MetaCloak-JPEG uses a DiffJPEG layer with straight-through estimator inside a JPEG-aware EOT and curriculum meta-learning loop to produce l-inf bounded perturbations that retain 91.3% effectiveness after real JPEG compression.
Towards deep learning models resistant to adversarial attacks
4 Pith papers cite this work. Polarity classification is still indexing.
representative citing papers
The paper delivers the first comprehensive systematization of adversarial robustness in QML with new empirical tests showing an accuracy-robustness trade-off, amplitude encoding's vulnerability, and QML's greater susceptibility to evasion attacks than classical models.
The paper formalizes fixed-set worst-case corruption in PBE, implements corruption searches on a string DSL, and shows VPA recovers some margin-1 tasks but fails on public SyGuS where vote margins are near one.
An explainability-aware L0 penalty yields coherent counterfactual edits, and the same geometry defines a Tolerance-Region Confusion Matrix that quantifies class-to-class fragility under interpretable perturbations.
citing papers explorer
-
MetaCloak-JPEG: JPEG-Robust Adversarial Perturbation for Preventing Unauthorized DreamBooth-Based Deepfake Generation
MetaCloak-JPEG uses a DiffJPEG layer with straight-through estimator inside a JPEG-aware EOT and curriculum meta-learning loop to produce l-inf bounded perturbations that retain 91.3% effectiveness after real JPEG compression.
-
SoK: Critical Evaluation of Quantum Machine Learning for Adversarial Robustness
The paper delivers the first comprehensive systematization of adversarial robustness in QML with new empirical tests showing an accuracy-robustness trade-off, amplitude encoding's vulnerability, and QML's greater susceptibility to evasion attacks than classical models.
-
Fixed-Set Robustness in Programming by Example: Example Corruption and Semantic Partition Recovery
The paper formalizes fixed-set worst-case corruption in PBE, implements corruption searches on a string DSL, and shows VPA recovers some margin-1 tasks but fails on public SyGuS where vote margins are near one.
-
Optimized Instance Alteration for Explaining and Assessing Robustness of Classifiers
An explainability-aware L0 penalty yields coherent counterfactual edits, and the same geometry defines a Tolerance-Region Confusion Matrix that quantifies class-to-class fragility under interpretable perturbations.