REVIEW 3 major objections 6 minor 75 references
Adversarial Machine Learning Attacks on Financial Reporting via Maximum Violated Multi-Objective Attack
T0 review · 3 major / 6 minor · reviewed 2026-08-06 · deepseek-v4-flash
Pith's one-line read A new adversarial method called MVMO lets distressed firms raise reported earnings and lower their fraud-detection score at the same time.
desk verdict Genuinely new attack formulation for anti-correlated financial objectives, but the headline success rates rest on a perturbation algebra that doesn't articulate the balance sheet or cash-flow statement, so treat it as a proof-of-concept, not a proven real-world evasion risk. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing object is Algorithm 1, the MVMO update. Its defining loss is $L = \chi^\top \mathrm{Softmax}(\chi \cdot C)$, where $\chi$ is the vector of transformed objective changes $g(\Delta)=\operatorname{sign}(\Delta)\log(|\Delta|+1)$ relative to the original report and $C$ is an exaggeration constant. Because the softmax is close to one-hot, the gradient is spent almost entirely on whichever objective has improved least, which enforces the threat model's requirement that all targets must move in the correct direction. The projection $\pi(\cdot)$ keeps the solution inside the attack budget by limiting the relative change to any atom variable in the accounting hierarchy. A supporting theorem (Theorem 3.1) shows the year-over-year ratio objective is non-convex, since the diagonal of its Hessian can be negative, which justifies iterative gradient search rather than a closed-form solution.
What would settle it
Run the MVMO attack with the same objectives on a full double-entry accounting model that includes a cash-flow statement, sub-accounts for long-term debt and property, and no restatements of prior years: if the share of firm-years with both EPS up and M-score down falls to the roughly 14 percent level of standard PGD, the high success rate is an artifact of the simplified perturbation matrix.
Extended reading notes
Core claim
On the paper's own terms, the central discovery is that the Maximum Violated Multi-Objective (MVMO) attack lets a firm with access only to listed accounting reclassifications satisfy both anti-correlated goals at once: reported EPS goes up and the M-score goes down. The attack encodes the perturbations through a sparse matrix $M$ of dollar-for-dollar reclassifications among cost of goods sold, SG&A and staff expenses, inventory, current and long-term debt, receivables-backed phantom sales, property expenses, and depreciation. It then runs projected gradient descent on a loss that transforms each objective's change by $g(\Delta)=\operatorname{sign}(\Delta)\log(|\Delta|+1)$ and softmax-weights the objectives so that the least-improved target receives the most optimization effort. Across 979 firm-years drawn from confirmed-fraud companies, MVMO satisfies both objectives in 49.13 to 65.99 percent of firm-years depending on $\epsilon$, while the best standard PGD baseline satisfies at most 13.28 percent and simple weighted averages of the losses satisfy below 4 percent. With a third objective added (a second fraud model, the S-score), the method still satisfies all three in up to 62.7 percent of firm-years, and attacks trained against two objectives generalize to the third.
Load-bearing premise
The whole result rests on the matrix of perturbation strategies being a faithful and complete model of what a real fraudster can change under GAAP; if real manipulation requires offsetting entries, changes cash flows, or triggers audit scrutiny, the reported success rates overstate what an attacker can actually do.
Editorial extensions
If this is right
- A firm willing to commit fraud does not have to choose between inflating earnings and evading detection: in most firm-years both can be attacked together.
- Ratio-based fraud models in the M-score family are significantly more evadable than their long record of use would suggest, though success is well below the near-100 percent rates common in image-domain adversarial attacks.
- Regulators and auditors should treat a low M-score as only a weak signal when the firm controls the inputs, and the disclosed threat model can help direct scrutiny toward the cases where joint manipulation succeeds.
- The MVMO objective extends beyond two targets: adding the S-score as a third objective lowers the joint satisfaction rate only slightly, from roughly 66 to 63 percent at $\epsilon=40\%$.
- Standard multi-objective attacks, including weighted averages of losses, fail when objectives are anti-correlated and differ in scale; the softmax-gating principle rather than scale matching is what makes the attack work.
Reading between the lines
- Editorial inference: because the perturbation matrix treats several variables, such as long-term debt, as undecomposed atoms, real manipulation at the sub-account level may be even more powerful, making the paper's success rates a lower bound on attacker capability.
