SearcharxivSearch

arXiv subjects

Mohamed Tamaazousti

Publications and source records attributed to Mohamed Tamaazousti.

At least 19 recordsLinked to original sources

The Power of Backdoor Absorption in Community Training

Backdoor attacks severely threaten large-scale AI models. When model owners delegate training to external compute providers within a decentralized training paradigm, adversaries can craft stealthy, low-frequency triggers to inject malicious behavior while evading standard audits. Traditionally, detecting these attacks requires a full re-computation of the training steps--a prohibitive overhead that directly contradicts the owner's resource constraints. To address this, we investigate the resilience of continuous optimization dynamics under Byzantine perturbations, where adversaries are forced to compete against a continuous influx of honest updates. Under a threat model where an adversary compromises f out of n total trainers, we quantify the minimum auditing overhead required by the model owner to probabilistically bound the attack success rate. We formalize this injection-absorption dynamic as a Discrete-Time Markov Chain (DTMC). Using this framework, we prove that the success probability of any bounded adversary asymptotically collapses to zero under a defense strategy combining natural absorption, a randomized scheduler, and lazy verification oracle. Empirical results demonstrate significant backdoor suppression with zero utility degradation even when invoking the verification oracle on merely 10% of the total training steps. This approach yields a provably sound and computationally efficient defense for safety-critical AI.

cs.CR

Functional Renormalization Group Approach for Signal Detection

This review paper uses renormalization group techniques for signal detection in nearly-continuous positive spectra. We highlight universal aspects of the analogue field-theory approach. The first aim is to present an extended self-consistent construction of the analogue effective field-theory framework for data, which can be viewed as a maximum entropy model. In particular and exploiting universality arguments, we justify the $\mathbb{Z}_2$-symmetry of the classical action and we stress the existence of a large-scale (local) regime and of a small-scale (nonlocal) regime. Secondly and related to noise models, we observe the universal relation between phase transition and symmetry breaking in the vicinity of the detection threshold. Finally, we discuss the issue of defining the covariance matrix for tensorial-like data. Based on the cutting graph prescription, we note the superiority of definitions based on complete graphs of large size for data analysis.

hep-th

Certification and Classification of Linear Quantum Error Mitigation Methods

Numerous mitigation methods exist for quantum noise suppression, making it challenging to identify the optimum approach for a specific application; especially as ongoing advances in hardware tuning and error correction are expected to reduce logical error rates. In order to facilitate the future-proof application-dependent comparison of mitigation methods, we develop a set of quantitative metrics that account for continual improvements in logical gate quality. We use these metrics to define qualitative criteria (e.g. scalability, efficiency, and robustness to characterised imperfections in the mitigation implementation), which we combine into application-specific certifications. We then provide a taxonomy of linear mitigation methods, characterising them by their features and requirements. Finally, we use our framework to produce and evaluate a mitigation strategy. A mitigation strategy is a collections of mitigation methods and compilation procedures designed to mitigate all relevant errors for a given piece of characterised hardware. Our example mitigation strategy is targeted at mitigating the outputs of hardware suffering from stochastic noise and/or rotational errors. We find the most significant determinant of efficient mitigation is accurate and precise characterisation.

quant-ph

Quantum error mitigation by hierarchy-informed sampling: chiral dynamics in the Schwinger model

Quantum simulations on current NISQ hardware are limited by its noisy nature, making efficient quantum error mitigation methods highly demanded. In this paper we introduce a novel mitigation scheme, applicable to arbitrary quantum simulations of time-dependent Hamiltonian dynamics on NISQ devices. The scheme uses a polynomial subset of extended qubit Bogoliubov-Born-Green-Kirkwood-Yvon (BBGKY) hierarchy equations as a sampling criterion of possible mitigated candidates for the quantum observables. We show that for favorable Hamiltonians the polynomial subset of BBGKY hierarchy equations leads to a polynomial overhead in both classical and quantum resources. We employ the method to mitigate simulations of the chiral magnetic effect (CME), a chiral feature of the Schwinger model. We empirically show the effectiveness of our scheme at recovering the real-time dynamics of the CME from noisy quantum simulations of the Schwinger model, for a range of different parameter values of the model. We numerically demonstrate a systematic reduction of quantum noise, together with an increasing noise reduction capability as the amount of BBGKY constraints grows.

quant-ph

Distribution-Aware Tensor Decomposition for Compression of Convolutional Neural Networks

