SearcharxivSearch

arXiv subjects

Charles Walter

Publications and source records attributed to Charles Walter.

16 recordsLinked to original sources

Restrict, Don't Retrain: Inference-Time VLM Guidance for Zero-Shot Aerial Segmentation

Global welfare often depends on the correct interpretation of aerial and satellite imagery. Acting on such imagery (mapping flooded ground, crop extent, or damaged infrastructure) demands pixel-level segmentation to ensure perfect class localization. Pretrained general foundation models, when applied directly, often miss important features and cannot always find all the classes belonging to a given scene, overlooking smaller objects that matter most. We use a single consumer-grade GPU running a vision-language model (VLM) to supply this missing guidance, improving segmentation while producing structured, auditable evidence that drives the result and can be inspected on its own. We fuse three approaches: the frozen foundation model that labels every pixel, and two queries to a VLM, one to choose the classes that matter, and one to locate the small objects the base model misses. Evaluating across four aerial datasets, we see consistent gains at each stage where the base model is competent.

cs.CV

Improving Stability Estimates in Adversarial Explainable AI through Alternate Search Methods

Advances in the effectiveness of machine learning models have come at the cost of enormous complexity resulting in a poor understanding of how they function. Local surrogate methods have been used to approximate the workings of these complex models, but recent work has revealed their vulnerability to adversarial attacks where the explanation produced is appreciably different while the meaning and structure of the complex model's output remains similar. This prior work has focused on the existence of these weaknesses but not on their magnitude. Here we explore using an alternate search method with the goal of finding minimum viable perturbations, the fewest perturbations necessary to achieve a fixed similarity value between the original and altered text's explanation. Intuitively, a method that requires fewer perturbations to expose a given level of instability is inferior to one which requires more. This nuance allows for superior comparisons of the stability of explainability methods.

cs.LG

Towards Robust and Accurate Stability Estimation of Local Surrogate Models in Text-based Explainable AI

Recent work has investigated the concept of adversarial attacks on explainable AI (XAI) in the NLP domain with a focus on examining the vulnerability of local surrogate methods such as Lime to adversarial perturbations or small changes on the input of a machine learning (ML) model. In such attacks, the generated explanation is manipulated while the meaning and structure of the original input remain similar under the ML model. Such attacks are especially alarming when XAI is used as a basis for decision making (e.g., prescribing drugs based on AI medical predictors) or for legal action (e.g., legal dispute involving AI software). Although weaknesses across many XAI methods have been shown to exist, the reasons behind why remain little explored. Central to this XAI manipulation is the similarity measure used to calculate how one explanation differs from another. A poor choice of similarity measure can lead to erroneous conclusions about the stability or adversarial robustness of an XAI method. Therefore, this work investigates a variety of similarity measures designed for text-based ranked lists referenced in related work to determine their comparative suitability for use. We find that many measures are overly sensitive, resulting in erroneous estimates of stability. We then propose a weighting scheme for text-based data that incorporates the synonymity between the features within an explanation, providing more accurate estimates of the actual weakness of XAI methods to adversarial examples.

cs.LG

The Effect of Similarity Measures on Accurate Stability Estimates for Local Surrogate Models in Text-based Explainable AI

Recent work has investigated the vulnerability of local surrogate methods to adversarial perturbations on a machine learning (ML) model's inputs, where the explanation is manipulated while the meaning and structure of the original input remains similar under the complex model. Although weaknesses across many methods have been shown to exist, the reasons behind why remain little explored. Central to the concept of adversarial attacks on explainable AI (XAI) is the similarity measure used to calculate how one explanation differs from another. A poor choice of similarity measure can lead to erroneous conclusions on the efficacy of an XAI method. Too sensitive a measure results in exaggerated vulnerability, while too coarse understates its weakness. We investigate a variety of similarity measures designed for text-based ranked lists, including Kendall's Tau, Spearman's Footrule, and Rank-biased Overlap to determine how substantial changes in the type of measure or threshold of success affect the conclusions generated from common adversarial attack processes. Certain measures are found to be overly sensitive, resulting in erroneous estimates of stability.

cs.LG

Privacy Threats in Stable Diffusion Models

This paper introduces a novel approach to membership inference attacks (MIA) targeting stable diffusion computer vision models, specifically focusing on the highly sophisticated Stable Diffusion V2 by StabilityAI. MIAs aim to extract sensitive information about a model's training data, posing significant privacy concerns. Despite its advancements in image synthesis, our research reveals privacy vulnerabilities in the stable diffusion models' outputs. Exploiting this information, we devise a black-box MIA that only needs to query the victim model repeatedly. Our methodology involves observing the output of a stable diffusion model at different generative epochs and training a classification model to distinguish when a series of intermediates originated from a training sample or not. We propose numerous ways to measure the membership features and discuss what works best. The attack's efficacy is assessed using the ROC AUC method, demonstrating a 60\% success rate in inferring membership information. This paper contributes to the growing body of research on privacy and security in machine learning, highlighting the need for robust defenses against MIAs. Our findings prompt a reevaluation of the privacy implications of stable diffusion models, urging practitioners and developers to implement enhanced security measures to safeguard against such attacks.

