Regularization improves robustness of smoothed classifiers.
problem Certifying robustness of smoothed classifiers.
method Regularizing prediction consistency over Gaussian noise.
result Significantly improved certified robustness with less training costs.
New method improves robustness of smoothed classifiers against adversarial attacks.
problem Improving robustness of smoothed classifiers against adversarial attacks.
method Proposes worst-case adversarial loss over input distributions as a robustness certificate, and uses duality and smoothness properties to provide an easy-to-compute upper bound.
result Shows superior robustness performance over state-of-the-art certified or heuristic methods.
Recent works have shown the effectiveness of randomized smoothing as a scalable technique for building neural network-based classifiers that are provably robust to ℓ2-norm adversarial perturbations. In this paper, we employ adversarial training to improve the performance of randomized smoothing. We design an adap…
Denoised smoothing defends pretrained classifiers against adversarial attacks.
problem Adversarial attacks on pretrained classifiers.
method Prepending a denoiser to any off-the-shelf classifier using randomized smoothing.
result Guaranteed ℓp-robustness to adversarial examples without modifying the pretrained classifier. New method improves certified robustness for classifier confidence.
problem Certifying confidence in classifier predictions.
method Randomized smoothing with modified Neyman-Pearson lemma.
result Certified radii for prediction confidence improved.
We show how to turn any classifier that classifies well under Gaussian noise into a new classifier that is certifiably robust to adversarial perturbations under the ℓ2 norm. This "randomized smoothing" technique has been proposed recently in the literature, but existing guarantees are loose. We prove a tight robu…
RS-Del provides robustness for sequence classifiers against edit distance attacks.
problem Certifying robustness of discrete sequence classifiers against edit distance attacks.
method Randomized deletion (RS-Del) for discrete sequence classifiers, focusing on edit distance-bounded adversaries.
result Achieved a certified accuracy of 91% at an edit distance radius of 128 bytes on malware detection.
New method improves robustness of smoothed classifiers.
problem Improving accuracy and robustness of smoothed classifiers.
method Regularized risk with adaptive regularization.
result Tighter robustness bounds with high probability.
This work introduces two strategies for training network classifiers with heterogeneous agents. One strategy promotes global smoothing over the graph and a second strategy promotes local smoothing over neighbourhoods. It is assumed that the feature sizes can vary from one agent to another, with some agents observing in…
Enhances robustness of deep neural networks with randomized smoothing.
problem Improving robustness of deep neural networks against noisy inputs and adversarial attacks.
method Introduces a variance-margin trade-off approach to increase certified robust radius using pre-trained models.
result Significant improvement in certified accuracy compared to state-of-the-art methods.
We develop the theory of smooth principal bundles for a smooth group G, using the framework of diffeological spaces. After giving new examples showing why arbitrary principal bundles cannot be classified, we define D-numerable bundles, the smooth analogs of numerable bundles from topology, and prove that pulling ba…
Unified smoothing for robust classification improves accuracy.
problem Improving robustness of classifiers against adversarial attacks.
method Learned smoothed densities and randomized smoothing.
result Provable robust accuracies higher than state-of-the-art defenses.
Classifies smooth isotopy of a specific Lagrangian embedding.
problem Classifying Lagrangian embeddings of a specific form.
method Smooth isotopy classification for all dimensions n≥3. result Lagrangian embeddings are fully classified up to isotopy.
New method improves robustness of large models without sacrificing accuracy.
problem Improving robustness of large pre-trained models without accuracy loss.
method Multi-scale diffusion denoised smoothing, selectively applying smoothing at multiple noise scales.
result Strong certified robustness at high noise levels with accuracy close to non-smoothed classifiers.
The study classifies complex smooth Fano varieties with large pseudoindex.
problem Classifying Fano varieties with specific properties.
method Analyzing Fano varieties with large pseudoindex and Picard number greater than one.
result Classification of Fano varieties with pseudoindex at least n-2 and Picard number greater than one.
SWEEN improves certified robustness via weighted ensembling of smoothed classifiers.
problem Finding optimal base classifiers for randomized smoothing.
method Smoothed WEighted ENsembling (SWEEN) scheme.
result SWEEN achieves optimal certified robustness under mild assumptions.
