Convolutional neural networks (CNN) have become one of the most popular machine learning tools and are being applied in various tasks, however, CNN models are vulnerable to universal perturbations, which are usually human-imperceptible but can cause natural images to be misclassified with high probability. One of the s…
arXiv research
A locally-built, LLM-digested index of recent arXiv papers in quant finance, geometry/topology, and statistical ML — keyword search served straight from SQLite on this machine.
Trend · papers per month
Deep networks have recently been shown to be vulnerable to universal perturbations: there exist very small image-agnostic perturbations that cause most natural images to be misclassified by such classifiers. In this paper, we propose the first quantitative analysis of the robustness of classifiers to universal perturba…
Given a state-of-the-art deep neural network text classifier, we show the existence of a universal and very small perturbation vector (in the embedding space) that causes natural text to be misclassified with high probability. Unlike images on which a single fixed-size adversarial perturbation can be found, text is of …
Given a state-of-the-art deep neural network classifier, we show the existence of a universal (image-agnostic) and very small perturbation vector that causes natural images to be misclassified with high probability. We propose a systematic algorithm for computing universal perturbations, and show that state-of-the-art …
Classifiers such as deep neural networks have been shown to be vulnerable against adversarial perturbations on problems with high-dimensional input space. While adversarial training improves the robustness of image classifiers against such adversarial perturbations, it leaves them sensitive to perturbations on a non-ne…
We present an algorithm for computing class-specific universal adversarial perturbations for deep neural networks. Such perturbations can induce misclassification in a large fraction of images of a specific class. Unlike previous methods that use iterative optimization for computing a universal perturbation, the propos…
Adversarial examples are inputs intentionally perturbed with the aim of forcing a machine learning model to produce a wrong prediction, while the changes are not easily detectable by a human. Although this topic has been intensively studied in the image domain, classification tasks in the audio domain have received les…
Neural networks are known to be vulnerable to adversarial examples, inputs that have been intentionally perturbed to remain visually similar to the source input, but cause a misclassification. It was recently shown that given a dataset and classifier, there exists so called universal adversarial perturbations, a single…
New method UADs improves transferability of adversarial perturbations.
While deep learning is remarkably successful on perceptual tasks, it was also shown to be vulnerable to adversarial perturbations of the input. These perturbations denote noise added to the input that was generated specifically to fool the system while being quasi-imperceptible for humans. More severely, there even exi…
We study the problem of finding a universal (image-agnostic) perturbation to fool machine learning (ML) classifiers (e.g., neural nets, decision tress) in the hard-label black-box setting. Recent work in adversarial ML in the white-box setting (model parameters are known) has shown that many state-of-the-art image clas…
In this work, we demonstrate the existence of universal adversarial audio perturbations that cause mis-transcription of audio signals by automatic speech recognition (ASR) systems. We propose an algorithm to find a single quasi-imperceptible perturbation, which when added to any arbitrary speech signal, will most likel…
Simple technique turns any adversarial attack into a universal one using few test examples.
GCNNs gain rotation invariance with more training augmentation, making SVD-Universal more effective.
We show that the perturbative invariant of rational homology 3-spheres can be recovered from the LMO invariant for any simple Lie algebra , i.e, the LMO invariant is universal among the perturbative invariants. This universality was conjectured in [25]. Since the perturbative invariants dominate …
New method generates universal adversarial perturbations across different image sources.
We demonstrate the existence of universal adversarial perturbations, which can fool a family of audio classification architectures, for both targeted and untargeted attack scenarios. We propose two methods for finding such perturbations. The first method is based on an iterative, greedy approach that is well-known in c…
DEceit constructs effective universal pixel-restricted perturbations for deep image classifiers.
New method creates universal perturbations to fool neural network interpretations.
The integrality of the Kontsevich integral and perturbative invariants is discussed. We show that the denominator of the degree part of the Kontsevich integral of any knot or link is a divisor of . We also show that the denominator of of the degree part of the universal perturbative invari…
New approach to quantum knot invariants using perturbed Gaussian generating functions.
The universal perturbative invariants of rational homology spheres can be extracted from the Chern-Simons partition function by combining perturbative and nonperturbative results. We spell out the general procedure to compute these invariants, and we work out in detail the case of Seifert spaces. By extending some prev…
New invariant counts graph configurations in 3D manifolds.
