Skip to main content

Showing 1–23 of 23 results for author: Wicker, M

Searching in archive cs. Search in all archives.
.
  1. arXiv:2406.13433  [pdf, other

    cs.LG cs.AI

    Certificates of Differential Privacy and Unlearning for Gradient-Based Training

    Authors: Matthew Wicker, Philip Sosnin, Adrianna Janik, Mark N. Müller, Adrian Weller, Calvin Tsay

    Abstract: Proper data stewardship requires that model owners protect the privacy of individuals' data used during training. Whether through anonymization with differential privacy or the use of unlearning in non-anonymized settings, the gold-standard techniques for providing privacy guarantees can come with significant performance penalties or be too weak to provide practical assurances. In part, this is du… ▽ More

    Submitted 19 June, 2024; originally announced June 2024.

    Comments: 15 pages, 14 figures

  2. arXiv:2406.05670  [pdf, other

    cs.LG cs.CR cs.CV

    Certified Robustness to Data Poisoning in Gradient-Based Training

    Authors: Philip Sosnin, Mark N. Müller, Maximilian Baader, Calvin Tsay, Matthew Wicker

    Abstract: Modern machine learning pipelines leverage large amounts of public data, making it infeasible to guarantee data quality and leaving models open to poisoning and backdoor attacks. However, provably bounding model behavior under such attacks remains an open problem. In this work, we address this challenge and develop the first framework providing provable guarantees on the behavior of models trained… ▽ More

    Submitted 9 June, 2024; originally announced June 2024.

    Comments: 15 pages, 5 figures

  3. arXiv:2311.11911  [pdf, other

    cs.LG cs.CY

    Certification of Distributional Individual Fairness

    Authors: Matthew Wicker, Vihari Piratia, Adrian Weller

    Abstract: Providing formal guarantees of algorithmic fairness is of paramount importance to socially responsible deployment of machine learning algorithms. In this work, we study formal guarantees, i.e., certificates, for individual fairness (IF) of neural networks. We start by introducing a novel convex approximation of IF constraints that exponentially decreases the computational cost of providing formal… ▽ More

    Submitted 20 November, 2023; originally announced November 2023.

    Comments: 21 Pages, Neural Information Processing Systems 2023

  4. arXiv:2310.01951  [pdf, other

    cs.LG cs.AI

    Probabilistic Reach-Avoid for Bayesian Neural Networks

    Authors: Matthew Wicker, Luca Laurenti, Andrea Patane, Nicola Paoletti, Alessandro Abate, Marta Kwiatkowska

    Abstract: Model-based reinforcement learning seeks to simultaneously learn the dynamics of an unknown stochastic environment and synthesise an optimal policy for acting in it. Ensuring the safety and robustness of sequential decisions made through a policy in such an environment is a key challenge for policies intended for safety-critical scenarios. In this work, we investigate two complementary problems: f… ▽ More

    Submitted 3 October, 2023; originally announced October 2023.

    Comments: 47 pages, 10 figures. arXiv admin note: text overlap with arXiv:2105.10134

  5. arXiv:2306.13614  [pdf, other

    cs.LG cs.AI

    Adversarial Robustness Certification for Bayesian Neural Networks

    Authors: Matthew Wicker, Andrea Patane, Luca Laurenti, Marta Kwiatkowska

    Abstract: We study the problem of certifying the robustness of Bayesian neural networks (BNNs) to adversarial input perturbations. Given a compact set of input points $T \subseteq \mathbb{R}^m$ and a set of output points $S \subseteq \mathbb{R}^n$, we define two notions of robustness for BNNs in an adversarial setting: probabilistic robustness and decision robustness. Probabilistic robustness is the probabi… ▽ More

    Submitted 23 June, 2023; originally announced June 2023.

  6. arXiv:2304.10828  [pdf, other

    cs.LG cs.CY

    Individual Fairness in Bayesian Neural Networks

    Authors: Alice Doherty, Matthew Wicker, Luca Laurenti, Andrea Patane

    Abstract: We study Individual Fairness (IF) for Bayesian neural networks (BNNs). Specifically, we consider the $ε$-$δ$-individual fairness notion, which requires that, for any pair of input points that are $ε$-similar according to a given similarity metrics, the output of the BNN is within a given tolerance $δ>0.$ We leverage bounds on statistical sampling over the input space and the relationship between a… ▽ More

    Submitted 21 April, 2023; originally announced April 2023.

