Skip to main content

Showing 1–6 of 6 results for author: Vaishnavi, P

.
  1. arXiv:2210.14283  [pdf, other

    cs.LG cs.CR cs.CV

    Accelerating Certified Robustness Training via Knowledge Transfer

    Authors: Pratik Vaishnavi, Kevin Eykholt, Amir Rahmati

    Abstract: Training deep neural network classifiers that are certifiably robust against adversarial attacks is critical to ensuring the security and reliability of AI-controlled systems. Although numerous state-of-the-art certified training methods have been developed, they are computationally expensive and scale poorly with respect to both dataset and network complexity. Widespread usage of certified traini… ▽ More

    Submitted 25 October, 2022; originally announced October 2022.

    Comments: NeurIPS '22 Camera Ready version (with appendix)

  2. arXiv:2210.12952  [pdf, other

    cs.LG cs.AI cs.CR

    Ares: A System-Oriented Wargame Framework for Adversarial ML

    Authors: Farhan Ahmed, Pratik Vaishnavi, Kevin Eykholt, Amir Rahmati

    Abstract: Since the discovery of adversarial attacks against machine learning models nearly a decade ago, research on adversarial machine learning has rapidly evolved into an eternal war between defenders, who seek to increase the robustness of ML models against adversarial attacks, and adversaries, who seek to develop better attacks capable of weakening or defeating these defenses. This domain, however, ha… ▽ More

    Submitted 24 October, 2022; originally announced October 2022.

    Comments: Presented at the DLS Workshop at S&P 2022

  3. arXiv:2202.09994  [pdf, other

    cs.LG cs.CR cs.CV

    Transferring Adversarial Robustness Through Robust Representation Matching

    Authors: Pratik Vaishnavi, Kevin Eykholt, Amir Rahmati

    Abstract: With the widespread use of machine learning, concerns over its security and reliability have become prevalent. As such, many have developed defenses to harden neural networks against adversarial examples, imperceptibly perturbed inputs that are reliably misclassified. Adversarial training in which adversarial examples are generated and used during training is one of the few known defenses able to… ▽ More

    Submitted 5 May, 2022; v1 submitted 21 February, 2022; originally announced February 2022.

    Comments: To appear at USENIX Security '22. Updated version with artifact evaluation badges and appendix

  4. arXiv:1911.11946  [pdf, other

    cs.CV cs.CR cs.LG

    Can Attention Masks Improve Adversarial Robustness?

    Authors: Pratik Vaishnavi, Tianji Cong, Kevin Eykholt, Atul Prakash, Amir Rahmati

    Abstract: Deep Neural Networks (DNNs) are known to be susceptible to adversarial examples. Adversarial examples are maliciously crafted inputs that are designed to fool a model, but appear normal to human beings. Recent work has shown that pixel discretization can be used to make classifiers for MNIST highly robust to adversarial examples. However, pixel discretization fails to provide significant protectio… ▽ More

    Submitted 21 December, 2019; v1 submitted 26 November, 2019; originally announced November 2019.

    Comments: Version presented at AAAI-20 workshop on Engineering Dependable and Secure Machine Learning Systems (EDSMLS)

  5. arXiv:1909.05921  [pdf, other

    cs.CV cs.LG

    Towards Model-Agnostic Adversarial Defenses using Adversarially Trained Autoencoders

    Authors: Pratik Vaishnavi, Kevin Eykholt, Atul Prakash, Amir Rahmati

    Abstract: Adversarial machine learning is a well-studied field of research where an adversary causes predictable errors in a machine learning algorithm through precise manipulation of the input. Numerous techniques have been proposed to harden machine learning algorithms and mitigate the effect of adversarial attacks. Of these techniques, adversarial training, which augments the training data with adversari… ▽ More

    Submitted 29 March, 2020; v1 submitted 12 September, 2019; originally announced September 2019.

  6. arXiv:1905.10904  [pdf, other

    cs.LG stat.ML

    Robust Classification using Robust Feature Augmentation

    Authors: Kevin Eykholt, Swati Gupta, Atul Prakash, Amir Rahmati, Pratik Vaishnavi, Haizhong Zheng

    Abstract: Existing deep neural networks, say for image classification, have been shown to be vulnerable to adversarial images that can cause a DNN misclassification, without any perceptible change to an image. In this work, we propose shock absorbing robust features such as binarization, e.g., rounding, and group extraction, e.g., color or shape, to augment the classification pipeline, resulting in more rob… ▽ More

    Submitted 17 September, 2019; v1 submitted 26 May, 2019; originally announced May 2019.