Neural networks are widely used for image-related tasks but typically demand considerable computing power. Once a network has been trained, however, its memory- and compute-footprint can be reduced by compression. In this work, we focus on compression through tensorization and low-rank representations. Whereas classical approaches search for a low-rank approximation by minimizing an isotropic norm such as the Frobenius norm in weight-space, we use data-informed norms that measure the error in function space. Concretely, we minimize the change in the layer's output distribution, which can be expressed as $\lVert (W - \widetilde{W}) Σ^{1/2}\rVert_F$ where $Σ^{1/2}$ is the square root of the covariance matrix of the layer's input and $W$, $\widetilde{W}$ are the original and compressed weights. We propose new alternating least square algorithms for the two most common tensor decompositions (Tucker-2 and CPD) that directly optimize the new norm. Unlike conventional compression pipelines, which almost always require post-compression fine-tuning, our data-informed approach often achieves competitive accuracy without any fine-tuning. We further show that the same covariance-based norm can be transferred from one dataset to another with only a minor accuracy drop, enabling compression even when the original training dataset is unavailable. Experiments on several CNN architectures (ResNet-18/50, and GoogLeNet) and datasets (ImageNet, FGVC-Aircraft, Cifar10, and Cifar100) confirm the advantages of the proposed method.

cs.LG

PoTS: Proof-of-Training-Steps for Backdoor Detection in Large Language Models

As Large Language Models (LLMs) gain traction across critical domains, ensuring secure and trustworthy training processes has become a major concern. Backdoor attacks, where malicious actors inject hidden triggers into training data, are particularly insidious and difficult to detect. Existing post-training verification solutions like Proof-of-Learning are impractical for LLMs due to their requirement for full retraining, lack of robustness against stealthy manipulations, and inability to provide early detection during training. Early detection would significantly reduce computational costs. To address these limitations, we introduce Proof-of-Training Steps, a verification protocol that enables an independent auditor (Alice) to confirm that an LLM developer (Bob) has followed the declared training recipe, including data batches, architecture, and hyperparameters. By analyzing the sensitivity of the LLMs' language modeling head (LM-Head) to input perturbations, our method can expose subtle backdoor injections or deviations in training. Even with backdoor triggers in up to 10 percent of the training data, our protocol significantly reduces the attacker's ability to achieve a high attack success rate (ASR). Our method enables early detection of attacks at the injection step, with verification steps being 3x faster than training steps. Our results highlight the protocol's potential to enhance the accountability and security of LLM development, especially against insider threats.

cs.CR

BBGKY hierarchy for quantum error mitigation

Mitigation of quantum errors is critical for current NISQ devices. In the present work, we address this task by treating the execution of quantum algorithms as the time evolution of an idealized physical system. We use knowledge of its physics to assist the mitigation of the quantum noise produced on the real device. In particular, the time evolution of the idealized system obeys a corresponding BBGKY hierarchy of equations. This is the basis for the novel error mitigation scheme that we propose. Specifically, we employ a subset of the BBGKY hierarchy as supplementary constraints in the ZNE method for error mitigation. We ensure that the computational cost of the scheme scales polynomially with the system size. We test our method on digital quantum simulations of the lattice Schwinger model under noise levels mimicking realistic quantum hardware. We demonstrate that our scheme systematically improves the error mitigation for the measurements of the particle number and the charge within this system. Relative to ZNE we obtain an average reduction of the error by $(18.2 \pm 0.5)\%$ and $(52.8 \pm 6.3)\%$ for the respective above observables. We propose further applications of the BBGKY hierarchy for quantum error mitigation.

quant-ph

Quantum Error Mitigation by Global Randomized Error Cancellation for Adiabatic Evolution in the Schwinger Model

We extend the global randomized error cancellation (GREC) method for quantum error mitigation (QEM) in an application to adiabatic evolution of states on a noisy quantum device. We apply the adiabatic GREC method to the evolution of eigenstates in the lattice Schwinger model on a simulated quantum device with custom noise. Our results suggest that the corresponding QEM learned in one parameter regime of the model successfully transfers to a different parameter regime. In particular, our findings indicate that it transfers between different phases of the model. We observe that adiabatic GREC produces a smaller error than zero noise extrapolation (ZNE). Furthermore, in general, adiabatic GREC can be more cost-efficient in terms of the total number of gates used for the simulations. We comment on approaches to further reduce the necessary quantum computational resources. We also outline extensions of the introduced adiabatic GREC QEM method.

quant-ph

Phase Diagram of the Schwinger Model by Adiabatic Preparation of States on a Quantum Simulator

We argue the feasibility to study the phase structure of a quantum physical system on quantum devices via adiabatic preparation of states. We introduce a novel method and successfully test it in application to the Schwinger model in the presence of a topological $θ$-term. We explore the first-order-phase-transition and the no-transition regions of the corresponding phase diagram. The core idea of the method is to separately evolve the ground and the first excited states with a time-dependent Hamiltonian, the time-dependence of which interpolates between different values of $θ$. Despite our approach being a direct application of the adiabatic theorem, in some cases we are able to demonstrate its advantages in comparison to a different method from the literature that also employs adiabatic state preparation.

