Study reveals how high-dimensional models are vulnerable to consistent adversarial attacks.
problem Understanding the vulnerability of high-dimensional linear classifiers to adversarial attacks.
method Introducing a new error metric to quantify model vulnerability, and rigorously characterizing these metrics in asymptotic settings.
result As models become more overparameterized, their vulnerability to label-preserving perturbations increases.
After Fossas-Parlier, we consider two graphs G 0 ( S ) \mathcal{G}_{0}(S) G 0 ( S ) and G ∞ ( S ) \mathcal{G}_{\infty}(S) G ∞ ( S ) , constructed from multicurves on connected, orientable surfaces of infinite-type. Our first result asserts that G ∞ ( S ) \mathcal{G}_{\infty}(S) G ∞ ( S ) has finite diameter, which extends a result of Fossas-Parlier. Next, we prove that the…
A fast method for discrete OT with group-sparse regularization for class label preservation.
problem Efficiently measuring the distance between two discrete distributions with class labels.
method Fast discrete OT with group-sparse regularizers using gradient-based algorithms.
result Up to 8.6 times faster than original method without degrading accuracy.
The generation of artificial data based on existing observations, known as data augmentation, is a technique used in machine learning to improve model accuracy, generalisation, and to control overfitting. Augmentor is a software package, available in both Python and Julia versions, that provides a high level API for th…
This paper explores a variety of models for frame-based music transcription, with an emphasis on the methods needed to reach state-of-the-art on human recordings. The translation-invariant network discussed in this paper, which combines a traditional filterbank with a convolutional neural network, was the top-performin…
Deep artificial neural networks require a large corpus of training data in order to effectively learn, where collection of such training data is often expensive and laborious. Data augmentation overcomes this issue by artificially inflating the training set with label preserving transformations. Recently there has been…
A new method resolves non-identifiability in reward modeling using anchor labels.
problem Non-identifiability in reward modeling from pairwise preferences alone.
method Anchor-guided Variance-aware Reward Modeling (AVRM) framework.
result AVRM resolves non-identifiability and improves reward modeling performance.
Paper develops heavy-tailed embeddings for better text classification and augmentation.
problem Improving text classification, especially for extreme values.
method Develops heavy-tailed embeddings using multivariate extreme value theory and introduces a scale-invariant classifier.
result The classifier outperforms baselines and generates meaningful augmented text.
Enhances data augmentation for regression tasks.
problem Limited effectiveness of data augmentation in regression.
method Curvature-Enhanced Manifold Sampling (CEMS).
result CEMS improves performance in regression tasks.
Regularising for invariance to data augmentation improves machine learning models.
problem Improving generalization in machine learning models through data augmentation.
method Explicit regularisation to encourage invariance at the level of individual model predictions.
result Explicit regularisation improves generalization and equalizes performance differences between objectives.
Paper improves bike-sharing demand prediction by adapting to changing patterns.
problem Improving bike-sharing demand prediction under temporal domain shifts.
method Gen-ROTDA, a robust optimal transport-guided residual domain adaptation framework.
result Gen-ROTDA achieves the lowest MAE and is the best OT-family method on average.
In recent years, deep learning has achieved remarkable achievements in many fields, including computer vision, natural language processing, speech recognition and others. Adequate training data is the key to ensure the effectiveness of the deep models. However, obtaining valid data requires a lot of time and labor reso…
Earth observation embeddings can convert discrete biome maps into continuous representations that better capture ecological variation.
problem Biome maps impose categorical boundaries that compress continuous variation in biotic communities.
method Fit a linear classifier on Earth observation embeddings to predict biome labels.
result Continuous biome representation outperforms discrete biome labels for predicting species occurrence.
Improved algorithm speeds up generation of universal adversarial perturbations.
problem Slow generation of universal adversarial perturbations.
method Optimized algorithm based on orientation of perturbation vectors.
result Significantly faster generation of universal perturbations with higher fooling rates.
This paper presents a new approach, called perturb-max, for high-dimensional statistical inference that is based on applying random perturbations followed by optimization. This framework injects randomness to maximum a-posteriori (MAP) predictors by randomly perturbing the potential function for the input. A classic re…
The paper tackles extrapolation of gene knockouts effects on RNA counts.
problem Modeling effects of gene knockouts on RNA counts for new perturbations.
method Formulated as a latent variable model with additive perturbation effects, proved identifiability, proposed PDAE for estimation.
result PDAE can accurately predict effects of unseen but identifiable perturbations.
