Adversarial Attacks, Coarse Robustness, and Dataless Neural Networks: Novel Techniques for Improved Classification and Combinatorial Optimization

Saved in:
Bibliographic Details
Title: Adversarial Attacks, Coarse Robustness, and Dataless Neural Networks: Novel Techniques for Improved Classification and Combinatorial Optimization
Authors: Alkhouri, Ismail
Committee Members: Mikhael, Wasfy
Summary: Neural networks (NN) have become a central component in most machine learning systems. However, studies have shown that these models are not robust against adversarial attacks. As such, in this dissertation, we explore four directions. In the first direction, we investigate adversarial attacks on two hierarchical classification (HC) models: the Flat HC (FHC), and the Top-Down HC (TDHC). In particular, we formulate attacks against these models by using convex programming. Through experimental results, it is shown that FHCs are more robust than TDHCs. Second, we formalize a new notion of coarse robustness that is defined with respect to a specified grouping of the class labels. We propose a training mechanism that incorporates the coarse label information in addition to the finer ones, and empirically and theoretically show that this mechanism improves the proposed notion of coarse robustness. The third direction is the Bidirectional One-Shot Synthesis (BOSS) problem for synthesizing adversarial examples using structures similar to generative adversarial networks. However, BOSS does not require the use of any training data. In particular, we explore solutions where the generated data must simultaneously satisfy input/output user-defined constraints. We prove that the BOSS problem is NP-complete, and experimentally verify that the our method either outperforms or performs on par with the state-of-the-art methods. Subsequently, for the fourth direction, we extend the synthesis problem of adversarial attacks to solving the Maximum Independent Set (MIS) problem. This is accomplished by presenting NN structures derived with respect to finding MISs in the graph, where no data is required for training the neural networks that produce the solution. Experimental results on various graphs demonstrate that our proposed method performs on par or outperforms state-of-the-art learning-based methods without requiring any training data.
URL: https://stars.library.ucf.edu/etd2020/1500
Database: OpenDissertations
FullText Text:
  Availability: 0
Header DbId: ddu
DbLabel: OpenDissertations
An: ddu.oai.stars.library.ucf.edu.etd2020.2499
AccessLevel: 6
PubType: Dissertation/ Thesis
PubTypeId: dissertation
PreciseRelevancyScore: 0
IllustrationInfo
Items – Name: Title
  Label: Title
  Group: Ti
  Data: Adversarial Attacks, Coarse Robustness, and Dataless Neural Networks: Novel Techniques for Improved Classification and Combinatorial Optimization
– Name: Author
  Label: Authors
  Group: Au
  Data: <searchLink fieldCode="AR" term="%22Alkhouri%2C+Ismail%22">Alkhouri, Ismail</searchLink>
– Name: Author
  Label: Committee Members
  Group: Au
  Data: <searchLink fieldCode="CO" term="%22Mikhael%2C+Wasfy%22">Mikhael, Wasfy</searchLink>
– Name: Abstract
  Label: Summary
  Group: Ab
  Data: Neural networks (NN) have become a central component in most machine learning systems. However, studies have shown that these models are not robust against adversarial attacks. As such, in this dissertation, we explore four directions. In the first direction, we investigate adversarial attacks on two hierarchical classification (HC) models: the Flat HC (FHC), and the Top-Down HC (TDHC). In particular, we formulate attacks against these models by using convex programming. Through experimental results, it is shown that FHCs are more robust than TDHCs. Second, we formalize a new notion of coarse robustness that is defined with respect to a specified grouping of the class labels. We propose a training mechanism that incorporates the coarse label information in addition to the finer ones, and empirically and theoretically show that this mechanism improves the proposed notion of coarse robustness. The third direction is the Bidirectional One-Shot Synthesis (BOSS) problem for synthesizing adversarial examples using structures similar to generative adversarial networks. However, BOSS does not require the use of any training data. In particular, we explore solutions where the generated data must simultaneously satisfy input/output user-defined constraints. We prove that the BOSS problem is NP-complete, and experimentally verify that the our method either outperforms or performs on par with the state-of-the-art methods. Subsequently, for the fourth direction, we extend the synthesis problem of adversarial attacks to solving the Maximum Independent Set (MIS) problem. This is accomplished by presenting NN structures derived with respect to finding MISs in the graph, where no data is required for training the neural networks that produce the solution. Experimental results on various graphs demonstrate that our proposed method performs on par or outperforms state-of-the-art learning-based methods without requiring any training data.
– Name: URL
  Label: URL
  Group: URL
  Data: <link linkTarget="URL" linkTerm="https://stars.library.ucf.edu/etd2020/1500" linkWindow="_blank">https://stars.library.ucf.edu/etd2020/1500</link>
PLink https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=ddu&AN=ddu.oai.stars.library.ucf.edu.etd2020.2499
RecordInfo BibRecord:
  BibEntity:
    Languages:
      – Code: eng
        Text: English
    Subjects:
      – SubjectFull: Adversarial attacks; Coarse robustness; Bidirectional One-Shot Synthesis; Maximum Independent Set; Classification optimization
        Type: general
      – SubjectFull: Electrical and Computer Engineering
        Type: general
      – SubjectFull: Neural networks (Computer science)--Research; Neural networks (Computer science)--Design and construction; Robust optimization; Combinatorial optimization; Neural networks (Computer science)--Mathematical models
        Type: general
    Titles:
      – TitleFull: Adversarial Attacks, Coarse Robustness, and Dataless Neural Networks: Novel Techniques for Improved Classification and Combinatorial Optimization
        Type: main
  BibRelationships:
    HasContributorRelationships:
      – PersonEntity:
          Name:
            NameFull: Alkhouri, Ismail
    IsPartOfRelationships:
      – BibEntity:
          Dates:
            – D: 01
              M: 01
              Type: published
              Y: 2023
ResultId 1