MACER trains robust models without adversarial training, faster and more effective.
problem Learning robust models without relying on attack-dependent adversarial training.
method MACER trains provably robust smoothed classifiers by maximizing certified radius.
result MACER achieves larger average certified radius and faster training time compared to state-of-the-art methods.
Proposes a method to learn adaptive ambiguity sets for robust optimization.
problem Misspecification in distributionally robust optimization (DRO).
method Learned predictive ambiguity sets (LPAS) using deep contextual models.
result Significantly improves portfolio optimization performance compared to baselines.
Logarithmic network width suffices for robust memorization.
problem Achieving robust memorization in neural networks.
method Established upper and lower bounds on robust memorization radius.
result Width logarithmic in the number of samples is necessary and sufficient for robust memorization.
Paper introduces robust market making using Wasserstein distance and entropy regularization.
problem Market making robustness under uncertainty.
method Wasserstein distance, entropy regularization, convex optimization, optimal radius selection.
result The robust market making problem can be reformulated as a convex optimization problem.
The paper assesses text classification robustness through maximal safe radius computation.
problem Vulnerability of neural network models to small input modifications.
method Maximal safe radius computation, Monte Carlo Tree Search, syntactic filtering, linear bounding techniques.
result Approximation methods for computing upper and lower bounds of maximal safe radius.
Proposes a new method for nonlinear models with robustness guarantees.
problem Distributional robustness in nonlinear models with causality.
method Representation learning and identifiable representation learning.
result First causality-inspired robustness method with finite-radius guarantees in nonlinear settings.
Paper optimizes hyperparameters for high-dimensional regression models.
problem Optimizing robustness radius in high-dimensional linear regression.
method Distributionally robust optimization (DRO) with high-dimensional asymptotic statistics.
result Optimal hyperparameter selection minimizes estimation error efficiently.
Develops a robust hedging valuation adjustment measure for dynamic hedging under liquidity-demand stress.
problem Dynamic hedging under liquidity-demand stress
method Define robust HVA as the worst-case expected loss over a relative-entropy neighborhood of the loss distribution generated by simulated rebalancing and maturity-unwind trades.
result Distinguishes fixed-radius convention from fixed benchmark-stress convention and shows wider no-trade bands lower rebalancing costs but raise hedge-error risk.
Paper develops a robust HVA measure for dynamic hedging under liquidity stress.
problem Valuation of dynamic hedging under liquidity stress.
method Defines robust HVA as worst-case expected loss over a relative-entropy neighborhood of loss distributions for no-trade bands.
result Wider no-trade bands lower rebalancing costs but increase hedge-error risk.
Enhances robustness of deep neural networks with randomized smoothing.
problem Improving robustness of deep neural networks against noisy inputs and adversarial attacks.
method Introduces a variance-margin trade-off approach to increase certified robust radius using pre-trained models.
result Significant improvement in certified accuracy compared to state-of-the-art methods.
We introduce RSE to measure robustness in estimation problems.
problem Estimating statistical models from observed data.
method Developed theory for spectral functions of measures to compute RSE.
result RSE reveals a reciprocal relationship with problem complexity.
A robust conformal method for set estimation using non-conformity scores.
problem Lack of robustness in standard conformal prediction methods for outliers or heavy tails.
method Robust conformal method based on non-conformity score defined as half-mass radius.
result Empirical conformal regions converge to robust population central set.
Develops a new method for robust risk measurement by averaging nearby payoffs.
problem Measuring risk under uncertainty with a focus on robustness.
method Averaging nearby payoffs weighted by a chosen metric.
result The method leads to a convex risk measure and provides stability under large neighborhoods.
Proposes a new method to measure classifier robustness.
problem Measuring robustness of classifiers is crucial but challenging.
method Weighting sample importance based on difficulty and using logistic regression as a theoretical case study.
result The proposed score is independent of sample choice and measures robustness effectively.
Gradient-trained shallow networks can generalize well but are vulnerable to small-radius adversarial attacks.
problem Adversarial robustness of gradient-trained shallow networks.
method Analysis of neuron alignment and polynomial ReLU activation.
result Gradient-trained shallow networks with polynomial ReLU activation are robust to small-radius adversarial attacks.
Optimal financial strategies minimize risk under uncertain models.
problem Maximizing utility in financial markets with model uncertainty.
method Optimized strategies converge to those with minimal norm as uncertainty increases.
result Optimal strategies with minimal norm emerge as uncertainty grows.
