Adversarial Training (AT) and Virtual Adversarial Training (VAT) are the regularization techniques that train Deep Neural Networks (DNNs) with adversarial examples generated by adding small but worst-case perturbations to input examples. In this paper, we propose xAT and xVAT, new adversarial training algorithms, that …
arXiv research
A locally-built, LLM-digested index of recent arXiv papers in quant finance, geometry/topology, and statistical ML — keyword search served straight from SQLite on this machine.
Trend · papers per month
New quantum invariant is asymptotically multiplicative under cyclic covers.
Meta framework generates noise to improve multi-attack robustness.
Defenses against adversarial examples, such as adversarial training, are typically tailored to a single perturbation type (e.g., small -noise). For other perturbations, these defenses offer no guarantees and, at times, even increase the model's vulnerability. Our aim is to understand the reasons underlying…
Proposes a defense method against multiple adversarial video types.
The paper strengthens a theorem on crossings under linear perturbations with Hausdorff measure estimates.
Proposes a new video attack method that multiplies perturbation to improve model robustness.
Owing to the susceptibility of deep learning systems to adversarial attacks, there has been a great deal of work in developing (both empirically and certifiably) robust classifiers. While most work has defended against a single type of attack, recent work has looked at defending against multiple perturbation models usi…
Graph convolutional networks (GCNs) are vulnerable to perturbations of the graph structure that are either random, or, adversarially designed. The perturbed links modify the graph neighborhoods, which critically affects the performance of GCNs in semi-supervised learning (SSL) tasks. Aiming at robustifying GCNs conditi…
Ensemble learning that can be used to combine the predictions from multiple learners has been widely applied in pattern recognition, and has been reported to be more robust and accurate than the individual learners. This ensemble logic has recently also been more applied in feature selection. There are basically two st…
CausalRegNet generates accurate data for gene perturbation experiments, improving CSL methods.
Enhances robustness of AT frameworks to multiple perturbations without increasing training complexity.
This work improves explanation quality for time series predictions by learning perturbations.
DBPA assesses LLM perturbations using frequentist hypothesis testing.
Motivated by the HRRT-formula for holographic entanglement entropy, we consider the following question: what are the position and the surface area of extremal surfaces in a perturbed geometry, given their anchor on the asymptotic boundary? We derive explicit expressions for the change in position and surface area, ther…
Simple regional perturbations maintain model transferability while reducing adversarial example distortion.
We propose a categorical data synthesizer with a quantifiable disclosure risk. Our algorithm, named Perturbed Gibbs Sampler, can handle high-dimensional categorical data that are often intractable to represent as contingency tables. The algorithm extends a multiple imputation strategy for fully synthetic data by utiliz…
The paper proves that most metrics satisfy a strong version of Arnold's conjecture for Laplace eigenvalues.
We consider a classifier whose test set is exposed to various perturbations that are not present in the training set. These test samples still contain enough features to map them to the same class as their unperturbed counterpart. Current architectures exhibit rapid degradation of accuracy when trained on standard data…
In this paper we prove that the generic singularities of mean curvature flow of closed embedded surfaces in modeled by closed self-shrinkers with multiplicity has multiplicity one. Together with the previous result by Colding-Minicozzi in [CM12], we conclude that the only generic singularity of mean curva…
Survey on Allen-Cahn equations and systems, focusing on multiplicity results and geometric interpretation.
Study reveals class-dependent effects in perturbation-based feature attribution metrics for time series classification.
The study examines the long-term behavior of mean curvature flows in closed 3-manifolds.
DIP-FAT improves adversarial training by diversifying perturbations.
New method uses unlabeled data to improve model robustness across different environments.
New method UADs improves transferability of adversarial perturbations.
The paper finds multiple ways a special curvature can blow up in high dimensions.
We develop several methods that allow us to compute all-loop partition functions in perturbative Chern-Simons theory with complex gauge group G_C, sometimes in multiple ways. In the background of a non-abelian irreducible flat connection, perturbative G_C invariants turn out to be interesting topological invariants, wh…
We propose a novel data-driven method to learn a mixture of multiple kernels with random features that is certifiabaly robust against adverserial inputs. Specifically, we consider a distributionally robust optimization of the kernel-target alignment with respect to the distribution of training samples over a distributi…
A machine learning model that generalizes well should obtain low errors on unseen test examples. Thus, if we know how to optimally perturb training examples to account for test examples, we may achieve better generalization performance. However, obtaining such perturbation is not possible in standard machine learning f…
DEceit constructs effective universal pixel-restricted perturbations for deep image classifiers.
Adversaries with multiple antennas can fool deep learning modulators more effectively.
In the current article we study complex cycles of higher multiplicity in a specific polynomial family of holomorphic foliations in the complex plane. The family in question is a perturbation of an exact polynomial one-form giving rise to a foliation by Riemann surfaces. In this setting, a complex cycle is defined as a …
P-OCS detects OOD samples in a low-dimensional subspace, outperforming existing methods.
Lower class selectivity makes networks more robust to natural perturbations but more vulnerable to adversarial attacks.
Consider the massless Dirac operator on a 3-torus equipped with Euclidean metric and standard spin structure. It is known that the eigenvalues can be calculated explicitly: the spectrum is symmetric about zero and zero itself is a double eigenvalue. The aim of the paper is to develop a perturbation theory for the eigen…
Privacy-preserving machine learning methods add randomness, leading to varying predictions.
Stochastic neural net weights are used in a variety of contexts, including regularization, Bayesian neural nets, exploration in reinforcement learning, and evolution strategies. Unfortunately, due to the large number of weights, all the examples in a mini-batch typically share the same weight perturbation, thereby limi…
This work introduces adversarial sparsity to measure robustness beyond adversarial accuracy.
The Yamabe flow can blow up in infinite time with small perturbations.
Machine Learning models are vulnerable to adversarial attacks that rely on perturbing the input data. This work proposes a novel strategy using Autoencoder Deep Neural Networks to defend a machine learning model against two gradient-based attacks: The Fast Gradient Sign attack and Fast Gradient attack. First we use an …
Given the ability to directly manipulate image pixels in the digital input space, an adversary can easily generate imperceptible perturbations to fool a Deep Neural Network (DNN) image classifier, as demonstrated in prior work. In this work, we propose ShapeShifter, an attack that tackles the more challenging problem o…
Existence of double bubbles with high constant mean curvatures in Riemannian manifolds.
This paper solves the convergence problem for estimating MGGD parameters with a convex formulation.
Deterministic bounds for tensor singular values and vectors, differing from matrix cases.
The paper calculates spectral torsion for rescaled Dirac operators on manifolds.
Inverse classification uses an induced classifier as a queryable oracle to guide test instances towards a preferred posterior class label. The result produced from the process is a set of instance-specific feature perturbations, or recommendations, that optimally improve the probability of the class label. In this work…
New mechanisms from primate vision improve neural network robustness.