hep-lat

Universal Scale Laws for Colors and Patterns in Imagery

Distribution of colors and patterns in images is observed through cascades that adjust spatial resolution and dynamics. Cascades of colors reveal the emergent universal property that Fully Colored Images (FCIs) of natural scenes adhere to the debated continuous linear log-scale law (slope $-2.00 \pm 0.01$) (L1). Cascades of discrete $2 \times 2$ patterns are derived from pixel squares reductions onto the seven unlabeled rotation-free textures (0000, 0001, 0011, 0012, 0101, 0102, 0123). They exhibit an unparalleled universal entropy maximum of $1.74 \pm 0.013$ at some dynamics regardless of spatial scale (L2). Patterns also adhere to the Integral Fluctuation Theorem ($1.00 \pm 0.01$) (L3), pivotal in studies of chaotic systems. Images with fewer colors exhibit quadratic shift and bias from L1 and L3 but adhere to L2. Randomized Hilbert fractals FCIs better match the laws than basic-to-AI-based simulations. Those results are of interest in Neural Networks, out of equilibrium physics and spectral imagery.

cs.CV

Universal Robustness via Median Randomized Smoothing for Real-World Super-Resolution

Most of the recent literature on image Super-Resolution (SR) can be classified into two main approaches. The first one involves learning a corruption model tailored to a specific dataset, aiming to mimic the noise and corruption in low-resolution images, such as sensor noise. However, this approach is data-specific, tends to lack adaptability, and its accuracy diminishes when faced with unseen types of image corruptions. A second and more recent approach, referred to as Robust Super-Resolution (RSR), proposes to improve real-world SR by harnessing the generalization capabilities of a model by making it robust to adversarial attacks. To delve further into this second approach, our paper explores the universality of various methods for enhancing the robustness of deep learning SR models. In other words, we inquire: "Which robustness method exhibits the highest degree of adaptability when dealing with a wide range of adversarial attacks ?". Our extensive experimentation on both synthetic and real-world images empirically demonstrates that median randomized smoothing (MRS) is more general in terms of robustness compared to adversarial learning techniques, which tend to focus on specific types of attacks. Furthermore, as expected, we also illustrate that the proposed universal robust method enables the SR model to handle standard corruptions more effectively, such as blur and Gaussian noise, and notably, corruptions naturally present in real-world images. These results support the significance of shifting the paradigm in the development of real-world SR methods towards RSR, especially via MRS.

eess.IV

Functional renormalization group for multilinear disordered Langevin dynamics II: Revisiting the $p=2\,$ spin dynamics for Wigner and Wishart ensembles

In this paper, we investigate the large-time behavior for a slightly modified version of the standard p=2 soft spins dynamics model, including a quartic or higher potential. The equilibrium states of such a model correspond to an effective field theory, which has been recently considered as a novel paradigm for signal detection in data science based on the renormalization group argument. We consider a Langevin-like equation, including a disorder term that leaves in the Wigner or Wishart ensemble. Then we construct a nonperturbative renormalization group formalism valid in the large N limit, where eigenvalues distributions for the disorder can be replaced by their analytic limits, namely the Wigner and Marchenko-Pastur laws. One of the main advantages of this approach is that the interactions remain local in time, avoiding the non-locality arising from the approaches that integrate out the disorder at the partition function level.

hep-th

A Multiple-View Geometric Model for Specularity Prediction on General Curved Surfaces

Specularity prediction is essential to many computer vision applications, giving important visual cues usable in Augmented Reality (AR), Simultaneous Localisation and Mapping (SLAM), 3D reconstruction and material modeling. However, it is a challenging task requiring numerous information from the scene including the camera pose, the geometry of the scene, the light sources and the material properties. Our previous work addressed this task by creating an explicit model using an ellipsoid whose projection fits the specularity image contours for a given camera pose. These ellipsoid-based approaches belong to a family of models called JOint-LIght MAterial Specularity (JOLIMAS), which we have gradually improved by removing assumptions on the scene geometry. However, our most recent approach is still limited to uniformly curved surfaces. This paper generalises JOLIMAS to any surface geometry while improving the quality of specularity prediction, without sacrificing computation performances. The proposed method establishes a link between surface curvature and specularity shape in order to lift the geometric assumptions made in previous work. Contrary to previous work, our new model is built from a physics-based local illumination model namely Torrance-Sparrow, providing an improved reconstruction. Specularity prediction using our new model is tested against the most recent JOLIMAS version on both synthetic and real sequences with objects of various general shapes. Our method outperforms previous approaches in specularity prediction, including the real-time setup, as shown in the supplementary videos.