Novel geometry-informed irreversible perturbation accelerates Langevin dynamics convergence.
problem Accelerating convergence of Langevin dynamics for Bayesian computation.
method Geometry-informed irreversible perturbation of Riemannian manifold Langevin dynamics.
result Improves estimation performance over irreversible perturbations that ignore geometry.
Study linear perturbations in Schwarzschild black hole spacetime.
problem Linear perturbations of Schwarzschild black hole spacetime.
method Investigate linearised perturbation of constant mass aspect function foliation at null infinity.
result Linearised perturbations of Bondi energy and mass vanish, and all linear momentum can be achieved.
New research evaluates various perturbation methods for improving neural network robustness.
problem Understanding and improving robustness of Convolutional Neural Networks (CNNs) against adversarial attacks.
method Detailed evaluation of five main perturbation-based defenses, comparing random and deterministic approaches.
result Perturbation-based defenses are equivalent in efficacy, and attacks transfer between them.
We study the transfer of adversarial robustness of deep neural networks between different perturbation types. While most work on adversarial examples has focused on L ∞ L_\infty L ∞ and L 2 L_2 L 2 -bounded perturbations, these do not capture all types of perturbations available to an adversary. The present work evaluates 32 attack…
EVILL uses randomised perturbations to improve exploration in bandit problems.
problem Improving exploration in structured stochastic bandit problems.
method Solves for the minimiser of a linearly perturbed regularised negative log-likelihood function.
result EVILL matches the performance of Thompson-sampling-style methods in theory and practice.
New bifurcation found in perturbations of non-generic closed self-shrinkers.
problem Understanding the behavior of perturbations in non-generic closed self-shrinkers.
method Analyzing the mean curvature flow singularity transitions.
result Different types of singularity transitions based on perturbation direction.
Adversarial perturbations fool deepfake detectors with high accuracy.
problem Improving deepfake detection accuracy against adversarial attacks.
method Used adversarial perturbations and two defenses: Lipschitz regularization and Deep Image Prior (DIP).
result Deepfake detectors achieved 27% accuracy on perturbed images, compared to 95% on unperturbed.
Advances FTPL results for bandit problems with unbounded perturbations.
problem Improving analytical foundations of FTPL in bandit problems.
method Revisiting classical FTRL-FTPL duality for unbounded perturbations.
result Establishes Best-of-Both-Worlds (BOBW) results for FTPL under a broad family of asymmetric unbounded perturbations.
Universal perturbations misclassify text with high accuracy.
problem Vulnerability of text classifiers to small perturbations.
method Algorithm to compute universal adversarial perturbations.
result Deep neural networks are highly vulnerable to universal adversarial perturbations.
Adversarial training adds dynamic perturbations to neural networks for robustness.
problem Accuracy trade-off and lack of diversity in adversarial examples.
method Dynamic adversarial perturbations in the parameter space of neural networks, updating perturbation biases during training.
result Adversarial training with negligible cost and reduced accuracy trade-off.
Generative Intervention Models predict perturbation effects without knowing the underlying mechanisms.
problem Predicting perturbation effects when the mechanisms are unknown.
method Generative Intervention Models (GIM) that map perturbation features to distributions over atomic interventions in a causal model.
result GIMs achieve robust out-of-distribution predictions and infer underlying perturbation mechanisms.
Identifies all perturbative vacua in bosonic string theory.
problem Identifying all perturbative vacua in bosonic string theory.
method Completely identified perturbative vacua through string fluctuations.
result Derivation of path-integrals up to any order from fluctuations.
Develops new methods to create imperceptible image changes that fool classifiers.
problem Improving the robustness of image classifiers by creating subtle changes undetectable to humans.
method Two methods: Edge-Aware and Color-Aware, designed to reduce detectability of image perturbations.
result Demonstrated that the new methods effectively cause misclassification and are computationally efficient.
SmoothFool efficiently computes smooth adversarial perturbations for deep networks.
problem Vulnerability of deep neural networks to adversarial attacks with specific statistical properties.
method SmoothFool: a general and computationally efficient framework for computing smooth adversarial perturbations.
result Smoothness significantly enhances robustness against adversarial attacks and improves transferability.
Charge measurements for instantons and gravitational perturbations.
problem Evaluating charges in Hermitian non-Kähler Einstein 4-manifolds and their perturbations.
method Evaluation of charges via Killing spinors and perturbation analysis of gravitational instantons.
result Generic gravitational perturbations admit a closed 2-form measuring the charge change.
Eigenvalues of Steklov eigenproblems change predictably with boundary tweaks.
problem Understanding how Steklov eigenvalues respond to boundary changes.
method Analyzing smooth boundary perturbations of Steklov eigenvalues.
result Steklov eigenvalues are generically simple under such perturbations.
