversarial estimators.
result Asymptotic normality of the parameter of interest as long as either the primal or dual inverse problem is sufficiently well-posed.
New findings on mesh group-planes validate Signature-inverse Theorem under specific conditions.
problem Invalidity of existing inverse theorems for mesh group-planes.
method Classification of three and five point meshes, analysis of joint invariant signatures.
result Valid conditions for the Signature-inverse Theorem in mesh group-planes.
Seismic inversion method uses GAN to improve efficiency and accuracy.
problem Difficulty in combining geological knowledge with seismic data and assessing uncertainty.
method Generative Adversarial Network (GAN) for seismic inversion.
result GAN-generated models conform to observation data with low uncertainty.
Develops an inverse particle filter for cognitive systems.
problem Tracking cognitive adversaries in counter-adversarial applications.
method Global filtering approach using Monte Carlo methods and differentiable I-PF.
result Demonstrates convergence to optimal inverse filter and improved estimation performance.
The paper studies Möbius inversion on surfaces in Minkowski 3-space.
problem Understanding transformations of surfaces in Minkowski space.
method Definition and properties of Möbius inversion on surfaces in Minkowski 3-space.
result Möbius inversion preserves lines of principal curvature and degenerate metric points but not parabolic sets.
Inversive distance circle packing metric was introduced by P Bowers and K Stephenson \cite{BS} as a generalization of Thurston's circle packing metric \cite{T1}. They conjectured that the inversive distance circle packings are rigid. For nonnegative inversive distance, Guo \cite{Guo} proved the infinitesimal rigidity a…
CNN outperforms other methods in gravity inversion.
problem Estimating subsurface density from gravitational field data.
method CNN, VAEs, GANs, iterative solvers (GD, GMRES, LGMRES, ICG).
result CNN provides the most reliable reconstructions.
The aim of the paper is to investigate the relation between inverse limit of branched manifolds and codimension zero laminations. We give necessary and sufficient conditions for such an inverse limit to be a lamination. We also show that codimension zero laminations are inverse limits of branched manifolds. The inverse…
The inversion formula for conservative multifractal measures was unveiled mathematically a decade ago, which is however not well tested in real complex systems. In this Letter, we propose to verify the inversion formula using high-frequency turbulent financial data. We construct conservative volatility measure based on…
Paper proposes efficient image inversion and editing using rectified stochastic differential equations.
problem Inversion and editing of real images using generative models.
method Proposes RF inversion using dynamic optimal control and a linear quadratic regulator, extending to stochastic sampler for Flux.
result Allows state-of-the-art performance in zero-shot inversion and editing, outperforming prior works.