The paper classifies smooth structures on product manifolds of 3-connected 8-manifolds with spheres.
problem Classifying smooth structures on product manifolds.
method Computational and classification methods for concordance and diffeomorphism.
result Diffeomorphism classification of MimesS1 for specific M and k. Classifies smooth manifolds homotopy equivalent to sphere products
problem Classifying smooth manifolds homotopy equivalent to sphere products
method Using normal-invariant map and explicit families of manifolds
result Classifies smooth manifolds up to almost diffeomorphism
Classifies certain high-dimensional manifolds with specific cohomology properties.
problem Classifying smooth manifolds with a specific cohomology structure.
method Analyzes cohomology rings and uses topological equivalences.
result Classifies manifolds up to diffeomorphism, homeomorphism, and homotopy equivalence.
It is well-known that classifiers are vulnerable to adversarial perturbations. To defend against adversarial perturbations, various certified robustness results have been derived. However, existing certified robustnesses are limited to top-1 predictions. In many real-world applications, top-k predictions are more rel…
Classifies holomorphic parabolic geometries on complex manifolds.
problem Classifying holomorphic parabolic geometries on complex manifolds.
method Bounding numerical dimension and using geometric invariants.
result Uncovering foliations and fibrations on smooth projective varieties.
This study improves scalability of randomized smoothing for certifying classifier robustness.
problem Certifying machine learning classifiers against adversarial attacks is challenging and scalable solutions are needed.
method The study reviews and explores randomized smoothing and its derivatives, focusing on scalability.
result The study provides theoretical guarantees and discusses scalability challenges of randomized smoothing.
A new method for efficient BNC parameter estimation outperforms HDP smoothing.
problem Efficiently estimating parameters for Bayesian network classifiers to match or exceed random forest performance.
method Uses log-linear regression to approximate hierarchical Dirichlet process (HDP) smoothing, making the approach simpler and faster.
result Our method outperforms HDP smoothing while being orders of magnitude faster and competitive with random forests.
The paper analyzes kernel classifiers' performance in Sobolev spaces and proves their optimality.
problem Theoretical analysis of kernel classifiers' performance in Sobolev spaces.
method Deriving upper and lower bounds on classification excess risk using kernel regression theory and estimating interpolation smoothness.
result The proposed kernel classifier is optimal in Sobolev spaces, with theoretical bounds confirmed by real data.
Classifies 4-manifolds with specific properties and fundamental group.
problem Classifying 4-manifolds with fundamental group Z and boundary. method Topological and smooth classification methods, including Hermitian forms and 2-handlebody constructions. result Every Hermitian form over Z[t±1] arises as the equivariant intersection form of exotic smooth 4-manifolds. New method makes machine learning models robust to label flipping attacks.
problem Machine learning models are vulnerable to label flipping attacks.
method Randomized smoothing over arbitrary functions to build certifiably robust classifiers.
result Linear classifiers are robust to label flipping attacks with deterministic bounds.
Extends randomized smoothing to certify robustness against various threat models and adversarial perturbations.
problem Certifying robustness of classifiers against adversarial perturbations.
method Develops a method to certify robustness against any ℓp (p∈N>0) minimized adversarial perturbation. result Randomized smoothing suffers from the curse of dimensionality, reducing effective radius as p increases. On the basis of Brylinski's work, we introduce a notion of equivariant smooth Deligne cohomology group, which is a generalization of both the ordinary smooth Deligne cohomology and the ordinary equivariant cohomology. Using the cohomology group, we classify equivariant circle bundles with connection, and equivariant ge…
Improved signal classification using multiple wavelets and their smooth coefficients.
problem Signal classification accuracy declines with reduced attributes.
method Transform data with multiple wavelets, combine outputs, apply ensemble classifiers.
result Proposed technique outperforms raw data and single wavelet approaches.
tl;dr: no, it cannot, at least not on average on the standard archive problems. We assess whether using six smoothing algorithms (moving average, exponential smoothing, Gaussian filter, Savitzky-Golay filter, Fourier approximation and a recursive median sieve) could be automatically applied to time series classificatio…
Novikov theorem extended to rational Pontryagin classes for cyclic group C4.
problem Classifying stable Cp-smoothings of high-dimensional manifolds. method Computing equivariant homotopy groups and applying to C4. result Novikov's theorem extended to rational Pontryagin classes for C4. Improves safety region certification for smoothed classifiers without changing smoothing scheme.
problem Certified safety regions for smoothed classifiers are often small compared to optimal.
method Generalizes certified radius calculation as nested optimization problem, uses 0th-1st order information, and designs efficient estimators.
result Certified safety regions are significantly larger than current methods, achieving significant improvements on various metrics.
