Skip to main content

Showing 1–19 of 19 results for author: Weng, T

Searching in archive stat. Search in all archives.
.
  1. arXiv:2411.01006  [pdf, other

    cs.LG stat.ML

    Abstracted Shapes as Tokens -- A Generalizable and Interpretable Model for Time-series Classification

    Authors: Yunshi Wen, Tengfei Ma, Tsui-Wei Weng, Lam M. Nguyen, Anak Agung Julius

    Abstract: In time-series analysis, many recent works seek to provide a unified view and representation for time-series across multiple domains, leading to the development of foundation models for time-series data. Despite diverse modeling techniques, existing models are black boxes and fail to provide insights and explanations about their representations. In this paper, we present VQShape, a pre-trained, ge… ▽ More

    Submitted 7 January, 2025; v1 submitted 1 November, 2024; originally announced November 2024.

    Comments: Published in Neural Information Processing Systems (NeurIPS) 2024

  2. arXiv:2312.10469  [pdf, other

    cs.LG stat.ML

    One step closer to unbiased aleatoric uncertainty estimation

    Authors: Wang Zhang, Ziwen Ma, Subhro Das, Tsui-Wei Weng, Alexandre Megretski, Luca Daniel, Lam M. Nguyen

    Abstract: Neural networks are powerful tools in various applications, and quantifying their uncertainty is crucial for reliable decision-making. In the deep learning field, the uncertainties are usually categorized into aleatoric (data) and epistemic (model) uncertainty. In this paper, we point out that the existing popular variance attenuation method highly overestimates aleatoric uncertainty. To address t… ▽ More

    Submitted 20 December, 2023; v1 submitted 16 December, 2023; originally announced December 2023.

  3. arXiv:2308.12820  [pdf, other

    cs.LG cs.CY stat.ML

    Prediction without Preclusion: Recourse Verification with Reachable Sets

    Authors: Avni Kothari, Bogdan Kulynych, Tsui-Wei Weng, Berk Ustun

    Abstract: Machine learning models are often used to decide who receives a loan, a job interview, or a public benefit. Models in such settings use features without considering their actionability. As a result, they can assign predictions that are fixed $-$ meaning that individuals who are denied loans and interviews are, in fact, precluded from access to credit and employment. In this work, we introduce a pr… ▽ More

    Submitted 1 May, 2024; v1 submitted 24 August, 2023; originally announced August 2023.

    Comments: ICLR 2024 Spotlight. The first two authors contributed equally

  4. arXiv:2111.06063  [pdf, other

    stat.ML cs.CV cs.LG math.OC

    On the Equivalence between Neural Network and Support Vector Machine

    Authors: Yilan Chen, Wei Huang, Lam M. Nguyen, Tsui-Wei Weng

    Abstract: Recent research shows that the dynamics of an infinitely wide neural network (NN) trained by gradient descent can be characterized by Neural Tangent Kernel (NTK) \citep{jacot2018neural}. Under the squared loss, the infinite-width NN trained by gradient descent with an infinitely small learning rate is equivalent to kernel regression with NTK \citep{arora2019exact}. However, the equivalence is only… ▽ More

    Submitted 7 July, 2022; v1 submitted 11 November, 2021; originally announced November 2021.

    Comments: 35th Conference on Neural Information Processing Systems (NeurIPS 2021)

  5. arXiv:2102.01208  [pdf, ps, other

    cs.LG stat.ML

    Fast Training of Provably Robust Neural Networks by SingleProp

    Authors: Akhilan Boopathy, Tsui-Wei Weng, Sijia Liu, Pin-Yu Chen, Gaoyuan Zhang, Luca Daniel

    Abstract: Recent works have developed several methods of defending neural networks against adversarial attacks with certified guarantees. However, these techniques can be computationally costly due to the use of certification during training. We develop a new regularizer that is both more efficient than existing certified defenses, requiring only one additional forward propagation through a network, and can… ▽ More

    Submitted 1 February, 2021; originally announced February 2021.