We give a complete proof of the fact that a contact structure that is sufficiently close to a Reebless foliation is universally tight.
Deep Convolutional Networks (DCNs) have been shown to be vulnerable to adversarial examples---perturbed inputs specifically designed to produce intentional errors in the learning algorithms at test time. Existing input-agnostic adversarial perturbations exhibit interesting visual patterns that are currently unexplained…
We study the problem of learning classifiers robust to universal adversarial perturbations. While prior work approaches this problem via robust optimization, adversarial training, or input transformation, we instead phrase it as a two-player zero-sum game. In this new formulation, both players simultaneously play the s…
Deep neural networks for video classification, just like image classification networks, may be subjected to adversarial manipulation. The main difference between image classifiers and video classifiers is that the latter usually use temporal information contained within the video. In this work we present a manipulation…
The paper shows instability in Minkowski spacetime for a quantum system.
Study on low-dimensional adversarial perturbations in classification models.
In recent years several adversarial attacks and defenses have been proposed. Often seemingly robust models turn out to be non-robust when more sophisticated attacks are used. One way out of this dilemma are provable robustness guarantees. While provably robust models for specific -perturbation models have been dev…
We present a project of classification of a certain class of bihamiltonian 1+1 PDEs depending on a small parameter. Our aim is to embed the theory of Gromov - Witten invariants of all genera into the theory of integrable systems. The project is focused at describing normal forms of the PDEs and their local bihamiltonia…
Deep Convolutional Networks (DCNs) have been shown to be sensitive to Universal Adversarial Perturbations (UAPs): input-agnostic perturbations that fool a model on large portions of a dataset. These UAPs exhibit interesting visual patterns, but this phenomena is, as yet, poorly understood. Our work shows that visually …
Based on a general threading of the spacetime , we obtain a new and simple splitting of a both the Einstein field equations (EFE) and the conservation laws in . As an application we obtain the splitting of (EFE) in an almost FLRW universe with energy-momentum tensor of a perfect fluid. In particul…
We give a purely topological definition of the perturbative quantum invariants of links and 3-manifolds associated with Chern-Simons field theory. Our definition is as close as possible to one given by Kontsevich. We will also establish some basic properties of these invariants, in particular that they are universally …
New insights into model robustness for random features and NTK models.
This work analyzes how different forms of compressibility affect adversarial robustness in neural networks.
Adversarial attacks can fool algorithmic trading systems.
New high-order universal portfolios outperform standard ones.
New method GSAT improves robustness against structured perturbations.
We give a new and simple proof for the computation of the oriented and the unoriented fold cobordism groups of Morse functions on surfaces. We also compute similar cobordism groups of Morse functions based on simple stable maps of 3-manifolds into the plane. Furthermore, we show that certain cohomology classes associat…
Let a compact connected orientable 4-manifold. We study the space of -structures of fixed fundamental class, as an infinite dimensional principal bundle on the manifold of riemannian metrics on . In order to study perturbations of the metric in Seiberg-Witten equations, we study the transversality of…
Adversarial weight perturbations can inject backdoors into trained neural models.
Recently, deep learning based natural language processing techniques are being extensively used to deal with spam mail, censorship evaluation in social networks, among others. However, there is only a couple of works evaluating the vulnerabilities of such deep neural networks. Here, we go beyond attacks to investigate,…
I sketch what it is supposed to mean to quantize gauge theory, and how this can be made more concrete in perturbation theory and also by starting with a finite-dimensional lattice approximation. Based on real experiments and computer simulations, quantum gauge theory in four dimensions is believed to have a mass gap. T…
New approach makes adversarial examples less suspicious without changing perceptual salience.
The study identifies conditions under which algorithmic stability explains generalization in interpolating learning systems.
We use the twistorial construction of D-instantons in Calabi-Yau compactifications of type II string theory to compute an explicit expression for the metric on the hypermultiplet moduli space affected by these non-perturbative corrections. In this way we obtain an exact quaternion-Kahler metric which is a non-trivial d…
The vulnerability of deep neural networks to adversarial attacks has been widely demonstrated (e.g., adversarial example attacks). Traditional attacks perform unstructured pixel-wise perturbation to fool the classifier. An alternative approach is to have perturbations in the latent space. However, such perturbations ar…