- Editorial inference: the mechanism is not finance-specific; any pair of regression objectives that are anti-correlated and differently scaled, such as raising a risk estimate while lowering a detection score, could be attacked with the same softmax-gated gradient update.
- Editorial inference: a natural next test is to add cash-flow consistency and an audit-scrutiny cost to the perturbation set; if MVMO still succeeds with those constraints, changing GAAP alone would not prevent this class of fraud.
- Editorial inference: the reported joint-success rate would likely drop if the attacker were forbidden from creating year-over-year volatility, since the paper itself notes that analysts punish volatile performance, and the current objective does not penalize such volatility.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper introduces Maximum Violated Multi-Objective (MVMO) attacks, an adversarial optimization method for financial reporting. The attacker perturbs 10-K line items, subject to a relative-change budget epsilon, with two anti-correlated objectives: increasing earnings per share (EPS) while decreasing the Beneish M-score fraud-detection score. The perturbation actions are encoded in a sparse matrix M of reclassification strategies (Section 3.1), and the optimization uses a softmax-weighted loss that focuses effort on the currently worse-satisfied objective (Equation 4, Algorithm 1). Experiments are run on 402 firms with confirmed fraud years, totaling 979 firm-years, comparing MVMO against several PGD baselines, SA-MOO, and a manifold-ELBO method. Table 2 reports that MVMO satisfies both objectives in 49–66% of firm-years depending on epsilon, versus under 14% for standard PGD variants; a three-objective extension adds the S-score fraud model (Table 3). The abstract and conclusion claim that in about 50% of cases a firm can inflate earnings by 100–200% while reducing fraud scores by 15%.
Significance. If the central claims hold, this is a useful contribution at the intersection of adversarial ML and forensic accounting: it studies an underexplored regression/multi-objective attack setting, uses real-world financial data, and evaluates against externally defined models (M-score, S-score, EPS) rather than a fitted surrogate, which keeps internal circularity low. The MVMO heuristic is simple and could be adopted by other multi-objective attack problems. The paper also gives a plausible explanation, via anti-correlated objectives and scale mismatch, for why standard PGD baselines underperform. However, the practical significance depends on two load-bearing points that need strengthening: the realism of the perturbation space under double-entry accounting, and the accuracy of the headline quantitative claims relative to the reported averages. A random baseline and uncertainty estimates are also needed before the absolute success-rate claims can be assessed.
major comments (3)
- [Abstract, §4 (Table 2), Conclusion] The headline claim that "in ≈50% of cases, a company could inflate their earnings by 100-200%, while simultaneously reducing their fraud scores by 15%" is not supported by the reported results. Table 2 reports mean EPS RPD values of 32.79–57.62% for MVMO across epsilon values, not 100–200%, and the mean M-score RPD reaches -15.54% only at the 40% epsilon setting. No conditional distribution, quantile table, or firm-year-level analysis is provided to show that the ≈50% satisfying subsample achieves 100–200% EPS inflation; the KDE in Figure 4 is not a substitute because it is a smoothed density over all firm-years, not a quantile of the satisfying subset. The abstract and conclusion should be revised to match the reported averages, or supplemented with the missing distributional evidence.
- [§3.1, Figure 2, §3.0.1] The perturbation space encoded in matrix M is not shown to be feasible under double-entry accounting, and several rows violate balance-sheet or cash-flow consistency. The SALE↔RECT "phantom sales" row increases assets and net income without any offsetting liability/equity entry or OANCF change; the XEQO↔PPEGT row capitalizes an expense without a cash or liability counterpart; and the depreciation row DP is unpaired, so it changes net income with no balancing item. Figure 2 explicitly omits retained earnings/equity and the cash-flow statement, and Section 3.0.1 concedes that the diagram is incomplete. Since the paper justifies the threat model by stating "By working with lawyers and professional accountants, we ensure our threat model is realistic," the authors should either enforce the full accounting identities (for example AT = LT + Equity and articulation with OANCF) and re-run the experiments, or provide external validation that the omitted entries do not affect the reported success rates. As written, the 49–66% success rates are upper bounds under an incompletely constrained action space.
