Cho‐Jui Hsieh
13 papers in the PaperMetrix corpus
Papers by this author
-
RecurJac: An Efficient Recursive Algorithm for Bounding Jacobian Matrix of Neural Networks and Its Applications
2019 · Proceedings of the AAAI Conference on Artificial Intelligence
The Jacobian matrix (or the gradient for single-output networks) is directly related to many important properties of neural networks, such as the function landscape, stationary points, (local) Lipschitz constants and robustness to adversarial attacks. In …
-
A Unified Framework for Data Poisoning Attack to Graph-based Semi-supervised Learning
2019 · arXiv (Cornell University)
In this paper, we proposed a general framework for data poisoning attacks to graph-based semi-supervised learning (G-SSL). In this framework, we first unify different tasks, goals, and constraints into a single formula for data poisoning …
-
Elastic-InfoGAN: Unsupervised Disentangled Representation Learning in Class-Imbalanced Data
2019 · arXiv (Cornell University)
We propose a novel unsupervised generative model that learns to disentangle object identity from other low-level aspects in class-imbalanced data. We first investigate the issues surrounding the assumptions about uniformity made by InfoGAN, and demonstrate …
-
MACER: Attack-free and Scalable Robust Training via Maximizing Certified Radius
2020 · arXiv (Cornell University)
Adversarial training is one of the most popular ways to learn robust models but is usually attack-dependent and time costly. In this paper, we propose the MACER algorithm, which learns robust models without using adversarial …
-
SSE-PT: Sequential Recommendation Via Personalized Transformer
2020
Temporal information is crucial for recommendation problems because user preferences are naturally dynamic in the real world. Recent advances in deep learning, especially the discovery of various attention mechanisms and newer architectures in addition to …
-
Stabilizing Differentiable Architecture Search via Perturbation-based Regularization
2020 · arXiv (Cornell University)
Differentiable architecture search (DARTS) is a prevailing NAS solution to identify architectures. Based on the continuous relaxation of the architecture space, DARTS learns a differentiable architecture weight and largely reduces the search cost. However, its …
-
Spanning Attack: Reinforce Black-box Attacks with Unlabeled Data
2020 · arXiv (Cornell University)
Adversarial black-box attacks aim to craft adversarial perturbations by querying input-output pairs of machine learning models. They are widely used to evaluate the robustness of pre-trained models. However, black-box attacks often suffer from the issue …
-
Automatic Perturbation Analysis for Scalable Certified Robustness and Beyond
2020 · arXiv (Cornell University)
Linear relaxation based perturbation analysis (LiRPA) for neural networks, which computes provable linear bounds of output neurons given a certain amount of input perturbation, has become a core component in robustness verification and certified defense. …
-
Deep Image Destruction: A Comprehensive Study on Vulnerability of Deep Image-to-Image Models against Adversarial Attacks.
2021 · arXiv (Cornell University)
Recently, the vulnerability of deep image classification models to adversarial attacks has been investigated. However, such an issue has not been thoroughly studied for image-to-image models that can have different characteristics in quantitative evaluation, consequences …
-
A Review of Adversarial Attack and Defense for Classification Methods
2021 · The American Statistician
Despite the efficiency and scalability of machine learning systems, recent studies have demonstrated that many classification methods, especially Deep Neural Networks (DNNs), are vulnerable to adversarial examples; that is, examples that are carefully crafted to …
-
Stochastic Optimization for Nonconvex Problem With Inexact Hessian Matrix, Gradient, and Function
2023 · IEEE Transactions on Neural Networks and Learning Systems
Trust region (TR) and adaptive regularization using cubics (ARC) have proven to have some very appealing theoretical properties for nonconvex optimization by concurrently computing function value, gradient, and Hessian matrix to obtain the next search …
-
Cluster-GCN
2019
Graph convolutional network (GCN) has been successfully applied to many graph-based applications; however, training a large-scale GCN remains challenging. Current SGD-based algorithms suffer from either a high computational cost that exponentially grows with number of …
-
VisualBERT: A Simple and Performant Baseline for Vision and Language
2019 · arXiv (Cornell University)
We propose VisualBERT, a simple and flexible framework for modeling a broad range of vision-and-language tasks. VisualBERT consists of a stack of Transformer layers that implicitly align elements of an input text and regions in …