High-dimensional smoothing techniques struggle with robustness guarantees against various attacks.
problem Challenges in extending randomized smoothing to other attack models in high-dimensional space.
method Analysis of isotropic and generalized Gaussian smoothing distributions, proving bounds on certified robustness radii.
result Certifiable robustness radii decrease as $O(1/d^{rac{1}{2} - rac{1}{p}})$ with dimension d for p>2. Unified representation for tree ensembles indexed by nodes
problem Unifying geometric object for tree ensembles indexed by nodes
method KPP indexes feature map by nodes, weighted by path metric
result Unified non-diagonal Gram for prediction, additive attribution, robust radius, and risk bounds
Enhances robustness for time series classification using self-ensemble method.
problem Limited adversarial robustness in time series classification.
method Proposes a self-ensemble method to improve Randomized Smoothing's robustness certification.
result Demonstrates superior robustness compared to baseline approaches.
Robust portfolio optimization considers uncertainty in market probabilities.
problem Uncertainty in market probabilities in multiperiod portfolio selection.
method Robust mean-variance optimization using Wasserstein ball centered at empirical data.
result Numerical simulations show improved performance compared to other strategies.
Despite the improved accuracy of deep neural networks, the discovery of adversarial examples has raised serious safety concerns. In this paper, we study two variants of pointwise robustness, the maximum safe radius problem, which for a given input sample computes the minimum distance to an adversarial example, and the …
New method improves certified robustness for classifier confidence.
problem Certifying confidence in classifier predictions.
method Randomized smoothing with modified Neyman-Pearson lemma.
result Certified radii for prediction confidence improved.
Adversarial training improves linear regression solutions, offering robustness against small perturbations.
problem Vulnerability of linear models to adversarial perturbations.
method Formulated as a min-max problem, adversarial training minimizes the best solution under worst-case attacks.
result Adversarial training yields the minimum-norm interpolating solution in overparameterized models, equivalent to parameter shrinking methods in underparameterized models.
Bayesian approach to portfolio selection reduces pessimism in frequent trading.
problem Tackling the challenge of estimating drift in Merton's portfolio selection model.
method Bayesian distributionally robust control with nonlinear Wasserstein projections.
result Reduced pessimism and improved performance in frequent rebalancing compared to existing methods.
Random smoothing struggles to certify high-dimensional image robustness.
problem Certifying adversarial robustness for high-dimensional images with p>2. method Analysis of random smoothing for ℓp robustness, focusing on ℓ∞. result Noise distribution required for ℓp robustness must have high variance, leading to trivial classifiers. This paper proposes a framework for certifying neural network defenses against data poisoning attacks.
problem Vulnerability of neural networks to data poisoning attacks.
method Random selection based defenses that average predictions on sub-datasets sampled from the training set.
result The certified radius of bagging derived by the framework is tighter than previous work.
In this work, we investigate black-box optimization from the perspective of frequentist kernel methods. We propose a novel batch optimization algorithm, which jointly maximizes the acquisition function and select points from a whole batch in a holistic way. Theoretically, we derive regret bounds for both the noise-free…
Building on a recent framework for distributionally robust optimization, we consider estimation of the inverse covariance matrix for multivariate data. We provide a novel notion of a Wasserstein ambiguity set specifically tailored to this estimation problem, leading to a tractable class of regularized estimators. Speci…
Deployment of deep neural networks (DNNs) in safety- or security-critical systems requires provable guarantees on their correct behaviour. A common requirement is robustness to adversarial perturbations in a neighbourhood around an input. In this paper we focus on the L0 norm and aim to compute, for a trained DNN an…
In the presence of model risk, it is well-established to replace classical expected values by worst-case expectations over all models within a fixed radius from a given reference model. This is the "robustness" approach. We show that previous methods for measuring this radius, e.g. relative entropy or polynomial diverg…
Adversarial training purifies hidden weights to remove small perturbations.
problem Understanding and removing adversarial perturbations in deep learning models.
method Introducing Feature Purification, a principle that adversarial training aims to remove small dense mixtures in hidden weights.
result Adversarial training can make neural networks robust against small perturbations, even with simple algorithms.
We solve robust optimization problems using Wasserstein balls and apply it to mean-CVaR optimization.
problem Distributionally robust optimization with Wasserstein ambiguity sets.
method Transformed robust optimization into non-robust with penalty term, selecting ambiguity set size.
result Impressive results in robust mean-CVaR optimization compared to other strategies.
Validates neural networks inputs to protect against adversarial examples.
problem Ensuring neural networks robustness against adversarial attacks.
method Runtime local robustness verification based on normal distribution of robustness radii.
result Improves neural network accuracy and protects against adversarial examples.
