Searcharxiv⌕ Search

arXiv subjects

Chengyu Song

Publications and source records attributed to Chengyu Song.

At least 37 records · Page 2Linked to original sources

MsPrompt: Multi-step Prompt Learning for Debiasing Few-shot Event Detection

Event detection (ED) is aimed to identify the key trigger words in unstructured text and predict the event types accordingly. Traditional ED models are too data-hungry to accommodate real applications with scarce labeled data. Besides, typical ED models are facing the context-bypassing and disabled generalization issues caused by the trigger bias stemming from ED datasets. Therefore, we focus on the true few-shot paradigm to satisfy the low-resource scenarios. In particular, we propose a multi-step prompt learning model (MsPrompt) for debiasing few-shot event detection, that consists of the following three components: an under-sampling module targeting to construct a novel training set that accommodates the true few-shot setting, a multi-step prompt module equipped with a knowledge-enhanced ontology to leverage the event semantics and latent prior knowledge in the PLMs sufficiently for tackling the context-bypassing problem, and a prototypical module compensating for the weakness of classifying events with sparse data and boost the generalization performance. Experiments on two public datasets ACE-2005 and FewEvent show that MsPrompt can outperform the state-of-the-art models, especially in the strict low-resource scenarios reporting 11.43% improvement in terms of weighted F1-score against the best-performing baseline and achieving an outstanding debiasing performance.

cs.CL↗

Blackbox Attacks via Surrogate Ensemble Search

Blackbox adversarial attacks can be categorized into transfer- and query-based attacks. Transfer methods do not require any feedback from the victim model, but provide lower success rates compared to query-based methods. Query attacks often require a large number of queries for success. To achieve the best of both approaches, recent efforts have tried to combine them, but still require hundreds of queries to achieve high success rates (especially for targeted attacks). In this paper, we propose a novel method for Blackbox Attacks via Surrogate Ensemble Search (BASES) that can generate highly successful blackbox attacks using an extremely small number of queries. We first define a perturbation machine that generates a perturbed image by minimizing a weighted loss function over a fixed set of surrogate models. To generate an attack for a given victim model, we search over the weights in the loss function using queries generated by the perturbation machine. Since the dimension of the search space is small (same as the number of surrogate models), the search requires a small number of queries. We demonstrate that our proposed method achieves better success rate with at least 30x fewer queries compared to state-of-the-art methods on different image classifiers trained with ImageNet. In particular, our method requires as few as 3 queries per image (on average) to achieve more than a 90% success rate for targeted attacks and 1-2 queries per image for over a 99% success rate for untargeted attacks. Our method is also effective on Google Cloud Vision API and achieved a 91% untargeted attack success rate with 2.9 queries per image. We also show that the perturbations generated by our proposed method are highly transferable and can be adopted for hard-label blackbox attacks. We also show effectiveness of BASES for hiding attacks on object detectors.

cs.LG↗

GAMA: Generative Adversarial Multi-Object Scene Attacks

The majority of methods for crafting adversarial attacks have focused on scenes with a single dominant object (e.g., images from ImageNet). On the other hand, natural scenes include multiple dominant objects that are semantically related. Thus, it is crucial to explore designing attack strategies that look beyond learning on single-object scenes or attack single-object victim classifiers. Due to their inherent property of strong transferability of perturbations to unknown models, this paper presents the first approach of using generative models for adversarial attacks on multi-object scenes. In order to represent the relationships between different objects in the input scene, we leverage upon the open-sourced pre-trained vision-language model CLIP (Contrastive Language-Image Pre-training), with the motivation to exploit the encoded semantics in the language space along with the visual space. We call this attack approach Generative Adversarial Multi-object scene Attacks (GAMA). GAMA demonstrates the utility of the CLIP model as an attacker's tool to train formidable perturbation generators for multi-object scenes. Using the joint image-text features to train the generator, we show that GAMA can craft potent transferable perturbations in order to fool victim classifiers in various attack settings. For example, GAMA triggers ~16% more misclassification than state-of-the-art generative approaches in black-box settings where both the classifier architecture and data distribution of the attacker are different from the victim. Our code is available here: https://abhishekaich27.github.io/gama.html

cs.CV↗

Leveraging Local Patch Differences in Multi-Object Scenes for Generative Adversarial Attacks

