Intriguing properties of neural networks
arXiv:1312.6199
Abstract
Deep neural networks are highly expressive models that have recently achieved state of the art performance on speech and visual recognition tasks. While their expressiveness is the reason they succeed, it also causes them to learn uninterpretable solutions that could have counter-intuitive properties. In this paper we report two such properties. First, we find that there is no distinction between individual high level units and random linear combinations of high level units, according to various methods of unit analysis. It suggests that it is the space, rather than the individual units, that contains of the semantic information in the high layers of neural networks. Second, we find that deep neural networks learn input-output mappings that are fairly discontinuous to a significant extend. We can cause the network to misclassify an image by applying a certain imperceptible perturbation, which is found by maximizing the network's prediction error. In addition, the specific nature of these perturbations is not a random artifact of learning: the same perturbation can cause a different network, that was trained on a different subset of the dataset, to misclassify the same input.
References in corpus (1)
Cited by in corpus (699)
- Explaining and Harnessing Adversarial Examples
- Deep learning with convolutional neural networks for EEG decoding and visualization
- A Review of Uncertainty Quantification in Deep Learning: Techniques, Applications and Challenges
- Diffusion Models Beat GANs on Image Synthesis
- Shortcut Learning in Deep Neural Networks
- Feature Squeezing: Detecting Adversarial Examples in Deep Neural Networks
- ZOO: Zeroth Order Optimization based Black-box Attacks to Deep Neural Networks without Training Substitute Models
- Understanding Neural Networks Through Deep Visualization
- Explaining Deep Neural Networks and Beyond: A Review of Methods and Applications
- Explaining NonLinear Classification Decisions with Deep Taylor Decomposition
- End-to-end Optimized Image Compression
- A trans-disciplinary review of deep learning research for water resources scientists
- Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples
- Recent Advances in Open Set Recognition: A Survey
- Deep Neural Networks and Tabular Data: A Survey
- BadNets: Identifying Vulnerabilities in the Machine Learning Model Supply Chain
- Image Quality Assessment: Unifying Structure and Texture Similarity
- Robust Real-World Image Super-Resolution against Adversarial Attacks
- Theoretically Principled Trade-off between Robustness and Accuracy
- Hands-on Bayesian Neural Networks -- a Tutorial for Deep Learning Users
- Applications of Deep Learning and Reinforcement Learning to Biological Data
- On instabilities of deep learning in image reconstruction - Does AI come at a cost?
- Blended Diffusion for Text-driven Editing of Natural Images
- Understanding Deep Convolutional Networks
- Synthesizing Robust Adversarial Examples
- Understanding Adversarial Attacks on Deep Learning Based Medical Image Analysis Systems
- Visualizing Deep Convolutional Neural Networks Using Natural Pre-Images
- Understanding Neural Networks through Representation Erasure
- Adversarial Personalized Ranking for Recommendation
- Artificial neural networks for neuroscientists: A primer
- Deep Text Classification Can be Fooled
- Understanding the Role of Individual Units in a Deep Neural Network
- Understanding Adversarial Training: Increasing Local Stability of Neural Nets through Robust Optimization
- Optimization Problems for Machine Learning: A Survey
- Generalizing Across Domains via Cross-Gradient Training
- Black-box Adversarial Attacks with Limited Queries and Information
- Layer-Wise Relevance Propagation for Explaining Deep Neural Network Decisions in MRI-Based Alzheimer's Disease Classification
- Adversarial Attack and Defense on Graph Data: A Survey
- DLFuzz: Differential Fuzzing Testing of Deep Learning Systems
- A Survey of End-to-End Driving: Architectures and Training Methods
- CNN Based Adversarial Embedding with Minimum Alteration for Image Steganography
- AdvHat: Real-world adversarial attack on ArcFace Face ID system
- Pathologies of Neural Models Make Interpretations Difficult
- X-ModalNet: A Semi-Supervised Deep Cross-Modal Network for Classification of Remote Sensing Data
- Februus: Input Purification Defense Against Trojan Attacks on Deep Neural Network Systems
- Neural Trojans
- Adversarial Examples: Opportunities and Challenges
- Uncertainty Quantification in Machine Learning for Engineering Design and Health Prognostics: A Tutorial
- Invisible for both Camera and LiDAR: Security of Multi-Sensor Fusion based Perception in Autonomous Driving Under Physical-World Attacks
- Multiplicative Normalizing Flows for Variational Bayesian Neural Networks
- A Note on the Inception Score
- Hardware and Software Optimizations for Accelerating Deep Neural Networks: Survey of Current Trends, Challenges, and the Road Ahead
- Learning to Compare Image Patches via Convolutional Neural Networks
- Federated Learning for Healthcare Domain - Pipeline, Applications and Challenges
- Stochastic Activation Pruning for Robust Adversarial Defense
- Measuring the tendency of CNNs to Learn Surface Statistical Regularities
- Evaluating and Improving Adversarial Robustness of Machine Learning-Based Network Intrusion Detectors
- Adversarial Example Detection for DNN Models: A Review and Experimental Comparison
- Local Model Poisoning Attacks to Byzantine-Robust Federated Learning
- Robust Audio Adversarial Example for a Physical Attack
- Ten Years of Generative Adversarial Nets (GANs): A survey of the state-of-the-art
- Towards Crafting Text Adversarial Samples
- Adversarial Attack on Graph Structured Data
- Quantum noise protects quantum classifiers against adversaries
- Copycat CNN: Stealing Knowledge by Persuading Confession with Random Non-Labeled Data
- Adversarial Sample Detection for Deep Neural Network through Model Mutation Testing
- SpaText: Spatio-Textual Representation for Controllable Image Generation
- AdvPC: Transferable Adversarial Perturbations on 3D Point Clouds
- Solving Inverse Problems With Deep Neural Networks -- Robustness Included?
- Smart Home Personal Assistants: A Security and Privacy Review
- Convolutional neural networks: a magic bullet for gravitational-wave detection?