  7. arXiv:2303.06419  [pdf, other

    cs.LG

    Use Perturbations when Learning from Explanations

    Authors: Juyeon Heo, Vihari Piratla, Matthew Wicker, Adrian Weller

    Abstract: Machine learning from explanations (MLX) is an approach to learning that uses human-provided explanations of relevant or irrelevant features for each input to ensure that model predictions are right for the right reasons. Existing MLX approaches rely on local model interpretation methods and require strong model smoothing to align model and human explanations, leading to sub-optimal performance. W… ▽ More

    Submitted 1 December, 2023; v1 submitted 11 March, 2023; originally announced March 2023.

    Comments: NeurIPS 2023; https://github.com/vihari/robust_mlx

  8. arXiv:2212.08507  [pdf, other

    cs.LG

    Robust Explanation Constraints for Neural Networks

    Authors: Matthew Wicker, Juyeon Heo, Luca Costabello, Adrian Weller

    Abstract: Post-hoc explanation methods are used with the intent of providing insights about neural networks and are sometimes said to help engender trust in their outputs. However, popular explanations methods have been found to be fragile to minor perturbations of input features or model parameters. Relying on constraint relaxation techniques from non-convex optimization, we develop a method that upper-bou… ▽ More

    Submitted 16 December, 2022; originally announced December 2022.

    Comments: 23 pages, 12 figures

  9. arXiv:2210.17406  [pdf, other

    cs.LG cs.CL

    Emergent Linguistic Structures in Neural Networks are Fragile

    Authors: Emanuele La Malfa, Matthew Wicker, Marta Kwiatkowska

    Abstract: Large Language Models (LLMs) have been reported to have strong performance on natural language processing tasks. However, performance metrics such as accuracy do not measure the quality of the model in terms of its ability to robustly represent complex linguistic structures. In this paper, focusing on the ability of language models to represent syntax, we propose a framework to assess the consiste… ▽ More

    Submitted 31 May, 2023; v1 submitted 31 October, 2022; originally announced October 2022.

  10. arXiv:2207.06154  [pdf, other

    cs.LG cs.AI cs.CR

    On the Robustness of Bayesian Neural Networks to Adversarial Attacks

    Authors: Luca Bortolussi, Ginevra Carbone, Luca Laurenti, Andrea Patane, Guido Sanguinetti, Matthew Wicker

    Abstract: Vulnerability to adversarial attacks is one of the principal hurdles to the adoption of deep learning in safety-critical applications. Despite significant efforts, both practical and theoretical, training deep learning models robust to adversarial attacks is still an open problem. In this paper, we analyse the geometry of adversarial attacks in the large-data, overparameterized limit for Bayesian… ▽ More

    Submitted 28 February, 2024; v1 submitted 13 July, 2022; originally announced July 2022.

    Comments: arXiv admin note: text overlap with arXiv:2002.04359

  11. arXiv:2205.05763  [pdf, other

    cs.LG

    Individual Fairness Guarantees for Neural Networks

    Authors: Elias Benussi, Andrea Patane, Matthew Wicker, Luca Laurenti, Marta Kwiatkowska

    Abstract: We consider the problem of certifying the individual fairness (IF) of feed-forward neural networks (NNs). In particular, we work with the $ε$-$δ$-IF formulation, which, given a NN and a similarity metric learnt from data, requires that the output difference between any pair of $ε$-similar individuals is bounded by a maximum decision tolerance $δ\geq 0$. Working with a range of metrics, including t… ▽ More

    Submitted 11 May, 2022; originally announced May 2022.

  12. arXiv:2204.14170  [pdf, other

    cs.LG cs.AI stat.ML

    Tractable Uncertainty for Structure Learning

    Authors: Benjie Wang, Matthew Wicker, Marta Kwiatkowska

    Abstract: Bayesian structure learning allows one to capture uncertainty over the causal directed acyclic graph (DAG) responsible for generating given data. In this work, we present Tractable Uncertainty for STructure learning (TRUST), a framework for approximate posterior inference that relies on probabilistic circuits as the representation of our posterior belief. In contrast to sample-based posterior appr… ▽ More

    Submitted 1 July, 2022; v1 submitted 29 April, 2022; originally announced April 2022.