cs.CV

Focused Adversarial Attacks

Recent advances in machine learning show that neural models are vulnerable to minimally perturbed inputs, or adversarial examples. Adversarial algorithms are optimization problems that minimize the accuracy of ML models by perturbing inputs, often using a model's loss function to craft such perturbations. State-of-the-art object detection models are characterized by very large output manifolds due to the number of possible locations and sizes of objects in an image. This leads to their outputs being sparse and optimization problems that use them incur a lot of unnecessary computation. We propose to use a very limited subset of a model's learned manifold to compute adversarial examples. Our \textit{Focused Adversarial Attacks} (FA) algorithm identifies a small subset of sensitive regions to perform gradient-based adversarial attacks. FA is significantly faster than other gradient-based attacks when a model's manifold is sparsely activated. Also, its perturbations are more efficient than other methods under the same perturbation constraints. We evaluate FA on the COCO 2017 and Pascal VOC 2007 detection datasets.

cs.LG

Ulixes: Facial Recognition Privacy with Adversarial Machine Learning

Facial recognition tools are becoming exceptionally accurate in identifying people from images. However, this comes at the cost of privacy for users of online services with photo management (e.g. social media platforms). Particularly troubling is the ability to leverage unsupervised learning to recognize faces even when the user has not labeled their images. In this paper we propose Ulixes, a strategy to generate visually non-invasive facial noise masks that yield adversarial examples, preventing the formation of identifiable user clusters in the embedding space of facial encoders. This is applicable even when a user is unmasked and labeled images are available online. We demonstrate the effectiveness of Ulixes by showing that various classification and clustering methods cannot reliably label the adversarial examples we generate. We also study the effects of Ulixes in various black-box settings and compare it to the current state of the art in adversarial machine learning. Finally, we challenge the effectiveness of Ulixes against adversarially trained models and show that it is robust to countermeasures.

cs.CV

Quaternionic Grassmannians and Borel classes in algebraic geometry

The quaternionic Grassmannian HGr(r,n) is the affine open subscheme of the ordinary Grassmannian parametrizing those 2r-dimensional subspaces of a 2n-dimensional symplectic vector space on which the symplectic form is nondegenerate. In particular there is HP^{n} = HGr(1,n+1). For a symplectically oriented cohomology theory A, including oriented theories but also hermitian K-theory, Witt groups and symplectic and special linear algebraic cobordism, we have A(HP^{n}) = A(pt)[p]/(p^{n+1}). We define Borel classes for symplectic bundles. They satisfy a splitting principle and the Cartan sum formula, and we use them to calculate the cohomology of quaternionic Grassmannians. In a symplectically oriented theory the Thom classes of rank 2 symplectic bundles determine Thom and Borel classes for all symplectic bundles, and the symplectic Thom classes can be recovered from the Borel classes.

math.AG

On the motivic commutative ring spectrum BO

We construct an algebraic commutative ring T- spectrum BO which is stably fibrant and (8,4)- periodic and such that on SmOp/S the cohomology theory (X,U) -> BO^{p,q}(X_{+}/U_{+}) and Schlichting's hermitian K-theory functor (X,U) -> KO^{[q]}_{2q-p}(X,U) are canonically isomorphic. We use the motivic weak equivalence Z x HGr -> KSp relating the infinite quaternionic Grassmannian to symplectic $K$-theory to equip BO with the structure of a commutative monoid in the motivic stable homotopy category. When the base scheme is Spec Z[1/2], this monoid structure and the induced ring structure on the cohomology theory BO^{*,*} are the unique structures compatible with the products KO^{[2m]}_{0}(X) x KO^{[2n]}_{0}(Y) -> KO^{[2m+2n]}_{0}(X x Y). on Grothendieck-Witt groups induced by the tensor product of symmetric chain complexes. The cohomology theory is bigraded commutative with the switch map acting on BO^{*,*}(T^{2}) in the same way as multiplication by the Grothendieck-Witt class of the symmetric bilinear space <-1>.

math.AG

On the algebraic cobordism spectra MSL and MSp

We construct algebraic cobordism spectra MSL and MSp. They are commutative monoids in the category of symmetric T^{2}- spectra. The spectrum MSp comes with a natural symplectic orientation given either by a tautological Thom class th^{MSp} in MSp^{4,2}(MSp_{2}), a tautological Borel class b_{1}^{MSp} in MSp^{4,2}(HP^{\infty}) or any of six other equivalent structures. For a commutative monoid E in the category SH(S) we prove that assignment g -> g(th^{MSp}) identifies the set of homomorphisms of monoids g : MSp -> E in the motivic stable homotopy category SH(S) with the set of tautological Thom elements of symplectic orientations of E. A weaker universality result is obtained for MSL and special linear orientations.

math.AG

On the relation of symplectic algebraic cobordism to hermitian K-theory

We reconstruct hermitian K-theory via algebraic symplectic cobordism. In the motivic stable homotopy category SH(S) there is a unique morphism g : MSp -> BO of commutative ring T- spectra which sends the Thom class th^{MSp} to the Thom class th^{BO}. We show that the induced morphism of bigraded cohomology theories MSp^{*,*} -> BO^{*,*} is isomorphic to the morphism of bigraded cohomology theories obtained by applying to MSp^{*,*} the "change of (simply graded) coefficients rings" MSp^{4*,2*} -> BO^{4*,2*}. This is an algebraic version of the theorem of Conner and Floyd reconstructing real K-theory via symplectic cobordism.