- Examining the Impact of Blur on Recognition by Convolutional Networks
- Adversarial Attacks on Deep Neural Networks for Time Series Classification
- A new approach to observational cosmology using the scattering transform
- PrivacyNet: Semi-Adversarial Networks for Multi-attribute Face Privacy
- advertorch v0.1: An Adversarial Robustness Toolbox based on PyTorch
- MagNet and "Efficient Defenses Against Adversarial Attacks" are Not Robust to Adversarial Examples
- Ensemble Kalman Inversion: A Derivative-Free Technique For Machine Learning Tasks
- Training robust neural networks using Lipschitz bounds
- Trustworthy AI and Robotics and the Implications for the AEC Industry: A Systematic Literature Review and Future Potentials
- How Deep Learning Sees the World: A Survey on Adversarial Attacks & Defenses
- Benchmarking Robustness in Object Detection: Autonomous Driving when Winter is Coming
- Adversarial EXEmples: A Survey and Experimental Evaluation of Practical Attacks on Machine Learning for Windows Malware Detection
- Decision-Based Adversarial Attacks: Reliable Attacks Against Black-Box Machine Learning Models
- Can stable and accurate neural networks be computed? -- On the barriers of deep learning and Smale's 18th problem
- Adversarial Attack Vulnerability of Medical Image Analysis Systems: Unexplored Factors
- Adversarial examples from computational constraints
- Accountability in an Algorithmic Society: Relationality, Responsibility, and Robustness in Machine Learning
- Delving into adversarial attacks on deep policies
- Poison Ink: Robust and Invisible Backdoor Attack
- Learning to Protect Communications with Adversarial Neural Cryptography
- Towards Proving the Adversarial Robustness of Deep Neural Networks
- Solving Electrical Impedance Tomography with Deep Learning
- RobustBench: a standardized adversarial robustness benchmark
- Manipulating Machine Learning: Poisoning Attacks and Countermeasures for Regression Learning
- Guessing Smart: Biased Sampling for Efficient Black-Box Adversarial Attacks
- Interpreting and Improving Adversarial Robustness of Deep Neural Networks with Neuron Sensitivity
- Are All Layers Created Equal?
- Going in circles is the way forward: the role of recurrence in visual inference
- Fast Feature Fool: A data independent approach to universal adversarial perturbations
- Fixed Point Strategies in Data Science
- Machine learning with neural networks
- Benchmarking Adversarial Patch Against Aerial Detection
- Adv-BNN: Improved Adversarial Defense through Robust Bayesian Neural Network
- Deep Convolutional Networks as shallow Gaussian Processes
- Universal Adversarial Examples in Remote Sensing: Methodology and Benchmark
- Bayesian deep learning for error estimation in the analysis of anomalous diffusion
- Verification for Machine Learning, Autonomy, and Neural Networks Survey
- UPSET and ANGRI : Breaking High Performance Image Classifiers
- Adversarial Attacks Against Deep Generative Models on Data: A Survey
- Analyzing the Robustness of Nearest Neighbors to Adversarial Examples
- It's Morphin' Time! Combating Linguistic Discrimination with Inflectional Perturbations
- Universal adversarial perturbations
- Traffic Sign Detection under Challenging Conditions: A Deeper Look Into Performance Variations and Spectral Characteristics
- Unsolved Problems in ML Safety
- Towards Interpretable Deep Neural Networks by Leveraging Adversarial Examples
- Assuring the Machine Learning Lifecycle: Desiderata, Methods, and Challenges
- Revisiting the Importance of Individual Units in CNNs via Ablation
- Towards Adversarial Malware Detection: Lessons Learned from PDF-based Attacks
- Optimization and Abstraction: A Synergistic Approach for Analyzing Neural Network Robustness
- AI Security for Geoscience and Remote Sensing: Challenges and Future Trends
- Learning with Learned Loss Function: Speech Enhancement with Quality-Net to Improve Perceptual Evaluation of Speech Quality
- Real Time Image Saliency for Black Box Classifiers
- Adversarial Samples on Android Malware Detection Systems for IoT Systems
- Diving Deep into Sentiment: Understanding Fine-tuned CNNs for Visual Sentiment Prediction
- Scattering Networks for Hybrid Representation Learning
- Towards quantum enhanced adversarial robustness in machine learning
- Graph Neural Networks with Continual Learning for Fake News Detection from Social Media
- PsyPhy: A Psychophysics Driven Evaluation Framework for Visual Recognition
- Robust Adversarial Perturbation on Deep Proposal-based Models
- Analyzing Human-Human Interactions: A Survey
- Semantic Robustness of Models of Source Code
- Gotta Catch 'Em All: Using Honeypots to Catch Adversarial Attacks on Neural Networks
- Deep Convolutional Neural Networks in the Face of Caricature: Identity and Image Revealed
- Adversarial Robustness May Be at Odds With Simplicity
- A Counter-Forensic Method for CNN-Based Camera Model Identification
- PRIMA: General and Precise Neural Network Certification via Scalable Convex Hull Approximations
- OpenAttack: An Open-source Textual Adversarial Attack Toolkit
- Facial Attributes: Accuracy and Adversarial Robustness
- Reachable Set Computation and Safety Verification for Neural Networks with ReLU Activations
- Unrestricted Adversarial Examples
- Malware Makeover: Breaking ML-based Static Analysis by Modifying Executable Bytes
- Sensitivity Analysis of Deep Neural Networks
- Do Explanations Reflect Decisions? A Machine-centric Strategy to Quantify the Performance of Explainability Algorithms
- Seq2Sick: Evaluating the Robustness of Sequence-to-Sequence Models with Adversarial Examples
- Synesthesia: Detecting Screen Content via Remote Acoustic Side Channels
- Promises and pitfalls of deep neural networks in neuroimaging-based psychiatric research
- Fast Facial Landmark Detection and Applications: A Survey
- FDA3 : Federated Defense Against Adversarial Attacks for Cloud-Based IIoT Applications
- 3D-VField: Adversarial Augmentation of Point Clouds for Domain Generalization in 3D Object Detection
- Hardware Trojan Attacks on Neural Networks
- How Can We Be So Dense? The Benefits of Using Highly Sparse Representations
- Partial success in closing the gap between human and machine vision
- How deep is deep enough? -- Quantifying class separability in the hidden layers of deep neural networks
- Predicting the hosts of prokaryotic viruses using GCN-based semi-supervised learning
- Can Adversarial Weight Perturbations Inject Neural Backdoors?
- Improving the Transferability of Adversarial Examples with Resized-Diverse-Inputs, Diversity-Ensemble and Region Fitting
- Maximal Jacobian-based Saliency Map Attack
- Deep Neural Networks as 0-1 Mixed Integer Linear Programs: A Feasibility Study
- DeepSafe: A Data-driven Approach for Checking Adversarial Robustness in Neural Networks
- A Survey of Adversarial Learning on Graphs
- Towards Evaluating the Robustness of Deep Diagnostic Models by Adversarial Attack
- Analysis and Optimization of Convolutional Neural Network Architectures
- Machine Learning in NextG Networks via Generative Adversarial Networks
- Characterizing and evaluating adversarial examples for Offline Handwritten Signature Verification
- Detection of Face Recognition Adversarial Attacks
- Are Accuracy and Robustness Correlated?
