11 papers
Feature-Space Bayesian Adversarial Learning Improved Malware Detector Robustness
Bao Gia Doan, Shuiqiao Yang, Paul Montague +6
We present a new algorithm to train a robust malware detector. Modern malware detectors rely on machine learning algorithms. Now, the adversarial objective is to devise alterations…
Room for Error: Large-Scale Simulation of Over-the-Air Acoustic Attacks
Andrew C. Cullen, Neil G. Marchant, Jiani Xie +4
While voice control is rapidly becoming a ubiquitous vector of human-AI communication, the risks facing these systems remain poorly understood. This is, in part, a product of the d…
What Was That Again? Certified Robustness for Automatic Speech Recognition
Andrew C. Cullen, Neil G. Marchant, Jiani Xie +2
Automatic Speech Recognition systems are notoriously both sensitive to adversarial and benign perturbations. While this has been repeatedly demonstrated using reference datasets, d…
Halt Fast! Early Stopping for Certified Robustness
Andrew C. Cullen, Paul Montague, Benjamin I. P. Rubinstein
Randomized Smoothing (RS) provides rigorous robustness guarantees for neural networks without architectural constraints, yet its adoption is limited by extreme computational costs.…
Fox in the Henhouse: Supply-Chain Backdoor Attacks Against Reinforcement Learning
Shijie Liu, Andrew C. Cullen, Paul Montague +2
The current state-of-the-art backdoor attacks against Reinforcement Learning (RL) rely upon unrealistically permissive access models, that assume the attacker can read (or even wri…
Hearing the Unspoken: Language Model Priors for Acoustic Adversarial Attacks
Jiani Xie, Andrew C. Cullen, Paul Montague +1
Automatic Speech Recognition (ASR) systems operating in real-time settings must process acoustic input under strict temporal constraints, where transcription decisions are inherent…