SearcharxivSearch

arXiv subjects

Pablo G. Arce

Publications and source records attributed to Pablo G. Arce.

4 recordsLinked to original sources

A unifying Bayesian framework for adversarial robustness

The vulnerability of machine learning models to adversarial attacks remains a critical societal security challenge. Traditional defenses, such as adversarial training, typically robustify models by minimizing a worst-case loss. These deterministic approaches do not account for uncertainty in the adversary's attack. While stochastic defenses placing a probability distribution on the adversary exist, they often lack statistical rigor and fail to make explicit their underlying assumptions. To resolve these issues, we introduce a formal Bayesian framework that models adversarial uncertainty through a stochastic channel, articulating all probabilistic assumptions. This yields two robustification strategies: a proactive defense enacted during training, aligned with adversarial training, and a reactive defense enacted during operations, aligned with adversarial purification. Several state-of-the-art defenses can be recovered as limiting cases of our model. We empirically validate our methodology, showcasing the benefits of explicitly modeling adversarial uncertainty.

stat.ML

Random points on $\mathbb{S}^3$ with small logarithmic energy

We analyse several constructions of random point sets on the sphere $\mathbb{S}^{3}\subset\mathbb{R}^4$ evaluating and comparing them through their discrete logarithmic energy: \begin{equation*} E_0(ω_N) = \sum_{\substack{i, j=1\\ i \neq j}}^{N} \log\frac{1}{\|x_i - x_j\|}, \; \text{ where}\; ω_N=\{x_1,\ldots,x_N\} \subset \mathbb{S}^3. \end{equation*} Using the Hopf fibration, we lift a range of well-distributed families of points from the $2$-dimensional sphere - including uniformly random points, antipodally symmetric sets, determinantal point processes, and the Diamond ensemble - to $\mathbb{S}^{3}$, in order to assess their energy performance. In particular, we carry out this asymptotic analysis for the Spherical ensemble (a well known determinantal point process on $\mathbb{S}^2$), obtaining as a result a family of points on the $3$-dimensional sphere whose logarithmic energy is asymptotically the lowest achieved to date. This, in turn, provides a new upper bound for the minimal logarithmic energy on $\mathbb{S}^3$. Although an analytic treatment of the lifted Diamond ensemble remains elusive, extensive simulations presented here show that its empirical energies lie below all other deterministic and non-deterministic constructions considered. Together, these results sharpen the quantitative link between potential-theoretic optima on $\mathbb{S}^{2}$ and $\mathbb{S}^{3}$ and provide both theoretical and numerical benchmarks for future work.

math.PR

Evasion Attacks Against Bayesian Predictive Models

There is an increasing interest in analyzing the behavior of machine learning systems against adversarial attacks. However, most of the research in adversarial machine learning has focused on studying weaknesses against evasion or poisoning attacks to predictive models in classical setups, with the susceptibility of Bayesian predictive models to attacks remaining underexplored. This paper introduces a general methodology for designing optimal evasion attacks against such models. We investigate two adversarial objectives: perturbing specific point predictions and altering the entire posterior predictive distribution. For both scenarios, we propose novel gradient-based attacks and study their implementation and properties in various computational setups.

stat.ML

Supporting product launching decisions with adversarial risk analysis

In a world of utility-driven marketing, each company acts as an adversary to other contenders, with all having competing interests. A major challenge for companies launching a new product is that, despite testing, flaws in their product can remain, potentially risking a loss in market share. However, delayed launch decisions can lead to losing first-mover advantages. Furthermore, each company generally has incomplete information on the launch strategy and the product quality of competing brands. From a buyer's perspective, along with the price, customers need to make their buying decisions based on noisy signals, e.g.\ regarding the quality of competing brands. This paper proposes how to support product launch decisions by a company in the presence of several competitors and multiple buyers, with the aid of adversarial risk analysis methods. We illustrate applications in two software launch cases that require deciding about timing, pricing, and quality, referring to single and multiple product purchases.

stat.AP