- Discretization based Solutions for Secure Machine Learning against Adversarial Attacks
- A Theoretical Explanation for Perplexing Behaviors of Backpropagation-based Visualizations
- Pseudo-Bag Mixup Augmentation for Multiple Instance Learning-Based Whole Slide Image Classification
- Adversarial Robustness of Deep Neural Networks: A Survey from a Formal Verification Perspective
- A Survey of Game Theoretic Approaches for Adversarial Machine Learning in Cybersecurity Tasks
- Gotta CAPTCHA 'Em All: A Survey of Twenty years of the Human-or-Computer Dilemma
- Training individually fair ML models with Sensitive Subspace Robustness
- Detecting Adversarial Examples by Input Transformations, Defense Perturbations, and Voting
- Boosting Adversarial Attacks with Momentum
- Adversarial Explanations for Understanding Image Classification Decisions and Improved Neural Network Robustness
- Inspect, Understand, Overcome: A Survey of Practical Methods for AI Safety
- ModelDiff: Testing-Based DNN Similarity Comparison for Model Reuse Detection
- Noise Flooding for Detecting Audio Adversarial Examples Against Automatic Speech Recognition
- CBA: Contextual Background Attack against Optical Aerial Detection in the Physical World
- Robust in Practice: Adversarial Attacks on Quantum Machine Learning
- A Survey on State-of-the-art Deep Learning Applications and Challenges
- Fault Sneaking Attack: a Stealthy Framework for Misleading Deep Neural Networks
- Neural networks in pulsed dipolar spectroscopy: a practical guide
- VisualBackProp: efficient visualization of CNNs
- Threatening Patch Attacks on Object Detection in Optical Remote Sensing Images
- Adversarial Attacks on Time-Series Intrusion Detection for Industrial Control Systems
- Defending against Adversarial Images using Basis Functions Transformations
- Towards Robust Neural Image Compression: Adversarial Attack and Model Finetuning
- Challenges in Building Intelligent Open-domain Dialog Systems
- Detection of Gravitational Waves Using Bayesian Neural Networks
- Adversarial Attacks and Defenses for Semantic Communication in Vehicular Metaverses
- VC Classes are Adversarially Robustly Learnable, but Only Improperly
- Defending Against Universal Attacks Through Selective Feature Regeneration
- Backdoors in Neural Models of Source Code
- Adaptative Perturbation Patterns: Realistic Adversarial Learning for Robust Intrusion Detection
- Evading Defenses to Transferable Adversarial Examples by Translation-Invariant Attacks
- Why is the Mahalanobis Distance Effective for Anomaly Detection?
- Semantic-Aware Adversarial Training for Reliable Deep Hashing Retrieval
- Deep Weighted Averaging Classifiers
- Weighted-Sampling Audio Adversarial Example Attack
- A deep architecture for unified aesthetic prediction
- Discovering interpretable elastoplasticity models via the neural polynomial method enabled symbolic regressions
- Indirect Adversarial Attacks via Poisoning Neighbors for Graph Convolutional Networks
- Adversarial Patch Attacks on Monocular Depth Estimation Networks
- Biomedical Image Reconstruction: From the Foundations to Deep Neural Networks
- Interpretable neural networks based on continuous-valued logic and multicriteria decision operators
- On Adversarial Examples and Stealth Attacks in Artificial Intelligence Systems
- The Vulnerability of Semantic Segmentation Networks to Adversarial Attacks in Autonomous Driving: Enhancing Extensive Environment Sensing
- Topological Persistence Machine of Phase Transitions
- On the Geometry of Adversarial Examples
- Biometric Backdoors: A Poisoning Attack Against Unsupervised Template Updating
- Unsupervised learning of object semantic parts from internal states of CNNs by population encoding
- Adversarially Robust Neural Architectures
- The worst of both worlds: A comparative analysis of errors in learning from data in psychology and machine learning
- Re-evaluating Evaluation
- Witches' Brew: Industrial Scale Data Poisoning via Gradient Matching
- Securing Deep Spiking Neural Networks against Adversarial Attacks through Inherent Structural Parameters
- Generation & Evaluation of Adversarial Examples for Malware Obfuscation
- PatchUp: A Feature-Space Block-Level Regularization Technique for Convolutional Neural Networks
- Exploiting Cultural Biases via Homoglyphs in Text-to-Image Synthesis
- PAD: Towards Principled Adversarial Malware Detection Against Evasion Attacks
- Quality Resilient Deep Neural Networks
- Hybrid Channel Based Pedestrian Detection
- Pixle: a fast and effective black-box attack based on rearranging pixels
- Markov Chain Monte Carlo-Based Machine Unlearning: Unlearning What Needs to be Forgotten
- Adversarial Attacks for Optical Flow-Based Action Recognition Classifiers
- Protecting Voice Controlled Systems Using Sound Source Identification Based on Acoustic Cues
- One-Trial Correction of Legacy AI Systems and Stochastic Separation Theorems
- Security for Machine Learning-based Systems: Attacks and Challenges during Training and Inference
- Quantifying Perceptual Distortion of Adversarial Examples
- Improving the Transferability of Adversarial Examples with Arbitrary Style Transfer
- White Box Methods for Explanations of Convolutional Neural Networks in Image Classification Tasks
- A Master Key Backdoor for Universal Impersonation Attack against DNN-based Face Verification
- Ethical Considerations and Statistical Analysis of Industry Involvement in Machine Learning Research
- Adversarial Multi-task Learning Enhanced Physics-informed Neural Networks for Solving Partial Differential Equations
- Attention Meets Perturbations: Robust and Interpretable Attention with Adversarial Training
- Learning Disentangled Behaviour Patterns for Wearable-based Human Activity Recognition
- When and How to Fool Explainable Models (and Humans) with Adversarial Examples
- Using Videos to Evaluate Image Model Robustness
- Software Testing for Machine Learning
- ReachNN: Reachability Analysis of Neural-Network Controlled Systems
- Interpretability Beyond Classification Output: Semantic Bottleneck Networks
- The Future of Misinformation Detection: New Perspectives and Trends
- Adversarial Robustness via Fisher-Rao Regularization
- Increasing the Confidence of Deep Neural Networks by Coverage Analysis
