A locally-built, LLM-digested index of recent arXiv papers in quant finance, geometry/topology, and statistical ML — keyword search served straight from SQLite on this machine.
If we consider the moduli space of flat connections of a non trivial principal SO(3)-bundle over a surface, then we can define a map from the set of perturbed closed geodesics, below a given energy level, into families of perturbed Yang-Mills connections depending on a small parameter. In this paper we show that this m…
We study the problem of finding a universal (image-agnostic) perturbation to fool machine learning (ML) classifiers (e.g., neural nets, decision tress) in the hard-label black-box setting. Recent work in adversarial ML in the white-box setting (model parameters are known) has shown that many state-of-the-art image clas…
Study robust online learning with adversarial perturbations.
problem Learning robust classifiers in the presence of adversarial perturbations.
method Formulated as an online learning problem, considered both realizable and agnostic learnability, defined new dimension controlling mistake/regret bounds.
result Showed new dimension controls mistake/regret bounds, generalized to multiclass hypothesis classes.
We investigate the optimality of perturbation based algorithms in the stochastic and adversarial multi-armed bandit problems. For the stochastic case, we provide a unified regret analysis for both sub-Weibull and bounded perturbations when rewards are sub-Gaussian. Our bounds are instance optimal for sub-Weibull pertur…
In a previous paper on coupled gravitational and electromagnetic perturbations of Reissner-Nordström spacetime in a polarized setting, we derived a system of wave equations for two independent quantities, one related to the Weyl curvature and one related to the Ricci curvature of the perturbed spacetime. We analyze her…
In this paper we study the property of phase retrievability by redundant sysems of vectors under perturbations of the frame set. Specifically we show that if a set $\fc$ of m vectors in the complex Hilbert space of dimension n allows for vector reconstruction from magnitudes of its coefficients, then there is a pertu…
Adversarial training, in which a network is trained on both adversarial and clean examples, is one of the most trusted defense methods against adversarial attacks. However, there are three major practical difficulties in implementing and deploying this method - expensive in terms of extra memory and computation costs; …
We consider a classifier whose test set is exposed to various perturbations that are not present in the training set. These test samples still contain enough features to map them to the same class as their unperturbed counterpart. Current architectures exhibit rapid degradation of accuracy when trained on standard data…
Deep neural networks (DNNs) have achieved superior performance in various prediction tasks, but can be very vulnerable to adversarial examples or perturbations. Therefore, it is crucial to measure the sensitivity of DNNs to various forms of perturbations in real applications. We introduce a novel perturbation manifold …
Classical matrix perturbation results, such as Weyl's theorem for eigenvalues and the Davis-Kahan theorem for eigenvectors, are general purpose. These classical bounds are tight in the worst case, but in many settings sub-optimal in the typical case. In this paper, we present perturbation bounds which consider the natu…
We introduce an efficient message passing scheme for solving Constraint Satisfaction Problems (CSPs), which uses stochastic perturbation of Belief Propagation (BP) and Survey Propagation (SP) messages to bypass decimation and directly produce a single satisfying assignment. Our first CSP solver, called Perturbed Blief …
We come up with infinite-dimensional prequantum line bundles and moment map interpretations of three different sets of equations - the generalised Monge-Amp`ere equation, the almost Hitchin system, and the Calabi-Yang-Mills equations. These are all perturbations of already existing equations. Our construction for the g…
We present CROSSGRAD, a method to use multi-domain training data to learn a classifier that generalizes to new domains. CROSSGRAD does not need an adaptation phase via labeled or unlabeled data, or domain features in the new domain. Most existing domain adaptation methods attempt to erase domain signals using technique…
State-of-the-art machine learning models frequently misclassify inputs that have been perturbed in an adversarial manner. Adversarial perturbations generated for a given input and a specific classifier often seem to be effective on other inputs and even different classifiers. In other words, adversarial perturbations s…
We prove a Freed-Uhlenbeck style generic smoothness theorem for the moduli space of solutions to the Vafa--Witten equations on a closed symplectic four-manifold by using a method developed by Feehan for the study of the PU(2)-monopole equations on smooth closed four-manifolds. We introduce a set of perturbation terms…
The paper proves the existence and uniqueness of certain spacelike hypersurfaces with specific curvature and boundary conditions.
problem Existence and uniqueness of convex, entire, spacelike hypersurfaces with constant σk curvature.
method Investigation of hypersurfaces with prescribed set of lightlike directions and perturbation on the ideal boundary at infinity.
result Existence and uniqueness of complete entire spacelike constant σk curvature hypersurfaces with prescribed lightlike directions and perturbation.
This paper examines how graph topology affects adversarial attacks on vertex classification.
problem Adversarial attacks on vertex classification are vulnerable to graph topology changes.
method Examined two topological graph characteristics and their impact on adversary perturbation budgets.
result Training sets including high-degree vertices or those ensuring all unlabeled nodes have neighbors can significantly increase the adversary's perturbation budget.
Defenses against adversarial examples, such as adversarial training, are typically tailored to a single perturbation type (e.g., small ℓ∞-noise). For other perturbations, these defenses offer no guarantees and, at times, even increase the model's vulnerability. Our aim is to understand the reasons underlying…