Paper defends deep learning classifiers against channel-aware adversarial attacks.
problem Deep learning classifiers are vulnerable to adversarial attacks.
method Channel-aware adversarial attacks are presented and defended against.
result Certified defense based on randomized smoothing makes classifiers robust.
We show a de Rham theory for cubical manifolds, and study rational homotopy type of the classifying spaces of smooth quandles. We also show that secondary characteristic classes in \cite{Dup2,DK} produce cocycles of quandles.
We classify smooth del Pezzo surfaces whose alpha-invariant of Tian is bigger than one.
Characteristic classes of oriented vector bundles can be identified with cohomology classes of the disjoint union of classifying spaces BSO_n of special orthogonal groups SO_n with n=0,1,... A characteristic class is stable if it extends to a cohomology class of a homotopy colimit BSO of classifying spaces BSO_n. Simil…
Despite achieving impressive performance, state-of-the-art classifiers remain highly vulnerable to small, imperceptible, adversarial perturbations. This vulnerability has proven empirically to be very intricate to address. In this paper, we study the phenomenon of adversarial perturbations under the assumption that the…
Fusion of robustness and uncertainty techniques improves adversarial defense.
problem Adversarial attacks on deep neural networks.
method Integrating uncertainty quantification into randomized smoothing for robustness guarantees.
result Improved robustness guarantees for uncertainty aware classifiers.
In this paper, we classify smooth 5-manifolds with fundamental group isomorphic to $\z/2$ and universal cover diffeomorphic to S2×S3. This gives a classification of smooth free involutions on S2×S3 up to conjugation.
Classifies Real line bundles with Real connections on manifolds with involution.
problem Classifying Real line bundles with Real connections on manifolds with involution.
method Defines Real smooth Deligne cohomology to interpolate between equivariant sheaf cohomology and smooth imaginary-valued forms.
result Classifies Real line bundles with Real connections on manifolds with involution.
Suppose one is faced with the challenge of tissue segmentation in MR images, without annotators at their center to provide labeled training data. One option is to go to another medical center for a trained classifier. Sadly, tissue classifiers do not generalize well across centers due to voxel intensity shifts caused b…
We classify the resolution graphs of weighted homogeneous surface singularities which admit rational homology disk smoothings. The nonexistence of rational homology disk smoothings is shown by symplectic geometric methods, while the existence is verified via smoothings of negative weights. In particular, it is shown th…
The study classifies Kähler threefolds with special fiber bundles.
problem Classifying Kähler threefolds with specific fiber bundles.
method Generalized from projective case, using fiber bundles over the circle and étale covers.
result Proves Kotschick's conjecture in dimension 3.
We classify closed, simply-connected cohomogeneity-one Alexandrov spaces in dimensions 5, 6 and 7. We show that every closed, simply-connected smooth n-orbifold, 2≤n≤7 with a cohomogeneity one action is equivariantly homeomorphic to a smooth good orbifold of cohomogeneity one.
Randomized smoothing reduces accuracy in ML models, especially at higher noise levels.
problem Adversarial attacks on ML models, especially randomized smoothing's accuracy drop.
method Theoretical and empirical analysis of randomized smoothing's effect on feasible hypotheses space.
result For some noise levels, randomized smoothing shrinks the set of feasible hypotheses, leading to accuracy drops.
We classify smooth locally free actions of the real affine group on closed orientable three-dimensional manifolds up to smooth conjugacy. As a corollary, there exists a non-homogeneous action when the manifold is the unit tangent bundle of a closed surface with a hyperbolic metric.
Classifies local boundary conditions for Dirac-type operators on manifolds.
problem Determining all local smooth boundary conditions for Dirac-type operators.
method Combining general theory of boundary value problems for Dirac operators and pointwise considerations.
result Classification of local self-adjoint regular boundary conditions for Dirac spinors in dimensions 3 and 4.
This paper classifies minimal fillings of lens spaces.
problem Determining the smallest smooth negative-definite fillings of lens spaces.
method Classification of minimal fillings based on forbidden subgraphs in plumbing graphs.
result Classification of lens spaces with minimal negative-definite canonical plumbing.