- To Drop or Not to Drop: Robustness, Consistency and Differential Privacy Properties of Dropout
- Learning Security Classifiers with Verified Global Robustness Properties
- Assaying Out-Of-Distribution Generalization in Transfer Learning
- Exactly Computing the Local Lipschitz Constant of ReLU Networks
- Deep reinforcement learning in World-Earth system models to discover sustainable management strategies
- Interpolated Adversarial Training: Achieving Robust Neural Networks without Sacrificing Too Much Accuracy
- Gradient-free activation maximization for identifying effective stimuli
- BadCM: Invisible Backdoor Attack Against Cross-Modal Learning
- Interpreting CNNs via Decision Trees
- Task dependent Deep LDA pruning of neural networks
- Query-Efficient Black-box Adversarial Examples (superceded)
- Adversarial Attacks on Machine Learning Systems for High-Frequency Trading
- Two Sides of the Same Coin: White-box and Black-box Attacks for Transfer Learning
- TrISec: Training Data-Unaware Imperceptible Security Attacks on Deep Neural Networks
- Investigating the significance of adversarial attacks and their relation to interpretability for radar-based human activity recognition systems
- Multimodal neural networks better explain multivoxel patterns in the hippocampus
- Towards Frequency-Based Explanation for Robust CNN
- Sensitivity analysis of Wasserstein distributionally robust optimization problems
- Predify: Augmenting deep neural networks with brain-inspired predictive coding dynamics
- Perfect density models cannot guarantee anomaly detection
- Why Does Little Robustness Help? A Further Step Towards Understanding Adversarial Transferability
- A Unified Gradient Regularization Family for Adversarial Examples
- ECGadv: Generating Adversarial Electrocardiogram to Misguide Arrhythmia Classification System
- Uncertainty Injection: A Deep Learning Method for Robust Optimization
- Interpretable Convolutional Neural Networks
- The SP theory of intelligence: distinctive features and advantages
- RobustECD: Enhancement of Network Structure for Robust Community Detection
- Provably scale-covariant continuous hierarchical networks based on scale-normalized differential expressions coupled in cascade
- The Emergence of Canalization and Evolvability in an Open-Ended, Interactive Evolutionary System
- Improving the Adversarial Robustness of NLP Models by Information Bottleneck
- Towards Visual Distortion in Black-Box Attacks
- Black-box adversarial attacks using Evolution Strategies
- Constrained Learning with Non-Convex Losses
- Fooling a Real Car with Adversarial Traffic Signs
- Towards Imperceptible and Robust Adversarial Example Attacks against Neural Networks
- Learnable Bernoulli Dropout for Bayesian Deep Learning
- When NAS Meets Robustness: In Search of Robust Architectures against Adversarial Attacks
- Backdoor Attacks for Remote Sensing Data with Wavelet Transform
- Scale-invariant scale-channel networks: Deep networks that generalise to previously unseen scales
- Gradient Masking Causes CLEVER to Overestimate Adversarial Perturbation Size
- Improving Pre-trained Language Model Fine-tuning with Noise Stability Regularization
- Improving Back-Propagation by Adding an Adversarial Gradient
- On the Adversarial Robustness of Quantized Neural Networks
- A backdoor attack against LSTM-based text classification systems
- Provable Certificates for Adversarial Examples: Fitting a Ball in the Union of Polytopes
- Toward Scalable Verification for Safety-Critical Deep Networks
- What You See is Not What the Network Infers: Detecting Adversarial Examples Based on Semantic Contradiction
- Plug & Play Directed Evolution of Proteins with Gradient-based Discrete MCMC
- Distribution Density, Tails, and Outliers in Machine Learning: Metrics and Applications
- Image and Model Transformation with Secret Key for Vision Transformer
- White Paper Machine Learning in Certified Systems
- Understanding and Mitigating Exploding Inverses in Invertible Neural Networks
- SAT: Improving Adversarial Training via Curriculum-Based Loss Smoothing
- Evaluating the visualization of what a Deep Neural Network has learned
- Classifier-agnostic saliency map extraction
- PeerNets: Exploiting Peer Wisdom Against Adversarial Attacks
- Online Deterministic Annealing for Classification and Clustering
- Interoceptive robustness through environment-mediated morphological development
- Knowledge Cross-Distillation for Membership Privacy
- InfoAT: Improving Adversarial Training Using the Information Bottleneck Principle
- Towards Assessing the Synthetic-to-Measured Adversarial Vulnerability of SAR ATR
- How Robust are Discriminatively Trained Zero-Shot Learning Models?
- Designing Perceptual Puzzles by Differentiating Probabilistic Programs
- Towards Understanding Adversarial Examples Systematically: Exploring Data Size, Task and Model Factors
- Unifying Adversarial Training Algorithms with Flexible Deep Data Gradient Regularization
- Improving adversarial robustness of deep neural networks by using semantic information
- Lipschitz Properties for Deep Convolutional Networks
- Image Deconvolution with Deep Image and Kernel Priors
- Adversarial Defense by Latent Style Transformations
- Wasserstein Smoothing: Certified Robustness against Wasserstein Adversarial Attacks
- nuScenes Knowledge Graph -- A comprehensive semantic representation of traffic scenes for trajectory prediction
- ConvNets and ImageNet Beyond Accuracy: Understanding Mistakes and Uncovering Biases
- Towards Analyzing Semantic Robustness of Deep Neural Networks
- Imperceptible Adversarial Examples by Spatial Chroma-Shift
- Detect & Reject for Transferability of Black-box Adversarial Attacks Against Network Intrusion Detection Systems
- SPAA: Stealthy Projector-based Adversarial Attacks on Deep Image Classifiers
- Adaptive Semantic Segmentation with a Strategic Curriculum of Proxy Labels
- Metamorphic Detection of Adversarial Examples in Deep Learning Models With Affine Transformations
- Defending From Physically-Realizable Adversarial Attacks Through Internal Over-Activation Analysis
- Adversarial Attack for Uncertainty Estimation: Identifying Critical Regions in Neural Networks
- Single-Node Attacks for Fooling Graph Neural Networks
- Does CLIP Know My Face?