- [§4, Tables 2 and 3] The central quantitative comparisons are reported as point estimates without any measure of uncertainty, and there is no random baseline. With 979 firm-years, bootstrap standard errors or confidence intervals are straightforward to compute and would let the reader judge whether the 49–66% MVMO success rates are distinguishable from random perturbations drawn from the same M-space at the same epsilon budget. Because the paper's core claim is the relative and absolute effectiveness of MVMO, the absence of error bars and a random control is a load-bearing gap.
minor comments (6)
- [§4, M-score definitions] In the TATA definition, the operating cash flow variable is written as ONCAF, but Table 1 defines OANCF as Operating Activities Net Cash; the notation should be harmonized.
- [Theorem 3.1] Theorem 3.1 states that the objective is "non-context" rather than "non-convex," and the Hessian expression contains an index mismatch (t−1 appears in a derivative with respect to β_i); please correct the statement and clarify the domain on which β_i can be negative.
- [Equation 4, Algorithm 1] The symbol C is called an "exaggeration constant" but is used inside Softmax(χ·C); please specify whether C is a temperature parameter and report how it was set, since Algorithm 1 only says it is initialized to 1 in the tests and no sensitivity analysis is given.
- [Abstract, §4] The abstract's "20× more satisfying attacks" is ambiguous: from Table 2, MVMO is about 18× better than PGD-Avg at 5% epsilon, but only about 3.7× better than PGD-EPS; please name the baseline used for the factor.
- [§2.1.3, §3.1] There are several small typos, e.g., "Benish's M-Score" should be "Beneish's M-Score" and "processional certified public accountants" should be "professional certified public accountants."
- [Table 3] The text after Table 3 refers to "MVMI-MS," which appears to be a typo for "MVMO-MS."
Circularity Check
No significant circularity; the MVMO results are an optimization evaluation against externally specified EPS and M-score formulas under an explicit threat model.
full rationale
The paper's central claim is an optimization result, not a fitted prediction. Equation 4 and Algorithm 1 define an attack objective over EPS and the Beneish M-score, both of which are externally specified formulas (Eqs. 2 and 3 with published coefficients); no parameter is estimated from the data and then presented as a predicted outcome. The success metric in Table 2 is the joint direction of change of these two external functions, and the baselines (PGD-M, PGD-EPS, PGD-Avg, SA-MOO, Manifold ELBO) are evaluated under the same threat model. The perturbation matrix M in Section 3.1 is a modeling assumption about feasible accounting moves, qualitatively validated by CPA/lawyer collaboration; it is not defined in terms of, nor fitted to, the M-score or EPS targets. The paper's own conclusion and Section 6 explicitly acknowledge that auditing, press scrutiny, and other non-ratio detection channels are outside the modeled attack, so the claim is appropriately scoped to the specific fraud-score models attacked. The self-citations ([51], [55]) appear in related-work framing and are not load-bearing for the algorithm's derivation or for the empirical success rates. I find no step in which a 'prediction' reduces by construction to its input, no fitted parameter renamed as a finding, and no uniqueness claim imported from the authors' prior work.
Assumptions & free parameters
free parameters (2)
- Exaggeration constant C =
1 (initialized in Algorithm 1, no sensitivity analysis)
- PGD iterations T and step size =
unspecified
assumptions (4)
- domain assumption The accounting hierarchy in Figure 2 is a sufficient representation of balance sheet and income statement relationships for the variables used.
- ad hoc to paper The five perturbation strategies in Section 3.1 are financially realistic and mutually compatible.
- domain assumption M-score and S-score coefficients from cited prior work are fixed and applied to perturbed reports without retraining or adaptation.
- domain assumption The Bao et al. dataset correctly labels fraud firm-years.