State-of-the-art generative model-based attacks against image classifiers overwhelmingly focus on single-object (i.e., single dominant object) images. Different from such settings, we tackle a more practical problem of generating adversarial perturbations using multi-object (i.e., multiple dominant objects) images as they are representative of most real-world scenes. Our goal is to design an attack strategy that can learn from such natural scenes by leveraging the local patch differences that occur inherently in such images (e.g. difference between the local patch on the object `person' and the object `bike' in a traffic scene). Our key idea is to misclassify an adversarial multi-object image by confusing the victim classifier for each local patch in the image. Based on this, we propose a novel generative attack (called Local Patch Difference or LPD-Attack) where a novel contrastive loss function uses the aforesaid local differences in feature space of multi-object scenes to optimize the perturbation generator. Through various experiments across diverse victim convolutional neural networks, we show that our approach outperforms baseline generative attacks with highly transferable perturbations when evaluated under different white-box and black-box settings.

cs.CV↗

Effects of Laser-Annealing on Fixed-Frequency Superconducting Qubits

As superconducting quantum processors increase in complexity, techniques to overcome constraints on frequency crowding are needed. The recently developed method of laser-annealing provides an effective post-fabrication method to adjust the frequency of superconducting qubits. Here, we present an automated laser-annealing apparatus based on conventional microscopy components and demonstrate preservation of highly coherent transmons. In one case, we observe a two-fold increase in coherence after laser-annealing and perform noise spectroscopy on this qubit to investigate the change in defect features, in particular two-level system defects. Finally, we present a local heating model as well as demonstrate aging stability for laser-annealing on the wafer scale. Our work constitutes an important first step towards both understanding the underlying physical mechanism and scaling up laser-annealing of superconducting qubits.

quant-ph↗

Zero-Query Transfer Attacks on Context-Aware Object Detectors

Adversarial attacks perturb images such that a deep neural network produces incorrect classification results. A promising approach to defend against adversarial attacks on natural multi-object scenes is to impose a context-consistency check, wherein, if the detected objects are not consistent with an appropriately defined context, then an attack is suspected. Stronger attacks are needed to fool such context-aware detectors. We present the first approach for generating context-consistent adversarial attacks that can evade the context-consistency check of black-box object detectors operating on complex, natural scenes. Unlike many black-box attacks that perform repeated attempts and open themselves to detection, we assume a "zero-query" setting, where the attacker has no knowledge of the classification decisions of the victim system. First, we derive multiple attack plans that assign incorrect labels to victim objects in a context-consistent manner. Then we design and use a novel data structure that we call the perturbation success probability matrix, which enables us to filter the attack plans and choose the one most likely to succeed. This final attack plan is implemented using a perturbation-bounded adversarial attack algorithm. We compare our zero-query attack against a few-query scheme that repeatedly checks if the victim system is fooled. We also compare against state-of-the-art context-agnostic attacks. Against a context-aware defense, the fooling rate of our zero-query approach is significantly higher than context-agnostic approaches and higher than that achievable with up to three rounds of the few-query scheme.

cs.CV↗

Context-Aware Transfer Attacks for Object Detection

Blackbox transfer attacks for image classifiers have been extensively studied in recent years. In contrast, little progress has been made on transfer attacks for object detectors. Object detectors take a holistic view of the image and the detection of one object (or lack thereof) often depends on other objects in the scene. This makes such detectors inherently context-aware and adversarial attacks in this space are more challenging than those targeting image classifiers. In this paper, we present a new approach to generate context-aware attacks for object detectors. We show that by using co-occurrence of objects and their relative locations and sizes as context information, we can successfully generate targeted mis-categorization attacks that achieve higher transfer success rates on blackbox object detectors than the state-of-the-art. We test our approach on a variety of object detectors with images from PASCAL VOC and MS COCO datasets and demonstrate up to $20$ percentage points improvement in performance compared to the other state-of-the-art methods.

cs.CV↗

Adversarial Attacks on Black Box Video Classifiers: Leveraging the Power of Geometric Transformations