- Adversarial Attacks for Tabular Data: Application to Fraud Detection and Imbalanced Data
- A Spectral View of Adversarially Robust Features
- Adversarial Margin Maximization Networks
- Density of States Estimation for Out-of-Distribution Detection
- Adversarial Detection and Correction by Matching Prediction Distributions
- Annealing Optimization for Progressive Learning with Stochastic Approximation
- Verification of Recurrent Neural Networks Through Rule Extraction
- ScaleCert: Scalable Certified Defense against Adversarial Patches with Sparse Superficial Layers
- Two Souls in an Adversarial Image: Towards Universal Adversarial Example Detection using Multi-view Inconsistency
- Web-Scale Training for Face Identification
- AdvFAS: A robust face anti-spoofing framework against adversarial examples
- Security of Deep Learning based Lane Keeping System under Physical-World Adversarial Attack
- Detecting Backdoors in Neural Networks Using Novel Feature-Based Anomaly Detection
- Sneaky Spikes: Uncovering Stealthy Backdoor Attacks in Spiking Neural Networks with Neuromorphic Data
- Physical Adversarial Attacks on Deep Neural Networks for Traffic Sign Recognition: A Feasibility Study
- Large Margin Deep Networks for Classification
- Prototype-based Neural Network Layers: Incorporating Vector Quantization
- A Low-Cost Attack against the hCaptcha System
- Attacking Graph-based Classification via Manipulating the Graph Structure
- Certified Robustness to Word Substitution Ranking Attack for Neural Ranking Models
- Multitask Learning Strengthens Adversarial Robustness
- Interpretability is a Kind of Safety: An Interpreter-based Ensemble for Adversary Defense
- Visualization Of Class Activation Maps To Explain AI Classification Of Network Packet Captures
- AdvSPADE: Realistic Unrestricted Attacks for Semantic Segmentation
- PatchAttack: A Black-box Texture-based Attack with Reinforcement Learning
- How adversarial attacks can disrupt seemingly stable accurate classifiers
- GreedyFool: Distortion-Aware Sparse Adversarial Attack
- Adversarial Image Color Transformations in Explicit Color Filter Space
- The gap between theory and practice in function approximation with deep neural networks
- The Convergence of Machine Learning and Communications
- Practical Attacks on Machine Learning: A Case Study on Adversarial Windows Malware
- Toward Zero-shot Character Recognition: A Gold Standard Dataset with Radical-level Annotations
- FooBaR: Fault Fooling Backdoor Attack on Neural Network Training
- The Feasibility and Inevitability of Stealth Attacks
- Backdoor Attacks on Crowd Counting
- A Robust Adversarial Network-Based End-to-End Communications System With Strong Generalization Ability Against Adversarial Attacks
- Defence against adversarial attacks using classical and quantum-enhanced Boltzmann machines
- Bridging the Performance Gap between FGSM and PGD Adversarial Training
- Generating Image Adversarial Examples by Embedding Digital Watermarks
- Subverting Fair Image Search with Generative Adversarial Perturbations
- A Thorough Comparison Study on Adversarial Attacks and Defenses for Common Thorax Disease Classification in Chest X-rays
- Identifying Audio Adversarial Examples via Anomalous Pattern Detection
- ATHENA: A Framework based on Diverse Weak Defenses for Building Adversarial Defense
- Appending Adversarial Frames for Universal Video Attack
- Perturbation Analysis of Gradient-based Adversarial Attacks
- Case Study: Verifying the Safety of an Autonomous Racing Car with a Neural Network Controller
- A Critical Reflection on the Use of Toxicity Detection Algorithms in Proactive Content Moderation Systems
- Detecting Adversarial Examples in Convolutional Neural Networks
- secml: A Python Library for Secure and Explainable Machine Learning
- Manifold Regularization for Locally Stable Deep Neural Networks
- EREBA: Black-box Energy Testing of Adaptive Neural Networks
- Spatio-Temporal Perturbations for Video Attribution
- Overparameterized Linear Regression under Adversarial Attacks
- Incorporating Unlabeled Data into Distributionally Robust Learning
- Defense against adversarial attacks on deep convolutional neural networks through nonlocal denoising
- Generating Hard Examples for Pixel-wise Classification
- Eight challenges in developing theory of intelligence
- Morphology of three-body quantum states from machine learning
- A Survey of Behavior Learning Applications in Robotics -- State of the Art and Perspectives
- HDXplore: Automated Blackbox Testing of Brain-Inspired Hyperdimensional Computing
- Convergence and Margin of Adversarial Training on Separable Data
- Scalable Verification of GNN-based Job Schedulers
- ImpNet: Imperceptible and blackbox-undetectable backdoors in compiled neural networks
- Building Robust Deep Neural Networks for Road Sign Detection
- Geometric robustness of deep networks: analysis and improvement
- Beyond the Self: Using Grounded Affordances to Interpret and Describe Others' Actions
- Lifecycle Management of Trustworthy AI Models in 6G Networks: The REASON Approach
- Towards Effective and Efficient Adversarial Defense with Diffusion Models for Robust Visual Tracking
- Learning Online Visual Invariances for Novel Objects via Supervised and Self-Supervised Training
- Towards Efficiently Evaluating the Robustness of Deep Neural Networks in IoT Systems: A GAN-based Method
- Active Speaker Detection as a Multi-Objective Optimization with Uncertainty-based Multimodal Fusion
- Limited-Memory Matrix Adaptation for Large Scale Black-box Optimization
- Jacobian Regularization for Mitigating Universal Adversarial Perturbations
- Block Switching: A Stochastic Approach for Deep Learning Security
- Robustness of Deep Neural Networks for Micro-Doppler Radar Classification
- Adversarial Attacks against Neural Networks in Audio Domain: Exploiting Principal Components
- Bayesian Inference with Certifiable Adversarial Robustness
- Security and Machine Learning in the Real World
- Rare event failure test case generation in Learning-Enabled-Controllers
- Bit Error Robustness for Energy-Efficient DNN Accelerators
- Optimal Transport as a Defense Against Adversarial Attacks
- Adversarial Attacks on Monocular Pose Estimation
- Using Undervolting as an On-Device Defense Against Adversarial Machine Learning Attacks
- Adversarial Visual Robustness by Causal Intervention
- Improved OOD Generalization via Adversarial Training and Pre-training
- A Visual Analytics Framework for Adversarial Text Generation
- On the Detection of Adaptive Adversarial Attacks in Speaker Verification Systems
- Adversarial Machine Learning Phases of Matter
- Decision-based Universal Adversarial Attack
- Certifiably-Robust Federated Adversarial Learning via Randomized Smoothing
- Deep Neural Networks for Choice Analysis: A Statistical Learning Theory Perspective
