T-BFA targets and misleads specific DNN inputs to a chosen output.
problem Targeted attack on DNN weight parameters to hijack function.
method Identifies critical weight bits, ranks them by class dependence, and flips them to mislead inputs.
result Successfully misclassifies images from 'Hen' to 'Goose' class with 100% success rate, maintaining 59.35% validation accuracy.
FlipOut prunes neural networks by flipping weights' signs, achieving high sparsity.
problem Redundant weights in neural networks increase training time and resource usage.
method Uses sign flips during training to determine weight saliency for pruning.
result Competitive with existing methods, achieving state-of-the-art performance for high sparsity.
New methods train neural networks without changing weights, achieving similar or higher performance.
problem Training neural networks efficiently with randomly initialized weights.
method Switching connections on and off, flipping weights' signs, minimizing changed connections.
result Achieves similar or higher performance with less computational cost than training all weights.
This paper uses the technology of weighted and regular triangulations to study discrete versions of the Laplacian on piecewise Euclidean manifolds. Regular triangulations are studied in some detail, including flip algorithms. The Laplacian is then studied as an operator on functions of the vertices as a generalized wei…
Study flip graphs for surfaces of infinite type, finding uncountably many connected components.
problem Understanding relationships between triangulations of infinite type surfaces via flips.
method Associate triangulations to flip graphs and study sequences of simultaneous flips.
result Flip graphs for infinite type surfaces have uncountably many connected components.
Finite subgraphs in flip graphs ensure unique surface embeddings.
problem Ensuring unique embeddings of surfaces based on flip graphs.
method Analyzing finite subgraphs within flip graphs of surfaces.
result Injective homomorphisms are uniquely extendable and induced by embeddings.
Study of flip graphs and their automorphism groups for infinite-type surfaces.
problem Understanding automorphism groups of flip graphs for infinite-type surfaces.
method Examined the relationship between mapping class groups and flip graphs for infinite-type surfaces.
result Extended mapping class groups are isomorphic to proper subgroups of automorphism groups of flip graphs.
Study shows flipping a small subset of labels can severely damage machine learning models.
problem Adversarial attacks on distributed machine learning models.
method Formalized label flipping attacks, proposed a greedy algorithm, demonstrated with logistic regression models.
result A budget of only 0.1% of labels at each training step can reduce model accuracy by 6%, and some models can perform worse than random guessing when up to 25% of labels are flipped.
Connected flip graphs for triangulations on hyperbolic surfaces.
problem Connecting triangulations on hyperbolic surfaces via flips.
method Proving connectedness of flip graphs and giving bounds on edge flips.
result Flip graphs of geometric triangulations are connected.
Study of skateboard flips as continuous curves in SO(3) group.
problem Characterize skateboard flip tricks as continuous motions.
method Model flips as curves in SO(3), analyze lifts to S3, derive formulas. result There are only four distinct flip tricks up to continuous deformation.
Proof of existence and uniqueness of weighted Voronoi-Delaunay on polyhedral surfaces.
problem Existence and uniqueness of weighted Voronoi-Delaunay on polyhedral surfaces.
method Construct an isotopic map instead of edge-flipping algorithm, generalizing Dyer et al's method.
result Strict proof of existence and uniqueness of weighted Voronoi-Delaunay on polyhedral surfaces.
Neural networks have been criticized for their lack of easy interpretation, which undermines confidence in their use for important applications. Here, we introduce a novel technique, interpreting a trained neural network by investigating its flip points. A flip point is any point that lies on the boundary between two o…
Flip symmetry on knot diagrams affects Khovanov homology.
problem Understanding the flip map on Khovanov homology.
method Analyzing the behavior of the flip map on unlinks and using it to determine the involution.
result The flip map is the identity map over \(\mathbb{F}_2\), confirming a conjecture.
Novel defense algorithm improves SVMs against data poisoning attacks.
problem Vulnerability of SVMs to targeted training data manipulations like poisoning attacks.
method Developed a weighted SVM using K-LID to de-emphasize suspicious data samples.
result Significant reduction in classification error rates (10% on average) with the proposed defense.
The flip graph and arc complex of a surface are shown to have finite rigidity.
problem Finite rigidity of flip graph and arc complex for surfaces.
method Embedding the flip graph in the arc complex and leveraging finite rigidity of the flip graph.
result Finite rigidity of the flip graph implies finite rigidity of the arc complex.