    Comments: Published at AAAI 2021

  6. arXiv:2010.06651  [pdf, other

    cs.LG stat.ML

    Higher-Order Certification for Randomized Smoothing

    Authors: Jeet Mohapatra, Ching-Yun Ko, Tsui-Wei Weng, Pin-Yu Chen, Sijia Liu, Luca Daniel

    Abstract: Randomized smoothing is a recently proposed defense against adversarial attacks that has achieved SOTA provable robustness against $\ell_2$ perturbations. A number of publications have extended the guarantees to other metrics, such as $\ell_1$ or $\ell_\infty$, by using different smoothing measures. Although the current framework has been shown to yield near-optimal $\ell_p$ radii, the total safet… ▽ More

    Submitted 13 October, 2020; originally announced October 2020.

    Comments: Accepted to NeurIPS2020(spotlight)

  7. arXiv:2008.01976  [pdf, other

    cs.LG cs.AI cs.CR stat.ML

    Robust Deep Reinforcement Learning through Adversarial Loss

    Authors: Tuomas Oikarinen, Wang Zhang, Alexandre Megretski, Luca Daniel, Tsui-Wei Weng

    Abstract: Recent studies have shown that deep reinforcement learning agents are vulnerable to small adversarial perturbations on the agent's inputs, which raises concerns about deploying such agents in the real world. To address this issue, we propose RADIAL-RL, a principled framework to train reinforcement learning agents with improved robustness against $l_p$-norm bounded adversarial attacks. Our framewor… ▽ More

    Submitted 10 November, 2021; v1 submitted 5 August, 2020; originally announced August 2020.

  8. arXiv:1908.06353  [pdf, other

    cs.LG stat.ML

    Verification of Neural Network Control Policy Under Persistent Adversarial Perturbation

    Authors: Yuh-Shyang Wang, Tsui-Wei Weng, Luca Daniel

    Abstract: Deep neural networks are known to be fragile to small adversarial perturbations. This issue becomes more critical when a neural network is interconnected with a physical system in a closed loop. In this paper, we show how to combine recent works on neural network certification tools (which are mainly used in static settings such as image classification) with robust control theory to certify a neur… ▽ More

    Submitted 17 August, 2019; originally announced August 2019.

  9. arXiv:1906.04214  [pdf, other

    cs.LG cs.CR cs.SI stat.ML

    Topology Attack and Defense for Graph Neural Networks: An Optimization Perspective

    Authors: Kaidi Xu, Hongge Chen, Sijia Liu, Pin-Yu Chen, Tsui-Wei Weng, Mingyi Hong, Xue Lin

    Abstract: Graph neural networks (GNNs) which apply the deep neural networks to graph data have achieved significant performance for the task of semi-supervised node classification. However, only few work has addressed the adversarial robustness of GNNs. In this paper, we first present a novel gradient-based attack method that facilitates the difficulty of tackling discrete graph data. When comparing to curr… ▽ More

    Submitted 14 October, 2019; v1 submitted 10 June, 2019; originally announced June 2019.

    Comments: Accepted by IJCAI 2019, the 28th International Joint Conference on Artificial Intelligence

    Journal ref: International Joint Conference on Artificial Intelligence (IJCAI-2019)

  10. arXiv:1905.07387  [pdf, other

    cs.LG cs.CR cs.CV stat.ML

    POPQORN: Quantifying Robustness of Recurrent Neural Networks

    Authors: Ching-Yun Ko, Zhaoyang Lyu, Tsui-Wei Weng, Luca Daniel, Ngai Wong, Dahua Lin

    Abstract: The vulnerability to adversarial attacks has been a critical issue for deep neural networks. Addressing this issue requires a reliable way to evaluate the robustness of a network. Recently, several methods have been developed to compute $\textit{robustness quantification}$ for neural networks, namely, certified lower bounds of the minimum adversarial perturbation. Such methods, however, were devis… ▽ More

    Submitted 17 May, 2019; originally announced May 2019.