- Laplacian Networks: Bounding Indicator Function Smoothness for Neural Network Robustness
- Towards Interpretable Face Recognition
- Adversarial Attacks in a Multi-view Setting: An Empirical Study of the Adversarial Patches Inter-view Transferability
- Consistent Counterfactuals for Deep Models
- Trust Region Based Adversarial Attack on Neural Networks
- Mitigating Evasion Attacks to Deep Neural Networks via Region-based Classification
- How Wrong Am I? - Studying Adversarial Examples and their Impact on Uncertainty in Gaussian Process Machine Learning Models
- PointCloud Saliency Maps
- GAP++: Learning to generate target-conditioned adversarial examples
- CNNs Avoid Curse of Dimensionality by Learning on Patches
- An Efficient Adversarial Attack for Tree Ensembles
- Adversarial Robustness through the Lens of Convolutional Filters
- Towards Resistant Audio Adversarial Examples
- ToyArchitecture: Unsupervised Learning of Interpretable Models of the World
- Adversarial Exposure Attack on Diabetic Retinopathy Imagery Grading
- Generating Universal Adversarial Perturbations for Quantum Classifiers
- Relationship between manifold smoothness and adversarial vulnerability in deep learning with local errors
- On the Importance of Consistency in Training Deep Neural Networks
- Adversarial Artifact Detection in EEG-Based Brain-Computer Interfaces
- Deep Roto-Translation Scattering for Object Classification
- Robust Proxy: Improving Adversarial Robustness by Robust Proxy Learning
- Adversarial Image Generation by Spatial Transformation in Perceptual Colorspaces
- A Methodology to Identify Cognition Gaps in Visual Recognition Applications Based on Convolutional Neural Networks
- Do Vision Models Encode Object-Level Semantic Relatedness? A Cognitive Psychology-Inspired Benchmark
- Improved Detection of Adversarial Images Using Deep Neural Networks
- LMD: A Learnable Mask Network to Detect Adversarial Examples for Speaker Verification
- BASAR:Black-box Attack on Skeletal Action Recognition
- From Hardware Fingerprint to Access Token: Enhancing the Authentication on IoT Devices
- From Heatmaps to Structural Explanations of Image Classifiers
- Exploring Adversarial Examples: Patterns of One-Pixel Attacks
- RoVISQ: Reduction of Video Service Quality via Adversarial Attacks on Deep Learning-based Video Compression
- Adversarial Attack and Defense in Deep Ranking
- Catch-Up Mix: Catch-Up Class for Struggling Filters in CNN
- SOAR: Second-Order Adversarial Regularization
- Using Mode Connectivity for Loss Landscape Analysis
- Maximally Invariant Data Perturbation as Explanation
- HoneyModels: Machine Learning Honeypots
- Recursive Inference for Variational Autoencoders
- Towards Lifelong Self-Supervision: A Deep Learning Direction for Robotics
- Offset-free setpoint tracking using neural network controllers
- Security Consideration For Deep Learning-Based Image Forensics
- On the Robustness of Human Pose Estimation
- Engineering problems in machine learning systems
- Adversarial Reinforcement Learning under Partial Observability in Autonomous Computer Network Defence
- Fingerprinting Encrypted Voice Traffic on Smart Speakers with Deep Learning
- Black-box Adversarial Attacks on Network-wide Multi-step Traffic State Prediction Models
- Deep Learning in Robotics: A Review of Recent Research
- Measuring and Understanding Sensory Representations within Deep Networks Using a Numerical Optimization Framework
- Data-Dependent Randomized Smoothing
- Generating Out of Distribution Adversarial Attack using Latent Space Poisoning
- Using a GAN to Generate Adversarial Examples to Facial Image Recognition
- Physically Consistent Multiple-Step Data-Driven Predictions Using Physics-based Filters
- Pay Attention to the Robustness of Chinese Minority Language Models! Syllable-level Textual Adversarial Attack on Tibetan Script
- Gray-box Adversarial Testing for Control Systems with Machine Learning Component
- Explaining Neural Networks Semantically and Quantitatively
- Provable Robustness Against a Union of Adversarial Attacks
- Gradient Shaping: Enhancing Backdoor Attack Against Reverse Engineering
- Blind Adversarial Network Perturbations
- Resilience of Autonomous Vehicle Object Category Detection to Universal Adversarial Perturbations
- Stress Test Evaluation of Biomedical Word Embeddings
- Neural Networks with Structural Resistance to Adversarial Attacks
- Improving Robustness and Generality of NLP Models Using Disentangled Representations
- Subset Scanning Over Neural Network Activations
- Stochastic Substitute Training: A Gray-box Approach to Craft Adversarial Examples Against Gradient Obfuscation Defenses
- Adversarial joint attacks on legged robots
- Noisy Computations during Inference: Harmful or Helpful?
- Deep Neural Networks for Choice Analysis: Extracting Complete Economic Information for Interpretation
- On Instabilities of Conventional Multi-Coil MRI Reconstruction to Small Adverserial Perturbations
- Towards an Awareness of Time Series Anomaly Detection Models' Adversarial Vulnerability
- 3D Adversarial Attacks Beyond Point Cloud
- Rearchitecting Classification Frameworks For Increased Robustness
- Data Curation with Deep Learning [Vision]
- Is Face Recognition Safe from Realizable Attacks?
- Intermediate Level Adversarial Attack for Enhanced Transferability
- Adversarial Robustness Guarantees for Gaussian Processes
- On the relationship between class selectivity, dimensionality, and robustness
- Physical machine learning outperforms "human learning" in Quantum Chemistry
- Towards Audit Requirements for AI-based Systems in Mobility Applications
- Sequential Randomized Smoothing for Adversarially Robust Speech Recognition
- MagDR: Mask-guided Detection and Reconstruction for Defending Deepfakes
- On the Current and Emerging Challenges of Developing Fair and Ethical AI Solutions in Financial Services
- Efficient Project Gradient Descent for Ensemble Adversarial Attack
- AutoGAN: Robust Classifier Against Adversarial Attacks
- Scalable Attack on Graph Data by Injecting Vicious Nodes
- Stochastic Combinatorial Ensembles for Defending Against Adversarial Examples
- 3D Point Cloud Completion with Geometric-Aware Adversarial Augmentation
- Careful What You Wish For: on the Extraction of Adversarially Trained Models
- Explainable and Trustworthy Traffic Sign Detection for Safe Autonomous Driving: An Inductive Logic Programming Approach
- Alternating Direction Method of Multipliers for Quantization
- Synthesis-guided Adversarial Scenario Generation for Gray-box Feedback Control Systems with Sensing Imperfections
- Preserving Semantics in Textual Adversarial Attacks
- Pelta: Shielding Transformers to Mitigate Evasion Attacks in Federated Learning
- RamBoAttack: A Robust Query Efficient Deep Neural Network Decision Exploit
- Benford's law: what does it say on adversarial images?
