← Search

Arjun Nitin Bhagoji

10 accepted papers

2023

Characterizing the Optimal $0-1$ Loss for Multi-class Classification with a Test-time Attacker

NeurIPS 2023spotlight

Finding classifiers robust to adversarial examples is critical for their safe deployment. Determining the robustness of the best possible classifier under a given threat model for a fixed data distribution and comparing it to that achieved by state-of-the-art training methods is thus an important di…

Cited by 4SourcePDFScholar
2022

Finding Naturally Occurring Physical Backdoors in Image Datasets

NeurIPS 2022accept

Extensive literature on backdoor poison attacks has studied attacks and defenses for backdoors using “digital trigger patterns.” In contrast, “physical backdoors” use physical objects as triggers, have only recently been identified, and are qualitatively different enough to resist most defenses tar…

Cited by 19SourcePDFScholar
2022

SparseFed: Mitigating Model Poisoning Attacks in Federated Learning with Sparsification

AISTATS 2022poster

Federated learning is inherently vulnerable to model poisoning attacks because its decentralized nature allows attackers to participate with compromised devices. In model poisoning attacks, the attacker reduces the model’s performance on targeted sub-tasks (e.g. classifying planes as birds) by uploa…

2022

Understanding Robust Learning through the Lens of Representation Similarities

NeurIPS 2022accept

Representation learning, \textit{i.e.} the generation of representations useful for downstream applications, is a task of fundamental importance that underlies much of the success of deep neural networks (DNNs). Recently, \emph{robustness to adversarial examples} has emerged as a desirable property…

2021

Backdoor Attacks Against Deep Learning Systems in the Physical World

CVPR 2021poster

Backdoor attacks embed hidden malicious behaviors into deep learning models, which only activate and cause misclassifications on model inputs containing a specific "trigger." Existing works on backdoor attacks and defenses, however, mostly focus on digital attacks that apply digitally generated patt…

Cited by 248PDFScholar
2021

Lower Bounds on Cross-Entropy Loss in the Presence of Test-time Adversaries

ICML 2021spotlight

Understanding the fundamental limits of robust supervised learning has emerged as a problem of immense interest, from both practical and theoretical standpoints. In particular, it is critical to determine classifier-agnostic bounds on the training loss to establish when learning is possible. In this…

2019

Analyzing Federated Learning through an Adversarial Lens

ICML 2019oral

Federated learning distributes model training among a multitude of agents, who, guided by privacy concerns, perform training using their local data but share only model parameter updates, for iterative aggregation at the server to train an overall global model. In this work, we explore how the feder…

2019

Lower Bounds on Adversarial Robustness from Optimal Transport

NeurIPS 2019poster

While progress has been made in understanding the robustness of machine learning classifiers to test-time adversaries (evasion attacks), fundamental questions remain unresolved. In this paper, we use optimal transport to characterize the maximum achievable accuracy in an adversarial classification s…

2018

Practical Black-box Attacks on Deep Neural Networks using Efficient Query Mechanisms

ECCV 2018poster

Existing black-box attacks on deep neural networks (DNNs) have largely focused on transferability, where an adversarial instance generated for a locally trained model can “transfer” to attack other learning models. In this paper, we propose novel Gradient Estimation black-box attacks for adversaries…

Cited by 325SourcePDFScholar