cs.CV

Self-Improving SLAM in Dynamic Environments: Learning When to Mask

Visual SLAM - Simultaneous Localization and Mapping - in dynamic environments typically relies on identifying and masking image features on moving objects to prevent them from negatively affecting performance. Current approaches are suboptimal: they either fail to mask objects when needed or, on the contrary, mask objects needlessly. Thus, we propose a novel SLAM that learns when masking objects improves its performance in dynamic scenarios. Given a method to segment objects and a SLAM, we give the latter the ability of Temporal Masking, i.e., to infer when certain classes of objects should be masked to maximize any given SLAM metric. We do not make any priors on motion: our method learns to mask moving objects by itself. To prevent high annotations costs, we created an automatic annotation method for self-supervised training. We constructed a new dataset, named ConsInv, which includes challenging real-world dynamic sequences respectively indoors and outdoors. Our method reaches the state of the art on the TUM RGB-D dataset and outperforms it on KITTI and ConsInv datasets.

cs.CV

A priori bounds and multiplicity results for slightly superlinear and sublinear elliptic p-Laplacian equations

We consider the following problem $ -Δ_{p}u= h(x,u) \mbox{ in }Ω$, $u\in W^{1,p}_{0}(Ω)$, where $Ω$ is a bounded domain in $\mathbb{R}^{N}$, $1 \frac{N}{p}$ and they are without sign condition. Firstly, we show a priori bound on solutions, then by using variational arguments, we prove the existence of at least two nonnegative solutions. One of the main difficulties is that the nonlinearity term $h(x,u)$ does not satisfy the standard Ambrosetti and Rabinowitz condition.

math.AP

EpipolarNVS: leveraging on Epipolar geometry for single-image Novel View Synthesis

Novel-view synthesis (NVS) can be tackled through different approaches, depending on the general setting: a single source image to a short video sequence, exact or noisy camera pose information, 3D-based information such as point clouds etc. The most challenging scenario, the one where we stand in this work, only considers a unique source image to generate a novel one from another viewpoint. However, in such a tricky situation, the latest learning-based solutions often struggle to integrate the camera viewpoint transformation. Indeed, the extrinsic information is often passed as-is, through a low-dimensional vector. It might even occur that such a camera pose, when parametrized as Euler angles, is quantized through a one-hot representation. This vanilla encoding choice prevents the learnt architecture from inferring novel views on a continuous basis (from a camera pose perspective). We claim it exists an elegant way to better encode relative camera pose, by leveraging 3D-related concepts such as the epipolar constraint. We, therefore, introduce an innovative method that encodes the viewpoint transformation as a 2D feature image. Such a camera encoding strategy gives meaningful insights to the network regarding how the camera has moved in space between the two views. By encoding the camera pose information as a finite number of coloured epipolar lines, we demonstrate through our experiments that our strategy outperforms vanilla encoding.

cs.CV

Pruning-based Topology Refinement of 3D Mesh using a 2D Alpha Mask

Image-based 3D reconstruction has increasingly stunning results over the past few years with the latest improvements in computer vision and graphics. Geometry and topology are two fundamental concepts when dealing with 3D mesh structures. But the latest often remains a side issue in the 3D mesh-based reconstruction literature. Indeed, performing per-vertex elementary displacements over a 3D sphere mesh only impacts its geometry and leaves the topological structure unchanged and fixed. Whereas few attempts propose to update the geometry and the topology, all need to lean on costly 3D ground-truth to determine the faces/edges to prune. We present in this work a method that aims to refine the topology of any 3D mesh through a face-pruning strategy that extensively relies upon 2D alpha masks and camera pose information. Our solution leverages a differentiable renderer that renders each face as a 2D soft map. Its pixel intensity reflects the probability of being covered during the rendering process by such a face. Based on the 2D soft-masks available, our method is thus able to quickly highlight all the incorrectly rendered faces for a given viewpoint. Because our module is agnostic to the network that produces the 3D mesh, it can be easily plugged into any self-supervised image-based (either synthetic or natural) 3D reconstruction pipeline to get complex meshes with a non-spherical topology.

cs.CV

Learning to Segment Dynamic Objects using SLAM Outliers

We present a method to automatically learn to segment dynamic objects using SLAM outliers. It requires only one monocular sequence per dynamic object for training and consists in localizing dynamic objects using SLAM outliers, creating their masks, and using these masks to train a semantic segmentation network. We integrate the trained network in ORB-SLAM 2 and LDSO. At runtime we remove features on dynamic objects, making the SLAM unaffected by them. We also propose a new stereo dataset and new metrics to evaluate SLAM robustness. Our dataset includes consensus inversions, i.e., situations where the SLAM uses more features on dynamic objects that on the static background. Consensus inversions are challenging for SLAM as they may cause major SLAM failures. Our approach performs better than the State-of-the-Art on the TUM RGB-D dataset in monocular mode and on our dataset in both monocular and stereo modes.

cs.CV