SearcharxivSearch

arXiv subjects

Melinda Sun

Publications and source records attributed to Melinda Sun.

2 recordsLinked to original sources

Incompatibility Clustering as a Defense Against Backdoor Poisoning Attacks

We propose a novel clustering mechanism based on an incompatibility property between subsets of data that emerges during model training. This mechanism partitions the dataset into subsets that generalize only to themselves, i.e., training on one subset does not improve performance on the other subsets. Leveraging the interaction between the dataset and the training process, our clustering mechanism partitions datasets into clusters that are defined by--and therefore meaningful to--the objective of the training process. We apply our clustering mechanism to defend against data poisoning attacks, in which the attacker injects malicious poisoned data into the training dataset to affect the trained model's output. Our evaluation focuses on backdoor attacks against deep neural networks trained to perform image classification using the GTSRB and CIFAR-10 datasets. Our results show that (1) these attacks produce poisoned datasets in which the poisoned and clean data are incompatible and (2) our technique successfully identifies (and removes) the poisoned data. In an end-to-end evaluation, our defense reduces the attack success rate to below 1% on 134 out of 165 scenarios, with only a 2% drop in clean accuracy on CIFAR-10 and a negligible drop in clean accuracy on GTSRB.

cs.LG

Bimonotone Subdivisions of Point Configurations in the Plane

Bimonotone subdivisions in two dimensions are subdivisions all of whose sides are either vertical or have nonnegative slope. They correspond to statistical estimates of probability distributions of strongly positively dependent random variables. The number of bimonotone subdivisions compared to the total number of subdivisions of a point configuration provides insight into how often the random variables are positively dependent. We give recursions as well as formulas for the numbers of bimonotone and total subdivisions of $2\times n$ grid configurations in the plane. Furthermore, we connect the former to the large Schröder numbers. We also show that the numbers of bimonotone and total subdivisions of a $2\times n$ grid are asymptotically equal. We then provide algorithms for counting bimonotone subdivisions for any $m \times n$ grid. Finally, we prove that all bimonotone triangulations of an $m \times n$ grid are connected by flips. This gives rise to an algorithm for counting the number of bimonotone (and total) triangulations of an $m\times n$ grid.

math.CO