    Comments: ICML 2022 (long talk); 20 pages

  13. arXiv:2105.10134  [pdf, other

    cs.LG

    Certification of Iterative Predictions in Bayesian Neural Networks

    Authors: Matthew Wicker, Luca Laurenti, Andrea Patane, Nicola Paoletti, Alessandro Abate, Marta Kwiatkowska

    Abstract: We consider the problem of computing reach-avoid probabilities for iterative predictions made with Bayesian neural network (BNN) models. Specifically, we leverage bound propagation techniques and backward recursion to compute lower bounds for the probability that trajectories of the BNN model reach a given set of states while avoiding a set of unsafe states. We use the lower bounds in the context… ▽ More

    Submitted 19 June, 2021; v1 submitted 21 May, 2021; originally announced May 2021.

    Comments: Accepted, UAI 2021. 17 pages

  14. arXiv:2102.05289  [pdf, other

    cs.LG cs.CR

    Bayesian Inference with Certifiable Adversarial Robustness

    Authors: Matthew Wicker, Luca Laurenti, Andrea Patane, Zhoutong Chen, Zheng Zhang, Marta Kwiatkowska

    Abstract: We consider adversarial training of deep neural networks through the lens of Bayesian learning, and present a principled framework for adversarial training of Bayesian Neural Networks (BNNs) with certifiable guarantees. We rely on techniques from constraint relaxation of non-convex optimisation problems and modify the standard cross-entropy error model to enforce posterior robustness to worst-case… ▽ More

    Submitted 22 February, 2021; v1 submitted 10 February, 2021; originally announced February 2021.

    Comments: Accepted AISTATS2021

  15. arXiv:2012.12640  [pdf, other

    cs.LG cs.CR

    Gradient-Free Adversarial Attacks for Bayesian Neural Networks

    Authors: Matthew Yuan, Matthew Wicker, Luca Laurenti

    Abstract: The existence of adversarial examples underscores the importance of understanding the robustness of machine learning models. Bayesian neural networks (BNNs), due to their calibrated uncertainty, have been shown to posses favorable adversarial robustness properties. However, when approximate Bayesian inference methods are employed, the adversarial robustness of BNNs is still not well understood. In… ▽ More

    Submitted 23 December, 2020; originally announced December 2020.

    Comments: 6 Pages, 2 Figures, AABI2021

  16. arXiv:2004.10281  [pdf, other

    cs.LG stat.ML

    Probabilistic Safety for Bayesian Neural Networks

    Authors: Matthew Wicker, Luca Laurenti, Andrea Patane, Marta Kwiatkowska

    Abstract: We study probabilistic safety for Bayesian Neural Networks (BNNs) under adversarial input perturbations. Given a compact set of input points, $T \subseteq \mathbb{R}^m$, we study the probability w.r.t. the BNN posterior that all the points in $T$ are mapped to the same region $S$ in the output space. In particular, this can be used to evaluate the probability that a network sampled from the BNN is… ▽ More

    Submitted 18 June, 2020; v1 submitted 21 April, 2020; originally announced April 2020.

    Comments: UAI 2020; 13 pages, 5 figures, 1 table

  17. arXiv:2002.04359  [pdf, other

    cs.LG stat.ML

    Robustness of Bayesian Neural Networks to Gradient-Based Attacks

    Authors: Ginevra Carbone, Matthew Wicker, Luca Laurenti, Andrea Patane, Luca Bortolussi, Guido Sanguinetti

    Abstract: Vulnerability to adversarial attacks is one of the principal hurdles to the adoption of deep learning in safety-critical applications. Despite significant efforts, both practical and theoretical, the problem remains open. In this paper, we analyse the geometry of adversarial attacks in the large-data, overparametrized limit for Bayesian Neural Networks (BNNs). We show that, in the limit, vulnerabi… ▽ More

    Submitted 24 June, 2020; v1 submitted 11 February, 2020; originally announced February 2020.

