Simple regional perturbations maintain model transferability while reducing adversarial example distortion.
problem Comparing efficacy of regional adversarial attacks without complex methods.
method Developed a simple regional adversarial perturbation attack using cross-entropy sign.
result Localized adversarial examples require significantly less Lp norm distortion compared to non-local counterparts. Paper proposes a new method for WDRO with local perturbations, achieving better accuracy.
problem Wasserstein distributionally robust optimization's theoretical understanding needs improvement.
method Develops a new approximation theorem and risk consistency results for WDRO.
result The proposed method achieves significantly higher accuracy on noisy datasets.
Paper proposes faster method to find local minima in nonconvex optimization.
problem Escaping saddle points and finding local minima in nonconvex optimization.
method LENA (Last stEp shriNkAge) framework for faster perturbed stochastic gradient methods.
result LENA finds (ε,εH)-approximate local minima within ildeO(ε−3+εH−6) evaluations. Local minimizers are convex and close to Wulff shapes.
problem Finding local minimizers in anisotropic isoperimetric problems.
method Showed local minimizers are geodesically convex and small smooth perturbations of tangent Wulff shapes.
result Local minimizers are quantitatively close to Wulff shapes.
Study local perturbations of vector bundles with polynomial curvature solutions.
problem Existence and stability of solutions to geometric PDEs under deformations.
method Geometric invariant theory, moment map framework, polystability conditions.
result Existence and uniqueness of solutions under local polystability conditions.
This research investigates reliable local explanations for machine listening models.
problem Generating reliable local explanations for machine listening models.
method Investigates the sensitivity of SoundLIME explanations to input perturbations and proposes a novel method for identifying suitable content types.
result SoundLIME explanations are sensitive to the content in occluded input regions, and the average magnitude of input mel-spectrogram bins is the most suitable content type for temporal explanations.
Local index density of perturbed de Rham complex is invariant under certain conditions.
problem Invariance of local index density for perturbed de Rham complex.
method Invariance theory applied to perturbed Laplacian and local index density.
result Local index density is invariant under perturbation by closed 1-forms.
In this work we prove the fact that, for a short time, it is possible to construct a smooth parametrized family of isometric embeddings of an arbitrary smooth parametrized family of Riemannian metrics on a smooth closed manifold into an Euclidean space. In order to prove this statement we work out stability estimates w…
Graph cuts find global optima for Potts models in slight perturbations.
problem Finding optimal solutions in Potts models with graph cuts.
method α-expansion algorithm for MAP inference, with certification for perturbations.
result All local minima are global minima in slight perturbations, and solutions are close to original.
Localized uncertainty attacks target uncertain regions to create imperceptible adversarial examples.
problem Adversarial examples that are imperceptible to humans and strong under deterministic classifiers.
method Localized uncertainty attacks by perturbing uncertain regions, using predictive uncertainty or surrogate models.
result Localized uncertainty attacks produce strong adversarial examples that retain input similarity.
Traditionally, there are two models on differential privacy: the central model and the local model. The central model focuses on the machine learning model and the local model focuses on the training data. In this paper, we study the \textit{input perturbation} method in differentially private empirical risk minimizati…
Charge measurements for instantons and gravitational perturbations.
problem Evaluating charges in Hermitian non-Kähler Einstein 4-manifolds and their perturbations.
method Evaluation of charges via Killing spinors and perturbation analysis of gravitational instantons.
result Generic gravitational perturbations admit a closed 2-form measuring the charge change.
On a smooth complete Riemannian spin manifold with smooth compact boundary, we demonstrate that the Atiyah-Singer Dirac operator DB in L2 depends Riesz continuously on L∞ perturbations of local boundary conditions B. The Lipschitz bound for the map ${…
Local isoperimetric inequality holds for balls with nonpositive curvature.
problem Preserving the isoperimetric ratio in perturbed ball metrics with nonpositive curvature.
method Analyzing perturbations of ball metrics with nonpositive curvature.
result Isoperimetric ratio is preserved only by homotheties of the ball.
We compute the Ricci curvature of a curved noncommutative three torus. The computation is done both for conformal and non-conformal perturbations of the flat metric. To perturb the flat metric, the standard volume form on the noncommutative three torus is perturbed and the corresponding perturbed Laplacian is analyzed.…
Study metric perturbations to make degenerate harmonic forms non-degenerate.
problem Dealing with degenerate harmonic 1-forms in Riemannian geometry.
method Combining analysis of local expansions with Nash-Moser implicit function theorem.
result Proves deformation to nearby non-degenerate Z/2-harmonic 1-forms.
