New adversarial training methods generate multiplicative perturbations for robust DNN training.
problem Training Deep Neural Networks with adversarial examples to improve robustness.
method Proposes xAT and xVAT, generating multiplicative perturbations for robust training.
result xAT and xVAT match or outperform state-of-the-art classification accuracies and are faster.
New quantum invariant is asymptotically multiplicative under cyclic covers.
problem Quantum invariants are not multiplicative under finite covers.
method Introduced a perturbative power series invariant of cusped hyperbolic 3-manifolds.
result The power series is asymptotically multiplicative under cyclic covers.
Meta framework generates noise to improve multi-attack robustness.
problem Extraneous defense against single type of adversarial perturbation.
method Meta-learning framework with Meta Noise Generator (MNG).
result Significantly outperforms baselines across multiple perturbations.
Defenses against adversarial examples, such as adversarial training, are typically tailored to a single perturbation type (e.g., small ℓ∞-noise). For other perturbations, these defenses offer no guarantees and, at times, even increase the model's vulnerability. Our aim is to understand the reasons underlying…
Proposes a defense method against multiple adversarial video types.
problem Lack of multi-perturbation robustness in existing defense approaches.
method Adversarial training with multiple independent BN layers and a BN selection module.
result Demonstrates stronger multi-perturbation robustness against different adversarial video types.
The paper strengthens a theorem on crossings under linear perturbations with Hausdorff measure estimates.
problem Understanding multiple-point crossings under linear perturbations.
method Establishes a transversality theorem with Hausdorff measure estimates for exceptional parameter sets.
result Explicit upper bounds on the Hausdorff dimension of the exceptional set.
Proposes a new video attack method that multiplies perturbation to improve model robustness.
problem Challenges existing defense methods for video recognition models against additive adversarial attacks.
method Introduces Multiplicative Adversarial Videos (MultAV) to impose perturbation by multiplication.
result Model trained against additive attacks is less robust to MultAV.
Owing to the susceptibility of deep learning systems to adversarial attacks, there has been a great deal of work in developing (both empirically and certifiably) robust classifiers. While most work has defended against a single type of attack, recent work has looked at defending against multiple perturbation models usi…
Graph convolutional networks (GCNs) are vulnerable to perturbations of the graph structure that are either random, or, adversarially designed. The perturbed links modify the graph neighborhoods, which critically affects the performance of GCNs in semi-supervised learning (SSL) tasks. Aiming at robustifying GCNs conditi…
Ensemble learning that can be used to combine the predictions from multiple learners has been widely applied in pattern recognition, and has been reported to be more robust and accurate than the individual learners. This ensemble logic has recently also been more applied in feature selection. There are basically two st…
CausalRegNet generates accurate data for gene perturbation experiments, improving CSL methods.
problem Assessing and selecting causal structure learning methods in gene perturbation experiments.
method CausalRegNet, a multiplicative effect structural causal model, generates accurate observational and interventional data.
result CausalRegNet generates more accurate distributions and scales better than current simulation frameworks.
Enhances robustness of AT frameworks to multiple perturbations without increasing training complexity.
problem Defending against the union of multiple perturbations in adversarial training.
method SNAP technique that augments a network with shaped noise to enhance robustness.
result 14%-to-20% improvement in adversarial accuracy for ResNet-18 on CIFAR-10.
This work improves explanation quality for time series predictions by learning perturbations.
problem Explaining predictions on multivariate time series data with time dependencies.
method Learning both masks and associated perturbations to explain predictions.
result Learning perturbations significantly improves explanation quality on time series data.
DBPA assesses LLM perturbations using frequentist hypothesis testing.
problem Quantifying input perturbation impacts on LLM outputs.
method DBPA reformulates perturbation analysis as frequentist hypothesis testing, using Monte Carlo sampling for empirical null and alternative distributions.
result DBPA provides interpretable p-values and scalar effect sizes for LLM perturbations.
Motivated by the HRRT-formula for holographic entanglement entropy, we consider the following question: what are the position and the surface area of extremal surfaces in a perturbed geometry, given their anchor on the asymptotic boundary? We derive explicit expressions for the change in position and surface area, ther…
Simple regional perturbations maintain model transferability while reducing adversarial example distortion.
problem Comparing efficacy of regional adversarial attacks without complex methods.
method Developed a simple regional adversarial perturbation attack using cross-entropy sign.
result Localized adversarial examples require significantly less Lp norm distortion compared to non-local counterparts. We propose a categorical data synthesizer with a quantifiable disclosure risk. Our algorithm, named Perturbed Gibbs Sampler, can handle high-dimensional categorical data that are often intractable to represent as contingency tables. The algorithm extends a multiple imputation strategy for fully synthetic data by utiliz…
The paper proves that most metrics satisfy a strong version of Arnold's conjecture for Laplace eigenvalues.
problem Understanding metrics that satisfy a strong version of Arnold's conjecture for Laplace eigenvalues.
method Using geometric characterizations and perturbation theory, the paper proves the conjecture for most metrics.
result The Strong Arnold Hypothesis is satisfied for all metrics except for a set of infinite codimension.