    Comments: 10 pages, Ching-Yun Ko and Zhaoyang Lyu contributed equally, accepted to ICML 2019. Please see arXiv source codes for the appendix by clicking [Other formats]

  11. arXiv:1901.07648  [pdf, other

    math.OC cs.LG stat.ML

    Finite-Sum Smooth Optimization with SARAH

    Authors: Lam M. Nguyen, Marten van Dijk, Dzung T. Phan, Phuong Ha Nguyen, Tsui-Wei Weng, Jayant R. Kalagnanam

    Abstract: The total complexity (measured as the total number of gradient computations) of a stochastic first-order optimization algorithm that finds a first-order stationary point of a finite-sum smooth nonconvex objective function $F(w)=\frac{1}{n} \sum_{i=1}^n f_i(w)$ has been proven to be at least $Ω(\sqrt{n}/ε)$ for $n \leq \mathcal{O}(ε^{-2})$ where $ε$ denotes the attained accuracy… ▽ More

    Submitted 22 April, 2019; v1 submitted 22 January, 2019; originally announced January 2019.

  12. arXiv:1812.08329  [pdf, other

    cs.LG cs.CR stat.ML

    PROVEN: Certifying Robustness of Neural Networks with a Probabilistic Approach

    Authors: Tsui-Wei Weng, Pin-Yu Chen, Lam M. Nguyen, Mark S. Squillante, Ivan Oseledets, Luca Daniel

    Abstract: With deep neural networks providing state-of-the-art machine learning models for numerous machine learning tasks, quantifying the robustness of these models has become an important area of research. However, most of the research literature merely focuses on the \textit{worst-case} setting where the input of the neural network is perturbed with noises that are constrained within an $\ell_p$ ball; a… ▽ More

    Submitted 7 January, 2019; v1 submitted 18 December, 2018; originally announced December 2018.

    Comments: updated ref [25]

  13. arXiv:1811.12395  [pdf, other

    stat.ML cs.CR cs.LG

    CNN-Cert: An Efficient Framework for Certifying Robustness of Convolutional Neural Networks

    Authors: Akhilan Boopathy, Tsui-Wei Weng, Pin-Yu Chen, Sijia Liu, Luca Daniel

    Abstract: Verifying robustness of neural network classifiers has attracted great interests and attention due to the success of deep neural networks and their unexpected vulnerability to adversarial perturbations. Although finding minimum adversarial distortion of neural networks (with ReLU activations) has been shown to be an NP-complete problem, obtaining a non-trivial lower bound of minimum distortion as… ▽ More

    Submitted 29 November, 2018; originally announced November 2018.

    Comments: Accepted by AAAI 2019

  14. arXiv:1811.00866  [pdf, other

    cs.LG cs.CR stat.ML

    Efficient Neural Network Robustness Certification with General Activation Functions

    Authors: Huan Zhang, Tsui-Wei Weng, Pin-Yu Chen, Cho-Jui Hsieh, Luca Daniel

    Abstract: Finding minimum distortion of adversarial examples and thus certifying robustness in neural network classifiers for given data points is known to be a challenging problem. Nevertheless, recently it has been shown to be possible to give a non-trivial certified lower bound of minimum adversarial distortion, and some recent progress has been made towards this direction by exploiting the piece-wise li… ▽ More

    Submitted 2 November, 2018; originally announced November 2018.

    Comments: Accepted by NIPS 2018. Huan Zhang and Tsui-Wei Weng contributed equally

  15. arXiv:1810.08640  [pdf, ps, other

    cs.LG cs.CR stat.ML

    On Extensions of CLEVER: A Neural Network Robustness Evaluation Algorithm

    Authors: Tsui-Wei Weng, Huan Zhang, Pin-Yu Chen, Aurelie Lozano, Cho-Jui Hsieh, Luca Daniel

    Abstract: CLEVER (Cross-Lipschitz Extreme Value for nEtwork Robustness) is an Extreme Value Theory (EVT) based robustness score for large-scale deep neural networks (DNNs). In this paper, we propose two extensions on this robustness score. First, we provide a new formal robustness guarantee for classifier functions that are twice differentiable. We apply extreme value theory on the new formal robustness gua… ▽ More

    Submitted 19 October, 2018; originally announced October 2018.