Cite this review
Pith. "Pith review of Adversarial Machine Learning Attacks on Financial Reporting via Maximum Violated Multi-Objective Attack." pith.science (2026). https://pith.science/paper/F2EFATUF
@misc{pith2026250705441,
author = {Pith},
title = {Pith review of: Adversarial Machine Learning Attacks on Financial Reporting via Maximum Violated Multi-Objective Attack},
year = {2026},
howpublished = {\url{https://pith.science/paper/F2EFATUF}},
note = {Machine review of arXiv:2507.05441}
}
abstract
Bad actors, primarily distressed firms, have the incentive and desire to manipulate their financial reports to hide their distress and derive personal gains. As attackers, these firms are motivated by potentially millions of dollars and the availability of many publicly disclosed and used financial modeling frameworks. Existing attack methods do not work on this data due to anti-correlated objectives that must both be satisfied for the attacker to succeed. We introduce Maximum Violated Multi-Objective (MVMO) attacks that adapt the attacker's search direction to find $20\times$ more satisfying attacks compared to standard attacks. The result is that in $\approx50\%$ of cases, a company could inflate their earnings by 100-200%, while simultaneously reducing their fraud scores by 15%. By working with lawyers and professional accountants, we ensure our threat model is realistic to how such frauds are performed in practice.
Figures
Reference graph
Works this paper leans on
-
[1]
Cornell Research Report On Enron 1998 | PDF | Enron | Discounted Cash Flow
1998. Cornell Research Report On Enron 1998 | PDF | Enron | Discounted Cash Flow. https://www.scribd.com/doc/66581069/Cornell-Research-Report-on- Enron-1998
-
[2]
Edward I. Altman. 1968. Financial Ratios, Discriminant Analysis and the Prediction of Corporate Bankruptcy. The Journal of Finance 23, 4 (1968), 589–609. https://doi.org/10.1111/j.1540-6261.1968.tb00843.x _eprint: https://onlinelibrary.wiley.com/doi/pdf/10.1111/j.1540-6261.1968.tb00843.x
-
[3]
Real Attackers Don’t Compute Gradients
Giovanni Apruzzese, Hyrum S. Anderson, Savino Dambra, David Freeman, Fabio Pierazzi, and Kevin Roundy. 2023. “Real Attackers Don’t Compute Gradients”: Bridging the Gap Between Adversarial ML Research and Practice. In 2023 IEEE Conference on Secure and Trustworthy Machine Learning (SaTML) . 339–364. https: //doi.org/10.1109/SaTML54575.2023.00031
arXiv 2023
-
[4]
Anish Athalye, Nicholas Carlini, and David Wagner. 2018. Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples. In International Conference on Machine Learning (ICML) . http://arxiv.org/abs/ 1802.00420 arXiv: 1802.00420
arXiv 2018
-
[5]
YANG BAO, BIN KE, BIN LI, Y. JULIA YU, and JIE ZHANG. 2020. Detecting Ac- counting Fraud in Publicly Traded U.S. Firms Using a Machine Learning Approach. Journal of Accounting Research 58, 1 (2020), 199–235. https://doi.org/10.1111/ 1475-679X.12292 arXiv:https://onlinelibrary.wiley.com/doi/pdf/10.1111/1475- 679X.12292
-
[6]
Nathalie Baracaldo, Bryant Chen, Heiko Ludwig, and Jaehoon Amir Safavi
-
[7]
Messod D. Beneish. 1997. Detecting GAAP violation: implications for assessing earnings management among firms with extreme financial performance. Journal of Accounting and Public Policy 16, 3 (Sept. 1997), 271–309. https://doi.org/10. 1016/S0278-4254(97)00023-9
work page 1997
-
[8]
Messod D. Beneish. 1999. The Detection of Earnings Manipulation. Financial Analysts Journal 55, 5 (Sept. 1999), 24–36. https://doi.org/10.2469/faj.v55.n5.2296 Publisher: Routledge _eprint: https://doi.org/10.2469/faj.v55.n5.2296
Show all 75 references
-
[9]
Beneish, Charles M
Messod D. Beneish, Charles M. C. Lee, and D. Craig Nichols. 2012. Fraud Detection and Expected Returns. https://doi.org/10.2139/ssrn.1998387
2012 doi
-
[10]
Beneish and Craig Nichols
Messod D. Beneish and Craig Nichols. 2007. The Predictable Cost of Earnings Manipulation. https://doi.org/10.2139/ssrn.1006840
2007 doi
-
[11]
Beneish and Craig Nichols
Messod D. Beneish and Craig Nichols. 2009. Identifying Overvalued Equity. https://doi.org/10.2139/ssrn.1134818
2009 doi
-
[12]
Battista Biggio, Giorgio Fumera, and Fabio Roli. 2014. Security evaluation of pattern classifiers under attack. IEEE Transactions on Knowledge and Data Engi- neering 26, 4 (2014), 984–996. https://doi.org/10.1109/TKDE.2013.57
2014 doi
-
[13]
Battista Biggio, Blaine Nelson, and Pavel Laskov. 2012. Poisoning Attacks Against Support Vector Machines. In Proceedings of the 29th International Coference on International Conference on Machine Learning. Omnipress, USA, 1467–1474. http: //dl.acm.org/citation.cfm?id=3042573....
