SearcharxivSearch

arXiv subjects

Habibur Rahaman

Publications and source records attributed to Habibur Rahaman.

11 recordsLinked to original sources

(A)iSpy: Parasitic Trojans for Machine Learning Infrastructure

Modern machine learning (ML) pipelines depend heavily on third party libraries for graph compilation and hardware acceleration. While current practices audit data and model artifacts or rely on file integrity checks, the execution environment remains implicitly trusted. This blind spot enables active threats where a malicious runtime module interacts directly with live training and inference dynamics: exploiting this interaction allows the Trojan to support complex objectives that are challenging for static code or binary modifications, achieving manipulations impossible for standard data and model level attacks. We expose this vulnerability by presenting (A)iSpy, a parasitic infrastructure Trojan that subverts ML systems through an active observe and execute paradigm. Operating within the computation graph, (A)iSpy monitors transient tensor states to perform targeted, stealthy manipulations with negligible overhead. To violate confidentiality, the Trojan identifies all critical training hyperparameters and covertly exfiltrates them via model weights or output logits. To break integrity, it acts as a gradient amplifier: by observing steganographic triggers, it transforms otherwise weak data poisoning into effective backdoor attacks, increasing success rates from near zero to 100%. We further demonstrate broad extensibility across the machine learning lifecycle by validating auxiliary attacks in the appendix, including subpopulation label flipping, availability disruptions, and inference stage manipulations. Importantly, the (A)iSpy module easily evades standard malware scanners, while the associated poisoned inputs and resulting compromised models bypass typical inspection tools. We demonstrate the practicality of this threat with an implementation in the ONNX Runtime training and inference engines.

cs.CR

Diophantine approximation with sums of two squares

For any given positive definite binary quadratic form $Q$ with integer coefficients, we establish two results on Diophantine approximation with integers represented by $Q$. Firstly, we show that for every irrational number $α$, there exist infinitely many positive integers $n$ represented by $Q$ and satisfying $||αn|| 0$. This is an easy consequence of a result by Cook on small fractional parts of diagonal quadratic forms. Secondly, we give a quantitative version with a lower bound of this result when the exponent $1/2-\varepsilon$ is replaced by any fixed $γ<3/7$. To this end, we use the Voronoi summation formula and a bound for bilinear forms with Kloosterman sums to fixed moduli by Kerr, Shparlinski, Wu and Xi.

math.NT

Diophantine approximation with integers having no large prime factors

Given any irrational number $α$, we show that for any $0<θ<6/17$, there are infinitely many $y$-smooth (friable) numbers $n$ such that $$\|nα\| < n^{-θ},$$ where $(\log n)^C\leq y\leq n$ for some large constant $C>0$. This improves the previous work of Baker, who obtained the exponent $1/3-2/(3C)+o(1)$ in the case of $y\geq (\log n)^C$, and that of Yau, who obtained the exponent $1/3$ when $y=n^{o(1)}$. Our proof is based on the dispersion method together with arithmetic inputs coming from the average bounds for Kloosterman sums over smooth numbers.

math.NT

Diophantine Approximation with Piatetski-Shapiro Primes

We prove that for every irrational number $α$, real number $β$, real number $c$ satisfying $1<c<9/8$ and positive real number $θ$ satisfying $θ<(9/c-8)/10$, there exist infinitely many primes of the form $p=\left[n^c\right]$ with $n\in \mathbb{N}$ such that $||αp||<p^{-θ}$.

math.NT

Diophantine approximation with sums of two squares II

Recently, the authors showed that for every irrational number $\alpha$, there exist infinitely many positive integers $n$ represented by any given positive definite binary quadratic form $Q$, satisfying $||\alpha n|| 0$. We also provided a quantitative version with a lower bound when the exponent $1/2-\varepsilon$ is replaced by a smaller exponent $\gamma<3/7-\varepsilon$. In this article, we establish a quantitative version for the exponent $1/2-\varepsilon$, where we confine ourselves to the particular case of sums of two squares.

math.NT

DASH: A Meta-Attack Framework for Synthesizing Effective and Stealthy Adversarial Examples

