Proposes new convex relaxations for certifying spatial robustness of neural networks.
arXiv research
A locally-built, LLM-digested index of recent arXiv papers in quant finance, geometry/topology, and statistical ML — keyword search served straight from SQLite on this machine.
Trend · papers per month
Despite their tremendous success in a range of domains, deep learning systems are inherently susceptible to two types of manipulations: adversarial inputs -- maliciously crafted samples that deceive target deep neural network (DNN) models, and poisoned models -- adversely forged DNNs that misbehave on pre-defined input…
We study offline data poisoning attacks in contextual bandits, a class of reinforcement learning problems with important applications in online recommendation and adaptive medical treatment, among others. We provide a general attack framework based on convex optimization and show that by slightly manipulating rewards i…
We consider technology-assisted mimicry attacks in the context of automatic speaker verification (ASV). We use ASV itself to select targeted speakers to be attacked by human-based mimicry. We recorded 6 naive mimics for whom we select target celebrities from VoxCeleb1 and VoxCeleb2 corpora (7,365 potential targets) usi…
This paper examines MEV attacks in dynamic AMMs and proposes new protections.
Artificial neural network (ANN) provides superior accuracy for nonlinear alternating current (AC) state estimation (SE) in smart grid over traditional methods. However, research has discovered that ANN could be easily fooled by adversarial examples. In this paper, we initiate a new study of adversarial false data injec…
This research secures deployed sentiment analysis models by identifying and defending against attack vectors.
CAVs reveal latent concept distributions, but are vulnerable to adversarial attacks.
We investigate a family of poisoning attacks against Support Vector Machines (SVM). Such attacks inject specially crafted training data that increases the SVM's test error. Central to the motivation for these attacks is the fact that most learning algorithms assume that their training data comes from a natural or well-…
Bayesian Optimization improves machine learning for detecting network attacks.
secml is a Python library for secure and explainable machine learning.
Adversarial attacks and the development of (deep) neural networks robust against them are currently two widely researched topics. The robustness of Learning Vector Quantization (LVQ) models against adversarial attacks has however not yet been studied to the same extent. We therefore present an extensive evaluation of t…
This work develops secure distributed algorithms for machine learning to protect against data poisoning and network attacks.
Despite the wide use of machine learning in adversarial settings including computer security, recent studies have demonstrated vulnerabilities to evasion attacks---carefully crafted adversarial samples that closely resemble legitimate instances, but cause misclassification. In this paper, we examine the adequacy of the…
We present five methods to the problem of network anomaly detection. These methods cover most of the common techniques in the anomaly detection field, including Statistical Hypothesis Tests (SHT), Support Vector Machines (SVM) and clustering analysis. We evaluate all methods in a simulated network that consists of nomi…
Hyperparameters are critical in machine learning, as different hyperparameters often result in models with significantly different performance. Hyperparameters may be deemed confidential because of their commercial value and the confidentiality of the proprietary algorithms that the learner uses to learn them. In this …
New sparsity attacks degrade DNN efficiency, raising concerns for resource-constrained systems.
Paper improves candlestick classification model's resistance to adversarial attacks.
DeepRobust is a PyTorch library for adversarial attacks and defenses.
Many machine learning models can be attacked with adversarial examples, i.e. inputs close to correctly classified examples that are classified incorrectly. However, most research on adversarial attacks to date is limited to vectorial data, in particular image data. In this contribution, we extend the field by introduci…
Novel defense algorithm improves SVMs against data poisoning attacks.
Recently, deep neural networks have significant progress and successful application in various fields, but they are found vulnerable to attack instances, e.g., adversarial examples. State-of-art attack methods can generate attack images by adding small perturbation to the source image. These attack images can fool the …
Network operators are generally aware of common attack vectors that they defend against. For most networks the vast majority of traffic is legitimate. However new attack vectors are continually designed and attempted by bad actors which bypass detection and go unnoticed due to low volume. One strategy for finding such …
We wish to attack the problems that H.~Anciaux and K.~Panagiotidou posed in [1], for non-degenerate real hypersurfaces in indefinite complex projective space. We will slightly change these authors' point of view, obtaining cleaner equations for the almost contact metric structure. To make the theory meaningful, we cons…
Adversarial attacks can manipulate ML-aided visualizations, tricking analysts.
Active subspace is a model reduction method widely used in the uncertainty quantification community. In this paper, we propose analyzing the internal structure and vulnerability and deep neural networks using active subspace. Firstly, we employ the active subspace to measure the number of "active neurons" at each inter…
Generating and eliminating adversarial examples has been an intriguing topic in the field of deep learning. While previous research verified that adversarial attacks are often fragile and can be defended via image-level processing, it remains unclear how high-level features are perturbed by such attacks. We investigate…
Deep learning models are vulnerable to adversarial attacks, leading to critical errors.
Paper proposes an ensemble of attacks to evaluate adversarial robustness more reliably.
Adversarial audio attacks can be considered as a small perturbation unperceptive to human ears that is intentionally added to the audio signal and causes a machine learning model to make mistakes. This poses a security concern about the safety of machine learning models since the adversarial attacks can fool such model…
This paper defends SVMs against poisoning attacks using DBSCAN and hardness proofs.
Privacy attacks reveal hidden information in network embeddings after node removal.
New method improves black-box attacks using pre-trained models.
Graph embedding leaks sensitive graph properties and subgraphs.
Paper transforms torse-forming vector fields into simpler forms.
The convolutional neural network (CNN) architecture is increasingly being applied to new domains, such as malware detection, where it is able to learn malicious behavior from raw bytes extracted from executables. These architectures reach impressive performance with no feature engineering effort involved, but their rob…
AFD learns features resistant to adversarial attacks.
This paper discusses adversarial attacks on cyber security systems using machine learning.
Machine learning-based IDSs in ICS are vulnerable to adversarial attacks that can bypass them.
Paper introduces attacks to infer GAN training dataset properties.
The paper proves that certain modified conformal vector fields are trivial on compact and non-compact manifolds.
Simple technique turns any adversarial attack into a universal one using few test examples.
The position vector field x is the most elementary and natural geometric object on a Euclidean submanifold . The position vector field plays very important roles in mathematics as well as in physics. Similarly, the tangential component x^T of the position vector field is the most natural vector field tangent to the …
Enhances GNN robustness during inference using Conditional Random Fields.
Conformal vector fields on LCP manifolds are orthogonal and Killing.
For a submanifold M in a Euclidean space, the tangential component x^T of the position vector field x of M is the most natural vector field tangent to the Euclidean submanifold, called the canonical vector field of M. In this article, first we prove that the canonical vector field of every Euclidean submanifold is alwa…
This paper evaluates and compares gradient leakage attacks in federated learning.
Study on vector fields on Lie groups reveals surprising algebraic coincidences.