Zum Hauptinhalt springen

Showing 1–9 of 9 results for author: Co, K T

Searching in archive cs. Search in all archives.
.
  1. arXiv:2204.08726  [pdf, other

    cs.LG cs.CR cs.CV

    Jacobian Ensembles Improve Robustness Trade-offs to Adversarial Attacks

    Authors: Kenneth T. Co, David Martinez-Rego, Zhongyuan Hau, Emil C. Lupu

    Abstract: Deep neural networks have become an integral part of our software infrastructure and are being deployed in many widely-used and safety-critical applications. However, their integration into many systems also brings with it the vulnerability to test time attacks in the form of Universal Adversarial Perturbations (UAPs). UAPs are a class of perturbations that when applied to any input causes model m… ▽ More

    Submitted 19 April, 2022; originally announced April 2022.

  2. arXiv:2105.07334  [pdf, other

    cs.LG cs.AI cs.CR cs.CV

    Real-time Detection of Practical Universal Adversarial Perturbations

    Authors: Kenneth T. Co, Luis Muñoz-González, Leslie Kanthan, Emil C. Lupu

    Abstract: Universal Adversarial Perturbations (UAPs) are a prominent class of adversarial examples that exploit the systemic vulnerabilities and enable physically realizable and robust attacks against Deep Neural Networks (DNNs). UAPs generalize across many different inputs; this leads to realistic and effective attacks that can be applied at scale. In this paper we propose HyperNeuron, an efficient and sca… ▽ More

    Submitted 22 May, 2021; v1 submitted 15 May, 2021; originally announced May 2021.

  3. arXiv:2104.10459  [pdf, ps, other

    cs.LG cs.AI cs.CR cs.CV

    Jacobian Regularization for Mitigating Universal Adversarial Perturbations

    Authors: Kenneth T. Co, David Martinez Rego, Emil C. Lupu

    Abstract: Universal Adversarial Perturbations (UAPs) are input perturbations that can fool a neural network on large sets of data. They are a class of attacks that represents a significant threat as they facilitate realistic, practical, and low-cost attacks on neural networks. In this work, we derive upper bounds for the effectiveness of UAPs based on norms of data-dependent Jacobians. We empirically verify… ▽ More

    Submitted 12 September, 2021; v1 submitted 21 April, 2021; originally announced April 2021.

    Comments: In Proceedings of the 30th International Conference on Artificial Neural Networks (ICANN 2021), related code available at: https://github.com/kenny-co/sgd-uap-torch

  4. arXiv:2102.03722  [pdf, other

    cs.CV cs.CR cs.LG

    Object Removal Attacks on LiDAR-based 3D Object Detectors

    Authors: Zhongyuan Hau, Kenneth T. Co, Soteris Demetriou, Emil C. Lupu

    Abstract: LiDARs play a critical role in Autonomous Vehicles' (AVs) perception and their safe operations. Recent works have demonstrated that it is possible to spoof LiDAR return signals to elicit fake objects. In this work we demonstrate how the same physical capabilities can be used to mount a new, even more dangerous class of attacks, namely Object Removal Attacks (ORAs). ORAs aim to force 3D object dete… ▽ More

    Submitted 7 February, 2021; originally announced February 2021.

    Comments: Accepted to AutoSec at NDSS 2021

  5. arXiv:2012.06024  [pdf, other

    cs.LG cs.AI cs.CR

    Robustness and Transferability of Universal Attacks on Compressed Models

    Authors: Alberto G. Matachana, Kenneth T. Co, Luis Muñoz-González, David Martinez, Emil C. Lupu

    Abstract: Neural network compression methods like pruning and quantization are very effective at efficiently deploying Deep Neural Networks (DNNs) on edge devices. However, DNNs remain vulnerable to adversarial examples-inconspicuous inputs that are specifically designed to fool these models. In particular, Universal Adversarial Perturbations (UAPs), are a powerful class of adversarial attacks which create… ▽ More

    Submitted 10 December, 2020; originally announced December 2020.

    Comments: Accepted to AAAI 2021 Workshop: Towards Robust, Secure and Efficient Machine Learning

  6. Universal Adversarial Robustness of Texture and Shape-Biased Models

    Authors: Kenneth T. Co, Luis Muñoz-González, Leslie Kanthan, Ben Glocker, Emil C. Lupu

    Abstract: Increasing shape-bias in deep neural networks has been shown to improve robustness to common corruptions and noise. In this paper we analyze the adversarial robustness of texture and shape-biased models to Universal Adversarial Perturbations (UAPs). We use UAPs to evaluate the robustness of DNN models with varying degrees of shape-based training. We find that shape-biased models do not markedly im… ▽ More

    Submitted 30 August, 2021; v1 submitted 23 November, 2019; originally announced November 2019.

    Comments: In Proceedings of the 28th IEEE International Conference on Image Processing (ICIP 2021), code available at: https://github.com/kenny-co/sgd-uap-torch

  7. arXiv:1909.05125  [pdf, other

    stat.ML cs.DC cs.LG

    Byzantine-Robust Federated Machine Learning through Adaptive Model Averaging

    Authors: Luis Muñoz-González, Kenneth T. Co, Emil C. Lupu

    Abstract: Federated learning enables training collaborative machine learning models at scale with many participants whilst preserving the privacy of their datasets. Standard federated learning techniques are vulnerable to Byzantine failures, biased local datasets, and poisoning attacks. In this paper we introduce Adaptive Federated Averaging, a novel algorithm for robust federated learning that is designed… ▽ More

    Submitted 11 September, 2019; originally announced September 2019.

  8. arXiv:1906.03455  [pdf, other

    cs.LG cs.CR stat.ML

    Sensitivity of Deep Convolutional Networks to Gabor Noise

    Authors: Kenneth T. Co, Luis Muñoz-González, Emil C. Lupu

    Abstract: Deep Convolutional Networks (DCNs) have been shown to be sensitive to Universal Adversarial Perturbations (UAPs): input-agnostic perturbations that fool a model on large portions of a dataset. These UAPs exhibit interesting visual patterns, but this phenomena is, as yet, poorly understood. Our work shows that visually similar procedural noise patterns also act as UAPs. In particular, we demonstrat… ▽ More

    Submitted 10 June, 2019; v1 submitted 8 June, 2019; originally announced June 2019.

    Comments: Accepted to ICML 2019 Workshop on Identifying and Understanding Deep Learning Phenomena

  9. Procedural Noise Adversarial Examples for Black-Box Attacks on Deep Convolutional Networks

    Authors: Kenneth T. Co, Luis Muñoz-González, Sixte de Maupeou, Emil C. Lupu

    Abstract: Deep Convolutional Networks (DCNs) have been shown to be vulnerable to adversarial examples---perturbed inputs specifically designed to produce intentional errors in the learning algorithms at test time. Existing input-agnostic adversarial perturbations exhibit interesting visual patterns that are currently unexplained. In this paper, we introduce a structured approach for generating Universal Adv… ▽ More

    Submitted 23 November, 2019; v1 submitted 30 September, 2018; originally announced October 2018.

    Comments: 16 pages, 10 figures. In Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security (CCS '19)