    Comments: Accepted by GlobalSIP 2018. Tsui-Wei Weng and Huan Zhang contributed equally

  16. arXiv:1804.09699  [pdf, other

    stat.ML cs.CR cs.CV cs.LG

    Towards Fast Computation of Certified Robustness for ReLU Networks

    Authors: Tsui-Wei Weng, Huan Zhang, Hongge Chen, Zhao Song, Cho-Jui Hsieh, Duane Boning, Inderjit S. Dhillon, Luca Daniel

    Abstract: Verifying the robustness property of a general Rectified Linear Unit (ReLU) network is an NP-complete problem [Katz, Barrett, Dill, Julian and Kochenderfer CAV17]. Although finding the exact minimum adversarial distortion is hard, giving a certified lower bound of the minimum distortion is possible. Current available methods of computing such a bound are either time-consuming or delivering low qua… ▽ More

    Submitted 2 October, 2018; v1 submitted 25 April, 2018; originally announced April 2018.

    Comments: Tsui-Wei Weng and Huan Zhang contributed equally

  17. arXiv:1801.10578  [pdf, other

    stat.ML cs.CR cs.LG

    Evaluating the Robustness of Neural Networks: An Extreme Value Theory Approach

    Authors: Tsui-Wei Weng, Huan Zhang, Pin-Yu Chen, Jinfeng Yi, Dong Su, Yupeng Gao, Cho-Jui Hsieh, Luca Daniel

    Abstract: The robustness of neural networks to adversarial examples has received great attention due to security implications. Despite various attack approaches to crafting visually imperceptible adversarial examples, little has been developed towards a comprehensive measure of robustness. In this paper, we provide a theoretical justification for converting robustness analysis into a local Lipschitz constan… ▽ More

    Submitted 31 January, 2018; originally announced January 2018.

    Comments: Accepted by Sixth International Conference on Learning Representations (ICLR 2018). Tsui-Wei Weng and Huan Zhang contributed equally

  18. arXiv:1611.02256  [pdf, ps, other

    cs.CE math.NA stat.CO

    A Big-Data Approach to Handle Many Process Variations: Tensor Recovery and Applications

    Authors: Zheng Zhang, Tsui-Wei Weng, Luca Daniel

    Abstract: Fabrication process variations are a major source of yield degradation in the nano-scale design of integrated circuits (IC), microelectromechanical systems (MEMS) and photonic circuits. Stochastic spectral methods are a promising technique to quantify the uncertainties caused by process variations. Despite their superior efficiency over Monte Carlo for many design cases, these algorithms suffer fr… ▽ More

    Submitted 7 November, 2016; originally announced November 2016.

    Comments: 8 figures

    Journal ref: IEEE Transactions on Component, Packaging and Manufacturing Technology, 2017

  19. arXiv:1603.06119  [pdf, ps, other

    cs.CE math.PR stat.CO

    A Big-Data Approach to Handle Process Variations: Uncertainty Quantification by Tensor Recovery

    Authors: Zheng Zhang, Tsui-Wei Weng, Luca Daniel

    Abstract: Stochastic spectral methods have become a popular technique to quantify the uncertainties of nano-scale devices and circuits. They are much more efficient than Monte Carlo for certain design cases with a small number of random parameters. However, their computational cost significantly increases as the number of random parameters increases. This paper presents a big-data approach to solve high-dim… ▽ More

    Submitted 19 March, 2016; originally announced March 2016.

    Comments: 2016 IEEE 20th Workshop on Signal and Power Integrity (SPI), 8-11 May 2016, Turin, Italy