math.AG

Exterior algebra methods for the Minimal Resolution Conjecture

If r\geq 6, r\neq 9, we show that the Minimal Resolution Conjecture fails for a general set of m points in P^r for almost 1/2\sqrt r values of m. This strengthens the result of Eisenbud and Popescu [1999], who found a unique such m for each r in the given range. Our proof begins like a variation of that of Eisenbud and Popescu, but uses exterior algebra methods as explained by Eisenbud and Schreyer [2000] to avoid the degeneration arguments that were the most difficult part of the Eisenbud-Popescu proof. Analogous techniques show that the Minimal Resolution Conjecture fails for linearly normal curves of degree d and genus g when d\geq 3g-2, g\geq 4, reproving results of Schreyer, Green, and Lazarsfeld.

math.AG

Lagrangian Subbundles and Codimension 3 Subcanonical Subscheme

We show that a Gorenstein subcanonical codimension 3 subscheme Z in X = P^N, N > 3, can be realized as the locus along which two Lagrangian subbundles of a twisted orthogonal bundle meet degenerately, and conversely. We extend this result to singular Z and all quasiprojective ambient schemes X under the necessary hypothesis that $Z$ is strongly subcanonical in a sense defined below. A central point is that a pair of Lagrangian subbundles can be transformed locally into an alternating map. In the local case our structure theorem reduces to that of Buchsbaum-Eisenbud and says that Z is Pfaffian. We also prove codimension one symmetric and skew-symmetric analogues of our structure theorems.

math.AG

Enriques Surfaces and other Non-Pfaffian Subcanonical Subschemes of Codimension 3

We give examples of subcanonical subvarieties of codimension 3 in projective n-space which are not Pfaffian, i.e. defined by the ideal sheaf of submaximal Pfaffians of an alternating map of vector bundles. This gives a negative answer to a question asked by Okonek. Walter had previously shown that a very large majority of subcanonical subschemes of codimension 3 in P^n are Pfaffian, but he left open the question whether the exceptional non-Pfaffian cases actually occur. We give non-Pfaffian examples of the principal types allowed by his theorem, including (Enriques) surfaces in P^5 in characteristic 2 and a smooth 4-fold in P^7. These examples are based on our previous work math.AG/9906170 showing that any strongly subcanonical subscheme of codimension 3 of a Noetherian scheme can be realized as a locus of degenerate intersection of a pair of Lagrangian (maximal isotropic) subbundles of a twisted orthogonal bundle.

math.AG

Evolution of Clusters in Cold plus Hot Dark Matter Models

We use N-body simulations to study evolution of galaxy clusters over the redshift interval 0 <= z <= 0.5 in cosmological models with a mixture of cold and hot dark matter (CHDM). Four different techniques are utilized: the cluster-cluster correlation function, axial ratios and quadrupoles of the dark matter distribution in individual clusters, and virial properties. We find that the correlation function for clusters of the same mass limit was larger and steeper at high redshifts. The slope increases from 1.8 at z=0 to 2.1 at z=0.5. Comoving correlation length r_c scales with the mass limit M within comoving radius 1.5 h^-1 Mpc and the redshift z as r_c ~= 20(1+z)(M/M_*)^1/3, where M_* = 3*10^14 h^-1 M_sun. When the correlation length is normalized to the mean cluster separation d_c, it remains almost constant: r_c~=(0.45-0.5) d_c. For small masses (M_clust <2*10^14 h^-1 M_sun) there is an indication that r_c goes slightly above the relation with the constant of proportionality being ~= 0.55-0.6. Anisotropy of density distribution in a cluster shows no change over redshift with axial ratios remaining constant around 1.2. In other words, clusters at present are as elongated as they were at the epoch of their first appearance. While the anisotropy of clusters does not change with time, the density profile shows visible evolution: the slope of density profile changes from gamma ~= -3.5 at z=0.5 to gamma ~= -2.5 at the present. We find that the core of a cluster remains essentially the same over time, but the density of the outlying regions increases noticeably. The virial relation M ~ v^2 is a good approximation, but there is a large fraction of clusters with peculiar velocities greater than given by this relation, and clusters with the same rms velocities have smaller masses in the past, a factor of 2 at z=0.5.

astro-ph

Irreducibility of Moduli Spaces of Vector Bundles on Birationally Ruled Surfaces

Let $S$ be a birationally ruled surface. We show that the moduli schemes $M_S(r,c_1,c_2)$ of semistable sheaves on $S$ of rank $r$ and Chern classes $c_1$ and $c_2$ are irreducible for all $(r,c_1,c_2)$ provided the polarization of $S$ used satisfies a simple numerical condition. This is accomplished by proving that the stacks of prioritary sheaves on $S$ of fixed rank and Chern classes are smooth and irreducible.

alg-geom