A new framework explains GNN predictions by simulating graph structure and feature changes.
problem Lack of transparency in GNN predictions hinders understanding.
method TraP2 framework using a three-layer architecture: Translation, Perturbation, and Paraphrase layers.
result TraP2 achieves 10.2% higher explanation accuracy than state-of-the-art methods.
In this paper we study perturbations of constant cocycles for actions of higher rank semi-simple algebraic groups and their lattices. Roughly speaking, for ergodic actions, Zimmer's cocycle superrigidity theorems implies that the perturbed cocycle is measurably conjugate to a constant cocycle modulo a compact valued co…
Explainability is a gateway between Artificial Intelligence and society as the current popular deep learning models are generally weak in explaining the reasoning process and prediction results. Local Interpretable Model-agnostic Explanation (LIME) is a recent technique that explains the predictions of any classifier f…
New algorithm optimizes robust estimation under mixed local and global corruptions.
problem Combining local and global corruptions in robust statistics.
method Information-theoretic approach using sliced-Wasserstein metric.
result Optimal error achieved in polynomial time for stronger local perturbations.
Constructing an efficient parameterization of a large, noisy data set of points lying close to a smooth manifold in high dimension remains a fundamental problem. One approach consists in recovering a local parameterization using the local tangent plane. Principal component analysis (PCA) is often the tool of choice, as…
Paper provides an explicit formula for local volatility in Cheyette models.
problem Approximating local volatility in Cheyette interest rate models.
method Extended Dupire framework, perturbation methods, probabilistic techniques.
result Explicit analytical formula for local volatility in Cheyette models.
New regularization techniques improve stability of deep neural networks.
problem Improving stability of deep neural networks in high-dimensional data.
method Apply manifold regularization to develop new regularizers based on graph Laplacian sparsification.
result Empirically, networks achieve high stability in various perturbation models, including adversarial attacks.
The paper improves SVM and localized SVM stability under triple perturbations.
problem Stability of SVMs and localized SVMs under triple perturbations.
method Generalizes and improves existing results, considering simultaneous variations in probability measure, regularization parameter, and kernel.
result Improved stability of SVMs and localized SVMs under triple perturbations.
One of the common tasks in unsupervised learning is dimensionality reduction, where the goal is to find meaningful low-dimensional structures hidden in high-dimensional data. Sometimes referred to as manifold learning, this problem is closely related to the problem of localization, which aims at embedding a weighted gr…
We introduce a new concept, data irrecoverability, and show that the well-studied concept of data privacy is sufficient but not necessary for data irrecoverability. We show that there are several regularized loss minimization problems that can use perturbed data with theoretical guarantees of generalization, i.e., loss…
Study vector fields with complex singularities, proving bounds and formulas.
problem Understanding the Milnor number of vector fields with specific singularities.
method Global and local formulas expressing Milnor/Poincare-Hopf contributions, sharp lower bounds under perturbations.
result Sharp lower bounds for Milnor number contributions under holomorphic perturbations.
Ricci flow simulations show unstable Fubini-Study metrics develop singularities.
problem Understanding the behavior of unstable perturbations in Ricci flow.
method Numerical simulations of Ricci flow starting from unstable Fubini-Study metrics.
result Ricci flow solutions from unstable Fubini-Study metrics develop local singularities.
Although federated learning improves privacy of training data by exchanging local gradients or parameters rather than raw data, the adversary still can leverage local gradients and parameters to obtain local training data by launching reconstruction and membership inference attacks. To defend such privacy attacks, many…
We propose a novel framework for the differentially private ERM, input perturbation. Existing differentially private ERM implicitly assumed that the data contributors submit their private data to a database expecting that the database invokes a differentially private mechanism for publication of the learned model. In i…
New framework assesses neural sensitivity to small perturbations.
problem Comparing neural representations' sensitivity to small changes.
method Local decodable information, Fisher information, and projected pullback/Fisher metric.
result Reveals differences in neural sensitivity not captured by activation alignment.
Study shows torsion order bounds band-unlinking number for knot cobordisms.
problem Understanding bounds on knot cobordisms using torsion orders.
method Established an inequality involving local maxima, genus, and torsion orders of Khovanov homology.
result Torsion order gives a lower bound for the band-unlinking number.
AMP regularization improves deep learning models by favoring flat minima.
problem Improving deep learning model generalization and avoiding overfitting.
method AMP regularization uses adversarial model perturbation to minimize a norm-bounded perturbation of the empirical risk.
result AMP regularization leads to state-of-the-art performance across various deep architectures.
