Adversarial Attacks, Coarse Robustness, and Dataless Neural Networks: Novel Techniques for Improved Classification and Combinatorial Optimization
Saved in:
| Title: | Adversarial Attacks, Coarse Robustness, and Dataless Neural Networks: Novel Techniques for Improved Classification and Combinatorial Optimization |
|---|---|
| Authors: | Alkhouri, Ismail |
| Committee Members: | Mikhael, Wasfy |
| Summary: | Neural networks (NN) have become a central component in most machine learning systems. However, studies have shown that these models are not robust against adversarial attacks. As such, in this dissertation, we explore four directions. In the first direction, we investigate adversarial attacks on two hierarchical classification (HC) models: the Flat HC (FHC), and the Top-Down HC (TDHC). In particular, we formulate attacks against these models by using convex programming. Through experimental results, it is shown that FHCs are more robust than TDHCs. Second, we formalize a new notion of coarse robustness that is defined with respect to a specified grouping of the class labels. We propose a training mechanism that incorporates the coarse label information in addition to the finer ones, and empirically and theoretically show that this mechanism improves the proposed notion of coarse robustness. The third direction is the Bidirectional One-Shot Synthesis (BOSS) problem for synthesizing adversarial examples using structures similar to generative adversarial networks. However, BOSS does not require the use of any training data. In particular, we explore solutions where the generated data must simultaneously satisfy input/output user-defined constraints. We prove that the BOSS problem is NP-complete, and experimentally verify that the our method either outperforms or performs on par with the state-of-the-art methods. Subsequently, for the fourth direction, we extend the synthesis problem of adversarial attacks to solving the Maximum Independent Set (MIS) problem. This is accomplished by presenting NN structures derived with respect to finding MISs in the graph, where no data is required for training the neural networks that produce the solution. Experimental results on various graphs demonstrate that our proposed method performs on par or outperforms state-of-the-art learning-based methods without requiring any training data. |
| URL: | https://stars.library.ucf.edu/etd2020/1500 |
| Database: | OpenDissertations |
| FullText | Text: Availability: 0 |
|---|---|
| Header | DbId: ddu DbLabel: OpenDissertations An: ddu.oai.stars.library.ucf.edu.etd2020.2499 AccessLevel: 6 PubType: Dissertation/ Thesis PubTypeId: dissertation PreciseRelevancyScore: 0 |
| IllustrationInfo | |
| Items | – Name: Title Label: Title Group: Ti Data: Adversarial Attacks, Coarse Robustness, and Dataless Neural Networks: Novel Techniques for Improved Classification and Combinatorial Optimization – Name: Author Label: Authors Group: Au Data: <searchLink fieldCode="AR" term="%22Alkhouri%2C+Ismail%22">Alkhouri, Ismail</searchLink> – Name: Author Label: Committee Members Group: Au Data: <searchLink fieldCode="CO" term="%22Mikhael%2C+Wasfy%22">Mikhael, Wasfy</searchLink> – Name: Abstract Label: Summary Group: Ab Data: Neural networks (NN) have become a central component in most machine learning systems. However, studies have shown that these models are not robust against adversarial attacks. As such, in this dissertation, we explore four directions. In the first direction, we investigate adversarial attacks on two hierarchical classification (HC) models: the Flat HC (FHC), and the Top-Down HC (TDHC). In particular, we formulate attacks against these models by using convex programming. Through experimental results, it is shown that FHCs are more robust than TDHCs. Second, we formalize a new notion of coarse robustness that is defined with respect to a specified grouping of the class labels. We propose a training mechanism that incorporates the coarse label information in addition to the finer ones, and empirically and theoretically show that this mechanism improves the proposed notion of coarse robustness. The third direction is the Bidirectional One-Shot Synthesis (BOSS) problem for synthesizing adversarial examples using structures similar to generative adversarial networks. However, BOSS does not require the use of any training data. In particular, we explore solutions where the generated data must simultaneously satisfy input/output user-defined constraints. We prove that the BOSS problem is NP-complete, and experimentally verify that the our method either outperforms or performs on par with the state-of-the-art methods. Subsequently, for the fourth direction, we extend the synthesis problem of adversarial attacks to solving the Maximum Independent Set (MIS) problem. This is accomplished by presenting NN structures derived with respect to finding MISs in the graph, where no data is required for training the neural networks that produce the solution. Experimental results on various graphs demonstrate that our proposed method performs on par or outperforms state-of-the-art learning-based methods without requiring any training data. – Name: URL Label: URL Group: URL Data: <link linkTarget="URL" linkTerm="https://stars.library.ucf.edu/etd2020/1500" linkWindow="_blank">https://stars.library.ucf.edu/etd2020/1500</link> |
| PLink | https://search.ebscohost.com/login.aspx?direct=true&site=eds-live&db=ddu&AN=ddu.oai.stars.library.ucf.edu.etd2020.2499 |
| RecordInfo | BibRecord: BibEntity: Languages: – Code: eng Text: English Subjects: – SubjectFull: Adversarial attacks; Coarse robustness; Bidirectional One-Shot Synthesis; Maximum Independent Set; Classification optimization Type: general – SubjectFull: Electrical and Computer Engineering Type: general – SubjectFull: Neural networks (Computer science)--Research; Neural networks (Computer science)--Design and construction; Robust optimization; Combinatorial optimization; Neural networks (Computer science)--Mathematical models Type: general Titles: – TitleFull: Adversarial Attacks, Coarse Robustness, and Dataless Neural Networks: Novel Techniques for Improved Classification and Combinatorial Optimization Type: main BibRelationships: HasContributorRelationships: – PersonEntity: Name: NameFull: Alkhouri, Ismail IsPartOfRelationships: – BibEntity: Dates: – D: 01 M: 01 Type: published Y: 2023 |
| ResultId | 1 |