When compared to the image classification models, black-box adversarial attacks against video classification models have been largely understudied. This could be possible because, with video, the temporal dimension poses significant additional challenges in gradient estimation. Query-efficient black-box attacks rely on effectively estimated gradients towards maximizing the probability of misclassifying the target video. In this work, we demonstrate that such effective gradients can be searched for by parameterizing the temporal structure of the search space with geometric transformations. Specifically, we design a novel iterative algorithm Geometric TRAnsformed Perturbations (GEO-TRAP), for attacking video classification models. GEO-TRAP employs standard geometric transformation operations to reduce the search space for effective gradients into searching for a small group of parameters that define these operations. This group of parameters describes the geometric progression of gradients, resulting in a reduced and structured search space. Our algorithm inherently leads to successful perturbations with surprisingly few queries. For example, adversarial examples generated from GEO-TRAP have better attack success rates with ~73.55% fewer queries compared to the state-of-the-art method for video adversarial attacks on the widely used Jester dataset. Overall, our algorithm exposes vulnerabilities of diverse video classification models and achieves new state-of-the-art results under black-box settings on two large datasets. Code is available here: https://github.com/sli057/Geo-TRAP

cs.CV↗

ADC: Adversarial attacks against object Detection that evade Context consistency checks

Deep Neural Networks (DNNs) have been shown to be vulnerable to adversarial examples, which are slightly perturbed input images which lead DNNs to make wrong predictions. To protect from such examples, various defense strategies have been proposed. A very recent defense strategy for detecting adversarial examples, that has been shown to be robust to current attacks, is to check for intrinsic context consistencies in the input data, where context refers to various relationships (e.g., object-to-object co-occurrence relationships) in images. In this paper, we show that even context consistency checks can be brittle to properly crafted adversarial examples and to the best of our knowledge, we are the first to do so. Specifically, we propose an adaptive framework to generate examples that subvert such defenses, namely, Adversarial attacks against object Detection that evade Context consistency checks (ADC). In ADC, we formulate a joint optimization problem which has two attack goals, viz., (i) fooling the object detector and (ii) evading the context consistency check system, at the same time. Experiments on both PASCAL VOC and MS COCO datasets show that examples generated with ADC fool the object detector with a success rate of over 85% in most cases, and at the same time evade the recently proposed context consistency checks, with a bypassing rate of over 80% in most cases. Our results suggest that how to robustly model context and check its consistency, is still an open problem.

cs.CV↗

Multi-scale characterization of hexagonal Si-4H: a hierarchical nanostructured material

In this work we present a detailed structural characterization of Si-4H, a newly discovered bulk form of hexagonal silicon (Si) with potential optoelectronic applications. Using multi-scale imaging, we reveal a hierarchical structure in the morphology of Si-4H obtained from high-pressure synthesis. We demonstrate discrete structural units, platelets, at an intermediate length-scale between the bulk pellets synthesized at high pressures and the flake-like crystallites inferred in previous studies. Direct observation of the platelets reveals their 2D structure, with planar faces spanning hundreds of nanometers to a few micrometers and thicknesses of only tens of nanometers. We separated and dispersed small packets of quasi-single platelets, which enabled us to analyze the crystalline domains within each grain. With this view, we demonstrate that Si-4H platelets represent the smallest crystalline structural units, which can bend at the single-domain level. Our characterization of the quasi-2D, flexible platelets of hexagonal Si-4H and proof of concept that the platelets can be dispersed and manipulated quite simply demonstrate opportunities to design novel optoelectronic and solar devices.

cond-mat.mtrl-sci↗

Exploiting Multi-Object Relationships for Detecting Adversarial Attacks in Complex Scenes

Vision systems that deploy Deep Neural Networks (DNNs) are known to be vulnerable to adversarial examples. Recent research has shown that checking the intrinsic consistencies in the input data is a promising way to detect adversarial attacks (e.g., by checking the object co-occurrence relationships in complex scenes). However, existing approaches are tied to specific models and do not offer generalizability. Motivated by the observation that language descriptions of natural scene images have already captured the object co-occurrence relationships that can be learned by a language model, we develop a novel approach to perform context consistency checks using such language models. The distinguishing aspect of our approach is that it is independent of the deployed object detector and yet offers very high accuracy in terms of detecting adversarial examples in practical scenes with multiple objects.