Numerous techniques have been proposed for generating adversarial examples in white-box settings under strict Lp-norm constraints. However, such norm-bounded examples often fail to align well with human perception, and only a few methods specifically explore perceptually aligned adversarial examples. Moreover, it remains unclear whether insights from Lp-constrained attacks can be effectively leveraged to improve perceptual efficacy. In this paper, we introduce DASH, a fully differentiable meta-attack framework that generates effective and perceptually aligned adversarial examples by strategically composing existing Lp-based attack methods. DASH operates in a multi-stage fashion: at each stage, it aggregates candidate adversarial examples from multiple base attacks using learned, adaptive weights and propagates the result to the next stage. A novel meta-loss function guides this process by jointly minimizing misclassification loss and perceptual distortion, enabling the framework to dynamically modulate the contribution of each base attack throughout the stages. We evaluate DASH on adversarially trained models across CIFAR-10, CIFAR-100, and ImageNet. Despite relying solely on Lp-constrained based methods, DASH significantly outperforms state-of-the-art perceptual attacks such as AdvAD, achieving higher attack success rates (e.g., 20.63% improvement) and superior visual quality, as measured by SSIM, LPIPS, and FID (improvements $\approx$ of 11, 0.015, and 5.7, respectively). Furthermore, DASH generalizes well to unseen defenses, making it a practical and strong baseline for evaluating robustness without requiring handcrafted adaptive attacks for each new defense.

cs.CV

Primes and polygonal numbers

A linear combination $aT_r(m)+bT_s(n)$ of an \mbox{$r$-gonal} number $T_r(m)$ and an $s$-gonal number $T_s(n)$ with mutually coprime positive integer coefficients $a$ and $b$ produces infinitely many primes as $m$ and~$n$ varies over the natural numbers, whereas the sum of the reciprocals of such primes converges unless $T_r(m)=m^2$ and $T_s(n)=n^2$. For each pair of coprime positive integers $a$ and $b$, there are arbitrary long arithmetic progressions among the primes of the form $am^2+bn^2$.

math.NT

Secure and Storage-Efficient Deep Learning Models for Edge AI Using Automatic Weight Generation

Complex neural networks require substantial memory to store a large number of synaptic weights. This work introduces WINGs (Automatic Weight Generator for Secure and Storage-Efficient Deep Learning Models), a novel framework that dynamically generates layer weights in a fully connected neural network (FC) and compresses the weights in convolutional neural networks (CNNs) during inference, significantly reducing memory requirements without sacrificing accuracy. WINGs framework uses principal component analysis (PCA) for dimensionality reduction and lightweight support vector regression (SVR) models to predict layer weights in the FC networks, removing the need for storing full-weight matrices and achieving substantial memory savings. It also preferentially compresses the weights in low-sensitivity layers of CNNs using PCA and SVR with sensitivity analysis. The sensitivity-aware design also offers an added level of security, as any bit-flip attack with weights in compressed layers has an amplified and readily detectable effect on accuracy. WINGs achieves 53x compression for the FC layers and 28x for AlexNet with MNIST dataset, and 18x for Alexnet with CIFAR-10 dataset with 1-2% accuracy loss. This significant reduction in memory results in higher throughput and lower energy for DNN inference, making it attractive for resource-constrained edge applications.

cs.LG

Runtime Detection of Adversarial Attacks in AI Accelerators Using Performance Counters

Rapid adoption of AI technologies raises several major security concerns, including the risks of adversarial perturbations, which threaten the confidentiality and integrity of AI applications. Protecting AI hardware from misuse and diverse security threats is a challenging task. To address this challenge, we propose SAMURAI, a novel framework for safeguarding against malicious usage of AI hardware and its resilience to attacks. SAMURAI introduces an AI Performance Counter (APC) for tracking dynamic behavior of an AI model coupled with an on-chip Machine Learning (ML) analysis engine, known as TANTO (Trained Anomaly Inspection Through Trace Observation). APC records the runtime profile of the low-level hardware events of different AI operations. Subsequently, the summary information recorded by the APC is processed by TANTO to efficiently identify potential security breaches and ensure secure, responsible use of AI. SAMURAI enables real-time detection of security threats and misuse without relying on traditional software-based solutions that require model integration. Experimental results demonstrate that SAMURAI achieves up to 97% accuracy in detecting adversarial attacks with moderate overhead on various AI models, significantly outperforming conventional software-based approaches. It enhances security and regulatory compliance, providing a comprehensive solution for safeguarding AI against emergent threats.

cs.CR

Primes in Tuples of Linear Forms in Number Fields and Function Fields

Following the work of Castillo-Hall-Oliver-Pollack-Thompson who extended Maynard-Tao theorem on admissible tuples to number fields and function fields for tuples with monic linear forms, here we obtain the Maynard-Tao theorem for admissible tuples of linear forms with arbitrary leading coefficients in number fields and function fields. Also, we provide some applications of our results.

math.NT

Representation of even Gaussian integer à la Chen

In this article, we represent an even Gaussian integer with sufficiently large norm as a sum of a Gaussian prime and a Gaussian integer with at most two Gaussian prime factors akin to Chen in the rational case.

math.NT