Study on measuring vulnerability of neural network parameters via corruption.
arXiv research
A locally-built, LLM-digested index of recent arXiv papers in quant finance, geometry/topology, and statistical ML — keyword search served straight from SQLite on this machine.
Trend · papers per month
Over the past few years, neural networks were proven vulnerable to adversarial images: targeted but imperceptible image perturbations lead to drastically different predictions. We show that adversarial vulnerability increases with the gradients of the training objective when viewed as a function of the inputs. Surprisi…
This paper extensively evaluates the vulnerability of capsule networks to different adversarial attacks. Recent work suggests that these architectures are more robust towards adversarial attacks than other neural networks. However, our experiments show that capsule networks can be fooled as easily as convolutional neur…
Despite the remarkable performance of deep neural networks on various computer vision tasks, they are known to be susceptible to adversarial perturbations, which makes it challenging to deploy them in real-world safety-critical applications. In this paper, we conjecture that the leading cause of adversarial vulnerabili…
Study reveals how neural network smoothness affects their vulnerability to adversarial attacks.
Paper analyzes neural networks using active subspace for structural analysis and vulnerability, reducing model size and improving attacks.
Mathematical framework to understand neural network vulnerability.
Lazy neural networks are vulnerable to adversarial attacks.
NTK neural networks are robust to adversarial attacks in nonparametric regression.
New attack method improves neural network security.
Deep networks can overfit benignly but still be vulnerable to adversarial attacks.
Graph neural network (GNN), as a powerful representation learning model on graph data, attracts much attention across various disciplines. However, recent studies show that GNN is vulnerable to adversarial attacks. How to make GNN more robust? What are the key vulnerabilities in GNN? How to address the vulnerabilities …
Vulnerability identification is crucial to protect the software systems from attacks for cyber security. It is especially important to localize the vulnerable functions among the source code to facilitate the fix. However, it is a challenging and tedious process, and also requires specialized security expertise. Inspir…
The paper proves neural networks are almost always surjective, impacting model safety.
Graph neural networks are vulnerable to adversarial attacks by manipulating graph structure.
Two-layer networks trained on low-dimensional subspaces are vulnerable to adversarial examples.
With rapid progress and significant successes in a wide spectrum of applications, deep learning is being applied in many safety-critical environments. However, deep neural networks have been recently found vulnerable to well-designed input samples, called adversarial examples. Adversarial examples are imperceptible to …
GTA is the first backdoor attack on GNNs, demonstrating vulnerabilities in graph-oriented security models.
Securely trains neural networks remotely with deep learning's flaws.
mFI-PSO generates effective adversarial images for DNNs.
Many deployed learned models are black boxes: given input, returns output. Internal information about the model, such as the architecture, optimisation procedure, or training data, is not disclosed explicitly as it might contain proprietary information or make the system more vulnerable. This work shows that such attri…
New normalization method makes neural networks more robust to adversarial attacks.
Spiking Neural Networks (SNNs) claim to present many advantages in terms of biological plausibility and energy efficiency compared to standard Deep Neural Networks (DNNs). Recent works have shown that DNNs are vulnerable to adversarial attacks, i.e., small perturbations added to the input data can lead to targeted or r…
Despite their impressive performance, deep neural networks exhibit striking failures on out-of-distribution inputs. One core idea of adversarial example research is to reveal neural network errors under such distribution shifts. We decompose these errors into two complementary sources: sensitivity and invariance. We sh…
New method bounds membership inference attack success using mutual information.
Lower class selectivity makes networks more robust to natural perturbations but more vulnerable to adversarial attacks.
Bayesian Neural Networks are robust to gradient-based attacks in the large-data limit.
Deep neural networks (DNNs) have achieved superior performance in various prediction tasks, but can be very vulnerable to adversarial examples or perturbations. Therefore, it is crucial to measure the sensitivity of DNNs to various forms of perturbations in real applications. We introduce a novel perturbation manifold …
Deep-CAPTCHA cracks visual CAPTCHAs using deep learning.
New defense method reduces adversarial attacks on neural networks.
Backdoors can be implanted in neural models of source code, and we detect and remove them.
Class selectivity affects robustness to corruptions but not to adversarial attacks.
New method certifies joint adversarial robustness of model ensembles.
Many deep learning models are vulnerable to the adversarial attack, i.e., imperceptible but intentionally-designed perturbations to the input can cause incorrect output of the networks. In this paper, using information geometry, we provide a reasonable explanation for the vulnerability of deep learning models. By consi…
Thousands of security vulnerabilities are discovered in production software each year, either reported publicly to the Common Vulnerabilities and Exposures database or discovered internally in proprietary code. Vulnerabilities often manifest themselves in subtle ways that are not obvious to code reviewers or the develo…
New insights into adversarial vulnerability linked to manifold separability issues.
It has been demonstrated that deep neural networks are prone to noisy examples particular adversarial samples during inference process. The gap between robust deep learning systems in real world applications and vulnerable neural networks is still large. Current adversarial training strategies improve the robustness ag…
Deep learning takes advantage of large datasets and computationally efficient training algorithms to outperform other approaches at various machine learning tasks. However, imperfections in the training phase of deep neural networks make them vulnerable to adversarial samples: inputs crafted by adversaries with the int…
Machine learning classifiers are known to be vulnerable to inputs maliciously constructed by adversaries to force misclassification. Such adversarial examples have been extensively studied in the context of computer vision applications. In this work, we show adversarial attacks are also effective when targeting neural …
Paper detects adversarial speech inputs with high accuracy.
Deep neural networks were shown to be vulnerable to single pixel modifications. However, the reason behind such phenomena has never been elucidated. Here, we propose Propagation Maps which show the influence of the perturbation in each layer of the network. Propagation Maps reveal that even in extremely deep networks s…
The paper introduces a method to make neural networks more robust to adversarial attacks.
Batch normalization (batch norm) is often used in an attempt to stabilize and accelerate training in deep neural networks. In many cases it indeed decreases the number of parameter updates required to achieve low training error. However, it also reduces robustness to small adversarial input perturbations and noise by d…
Federated learning can be vulnerable to adversarial attacks, which this work addresses.
New mechanism protects neural network weights from privacy attacks during self-supervised learning.
Massif helps interpret adversarial attacks on deep learning models.
Recently it's been shown that neural networks can use images of human faces to accurately predict Body Mass Index (BMI), a widely used health indicator. In this paper we demonstrate that a neural network performing BMI inference is indeed vulnerable to test-time adversarial attacks. This extends test-time adversarial a…
SmoothFool efficiently computes smooth adversarial perturbations for deep networks.