Fusion of robustness and uncertainty techniques improves adversarial defense.
problem Adversarial attacks on deep neural networks.
method Integrating uncertainty quantification into randomized smoothing for robustness guarantees.
result Improved robustness guarantees for uncertainty aware classifiers.
Unified framework for optimizing portfolios with distributions over weights, returns, and parameters.
problem Traditional portfolio optimization treats expected returns, covariances, and allocations as fixed. Modern practice replaces at least one with a distribution.
method Unified framework using Gamma_theta(dw,dr) coupling to organize Bayesian, robust, chance-constrained, stochastic-allocation, and distributional reinforcement-learning methods.
result Synthetic and structural contributions, including a portfolio specialization of Wasserstein-CVaR duality and a static no-randomization theorem.
Explaining the unreasonable effectiveness of deep learning has eluded researchers around the globe. Various authors have described multiple metrics to evaluate the capacity of deep architectures. In this paper, we allude to the radius margin bounds described for a support vector machine (SVM) with hinge loss, apply the…
Study robustness of polynomial neural networks using algebraic geometry.
problem Certify robustness radius of polynomial neural networks.
method Metric algebraic geometry, Euclidean distance degree, symbolic elimination, homotopy-continuation methods.
result Found decision boundaries with lower ED degree than generic cubic hypersurfaces.
In this paper we prove the following pointwise and curvature-free estimates on convexity radius, injectivity radius and local behavior of geodesics in a complete Riemannian manifold M: 1) the convexity radius of p, $\operatorname{conv}(p)\ge \min\{\frac{1}{2}\operatorname{inj}(p),\operatorname{foc}(B_{\operatorname…
Positive injectivity radius for manifolds with Lie structure at infinity.
problem Injectivity radius positivity for manifolds with specific boundary conditions.
method Lie groupoids to prove injectivity radius positivity.
result Injectivity radius is positive for manifolds with Lie structure at infinity.
The ratio of convexity radius over injectivity radius may be made arbitrarily small within the class of compact Riemannian manifolds of any fixed dimension at least two. This is proved using Gulliver's method of constructing manifolds with focal points but no conjugate points. The approach is suggested by a characteriz…
Uniform curvature bounds for regularized metrics with bounds on Ricci tensor and injectivity radius.
problem Bounding curvature of regularized metrics with constraints on Ricci tensor and injectivity radius.
method Mollification of riemannian metrics, uniform W2,p-harmonic radius bounds, Ricci tensor bounds, injectivity radius bounds. result Uniform estimate on the change of sectional curvature for regularized metrics.
Upper bound for conjugate radius in open manifolds with scalar curvature and spectrum constraints.
problem Bounding the conjugate radius of open manifolds with specific curvature and spectrum conditions.
method Established an upper bound using scalar curvature and bottom-of-spectrum constraints.
result For certain conditions, the conjugate radius is no more than π.
Proves upper bound on filling radius for manifolds with positive scalar curvature.
problem Bounding the filling radius of manifolds with positive scalar curvature.
method Quantitative operator K-theory and index theory.
result Proves a quantitative upper bound on the filling radius.
Compact theorem for minimal surfaces with lower injectivity radius.
problem Proving compactness of minimal surfaces with lower injectivity radius.
method Variant of Choi--Schoen compactness theorem, focusing on injectivity radius.
result Proved compactness theorem for minimal surfaces.
Injectivity radius on Stiefel manifold is π.
problem Determining the injectivity radius of the compact Stiefel manifold.
method Utilized the property of geodesics being space curves of constant Frenet curvatures.
result The injectivity radius on the Stiefel manifold under the Euclidean metric is π.
Lower bound on boundary injectivity radius for specific tubes.
problem Estimating the boundary injectivity radius of Margulis tubes.
method Using curvature bounds to derive a lower bound.
result A lower bound on the boundary injectivity radius is provided.
Extends randomized smoothing to certify robustness against various threat models and adversarial perturbations.
problem Certifying robustness of classifiers against adversarial perturbations.
method Develops a method to certify robustness against any ℓp (p∈N>0) minimized adversarial perturbation. result Randomized smoothing suffers from the curse of dimensionality, reducing effective radius as p increases. Strong theoretical guarantees of robustness can be given for ensembles of classifiers generated by input randomization. Specifically, an ℓ2 bounded adversary cannot alter the ensemble prediction generated by an additive isotropic Gaussian noise, where the radius for the adversary depends on both the variance of t…