33 citations · 71 across the 9 of their papers we have counts for
15 papers
K-SAM: Sharpness-Aware Minimization at the Speed of SGD
Renkun Ni, Ping-yeh Chiang, Jonas Geiping +3
Sharpness-Aware Minimization (SAM) has recently emerged as a robust technique for improving the accuracy of deep neural networks. However, SAM incurs a high computational cost in p…
Thinking Two Moves Ahead: Anticipating Other Users Improves Backdoor Attacks in Federated Learning
Yuxin Wen, Jonas Geiping, Liam Fowl +4
Federated learning is particularly susceptible to model poisoning and backdoor attacks because individual users have direct control over the training data and model updates. At the…
A Simple Strategy to Provable Invariance via Orbit Mapping
Kanchana Vaishnavi Gandikota, Jonas Geiping, Zorah Lähner +2
Many applications require robustness, or ideally invariance, of neural networks to certain transformations of input data. Most commonly, this requirement is addressed by training d…
Poisons that are learned faster are more effective
Pedro Sandoval-Segura, Vasu Singla, Liam Fowl +4
Imperceptible poisoning attacks on entire datasets have recently been touted as methods for protecting data privacy. However, among a number of defenses preventing the practical us…
Adversarial Examples Make Strong Poisons
Liam Fowl, Micah Goldblum, Ping-yeh Chiang +3
The adversarial machine learning literature is largely partitioned into evasion attacks on testing data and poisoning attacks on training data. In this work, we show that adversari…
Training or Architecture? How to Incorporate Invariance in Neural Networks
Kanchana Vaishnavi Gandikota, Jonas Geiping, Zorah Lähner +2
Many applications require the robustness, or ideally the invariance, of a neural network to certain transformations of input data. Most commonly, this requirement is addressed by e…