2012
-
[14]
Battista Biggio and Fabio Roli. 2018. Wild patterns: Ten years after the rise of adversarial machine learning. Pattern Recognition 84 (Dec. 2018), 317–331. https://doi.org/10.1016/j.patcog.2018.07.023 arXiv: 1712.03141
2018 arXiv
-
[15]
Mathieu Blondel, Quentin Berthet, Marco Cuturi, Roy Frostig, Stephan Hoyer, Felipe Llinares-López, Fabian Pedregosa, and Jean-Philippe Vert. 2021. Efficient and Modular Implicit Differentiation. arXiv preprint arXiv:2105.15183 (2021)
2021 arXiv
-
[16]
James Bradbury, Roy Frostig, Peter Hawkins, Matthew James Johnson, Chris Leary, Dougal Maclaurin, George Necula, Adam Paszke, Jake VanderPlas, Skye Wanderman-Milne, and Qiao Zhang. 2018. JAX: composable transformations of Python+NumPy programs. http://github.com/google/jax
2018
- [17]
-
[18]
Anh Tuan Bui, Trung Le, He Zhao, Quan Hung Tran, Paul Montague, and Dinh Phung. 2023. Generating Adversarial Examples with Task Oriented Multi- Objective Optimization. Transactions on Machine Learning Research (2023). https://openreview.net/forum?id=2f81Q622ww
2023
-
[19]
Nicholas Carlini, Ariel Herbert-voss, Dawn Song, Florian Tramèr, Katherine Lee, Eric Wallace, Adam Roberts, Alina Oprea, Matthew Jagielski, Tom Brown, Colin Raffel, and Peter W. 2021. Extracting Training Data from Large Language Models. In USENIX Security. https://arxiv.org/ab...
2021 arXiv
-
[20]
Nicholas Carlini, Chang Liu, Jernej Kos, Úlfar Erlingsson, and Dawn Song. 2018. The Secret Sharer: Measuring Unintended Neural Network Memorization & Extracting Secrets. (2018). http://arxiv.org/abs/1802.08232 arXiv: 1802.08232
2018 arXiv
-
[21]
Nicholas Carlini and David Wagner. 2017. Towards Evaluating the Robustness of Neural Networks. In 2017 IEEE Symposium on Security and Privacy (SP) . IEEE, 39–57. https://doi.org/10.1109/SP.2017.49
2017 doi
- [22]
-
[23]
Nilanjana Das, Edward Raff, Aman Chadha, and Manas Gaur. 2025. Human- Readable Adversarial Prompts: An Investigation into LLM Vulnerabilities Using Situational Context. arXiv:2412.16359 [cs.CL] https://arxiv.org/abs/2412.16359
2025 arXiv
-
[24]
Dechow and Ilia D
Patricia M. Dechow and Ilia D. Dichev. 2002. The Quality of Accruals and Earnings: The Role of Accrual Estimation Errors. The Accounting Review 77, s-1 (March 2002), 35–59. https://doi.org/10.2308/accr.2002.77.s-1.35
2002 doi
-
[25]
Dechow, Richard G
Patricia M. Dechow, Richard G. Sloan, and Amy P. Sweeney. 1995. Detecting Earnings Management. The Accounting Review 70, 2 (1995), 193–225. https: //www.jstor.org/stable/248303 Publisher: American Accounting Association
1995
-
[26]
DeFond and James Jiambalvo
Mark L. DeFond and James Jiambalvo. 1994. Debt covenant violation and ma- nipulation of accruals. Journal of Accounting and Economics 17, 1 (Jan. 1994), 145–176. https://doi.org/10.1016/0165-4101(94)90008-6
1994 doi
-
[27]
Philip Doldo, Derek Everett, Amol Khanna, Andre T Nguyen, and Edward Raff
-
[28]
Rong-En Fan, Kai-Wei Chang, Cho-Jui Hsieh, Xiang-Rui Wang, and Chih-Jen Lin. 2008. LIBLINEAR: A Library for Large Linear Classification. The Journal of Machine Learning Research 9 (2008), 1871–1874
2008
-
[29]
Giuseppe Floris, Raffaele Mura, Luca Scionis, Giorgio Piras, Maura Pintor, Ambra Demontis, and Battista Biggio. 2023. Improving Fast Minimum-Norm Attacks with Hyperparameter Optimization. In ESANN 2023 proceesdings. 127–132. https: //doi.org/10.14428/esann/2023.ES2023-164 arXi...
