SearcharxivSearch

arXiv subjects

Donald Flynn

Publications and source records attributed to Donald Flynn.

3 recordsLinked to original sources

When Stronger Triggers Backfire: A High-Dimensional Theory of Backdoor Attacks

Backdoor poisoning attacks behave counter-intuitively in high dimensions: stronger training triggers can help the defender. We study regularised generalised linear models on Gaussian-mixture data in the proportional regime ($p/n \to \kappa$), varying the training trigger strength $\alpha$ against a fixed test trigger. Three phenomena emerge: (i) clean test accuracy increases with $\alpha$; (ii) attack success peaks at a finite $\alpha$ and then declines; and (iii) the most damaging trigger direction is the minimum eigenvector of the data covariance. We prove all three results in closed form for the squared loss, and extend (i) and (ii) to general convex GLM losses via a Gaussian-proxy fixed-point system. We identify a finite-sample noise floor proportional to $\kappa$ as the mechanism behind (i), invisible to classical $n \gg p$ analysis. Experiments on CIFAR-10 and Gaussian surrogates match the theory closely; ResNet-18 experiments show the same phenomena beyond the convex setting.

cs.LG

A Linear Approach to Data Poisoning

Backdoor and data-poisoning attacks can flip predictions with tiny training corruptions, yet a sharp theory linking poisoning strength, overparameterization, and regularization is lacking. We analyze ridge least squares with an unpenalized intercept in the high-dimensional regime \(p,n\to\infty\), \(p/n\to c\). Targeted poisoning is modelled by shifting a \(\theta\)-fraction of one class by a direction \(\mathbf{v}\) and relabelling. Using resolvent techniques and deterministic equivalents from random matrix theory, we derive closed-form limits for the poisoned score explicit in the model parameters. The formulas yield scaling laws, recover the interpolation threshold as \(c\to1\) in the ridgeless limit, and show that the weights align with the poisoning direction. Synthetic experiments match theory across sweeps of the parameters and MNIST backdoor tests show qualitatively consistent trends. The results provide a tractable framework for quantifying poisoning in linear models.

stat.ML

Brownian Bees with Drift: Finding the Criticality

This dissertation examines the impact of a drift {\mu} on Brownian Bees, which is a type of branching Brownian motion that retains only the N closest particles to the origin. The selection effect in the 0-drift system ensures that it remains recurrent and close to the origin. The study presents two novel findings that establish a threshold for {\mu}: below this value, the system remains recurrent, and above it, the system becomes transient. Moreover, the paper proves convergence to a unique invariant distribution for the small drift case. The research also explores N-BBM, a variant of branching Brownian motion where the N leftmost particles are retained, and presents one new result and further discussion on this topic.

math.PR