A new approach to maximum likelihood learning of discrete graphical models and RBM in particular is introduced. Our method, Perturb and Descend (PD) is inspired by two ideas (I) perturb and MAP method for sampling (II) learning by Contrastive Divergence minimization. In contrast to perturb and MAP, PD leverages trainin…
Local convolutions bias neural networks towards high-frequency adversarial examples.
problem High-frequency adversarial examples in neural networks.
method Analysis of different linear and nonlinear architectures, focusing on the impact of local convolution operations.
result Local convolutions induce an implicit bias towards high frequency features, leading to high-frequency adversarial examples.
SGD generalization bounds derived from information theory.
problem Understanding generalization of SGD for non-convex functions.
method Combining information-theoretic bounds with perturbation analysis.
result Upper bounds on SGD's generalization error based on gradient variance and function smoothness.
EAGLE improves reproducibility and stability of model explanations.
problem Creating reliable explanations for opaque machine learning models.
method Formulates perturbation selection as an information-theoretic active learning problem.
result EAGLE learns a linear surrogate model with feature importance scores and uncertainty estimates.
It has been widely recognized that adversarial examples can be easily crafted to fool deep networks, which mainly root from the locally non-linear behavior nearby input examples. Applying mixup in training provides an effective mechanism to improve generalization performance and model robustness against adversarial per…
Deep neural networks were shown to be vulnerable to single pixel modifications. However, the reason behind such phenomena has never been elucidated. Here, we propose Propagation Maps which show the influence of the perturbation in each layer of the network. Propagation Maps reveal that even in extremely deep networks s…
The paper shows how solutions of perturbed Dirac operators concentrate near singular sets.
problem Understanding concentration of solutions for perturbed Dirac operators.
method Analyzing the algebraic criterion on $(c, \A)$ and spectral properties of deformed Laplacians.
result Proves an index localization theorem based on spectral separation properties.
Study of free particle's geometry and its perturbations using complex projective structures.
problem Understanding the geometry of a free particle and its perturbations.
method Use of complex projective structures and quasiconformal geometry to study perturbations.
result Main results loosely modeled on algebraic transformation theory, foundational for geometric understanding of the exact WKB method.
We discuss our recent work [4] in which gravitational radiation was studied by evaluating the Wang-Yau quasi-local mass of surfaces of fixed size at the infinity of both axial and polar perturbations of the Schwarzschild spacetime, à la Chandrasekhar [1].
Motivated by the HRRT-formula for holographic entanglement entropy, we consider the following question: what are the position and the surface area of extremal surfaces in a perturbed geometry, given their anchor on the asymptotic boundary? We derive explicit expressions for the change in position and surface area, ther…
This work examines how adversarial vulnerability changes with the dimensionality of the subspace of perturbations.
problem Understanding adversarial vulnerability in constrained input spaces.
method Investigates adversarial vulnerability in subspace V of the input space X with varying dimensions, using PGD attacks and analyzing the dependence on ε and dim(V)/dim(X). result Adversarial success of PGD attacks is a monotonically increasing function of $ε(rac{dim(V)}{dim(X)})^{rac{1}{q}}$.
Solutions to scalar curvature equations have the property that all possible blow-up points are isolated, at least in low dimensions. This property is commonly used as the first step in the proofs of compactness. We show that this result becomes false for some arbitrarily small, smooth perturbations of the potential.
SGD converges with perturbed forward-backward passes, explained by geometric amplification.
problem Analyzing convergence of SGD with perturbed forward-backward passes in composite optimization.
method Characterized propagation and amplification of perturbations, derived convergence guarantees for non-convex and PL objectives.
result Perturbations cascade through the computational graph, affecting convergence order under specific conditions.
The paper assesses machine learning robustness with covariate perturbations.
problem Ensuring robustness of machine learning models against adversarial attacks and data changes.
method Proposes a framework using covariate perturbation techniques to assess model robustness.
result Demonstrates the effectiveness of the approach in comparing robustness across models and identifying instabilities.
Study how nodal domains change on surfaces under perturbations.
problem How eigenfunction nodal domains change on surfaces under smooth perturbations.
method Sector/graph count near nodal critical points, upper semicontinuity proof, branch-free on spectral clusters, wavelength-scale analysis.
result Upper semicontinuity of nodal domain count, no new domains created at wavelength scale, stable count in noncritical cases.