← Search

Nurislam Tursynbek

3 accepted papers

2022

CC-CERT: A Probabilistic Approach to Certify General Robustness of Neural Networks

AAAI 2022technical

In safety-critical machine learning applications, it is crucial to defend models against adversarial attacks --- small modifications of the input that change the predictions. Besides rigorously studied $ell_p$-bounded additive perturbations, semantic perturbations (e.g. rotation, translation) raise…

2022

Smoothed Embeddings for Certified Few-Shot Learning

NeurIPS 2022accept

Randomized smoothing is considered to be the state-of-the-art provable defense against adversarial perturbations. However, it heavily exploits the fact that classifiers map input objects to class probabilities and do not focus on the ones that learn a metric space in which classification is performe…

2021

Adversarial Turing Patterns from Cellular Automata

AAAI 2021technical

State-of-the-art deep classifiers are intriguingly vulnerable to universal adversarial perturbations: single disturbances of small magnitude that lead to misclassification of most inputs. This phenomena may potentially result in a serious security problem. Despite the extensive research in this area…