Efficiently poisons offline RLHF models by flipping preference labels.
problem Vulnerability of offline RLHF models to preference label flipping attacks.
method Developed two attack methods: BAL-A and BMP-A, solving a structured binary sparse approximation problem.
result Demonstrated that flipping one preference label induces a parameter-independent shift in the DPO gradient, enabling structured binary sparse approximation.
New examples show flip distance and polyhedron triangulation numbers differ, with ratio close to 3/2.
problem Understanding the relationship between flip distance and polyhedron triangulation numbers.
method Provided examples to demonstrate the difference between flip distance and polyhedron triangulation numbers.
result Ratio of flip distance to polyhedron triangulation numbers can be arbitrarily close to 3/2.
We prove that every injective simplicial map F(S)→F(S′) between flip graphs is induced by a subsurface inclusion S→S′, except in finitely many cases. This extends a result of Korkmaz--Papadopoulos which asserts that every automorphism of the flip graph of a surface without boundary is ind…
We prove that for a given flat surface with conical singularities, any pair of geometric triangulations can be connected by a chain of flips.
We introduce a notion of cross-flips: local moves that transform a balanced (i.e., properly (d+1)-colored) triangulation of a combinatorial d-manifold into another balanced triangulation. These moves form a natural analog of bistellar flips (also known as Pachner moves). Specifically, we establish the following the…
This paper is about the geometry of flip-graphs associated to triangulations of surfaces. More precisely, we consider a topological surface with a privileged boundary curve and study the spaces of its triangulations with n vertices on the boundary curve. The surfaces we consider topologically fill this boundary curve s…
Geodesics count exponentially between triangulations of surfaces with enough topology.
problem Counting geodesics in triangulations of surfaces.
method Analyzing the flip-graph of triangulations and their geodesics.
result The number of geodesics grows exponentially for surfaces with enough topology.
Identifies minimal training subset to flip a prediction.
problem Flipping predictions in machine learning models.
method Extended influence function for relabeling minimal subset.
result Relabeling fewer than 2% of training points can flip a prediction.
In order to model volatile real-world network behavior, we analyze phase-flipping dynamical scale-free network in which nodes and links fail and recover. We investigate how stochasticity in a parameter governing the recovery process affects phase-flipping dynamics, and find the probability that no more than q% of nodes…
Let Σ be a compact surface. We prove that the set of surface cubications modulo flips, up to isotopy, is in one-to-one correspondence with Z/2Z⊕H1(Σ,Z/2Z).
We use flip points to explain and audit deep learning models, revealing decision boundaries and improving model performance.
problem Lack of interpretability in deep learning models hinders their use in important applications.
method Flip points are used to analyze decision boundaries of deep learning models with continuous output scores.
result Flip points reveal the least changes in input that would alter a model's classification, enabling better understanding and improvement of model behavior.
Study finds flipped classrooms improve student self-concept, enjoyment, but not exam scores.
problem Evaluating the impact of flipped classrooms on higher education outcomes.
method Double/debiased machine learning (DML) approach to analyze student data.
result No significant positive effects on exam scores, passing rates, or knowledge retention.
Study quasisymmetric maps on hyperbolic plane boundaries.
problem Identify quasisymmetric maps corresponding to specific lambda lengths and flip distances.
method Analyze maps on Farey triangulation, relate to shearing coordinates and flip distance.
result Identify quasisymmetric maps corresponding to pinched lambda lengths and flip distances.
We study flip-graphs of triangulations on topological surfaces where distance is measured by counting the number of necessary flip operations between two triangulations. We focus on surfaces of positive genus g with a single boundary curve and n marked points on this curve; we consider triangulations up to homeomor…
Using existing technology, we prove a Masur-Minsky style distance formula for flip- graph distance between two triangulations, expressed as a sum of the distances of the projections of these triangulations into arc graphs of the suitable subsurfaces of S.
We investigate a type of distance between triangulations on finite type surfaces where one moves between triangulations by performing simultaneous flips. We consider triangulations up to homeomorphism and our main results are upper bounds on distance between triangulations that only depend on the topology of the surfac…
Deep Partition Aggregation defends against poisoning attacks with provable certificates.
problem Adversarial poisoning attacks corrupt classifier test-time behavior.
method Deep Partition Aggregation (DPA) is an ensemble method using hash partitions and base models trained on these partitions.
result DPA can certify >= 50% of test images against over 500 poison image insertions on MNIST, and nine insertions on CIFAR-10.