cs.CV↗

Localization and reduction of superconducting quantum coherent circuit losses

Quantum sensing and computation can be realized with superconducting microwave circuits. Qubits are engineered quantum systems of capacitors and inductors with non-linear Josephson junctions. They operate in the single-excitation quantum regime, photons of $27 μ$eV at 6.5 GHz. Quantum coherence is fundamentally limited by materials defects, in particular atomic-scale parasitic two-level systems (TLS) in amorphous dielectrics at circuit interfaces.[1] The electric fields driving oscillating charges in quantum circuits resonantly couple to TLS, producing phase noise and dissipation. We use coplanar niobium-on-silicon superconducting resonators to probe decoherence in quantum circuits. By selectively modifying interface dielectrics, we show that most TLS losses come from the silicon surface oxide, and most non-TLS losses are distributed throughout the niobium surface oxide. Through post-fabrication interface modification we reduced TLS losses by 85% and non-TLS losses by 72%, obtaining record single-photon resonator quality factors above 5 million and approaching a regime where non-TLS losses are dominant. [1]Müller, C., Cole, J. H. & Lisenfeld, J. Towards understanding two-level-systems in amorphous solids: insights from quantum circuits. Rep. Prog. Phys. 82, 124501 (2019)

quant-ph↗

Origins of the transformability of Nickel-Titanium shape memory alloys

The near equiatomic NiTi alloy is the most successful shape memory alloy by a large margin. It is widely and increasingly used in biomedical devices. Yet, despite having a repeatable superelastic effect and excellent shape-memory, NiTi is very far from satisfying the conditions that characterize the most reversible phase transforming materials. Thus, the scientific reasons underlying its vast success present an enigma. In this work, we perform rigorous mathematical derivation and accurate DFT calculation of transformation mechanisms to seek previously unrecognized twin-like defects that we term involution domains, and we observe them in real space in NiTi by the aberration-corrected scanning transmission electron microscopy. Involution domains lead to an additional 216 compatible interfaces between phases in NiTi, and we theorize that this feature contributes importantly to its reliability. They are expected to arise in other transformations and to alter the conventional interpretation of the mechanism of the martensitic transformation.

cond-mat.mtrl-sci↗

Stabilization of NbTe3, VTe3, and TiTe3 via Nanotube Encapsulation

The structure of MX3 transition metal trichalcogenides (TMTs, with M a transition metal and X a chalcogen) is typified by one-dimensional (1D) chains weakly bound together via van der Waals interactions. This structural motif is common across a range of M and X atoms (e.g. NbSe3, HfTe3, TaS3), but not all M and X combinations are stable. We report here that three new members of the MX3 family which are not stable in bulk, specifically NbTe3, VTe3, and TiTe3, can be synthesized in the few- to single-chain limit via nano-confined growth within the stabilizing cavity of multi-walled carbon nanotubes. Transmission electron microscopy (TEM) and atomic-resolution scanning transmission electron microscopy (STEM) reveal the chain-like nature and the detailed atomic structure. The synthesized materials exhibit behavior unique to few-chain quasi-1D structures, such as multi-chain spiraling and a trigonal anti-prismatic rocking distortion in the single-chain limit. Density functional theory (DFT) calculations provide insight into the crystal structure and stability of the materials, as well as their electronic structure.

cond-mat.mtrl-sci↗

Measurement-driven Security Analysis of Imperceptible Impersonation Attacks

The emergence of Internet of Things (IoT) brings about new security challenges at the intersection of cyber and physical spaces. One prime example is the vulnerability of Face Recognition (FR) based access control in IoT systems. While previous research has shown that Deep Neural Network(DNN)-based FR systems (FRS) are potentially susceptible to imperceptible impersonation attacks, the potency of such attacks in a wide set of scenarios has not been thoroughly investigated. In this paper, we present the first systematic, wide-ranging measurement study of the exploitability of DNN-based FR systems using a large scale dataset. We find that arbitrary impersonation attacks, wherein an arbitrary attacker impersonates an arbitrary target, are hard if imperceptibility is an auxiliary goal. Specifically, we show that factors such as skin color, gender, and age, impact the ability to carry out an attack on a specific target victim, to different extents. We also study the feasibility of constructing universal attacks that are robust to different poses or views of the attacker's face. Our results show that finding a universal perturbation is a much harder problem from the attacker's perspective. Finally, we find that the perturbed images do not generalize well across different DNN models. This suggests security countermeasures that can dramatically reduce the exploitability of DNN-based FR systems.

