Skip to main content

Showing 1–10 of 10 results for author: Kumano, S

Searching in archive cs. Search in all archives.
.
  1. arXiv:2505.14042  [pdf, ps, other

    cs.LG cs.CV stat.ML

    Adversarially Pretrained Transformers may be Universally Robust In-Context Learners

    Authors: Soichiro Kumano, Hiroshi Kera, Toshihiko Yamasaki

    Abstract: Adversarial training is one of the most effective adversarial defenses, but it incurs a high computational cost. In this study, we show that transformers adversarially pretrained on diverse tasks can serve as robust foundation models and eliminate the need for adversarial training in downstream tasks. Specifically, we theoretically demonstrate that through in-context learning, a single adversarial… ▽ More

    Submitted 20 May, 2025; originally announced May 2025.

  2. arXiv:2505.14021  [pdf, ps, other

    cs.LG cs.CV stat.ML

    Adversarial Training from Mean Field Perspective

    Authors: Soichiro Kumano, Hiroshi Kera, Toshihiko Yamasaki

    Abstract: Although adversarial training is known to be effective against adversarial examples, training dynamics are not well understood. In this study, we present the first theoretical analysis of adversarial training in random deep neural networks without any assumptions on data distributions. We introduce a new theoretical framework based on mean field theory, which addresses the limitations of existing… ▽ More

    Submitted 20 May, 2025; originally announced May 2025.

    Comments: NeurIPS23

  3. arXiv:2410.23677  [pdf, other

    cs.LG cs.CV stat.ML

    Wide Two-Layer Networks can Learn from Adversarial Perturbations

    Authors: Soichiro Kumano, Hiroshi Kera, Toshihiko Yamasaki

    Abstract: Adversarial examples have raised several open questions, such as why they can deceive classifiers and transfer between different models. A prevailing hypothesis to explain these phenomena suggests that adversarial perturbations appear as random noise but contain class-specific features. This hypothesis is supported by the success of perturbation learning, where classifiers trained solely on advers… ▽ More

    Submitted 17 January, 2025; v1 submitted 31 October, 2024; originally announced October 2024.

    Comments: NeurIPS24

  4. arXiv:2406.02889  [pdf, other

    cs.CV

    Language-guided Detection and Mitigation of Unknown Dataset Bias

    Authors: Zaiying Zhao, Soichiro Kumano, Toshihiko Yamasaki

    Abstract: Dataset bias is a significant problem in training fair classifiers. When attributes unrelated to classification exhibit strong biases towards certain classes, classifiers trained on such dataset may overfit to these bias attributes, substantially reducing the accuracy for minority groups. Mitigation techniques can be categorized according to the availability of bias information (\ie, prior knowled… ▽ More

    Submitted 4 June, 2024; originally announced June 2024.

  5. arXiv:2402.10470  [pdf, other

    cs.LG cs.CV stat.ML

    Theoretical Understanding of Learning from Adversarial Perturbations

    Authors: Soichiro Kumano, Hiroshi Kera, Toshihiko Yamasaki

    Abstract: It is not fully understood why adversarial examples can deceive neural networks and transfer between different networks. To elucidate this, several studies have hypothesized that adversarial perturbations, while appearing as noises, contain class features. This is supported by empirical evidence showing that networks trained on mislabeled adversarial examples can still generalize well to correctly… ▽ More

    Submitted 16 February, 2024; originally announced February 2024.

    Comments: ICLR24

  6. arXiv:2402.02150  [pdf, other

    cs.CV cs.AI

    Data-Driven Prediction of Seismic Intensity Distributions Featuring Hybrid Classification-Regression Models

    Authors: Koyu Mizutani, Haruki Mitarai, Kakeru Miyazaki, Soichiro Kumano, Toshihiko Yamasaki

    Abstract: Earthquakes are among the most immediate and deadly natural disasters that humans face. Accurately forecasting the extent of earthquake damage and assessing potential risks can be instrumental in saving numerous lives. In this study, we developed linear regression models capable of predicting seismic intensity distributions based on earthquake parameters: location, depth, and magnitude. Because it… ▽ More

    Submitted 3 February, 2024; originally announced February 2024.

  7. arXiv:2209.02369  [pdf, other

    cs.CV

    Improving Robustness to Out-of-Distribution Data by Frequency-based Augmentation

    Authors: Koki Mukai, Soichiro Kumano, Toshihiko Yamasaki

    Abstract: Although Convolutional Neural Networks (CNNs) have high accuracy in image recognition, they are vulnerable to adversarial examples and out-of-distribution data, and the difference from human recognition has been pointed out. In order to improve the robustness against out-of-distribution data, we present a frequency-based data augmentation technique that replaces the frequency components with other… ▽ More

    Submitted 6 September, 2022; originally announced September 2022.

    Comments: ICIP 2022

  8. arXiv:2208.07565  [pdf, other

    cs.CV

    Prediction of Seismic Intensity Distributions Using Neural Networks

    Authors: Koyu Mizutani, Haruki Mitarai, Kakeru Miyazaki, Ryugo Shimamura, Soichiro Kumano, Toshihiko Yamasaki

    Abstract: The ground motion prediction equation is commonly used to predict the seismic intensity distribution. However, it is not easy to apply this method to seismic distributions affected by underground plate structures, which are commonly known as abnormal seismic distributions. This study proposes a hybrid of regression and classification approaches using neural networks. The proposed model treats the… ▽ More

    Submitted 16 August, 2022; originally announced August 2022.

    Comments: 2 pages, 2 figures, IEEE GCCE2022 accepted

  9. arXiv:2205.14629  [pdf, other

    cs.CV

    Superclass Adversarial Attack

    Authors: Soichiro Kumano, Hiroshi Kera, Toshihiko Yamasaki

    Abstract: Adversarial attacks have only focused on changing the predictions of the classifier, but their danger greatly depends on how the class is mistaken. For example, when an automatic driving system mistakes a Persian cat for a Siamese cat, it is hardly a problem. However, if it mistakes a cat for a 120km/h minimum speed sign, serious problems can arise. As a stepping stone to more threatening adversar… ▽ More

    Submitted 14 July, 2022; v1 submitted 29 May, 2022; originally announced May 2022.

    Comments: ICML Workshop 2022 on Adversarial Machine Learning Frontiers

  10. arXiv:2012.03843  [pdf, other

    cs.CV

    Are DNNs fooled by extremely unrecognizable images?

    Authors: Soichiro Kumano, Hiroshi Kera, Toshihiko Yamasaki

    Abstract: Fooling images are a potential threat to deep neural networks (DNNs). These images are not recognizable to humans as natural objects, such as dogs and cats, but are misclassified by DNNs as natural-object classes with high confidence scores. Despite their original design concept, existing fooling images retain some features that are characteristic of the target objects if looked into closely. Henc… ▽ More

    Submitted 26 March, 2022; v1 submitted 7 December, 2020; originally announced December 2020.