The paper solves pentagon equations using triangulations and edge transformations.
problem Solving pentagon equations with triangulations and edge transformations.
method General data and transformation rule method applied to triangulations.
result Recovery of initial data after transformations.
New method makes machine learning models robust to label flipping attacks.
problem Machine learning models are vulnerable to label flipping attacks.
method Randomized smoothing over arbitrary functions to build certifiably robust classifiers.
result Linear classifiers are robust to label flipping attacks with deterministic bounds.
Study evaluates data augmentation methods for prostate cancer detection in MRI.
problem Limited data for prostate cancer detection in MRI.
method Static application of five augmentation techniques (rotation, flip, crop, translation) to MRI dataset.
result Rotation method improved 2D slice-based AUC to 0.85.
Graph convolutional networks (GCNs) are vulnerable to perturbations of the graph structure that are either random, or, adversarially designed. The perturbed links modify the graph neighborhoods, which critically affects the performance of GCNs in semi-supervised learning (SSL) tasks. Aiming at robustifying GCNs conditi…
We explore several families of flip-graphs, all related to polygons or punctured polygons. In particular, we consider the topological flip-graphs of once-punctured polygons which, in turn, contain all possible geometric flip-graphs of polygons with a marked point as embedded sub-graphs. Our main focus is on the geometr…
Unified routing and arbitrage with concave continuation.
problem Combining routing and arbitrage in financial markets.
method Extending AMM trade functions to negative inputs via concave continuation.
result Unified approach unifies routing and arbitrage.
Many machine learning systems rely on data collected in the wild from untrusted sources, exposing the learning algorithms to data poisoning. Attackers can inject malicious data in the training dataset to subvert the learning process, compromising the performance of the algorithm producing errors in a targeted or an ind…
The study examines flip-graphs of non-orientable surfaces and their diameters.
problem Understanding the structure and diameter of flip-graphs of non-orientable surfaces.
method Constructing triangulations of non-orientable surfaces, quotienting by homeomorphisms, and analyzing the resulting flip-graphs.
result Bounds on the diameter of flip-graphs of non-orientable surfaces, with specific growth rates for Möbius strips.
Improves bit error tolerance in RRAM-based BNNs without overfitting.
problem Bit errors in RRAM-based BNNs reduce accuracy and overfit to training error rates.
method Proposes straight-through gradient approximation and a novel regularizer.
result Improves BNNs' robustness to bit errors without overfitting.
The paper explores orthogeodesics on hyperbolic surfaces and their integer traces.
problem Computing and understanding orthogeodesics on hyperbolic surfaces.
method Recursive method for computing orthogeodesic traces and combinatorial proof of Basmajian's identity.
result Existence of surfaces where orthogeodesic traces are integers.
This paper explores using nonlinear control for robust logarithmic growth in coin flipping games.
problem Tackles the use of nonlinear control in recursive betting games with logarithmic growth.
method Formulates a robust nonlinear control problem for a simple coin flipping game, considering a probability range for the coin's bias.
result Provides a closed-form description of the optimal robust nonlinear controller, which outperforms linear controllers.
Paper proposes NeuroAttack to undermine SNNs security through bit-flips.
problem Security and reliability issues in SNNs.
method Cross-layer attack exploiting low-level reliability issues via adversarial input noise.
result Serious integrity threat to SNNs and DNNs.
Double pants decompositions were introduced in our paper "Double pants decompositions of 2-surfaces" (Mosc. Math. J. 11 (2011), no. 2, 231-258, arXiv:1005.0073), together with a flip-twist groupoid acting on these decompositions. It was shown that flip-twist groupoid acts transitively on a certain topological class of …
Adaptive dropout and regularization are shown to be dual in linear networks.
problem Sparsifying deep neural networks.
method Examining dropout in the linear case, revealing a duality with regularization.
result Adaptive dropout methods lead to sparse solutions with effective penalties similar to classical sparse optimization penalties.
Any two triangulations of a closed surface with the same number of vertices can be transformed into each other by a sequence of regular flips, provided the number of vertices exceeds a number N depending on the surface. Examples show that in general N is bigger than the minimal number of vertices of a triangulation. Th…
Over the past two decades, several consistent procedures have been designed to infer causal conclusions from observational data. We prove that if the true causal network might be an arbitrary, linear Gaussian network or a discrete Bayes network, then every unambiguous causal conclusion produced by a consistent method f…