Skip to main content

Showing 1–4 of 4 results for author: Schmidt, F R

Searching in archive stat. Search in all archives.
.
  1. arXiv:2007.00147  [pdf, other

    cs.LG stat.ML

    Neural Network Virtual Sensors for Fuel Injection Quantities with Provable Performance Specifications

    Authors: Eric Wong, Tim Schneider, Joerg Schmitt, Frank R. Schmidt, J. Zico Kolter

    Abstract: Recent work has shown that it is possible to learn neural networks with provable guarantees on the output of the model when subject to input perturbations, however these works have focused primarily on defending against adversarial examples for image classifiers. In this paper, we study how these provable guarantees can be naturally applied to other real world settings, namely getting performance… ▽ More

    Submitted 30 June, 2020; originally announced July 2020.

  2. arXiv:1904.00759  [pdf, other

    cs.CV cs.CR cs.LG stat.ML

    Adversarial camera stickers: A physical camera-based attack on deep learning systems

    Authors: Juncheng Li, Frank R. Schmidt, J. Zico Kolter

    Abstract: Recent work has documented the susceptibility of deep learning systems to adversarial examples, but most such attacks directly manipulate the digital input to a classifier. Although a smaller line of work considers physical adversarial attacks, in all cases these involve manipulating the object of interest, e.g., putting a physical sticker on an object to misclassify it, or manufacturing an object… ▽ More

    Submitted 8 June, 2019; v1 submitted 21 March, 2019; originally announced April 2019.

    Journal ref: Proceedings of the 36th International Conference on Machine Learning, PMLR 97:3896-3904, 2019

  3. arXiv:1902.07906  [pdf, other

    cs.LG stat.ML

    Wasserstein Adversarial Examples via Projected Sinkhorn Iterations

    Authors: Eric Wong, Frank R. Schmidt, J. Zico Kolter

    Abstract: A rapidly growing area of work has studied the existence of adversarial examples, datapoints which have been perturbed to fool a classifier, but the vast majority of these works have focused primarily on threat models defined by $\ell_p$ norm-bounded perturbations. In this paper, we propose a new threat model for adversarial attacks based on the Wasserstein distance. In the image classification se… ▽ More

    Submitted 18 January, 2020; v1 submitted 21 February, 2019; originally announced February 2019.

  4. arXiv:1805.12514  [pdf, other

    cs.LG cs.AI math.OC stat.ML

    Scaling provable adversarial defenses

    Authors: Eric Wong, Frank R. Schmidt, Jan Hendrik Metzen, J. Zico Kolter

    Abstract: Recent work has developed methods for learning deep network classifiers that are provably robust to norm-bounded adversarial perturbation; however, these methods are currently only possible for relatively small feedforward networks. In this paper, in an effort to scale these approaches to substantially larger models, we extend previous work in three main directions. First, we present a technique f… ▽ More

    Submitted 21 November, 2018; v1 submitted 31 May, 2018; originally announced May 2018.