  18. arXiv:1909.09884  [pdf, other

    cs.LG stat.ML

    Uncertainty Quantification with Statistical Guarantees in End-to-End Autonomous Driving Control

    Authors: Rhiannon Michelmore, Matthew Wicker, Luca Laurenti, Luca Cardelli, Yarin Gal, Marta Kwiatkowska

    Abstract: Deep neural network controllers for autonomous driving have recently benefited from significant performance improvements, and have begun deployment in the real world. Prior to their widespread adoption, safety guarantees are needed on the controller behaviour that properly take account of the uncertainty within the model as well as sensor noise. Bayesian neural networks, which assume a prior over… ▽ More

    Submitted 21 September, 2019; originally announced September 2019.

    Comments: 7 pages, 3 figures, submitted to ICRA 2020

  19. arXiv:1904.00923  [pdf, other

    cs.CV cs.CR cs.LG

    Robustness of 3D Deep Learning in an Adversarial Setting

    Authors: Matthew Wicker, Marta Kwiatkowska

    Abstract: Understanding the spatial arrangement and nature of real-world objects is of paramount importance to many complex engineering tasks, including autonomous navigation. Deep learning has revolutionized state-of-the-art performance for tasks in 3D environments; however, relatively little is known about the robustness of these approaches in an adversarial setting. The lack of comprehensive analysis mak… ▽ More

    Submitted 1 April, 2019; originally announced April 2019.

    Comments: 10 pages, 8 figures, 1 table

  20. arXiv:1903.01980  [pdf, other

    cs.LG cs.CV stat.ML

    Statistical Guarantees for the Robustness of Bayesian Neural Networks

    Authors: Luca Cardelli, Marta Kwiatkowska, Luca Laurenti, Nicola Paoletti, Andrea Patane, Matthew Wicker

    Abstract: We introduce a probabilistic robustness measure for Bayesian Neural Networks (BNNs), defined as the probability that, given a test point, there exists a point within a bounded set such that the BNN prediction differs between the two. Such a measure can be used, for instance, to quantify the probability of the existence of adversarial examples. Building on statistical verification techniques for pr… ▽ More

    Submitted 5 March, 2019; originally announced March 2019.

    Comments: 9 pages, 6 figures

  21. arXiv:1807.03571  [pdf, other

    cs.LG cs.AI stat.ML

    A Game-Based Approximate Verification of Deep Neural Networks with Provable Guarantees

    Authors: Min Wu, Matthew Wicker, Wenjie Ruan, Xiaowei Huang, Marta Kwiatkowska

    Abstract: Despite the improved accuracy of deep neural networks, the discovery of adversarial examples has raised serious safety concerns. In this paper, we study two variants of pointwise robustness, the maximum safe radius problem, which for a given input sample computes the minimum distance to an adversarial example, and the feature robustness problem, which aims to quantify the robustness of individual… ▽ More

    Submitted 6 March, 2019; v1 submitted 10 July, 2018; originally announced July 2018.

    Journal ref: Theoretical Computer Science 807 (2020) 298-329

  22. arXiv:1801.06900  [pdf, ps, other

    cs.DS cs.AI

    Efficient Learning of Optimal Markov Network Topology with k-Tree Modeling

    Authors: Liang Ding, Di Chang, Russell Malmberg, Aaron Martinez, David Robinson, Matthew Wicker, Hongfei Yan, Liming Cai

    Abstract: The seminal work of Chow and Liu (1968) shows that approximation of a finite probabilistic system by Markov trees can achieve the minimum information loss with the topology of a maximum spanning tree. Our current paper generalizes the result to Markov networks of tree width $\leq k$, for every fixed $k\geq 2$. In particular, we prove that approximation of a finite probabilistic system with such Ma… ▽ More

    Submitted 21 January, 2018; originally announced January 2018.

    Comments: 18 pages main text, 2 pages appendix

  23. arXiv:1710.07859  [pdf, other

    cs.CV

    Feature-Guided Black-Box Safety Testing of Deep Neural Networks

    Authors: Matthew Wicker, Xiaowei Huang, Marta Kwiatkowska

    Abstract: Despite the improved accuracy of deep neural networks, the discovery of adversarial examples has raised serious safety concerns. Most existing approaches for crafting adversarial examples necessitate some knowledge (architecture, parameters, etc.) of the network at hand. In this paper, we focus on image classifiers and propose a feature-guided black-box approach to test the safety of deep neural n… ▽ More

    Submitted 20 February, 2018; v1 submitted 21 October, 2017; originally announced October 2017.

    Comments: 35 pages, 5 tables, 23 figures