We consider a classifier whose test set is exposed to various perturbations that are not present in the training set. These test samples still contain enough features to map them to the same class as their unperturbed counterpart. Current architectures exhibit rapid degradation of accuracy when trained on standard data…
In this paper we prove that the generic singularities of mean curvature flow of closed embedded surfaces in R3 modeled by closed self-shrinkers with multiplicity has multiplicity one. Together with the previous result by Colding-Minicozzi in [CM12], we conclude that the only generic singularity of mean curva…
Survey on Allen-Cahn equations and systems, focusing on multiplicity results and geometric interpretation.
problem Multiplicity results for Allen-Cahn equations and systems in singular perturbation regime.
method Photography method, variational-topological approach based on localized approximate solutions and barycenter maps.
result Encoding of topology into multiplicity results through variational-topological approach.
Study reveals class-dependent effects in perturbation-based feature attribution metrics for time series classification.
problem Varying effectiveness of perturbation-based metrics across different classes in time series models.
method Systematic empirical analysis across multiple datasets, model architectures, and perturbation strategies.
result Perturbation-based metrics show varying effectiveness across classes, with some metrics performing better for certain classes.
The study examines the long-term behavior of mean curvature flows in closed 3-manifolds.
problem Understanding the long-term behavior of mean curvature flows in closed 3-manifolds.
method The approach involves constructing piecewise almost regular flows and applying perturbative arguments.
result The study constructs minimal surfaces in 3-manifolds via parabolic methods.
DIP-FAT improves adversarial training by diversifying perturbations.
problem Adversarial examples fool deep neural networks, leading to overfitting and poor performance.
method DIP-FAT uses random directions to diversify perturbations in adversarial training.
result DIP-FAT reduces overfitting and improves clean data accuracy.
New method uses unlabeled data to improve model robustness across different environments.
problem Learning robust models for new, unseen environments when labeled data are scarce.
method Regularizes model sensitivity to perturbations in covariate means and covariances without requiring labels.
result Empirically validated on physical and physiological datasets, demonstrating improved robustness.
New method UADs improves transferability of adversarial perturbations.
problem Transferability of adversarial perturbations across different DNN architectures.
method Proposes Universal Adversarial Directions (UADs) to improve transferability.
result UADs can achieve a Nash equilibrium, indicating potential transferability.
The paper finds multiple ways a special curvature can blow up in high dimensions.
problem Finding multiple metrics with constant Q-curvature in high dimensions.
method Constructing small perturbations of standard bubbles.
result Infinitely many smooth metrics with the same constant Q-curvature and arbitrarily large energy.
We develop several methods that allow us to compute all-loop partition functions in perturbative Chern-Simons theory with complex gauge group G_C, sometimes in multiple ways. In the background of a non-abelian irreducible flat connection, perturbative G_C invariants turn out to be interesting topological invariants, wh…
We propose a novel data-driven method to learn a mixture of multiple kernels with random features that is certifiabaly robust against adverserial inputs. Specifically, we consider a distributionally robust optimization of the kernel-target alignment with respect to the distribution of training samples over a distributi…
A machine learning model that generalizes well should obtain low errors on unseen test examples. Thus, if we know how to optimally perturb training examples to account for test examples, we may achieve better generalization performance. However, obtaining such perturbation is not possible in standard machine learning f…
DEceit constructs effective universal pixel-restricted perturbations for deep image classifiers.
problem Creating effective universal pixel-restricted perturbations for deep neural networks.
method DEceit algorithm for black-box feedback, targeting 10% of pixels in images.
result Perturbing only 10% of pixels achieves high Fooling Rate and visual similarity.
Adversaries with multiple antennas can fool deep learning modulators more effectively.
problem Improving evasion attacks on deep learning-based modulation classifiers.
method Utilizing multiple antennas to enhance adversarial attacks on deep learning classifiers.
result Adversarial attacks with multiple antennas significantly improve classifier accuracy.