- kk2018 at SemEval-2020 Task 9: Adversarial Training for Code-Mixing Sentiment Classification
- The Domain Shift Problem of Medical Image Segmentation and Vendor-Adaptation by Unet-GAN
- A Data Augmentation-based Defense Method Against Adversarial Attacks in Neural Networks
- mFI-PSO: A Flexible and Effective Method in Adversarial Image Generation for Deep Neural Networks
- Robust Neural Machine Translation with Joint Textual and Phonetic Embedding
- Adversarial Attacks on Classifiers for Eye-based User Modelling
- Bayesian Reasoning with Trained Neural Networks
- Amplification trojan network: Attack deep neural networks by amplifying their inherent weakness
- Rethinking the Artificial Neural Networks: A Mesh of Subnets with a Central Mechanism for Storing and Predicting the Data
- Understanding Catastrophic Overfitting in Adversarial Training
- Adversarial Robustness in Deep Learning: Attacks on Fragile Neurons
- Variation Enhanced Attacks Against RRAM-based Neuromorphic Computing System
- Reducing Adversarially Robust Learning to Non-Robust PAC Learning
- Are Adversarial Examples Created Equal? A Learnable Weighted Minimax Risk for Robustness under Non-uniform Attacks
- A Self-supervised Approach for Adversarial Robustness
- Regularity Normalization: Neuroscience-Inspired Unsupervised Attention across Neural Network Layers
- Omni: Automated Ensemble with Unexpected Models against Adversarial Evasion Attack
- A Singular Value Perspective on Model Robustness
- Learning Automata Based Q-learning for Content Placement in Cooperative Caching
- Modular Learning Component Attacks: Today's Reality, Tomorrow's Challenge
- Analysis and Applications of Class-wise Robustness in Adversarial Training
- Low-Interception Waveform: To Prevent the Recognition of Spectrum Waveform Modulation via Adversarial Examples
- Reducing the Amortization Gap in Variational Autoencoders: A Bayesian Random Function Approach
- Contextual Classification Using Self-Supervised Auxiliary Models for Deep Neural Networks
- Resilient Linear Classification: An Approach to Deal with Attacks on Training Data
- A4 : Evading Learning-based Adblockers
- Backpropagation for Implicit Spectral Densities
- A Reflection on Learning from Data: Epistemology Issues and Limitations
- Modularity Matters: Learning Invariant Relational Reasoning Tasks
- Preventing Clean Label Poisoning using Gaussian Mixture Loss
- Natural Perturbed Training for General Robustness of Neural Network Classifiers
- Learning Based on CC1 and CC4 Neural Networks
- Toward Few-step Adversarial Training from a Frequency Perspective
- A Geometrical Approach to Evaluate the Adversarial Robustness of Deep Neural Networks
- Seeing eye-to-eye? A comparison of object recognition performance in humans and deep convolutional neural networks under image manipulation
- Adversarial Feature Desensitization
- Towards User Guided Actionable Recourse
- Time-varying Gaussian Process Bandit Optimization with Non-constant Evaluation Time
- Pretraining Image Encoders without Reconstruction via Feature Prediction Loss
- Iterative Window Mean Filter: Thwarting Diffusion-based Adversarial Purification
- Detecting Adversarial Patches with Class Conditional Reconstruction Networks
- The Tensor Track VII: From Quantum Gravity to Artificial Intelligence
- FedServing: A Federated Prediction Serving Framework Based on Incentive Mechanism
- Coverage-Guaranteed Prediction Sets for Out-of-Distribution Data
- To Make Yourself Invisible with Adversarial Semantic Contours
- On the randomised stability constant for inverse problems
- Lifted Regression/Reconstruction Networks
- Live Trojan Attacks on Deep Neural Networks
- Seeing in the dark with recurrent convolutional neural networks
- Regional Image Perturbation Reduces Norms of Adversarial Examples While Maintaining Model-to-model Transferability
- CAAD 2018: Iterative Ensemble Adversarial Attack
- Attacking Optical Flow
- On Lipschitz Bounds of General Convolutional Neural Networks
- MEAT: Median-Ensemble Adversarial Training for Improving Robustness and Generalization
- Patch augmentation: Towards efficient decision boundaries for neural networks
- Classification Uncertainty of Deep Neural Networks Based on Gradient Information
- Clarifying Myths About the Relationship Between Shape Bias, Accuracy, and Robustness
- Class Subset Selection for Transfer Learning using Submodularity
- Bidirectional Inference Networks: A Class of Deep Bayesian Networks for Health Profiling
- torchosr -- a PyTorch extension package for Open Set Recognition models evaluation in Python
- Model Interpretability and Rationale Extraction by Input Mask Optimization
- Robust Stability Analysis of Positive Lure System with Neural Network Feedback
- Feedback Techniques in Computer-Based Simulation Training: A Survey
- Adequacy of the Gradient-Descent Method for Classifier Evasion Attacks
- Generalization Error Analysis of Neural networks with Gradient Based Regularization
- Using Synthetic Corruptions to Measure Robustness to Natural Distribution Shifts
- Can Perceptual Guidance Lead to Semantically Explainable Adversarial Perturbations?
