← Search

Mohammad Mahmoody

7 accepted papers

2022

On Optimal Learning Under Targeted Data Poisoning

NeurIPS 2022accept

Consider the task of learning a hypothesis class $\mathcal{H}$ in the presence of an adversary that can replace up to an $\eta$ fraction of the examples in the training set with arbitrary adversarial examples. The adversary aims to fail the learner on a particular target test point $x$ which is \emp…

Cited by 7SourcePDFScholar
2022

Overparameterization from Computational Constraints

NeurIPS 2022accept

Overparameterized models with millions of parameters have been hugely successful. In this work, we ask: can the need for large models be, at least in part, due to the \emph{computational} limitations of the learner? Additionally, we ask, is this situation exacerbated for \emph{robust} learning? We…

Cited by 3SourcePDFScholar
2021

A Separation Result Between Data-oblivious and Data-aware Poisoning Attacks

NeurIPS 2021poster

Poisoning attacks have emerged as a significant security threat to machine learning algorithms. It has been demonstrated that adversaries who make small changes to the training set, such as adding specially crafted data points, can hurt the performance of the output model. Most of these attacks requ…

Cited by 3SourcePDFScholar
2019

Empirically Measuring Concentration: Fundamental Limits on Intrinsic Robustness

NeurIPS 2019spotlight

Many recent works have shown that adversarial examples that fool classifiers can be found by minimally perturbing a normal input. Recent theoretical results, starting with Gilmer et al. (2018b), show that if the inputs are drawn from a concentrated metric probability space, then adversarial examples…

2018

Adversarial Risk and Robustness: General Definitions and Implications for the Uniform Distribution

NeurIPS 2018poster

We study adversarial perturbations when the instances are uniformly distributed over {0,1}^n. We study both "inherent" bounds that apply to any problem and any classifier for such a problem as well as bounds that apply to specific problems and specific hypothesis classes.

Cited by 95SourcePDFScholar