In the current article we study complex cycles of higher multiplicity in a specific polynomial family of holomorphic foliations in the complex plane. The family in question is a perturbation of an exact polynomial one-form giving rise to a foliation by Riemann surfaces. In this setting, a complex cycle is defined as a …
P-OCS detects OOD samples in a low-dimensional subspace, outperforming existing methods.
problem Efficient OOD detection for deep learning models in open-world environments.
method P-OCS operates in the orthogonal complement of the principal subspace, applying a single projected perturbation.
result P-OCS achieves state-of-the-art OOD detection with negligible computational cost and without requiring model retraining.
Lower class selectivity makes networks more robust to natural perturbations but more vulnerable to adversarial attacks.
problem Understanding how class selectivity affects robustness to different types of perturbations in neural networks.
method Investigated the relationship between class selectivity and robustness to natural and adversarial perturbations in neural networks.
result Lower class selectivity increases robustness to natural perturbations but decreases robustness to adversarial attacks.
Consider the massless Dirac operator on a 3-torus equipped with Euclidean metric and standard spin structure. It is known that the eigenvalues can be calculated explicitly: the spectrum is symmetric about zero and zero itself is a double eigenvalue. The aim of the paper is to develop a perturbation theory for the eigen…
Privacy-preserving machine learning methods add randomness, leading to varying predictions.
problem Privacy-preserving machine learning methods add randomness, leading to varying predictions.
method The study analyzes three DP-ensuring algorithms: output perturbation, objective perturbation, and DP-SGD.
result The degree of predictive multiplicity rises as the level of privacy increases, and is unevenly distributed across individuals and demographic groups.
Stochastic neural net weights are used in a variety of contexts, including regularization, Bayesian neural nets, exploration in reinforcement learning, and evolution strategies. Unfortunately, due to the large number of weights, all the examples in a mini-batch typically share the same weight perturbation, thereby limi…
This work introduces adversarial sparsity to measure robustness beyond adversarial accuracy.
problem Evaluating robustness to adversarial attacks beyond just accuracy.
method Adversarial sparsity, which quantifies the difficulty of finding perturbations.
result Sparsity provides valuable insights into neural networks and suggests improvements in robustness.
The Yamabe flow can blow up in infinite time with small perturbations.
problem Understanding the behavior of the Yamabe flow under small perturbations.
method Constructive proof using solutions of the Yamabe problem on the unit sphere as blow-up profiles.
result The Yamabe flow can blow up at multiple points on a Riemannian manifold in infinite time with small perturbations.
Machine Learning models are vulnerable to adversarial attacks that rely on perturbing the input data. This work proposes a novel strategy using Autoencoder Deep Neural Networks to defend a machine learning model against two gradient-based attacks: The Fast Gradient Sign attack and Fast Gradient attack. First we use an …
Given the ability to directly manipulate image pixels in the digital input space, an adversary can easily generate imperceptible perturbations to fool a Deep Neural Network (DNN) image classifier, as demonstrated in prior work. In this work, we propose ShapeShifter, an attack that tackles the more challenging problem o…
Existence of double bubbles with high constant mean curvatures in Riemannian manifolds.
problem Existence of double bubbles with high constant mean curvatures in Riemannian manifolds.
method Perturbations of geodesic standard double bubbles centered at critical points of the ambient scalar curvature and aligned along eigen-vectors of the ambient Ricci tensor, with general multiplicity results via Lusternik-Schnirelman theory.
result Existence of double bubbles with high constant mean curvatures in Riemannian manifolds.
This paper solves the convergence problem for estimating MGGD parameters with a convex formulation.
problem Establishing convergence properties for estimating MGGD parameters with unknown mean and precision matrix.
method Proposes a convex formulation with well-established convergence properties for robust estimation in noisy scenarios.
result Demonstrates improved accuracy in precision and covariance matrix estimation compared to existing methods.
Improved DOA estimation with distributed sensors across multiple frequencies.
problem Sensor gain uncertainties and directional perturbations in multi-frequency scenarios.
method Distributed optimization with local coherence models and iterative exchange of information.
result Advantages in statistical and computational efficiency through parallel iterative technique.
Deterministic bounds for tensor singular values and vectors, differing from matrix cases.
problem Spectral learning of higher-order orthogonally decomposable tensors.
method Deterministic perturbation bounds for singular values and vectors of orthogonally decomposable tensors.
result Perturbation affects each essential singular value/vector in isolation, independent of multiplicity and distance from other singular values.
The paper calculates spectral torsion for rescaled Dirac operators on manifolds.
problem Computing spectral torsion for rescaled Dirac operators.
method Using trilinear Clifford multiplication and functional of differential one-forms.
result Computed spectral torsion for four types of rescaled Dirac operators.
Inverse classification uses an induced classifier as a queryable oracle to guide test instances towards a preferred posterior class label. The result produced from the process is a set of instance-specific feature perturbations, or recommendations, that optimally improve the probability of the class label. In this work…