- A Robust Classification-autoencoder to Defend Outliers and Adversaries
- Adversarial Robustness on Image Classification with -means
- Robustifying automatic speech recognition by extracting slowly varying features
- Interpretabilité des modèles : état des lieux des méthodes et application à l'assurance
- Search Space of Adversarial Perturbations against Image Filters
- Conditional Adversarial Camera Model Anonymization
- A Deep Value-network Based Approach for Multi-Driver Order Dispatching
- Black-box Adversarial Sample Generation Based on Differential Evolution
- ReLUSyn: Synthesizing Stealthy Attacks for Deep Neural Network Based Cyber-Physical Systems
- MixDefense: A Defense-in-Depth Framework for Adversarial Example Detection Based on Statistical and Semantic Analysis
- Improving Fast Minimum-Norm Attacks with Hyperparameter Optimization
- Technical Report: When Does Machine Learning FAIL? Generalized Transferability for Evasion and Poisoning Attacks
- Neural Belief Reasoner
- The art of defense: letting networks fool the attacker
- What do CNN neurons learn: Visualization & Clustering
- Versatile Verification of Tree Ensembles
- Online Black-Box Confidence Estimation of Deep Neural Networks
- Analytical bounds on the local Lipschitz constants of affine-ReLU functions
- Visual Explanation for Identification of the Brain Bases for Dyslexia on fMRI Data
- Minimizing Perceived Image Quality Loss Through Adversarial Attack Scoping
- Efficient Proximal Mapping of the 1-path-norm of Shallow Networks
- The Vulnerability of the Neural Networks Against Adversarial Examples in Deep Learning Algorithms
- Sampling Prediction-Matching Examples in Neural Networks: A Probabilistic Programming Approach
- Real World Robustness from Systematic Noise
- Heat and Blur: An Effective and Fast Defense Against Adversarial Examples
- Enhance Diffusion to Improve Robust Generalization
- Cross-domain Cross-architecture Black-box Attacks on Fine-tuned Models with Transferred Evolutionary Strategies
- Exploring the Deep Feature Space of a Cell Classification Neural Network
- Natural Adversarial Objects
- A statistical framework for efficient out of distribution detection in deep neural networks
- The best defense is a good offense: Countering black box attacks by predicting slightly wrong labels
- Blind Adversarial Pruning: Balance Accuracy, Efficiency and Robustness
- When Side-Channel Attacks Break the Black-Box Property of Embedded Artificial Intelligence
- Addressing Weak Decision Boundaries in Image Classification by Leveraging Web Search and Generative Models
- Robust and Information-theoretically Safe Bias Classifier against Adversarial Attacks
- Robust Deep Learning as Optimal Control: Insights and Convergence Guarantees
- Being Single Has Benefits. Instance Poisoning to Deceive Malware Classifiers
- Rethinking Empirical Evaluation of Adversarial Robustness Using First-Order Attack Methods
- Access Control with Encrypted Feature Maps for Object Detection Models
- Towards Safety Verification of Direct Perception Neural Networks
- Adversarial Edit Attacks for Tree Data
- Deep Likelihood Network for Image Restoration with Multiple Degradation Levels
- Mapper Based Classifier
- Streaming Networks: Enable A Robust Classification of Noise-Corrupted Images
- Who is Responsible for Adversarial Defense?
- Can audio-visual integration strengthen robustness under multimodal attacks?
- Towards Evaluating and Training Verifiably Robust Neural Networks
- Fast Approximate Spectral Normalization for Robust Deep Neural Networks
- Bio-inspired Robustness: A Review
- Comparing Reinforcement Learning and Human Learning using the Game of Hidden Rules
- A Useful Taxonomy for Adversarial Robustness of Neural Networks
- Regularized Ensembles and Transferability in Adversarial Learning
- A cryptographic approach to black box adversarial machine learning
- Adversarial Jamming for a More Effective Constellation Attack
- Robust Single-step Adversarial Training with Regularizer
- Improved Algorithms for White-Box Adversarial Streams
- Defenses Against Multi-Sticker Physical Domain Attacks on Classifiers
- Simpler Certified Radius Maximization by Propagating Covariances
- An Efficient Pre-processing Method to Eliminate Adversarial Effects
- Beyond Categorical Label Representations for Image Classification
- Decoder-free Robustness Disentanglement without (Additional) Supervision
- Towards Leveraging the Information of Gradients in Optimization-based Adversarial Attack
- On Configurable Defense against Adversarial Example Attacks
- Understanding Robustness in Teacher-Student Setting: A New Perspective
- Comments on Sejnowski's "The unreasonable effectiveness of deep learning in artificial intelligence" [arXiv:2002.04806]
- Modelling Identity Rules with Neural Networks
- advPattern: Physical-World Attacks on Deep Person Re-Identification via Adversarially Transformable Patterns
- Adversarially Robust and Explainable Model Compression with On-Device Personalization for Text Classification
- Towards Robust Neural Networks with Lipschitz Continuity
- Boosting the Robustness Verification of DNN by Identifying the Achilles's Heel
- A note on hyperparameters in black-box adversarial examples
- Lethean Attack: An Online Data Poisoning Technique
- On educating machines
- Robust Deep Neural Networks Inspired by Fuzzy Logic
- Synthetic Data Generation for Economists
- Understanding Misclassifications by Attributes
- Warp: a method for neural network interpretability applied to gene expression profiles
- Perception Matters: Exploring Imperceptible and Transferable Anti-forensics for GAN-generated Fake Face Imagery Detection
- TEAM: An Taylor Expansion-Based Method for Generating Adversarial Examples
- Are L2 adversarial examples intrinsically different?
- Confidence Preservation Property in Knowledge Distillation Abstractions
- Leaky ReLUs That Differ in Forward and Backward Pass Facilitate Activation Maximization in Deep Neural Networks
- Latent Cognizance: What Machine Really Learns
- Calibrated Adversarial Training
- Architectural Resilience to Foreground-and-Background Adversarial Noise
- Universal Stego Post-processing for Enhancing Image Steganography
- Exploring Adversarial Examples for Efficient Active Learning in Machine Learning Classifiers
- Adversarially Robust Frame Sampling with Bounded Irregularities
- Understanding Convolutional Neural Networks with A Mathematical Model
- Recognition Awareness: An Application of Latent Cognizance to Open-Set Recognition
- Semantic Network Interpretation
- Adversarial Detection by Approximation of Ensemble Boundary
- Spatiotemporal Attacks for Embodied Agents
- Leave-one-out Unfairness
- Intriguing Properties of Input-dependent Randomized Smoothing
- Minimum sharpness: Scale-invariant parameter-robustness of neural networks
- Delving into the pixels of adversarial samples
- On Inductive Biases for Machine Learning in Data Constrained Settings
- A neural network model of perception and reasoning
- Adversarial Attacks on Deep Models for Financial Transaction Records
- Towards Explaining Adversarial Examples Phenomenon in Artificial Neural Networks
- Amicable Aid: Perturbing Images to Improve Classification Performance
- Low-Cost Transfer Learning of Face Tasks
- Boosting Black-Box Adversarial Attacks with Meta Learning
- Towards Optimal Randomized Strategies in Adversarial Example Game
- Explainability-Aware One Point Attack for Point Cloud Neural Networks
- Robust Neural Networks inspired by Strong Stability Preserving Runge-Kutta methods
- Efficient and Transferable Adversarial Examples from Bayesian Neural Networks
- Local Linearity and Double Descent in Catastrophic Overfitting
- Wiggling Weights to Improve the Robustness of Classifiers
- Formal Verification of Long Short-Term Memory based Audio Classifiers: A Star based Approach
- State-Reification Networks: Improving Generalization by Modeling the Distribution of Hidden Representations
- CNN-based Steganalysis and Parametric Adversarial Embedding: a Game-Theoretic Framework
- Training Efficiency and Robustness in Deep Learning
- Counterfactual Explanations via Latent Space Projection and Interpolation
- Combining Different V1 Brain Model Variants to Improve Robustness to Image Corruptions in CNNs
- And/or trade-off in artificial neurons: impact on adversarial robustness
- CodNN -- Robust Neural Networks From Coded Classification