This paper explores adversarial training limits and improves model robustness against norm-bounded perturbations.
arXiv research
A locally-built, LLM-digested index of recent arXiv papers in quant finance, geometry/topology, and statistical ML — keyword search served straight from SQLite on this machine.
Trend · papers per month
Free adversarial training reduces the generalization gap compared to vanilla method.
Generative models improve adversarial robustness by adding synthetic data.
AMP regularization improves deep learning models by favoring flat minima.
Data augmentation improves robustness in adversarial training.
New approach to adversarial robustness with non-uniform perturbations.
Adversarial testing methods based on Projected Gradient Descent (PGD) are widely used for searching norm-bounded perturbations that cause the inputs of neural networks to be misclassified. This paper takes a deeper look at these methods and explains the effect of different hyperparameters (i.e., optimizer, step size an…
New method creates universal perturbations to fool neural network interpretations.
New method defends deep nets against large perturbations perceptible to humans.
Adversarial examples are typically constructed by perturbing an existing data point within a small matrix norm, and current defense methods are focused on guarding against this type of attack. In this paper, we propose unrestricted adversarial examples, a new threat model where the attackers are not restricted to small…
Enhances robustness of AT frameworks to multiple perturbations without increasing training complexity.
Paper defends machine learning models from adversarial attacks using GLRT.
The paper improves confidence regions for band-limited functions using tighter norm bounds and majority voting.
Recent work has developed methods for learning deep network classifiers that are provably robust to norm-bounded adversarial perturbation; however, these methods are currently only possible for relatively small feedforward networks. In this paper, in an effort to scale these approaches to substantially larger models, w…
Many state-of-the-art machine learning models such as deep neural networks have recently shown to be vulnerable to adversarial perturbations, especially in classification tasks. Motivated by adversarial machine learning, in this paper we investigate the robustness of sparse regression models with strongly correlated co…
Deep neural networks are known to be fragile to small adversarial perturbations. This issue becomes more critical when a neural network is interconnected with a physical system in a closed loop. In this paper, we show how to combine recent works on neural network certification tools (which are mainly used in static set…
Proposes model-based robust deep learning to handle natural variation in data.
Recent research has made the surprising finding that state-of-the-art deep learning models sometimes fail to generalize to small variations of the input. Adversarial training has been shown to be an effective approach to overcome this problem. However, its application has been limited to enforcing invariance to analyti…
Several recent works have developed methods for training classifiers that are certifiably robust against norm-bounded adversarial perturbations. These methods assume that all the adversarial transformations are equally important, which is seldom the case in real-world applications. We advocate for cost-sensitive robust…
Adversarial examples are malicious inputs crafted to cause a model to misclassify them. Their most common instantiation, "perturbation-based" adversarial examples introduce changes to the input that leave its true label unchanged, yet result in a different model prediction. Conversely, "invariance-based" adversarial ex…
New method improves robustness of smoothed classifiers.
We provide recovery guarantees for compressible signals that have been corrupted with noise and extend the framework introduced in \cite{bafna2018thwarting} to defend neural networks against -norm, -norm, and -norm attacks. Our results are general as they can be applied to most unitary tr…
Recent work has shown that it is possible to train deep neural networks that are provably robust to norm-bounded adversarial perturbations. Most of these methods are based on minimizing an upper bound on the worst-case loss over all possible adversarial perturbations. While these techniques show promise, they often res…
Develops GLRT for defending against adversarial attacks in hypothesis testing.
Paper analyzes adversarial training's performance in binary classification.
Adversarial training is an effective methodology for training deep neural networks that are robust against adversarial, norm-bounded perturbations. However, the computational cost of adversarial training grows prohibitively as the size of the model and number of input dimensions increase. Further, training against less…
We present an efficient technique, which allows to train classification networks which are verifiably robust against norm-bounded adversarial attacks. This framework is built upon the work of Gowal et al., who applies the interval arithmetic to bound the activations at each layer and keeps the prediction invariant to t…
New IDS algorithm refines parameter norm bounds for better bandit performance.
A rapidly growing area of work has studied the existence of adversarial examples, datapoints which have been perturbed to fool a classifier, but the vast majority of these works have focused primarily on threat models defined by norm-bounded perturbations. In this paper, we propose a new threat model for adver…
New neural network design resists small -norm adversarial perturbations.
In this note, we derive concentration inequalities for random vectors with subGaussian norm (a generalization of both subGaussian random vectors and norm bounded random vectors), which are tight up to logarithmic factors.
Unified framework TSS certifies robustness against semantic transformations.
New approach to certifiably robust neural networks using Boolean function perspective.
Uniform convergence of interpolators proven for Gaussian data.
Neural networks classify OOD images by their nearest neighbor in training data.
Optimal policies in Markov decision processes (MDPs) are very sensitive to model misspecification. This raises serious concerns about deploying them in high-stake domains. Robust MDPs (RMDP) provide a promising framework to mitigate vulnerabilities by computing policies with worst-case guarantees in reinforcement learn…
Study analyzes and enhances robustness of neural networks for classification and regression.
RADIAL-RL improves deep RL agents' robustness against adversarial attacks.
While progress has been made in understanding the robustness of machine learning classifiers to test-time adversaries (evasion attacks), fundamental questions remain unresolved. In this paper, we use optimal transport to characterize the minimum possible loss in an adversarial classification scenario. In this setting, …
We consider the moduli space of the extremal Kähler metrics on compact manifolds. We show that under the conditions of two-sided total volume bounds, -norm bounds on $\Riem$, and Sobolev constant bounds, this Moduli space can be compactified by including (reduced) orbifolds with finitely many singularities…
Proposes DP-MERF for privacy-preserving synthetic data generation.
A large body of recent work has investigated the phenomenon of evasion attacks using adversarial examples for deep learning systems, where the addition of norm-bounded perturbations to the test inputs leads to incorrect output classification. Previous work has investigated this phenomenon in closed-world systems where …
We review recent work on the local geometry and optimal regularity of Lorentzian manifolds with bounded curvature. Our main results provide an estimate of the injectivity radius of an observer, and a local canonical foliations by CMC (Constant Mean Curvature) hypersurfaces, together with spatially harmonic coordinates.…
In this paper, we extend the work in \cite{D}\cite{ChrusLiWe}\cite{ChrusCo}\cite{Co}. We weaken the asymptotic conditions on the second fundamental form, and we also give an norm bound for the difference between general data and Extreme Kerr data or Extreme Kerr-Newman data by proving convexity of the renormali…
Orthogonal deep models defend against black-box attacks by ensuring internal representations are nearly orthogonal.
Making neural networks robust against adversarial inputs has resulted in an arms race between new defenses and attacks. The most promising defenses, adversarially robust training and verifiably robust training, have limitations that restrict their practical applications. The adversarially robust training only makes the…
New regularizers tighten convex relaxation bounds for neural networks.
If is a compact real analytic Riemannian manifold, we give a necessary and sufficient condition for there to be a sequence of quasimodes of order saturating sup-norm estimates. In particular, it gives optimal conditions for existence of eigenfunctions satisfying maximal sup norm bounds. The condition is …