Study linear perturbations of Spin(7) metrics, finding only rank one nilpotent matrices.
problem Linear perturbations of Spin(7) metrics.
method Applying the method of linear perturbations to Spin(7)-structures.
result Only rank one nilpotent matrices determine nontrivial perturbations.
Simple perturbation of Vafa-Witten equations leads to transversality.
problem Transversality of Vafa-Witten moduli space.
method Simple perturbation of Vafa-Witten equations, proving transversality for S U ( 2 ) SU(2) S U ( 2 ) or S O ( 3 ) SO(3) S O ( 3 ) structure groups. result For generic perturbation parameter, the full rank part of the moduli space satisfies transversality.
We developed a perturbation model for affine gravity theories.
problem Cosmological perturbations in theories without metric.
method Segregated perturbations into symmetric and antisymmetric components, decomposing into irreducible elements.
result Fully addressed gauge freedom in affine gravity theories.
Classifiers such as deep neural networks have been shown to be vulnerable against adversarial perturbations on problems with high-dimensional input space. While adversarial training improves the robustness of image classifiers against such adversarial perturbations, it leaves them sensitive to perturbations on a non-ne…
DBPA assesses LLM perturbations using frequentist hypothesis testing.
problem Quantifying input perturbation impacts on LLM outputs.
method DBPA reformulates perturbation analysis as frequentist hypothesis testing, using Monte Carlo sampling for empirical null and alternative distributions.
result DBPA provides interpretable p-values and scalar effect sizes for LLM perturbations.
The paper learns perturbation sets from data to improve robustness in machine learning.
problem Real-world perturbations are not well characterized in adversarial defenses.
method A conditional generator defines perturbation sets over latent space, with properties for quality measured.
result Learned perturbation sets generate diverse, meaningful perturbations and improve model robustness.
A fast method computes class-specific adversarial perturbations for deep networks.
problem Computing robust adversarial perturbations for deep networks.
method Linear function of weights, no training data, no hyper-parameters.
result Obtains 34% to 51% fooling rate on ImageNet, transfers across models.
Study metric perturbations to make degenerate harmonic forms non-degenerate.
problem Dealing with degenerate harmonic 1-forms in Riemannian geometry.
method Combining analysis of local expansions with Nash-Moser implicit function theorem.
result Proves deformation to nearby non-degenerate Z/2-harmonic 1-forms.
In this paper we investigate the usage of adversarial perturbations for the purpose of privacy from human perception and model (machine) based detection. We employ adversarial perturbations for obfuscating certain variables in raw data while preserving the rest. Current adversarial perturbation methods are used for dat…
The paper proves new theorems about specific types of operator perturbations.
problem Analyzing conformal perturbations of Dirac and signature operators.
method Developed Kastler-Kalau-Walze type theorems for specific operator types.
result Established new theorems for six-dimensional manifolds with boundary.
The paper introduces extremal perturbations for better attribution analysis in deep networks.
problem Identifying input parts responsible for model outputs.
method Extremal perturbations, smooth masks, and technical innovations for computation.
result Demonstrates excellent sensitivity to spatial properties of deep neural networks.
The study reveals how adversarial perturbations can include class features for generalization.
problem Understanding why adversarial examples deceive neural networks and transfer between networks.
method A one-hidden-layer network trained on mutually orthogonal samples.
result Adversarial perturbations, even of a few pixels, contain sufficient class features for generalization.
Deep networks have recently been shown to be vulnerable to universal perturbations: there exist very small image-agnostic perturbations that cause most natural images to be misclassified by such classifiers. In this paper, we propose the first quantitative analysis of the robustness of classifiers to universal perturba…
Improved online Lasso reduces regret in sparse linear contextual bandits.
problem Sparse linear contextual bandit problem with inefficient sampling.
method Perturbed adversary approach to alleviate sampling inefficiency.
result Online Lasso achieves O ( k T log d ) \mathcal{O}(\sqrt{kT\log d}) O ( k T log d ) regret bound. New method μ P 2 μP^2 μ P 2 improves neural network training by scaling perturbations layerwise.
problem Improving neural network performance as models scale up.
method Layerwise perturbation scaling in the infinite-width limit of neural networks.
result Layerwise perturbation scaling ensures all layers are effectively perturbed in the limit.
Paper proposes a method to generate adversarial perturbations for black-box attacks without accessing inner states.
problem Generating adversarial perturbations for black-box attacks without accessing inner states of a DNN.
method Matrix-free generation method that requires fewer query trials.
result The proposed method successfully deceives a DNN for semantic segmentation more effectively than random noise.