This paper introduces metrics to evaluate robustness of neural networks to natural adversarial examples.
arXiv research
A locally-built, LLM-digested index of recent arXiv papers in quant finance, geometry/topology, and statistical ML — keyword search served straight from SQLite on this machine.
Trend · papers per month
Adversarial fog tests autonomous navigation models.
Given a state-of-the-art deep neural network classifier, we show the existence of a universal (image-agnostic) and very small perturbation vector that causes natural images to be misclassified with high probability. We propose a systematic algorithm for computing universal perturbations, and show that state-of-the-art …
We consider scattering by an abstract compactly supported perturbation in R^n. To include the traditional cases of potential, obstacle and metric scattering without going into their particular nature we adopt the "black box" formalism developed jointly with Sjostrand [23]. It is quite likely that one could extend the r…
In this paper we investigate the usage of adversarial perturbations for the purpose of privacy from human perception and model (machine) based detection. We employ adversarial perturbations for obfuscating certain variables in raw data while preserving the rest. Current adversarial perturbation methods are used for dat…
This paper generates natural-looking perturbations to fool classifiers.
Classical matrix perturbation results, such as Weyl's theorem for eigenvalues and the Davis-Kahan theorem for eigenvectors, are general purpose. These classical bounds are tight in the worst case, but in many settings sub-optimal in the typical case. In this paper, we present perturbation bounds which consider the natu…
As most natural resources, fisheries are affected by random disturbances. The evolution of such resources may be modelled by a succession of deterministic process and random perturbations on biomass and/or growth rate at random times. We analyze the impact of the characteristics of the perturbations on the management o…
Study metric perturbations to make degenerate harmonic forms non-degenerate.
Prove that collapsing CSC metrics can be perturbed to invariant collapsing CSC metrics.
Study perturbations of submodules in Drury-Arveson space, finding smooth vector bundles with Hermitian connections.
Wider networks improve natural accuracy but worsen perturbation stability, affecting overall robustness.
A new method generates natural-looking adversarial examples by bounding internal activation values.
This paper presents a new approach, called perturb-max, for high-dimensional statistical inference that is based on applying random perturbations followed by optimization. This framework injects randomness to maximum a-posteriori (MAP) predictors by randomly perturbing the potential function for the input. A classic re…
In this paper, we propose novel generative models for creating adversarial examples, slightly perturbed images resembling natural images but maliciously crafted to fool pre-trained models. We present trainable deep neural networks for transforming images to adversarial perturbations. Our proposed models can produce ima…
We investigate the optimality of perturbation based algorithms in the stochastic and adversarial multi-armed bandit problems. For the stochastic case, we provide a unified regret analysis for both sub-Weibull and bounded perturbations when rewards are sub-Gaussian. Our bounds are instance optimal for sub-Weibull pertur…
Given a state-of-the-art deep neural network text classifier, we show the existence of a universal and very small perturbation vector (in the embedding space) that causes natural text to be misclassified with high probability. Unlike images on which a single fixed-size adversarial perturbation can be found, text is of …
Deep networks have recently been shown to be vulnerable to universal perturbations: there exist very small image-agnostic perturbations that cause most natural images to be misclassified by such classifiers. In this paper, we propose the first quantitative analysis of the robustness of classifiers to universal perturba…
Robust tensor CP decomposition involves decomposing a tensor into low rank and sparse components. We propose a novel non-convex iterative algorithm with guaranteed recovery. It alternates between low-rank CP decomposition through gradient ascent (a variant of the tensor power method), and hard thresholding of the resid…
We study the problem of finding a universal (image-agnostic) perturbation to fool machine learning (ML) classifiers (e.g., neural nets, decision tress) in the hard-label black-box setting. Recent work in adversarial ML in the white-box setting (model parameters are known) has shown that many state-of-the-art image clas…
Study assesses deep neural networks' robustness in mammogram images.
This work improves robustness guarantees for neural networks using low rank representations.
Convolutional neural networks (CNN) have become one of the most popular machine learning tools and are being applied in various tasks, however, CNN models are vulnerable to universal perturbations, which are usually human-imperceptible but can cause natural images to be misclassified with high probability. One of the s…
New method to compute tangle sums in character varieties.
We study the robustness of image classifiers to temporal perturbations derived from videos. As part of this study, we construct two datasets, ImageNet-Vid-Robust and YTBB-Robust , containing a total 57,897 images grouped into 3,139 sets of perceptually similar images. Our datasets were derived from ImageNet-Vid and You…
We investigate the robustness properties of image recognition models equipped with two features inspired by human vision, an explicit episodic memory and a shape bias, at the ImageNet scale. As reported in previous work, we show that an explicit episodic memory improves the robustness of image recognition models agains…
The paper learns perturbation sets from data to improve robustness in machine learning.
The inverse statistical problem of finding direct interactions in complex networks is difficult. In the natural sciences, well-controlled perturbation experiments are widely used to probe the structure of complex networks. However, our understanding of how and why perturbations aid inference remains heuristic, and we l…
New method for analyzing compositional data, addressing biases in summary statistics.
Adversarial examples are perturbed inputs designed to fool machine learning models. Most recent works on adversarial examples for image classification focus on directly modifying pixels with minor perturbations. A common requirement in all these works is that the malicious perturbations should be small enough (measured…
In a noncommutative torus, effect of perturbation by inner derivation on the associated quantum stochastic process and geometric parameters like volume and scalar curvature have been studied. Cohomological calculations show that the above perturbation produces new spectral triples. Also for the Weyl C^*-algebra, the La…
Following great success in the image processing field, the idea of adversarial training has been applied to tasks in the natural language processing (NLP) field. One promising approach directly applies adversarial training developed in the image processing field to the input word embedding space instead of the discrete…
Defenses against adversarial examples, such as adversarial training, are typically tailored to a single perturbation type (e.g., small -noise). For other perturbations, these defenses offer no guarantees and, at times, even increase the model's vulnerability. Our aim is to understand the reasons underlying…
New method identifies latent variables with sparse perturbations.
New approach to quantum knot invariants using perturbed Gaussian generating functions.
New non-perturbative counterexamples to Min-Oo's Conjecture are created.
Study shows current image classification models lack robustness to real-world dataset shifts.
Introduces a new geometric framework for non-perturbative BV-theory.
A new exploration strategy for contextual bandits reduces regret and is computationally efficient.
Paper shows robustness of gradient descent in matrix sensing despite perturbations.
Although gradient descent (GD) almost always escapes saddle points asymptotically [Lee et al., 2016], this paper shows that even with fairly natural random initialization schemes and non-pathological functions, GD can be significantly slowed down by saddle points, taking exponential time to escape. On the other hand, g…
Adversarial weight perturbations can inject backdoors into trained neural models.
New method defines GCM spheres in Kerr perturbations, proving their stability.
Lower class selectivity makes networks more robust to natural perturbations but more vulnerable to adversarial attacks.
The pentagram map's limit point is related to infinitesimal perturbations of polygons.
Paper addresses eigenvector perturbation in small eigen-gap scenarios.
Study perturbs mean curvature flow near non-spherical shrinkers.
We consider the structured-output prediction problem through probabilistic approaches and generalize the "perturb-and-MAP" framework to more challenging weighted Hamming losses, which are crucial in applications. While in principle our approach is a straightforward marginalization, it requires solving many related MAP …