cs.CV↗

Connecting the Dots: Detecting Adversarial Perturbations Using Context Inconsistency

There has been a recent surge in research on adversarial perturbations that defeat Deep Neural Networks (DNNs) in machine vision; most of these perturbation-based attacks target object classifiers. Inspired by the observation that humans are able to recognize objects that appear out of place in a scene or along with other unlikely objects, we augment the DNN with a system that learns context consistency rules during training and checks for the violations of the same during testing. Our approach builds a set of auto-encoders, one for each object class, appropriately trained so as to output a discrepancy between the input and output if an added adversarial perturbation violates context consistency rules. Experiments on PASCAL VOC and MS COCO show that our method effectively detects various adversarial attacks and achieves high ROC-AUC (over 0.95 in most cases); this corresponds to over 20% improvement over a state-of-the-art context-agnostic method.

cs.CV↗

Emergence of Topologically Non-trivial Spin-polarized States in a Segmented Linear Chain

The synthesis of new materials with novel or useful properties is one of the most important drivers in the fields of condensed matter physics and materials science. Discoveries of this kind are especially significant when they point to promising future basic research and applications. Van der Waals bonded materials comprised of lower-dimensional building blocks have been shown to exhibit emergent properties when isolated in an atomically thin form1-8. Here, we report the discovery of a transition metal chalcogenide in a heretofore unknown segmented linear chain form, where basic building blocks each consisting of two hafnium atoms and nine tellurium atoms (Hf2Te9) are van der Waals bonded end-to-end. First-principle calculations based on density functional theory reveal striking crystal-symmetry-related features in the electronic structure of the segmented chain, including giant spin splitting and nontrivial topological phases of selected energy band states. Atomic-resolution scanning transmission electron microscopy reveals single segmented Hf2Te9 chains isolated within the hollow cores of carbon nanotubes, with a structure consistent with theoretical predictions. Van der Waals-bonded segmented linear chain transition metal chalcogenide materials could open up new opportunities in low-dimensional, gate-tunable, magnetic and topological crystalline systems.

cond-mat.mtrl-sci↗

SPECCFI: Mitigating Spectre Attacks using CFI Informed Speculation

Spectre attacks and their many subsequent variants are a new vulnerability class affecting modern CPUs. The attacks rely on the ability to misguide speculative execution, generally by exploiting the branch prediction structures, to execute a vulnerable code sequence speculatively. In this paper, we propose to use Control-Flow Integrity (CFI), a security technique used to stop control-flow hijacking attacks, on the committed path, to prevent speculative control-flow from being hijacked to launch the most dangerous variants of the Spectre attacks (Spectre-BTB and Spectre-RSB). Specifically, CFI attempts to constrain the possible targets of an indirect branch to a set of legal targets defined by a pre-calculated control-flow graph (CFG). As CFI is being adopted by commodity software (e.g., Windows and Android) and commodity hardware (e.g., Intel's CET and ARM's BTI), the CFI information becomes readily available through the hardware CFI extensions. With the CFI information, we apply CFI principles to also constrain illegal control-flow during speculative execution. Specifically, our proposed defense, SPECCFI, ensures that control flow instructions target legal destinations to constrain dangerous speculation on forward control-flow paths (indirect calls and branches). We augment this protection with a precise speculation-aware hardware stack to constrain speculation on backward control-flow edges (returns). We combine this solution with existing solutions against branch target predictor attacks (Spectre-PHT) to close all known non-vendor-specific Spectre vulnerabilities. We show that SPECCFI results in small overheads both in terms of performance and additional hardware complexity.

cs.CR↗