2023 arXiv
-
[30]
Andrew Gelman. 2006. Prior distributions for variance parameters in hierarchical models (comment on article by Browne and Draper). Bayesian Analysis 1, 3 (Sept. 2006), 515–534. https://doi.org/10.1214/06-BA117A Publisher: International Society for Bayesian Analysis
2006 doi
-
[31]
Carlin, Hal S
Andrew Gelman, John B. Carlin, Hal S. Stern, David B Dunson, Aki Vehtari, and Donald B Rubin. 2013. Bayesian Data Analysis Third edition (with errors fixed as of 13 February 2020). February (2013), 677. ISBN: 978-1439840955
2013
-
[32]
Kavya Gupta, Beatrice Pesquet-Popescu, Fateh Kaakai, Jean-Christophe Pesquet, Fragkiskos D Malliaros, and Universite Paris-Saclay. 2021. An Adversarial At- tacker for Neural Networks in Regression Problems. Proceedings of the Workshop on Artificial Intelligence Safety 2021 co-...
2021
-
[33]
Paul M. Healy. 1985. The effect of bonus schemes on accounting decisions. Journal of Accounting and Economics 7, 1 (April 1985), 85–107. https://doi.org/ 10.1016/0165-4101(85)90029-1
1985 doi
-
[34]
Paul Hribar and Daniel W. Collins. 2002. Errors in Estimating Accru- als: Implications for Empirical Research. Journal of Accounting Research 40, 1 (2002), 105–134. https://doi.org/10.1111/1475-679X.00041 _eprint: https://onlinelibrary.wiley.com/doi/pdf/10.1111/1475-679X.00041
2002 doi
-
[35]
Henrik Höglund. 2012. Detecting earnings management with neural networks. Expert Systems with Applications 39, 10 (Aug. 2012), 9564–9570. https://doi.org/ 10.1016/j.eswa.2012.02.096
2012 doi
-
[36]
Jennifer J. Jones. 1991. Earnings Management During Import Relief Investigations. Journal of Accounting Research 29, 2 (1991), 193–228. https://doi.org/10.2307/ 2491047 Publisher: [Accounting Research Center, Booth School of Business, University of Chicago, Wiley]
1991
-
[37]
Amol Khanna, Fred Lu, and Edward Raff. 2025. Differentially Private Itera- tive Screening Rules for Linear Regression. In Proceedings of the Fifteenth ACM Conference on Data and Application Security and Privacy (Pittsburgh, PA, USA) (CODASPY ’25). Association for Computing Mac...
2025
-
[38]
Amol Khanna, Fred Lu, Edward Raff, and Brian Testa. 2023. Differentially Private Logistic Regression with Sparse Solutions. In Proceedings of the 16th ACM Workshop on Artificial Intelligence and Security (Copenhagen, Denmark) (AISec ’23) . Association for Computing Machinery, ...
2023
-
[39]
Amol Khanna, Edward Raff, and Nathan Inkawhich. 2024. SoK: A Review of Differentially Private Linear Models For High-Dimensional Data. In 2024 IEEE Conference on Secure and Trustworthy Machine Learning (SaTML) . 57–77. https: //doi.org/10.1109/SaTML59370.2024.00012
2024
-
[40]
Ashley Klein, Edward Raff, Elisabeth Seamon, Lily Foley, and Timothy Bussert
-
[41]
Xiangyin Kong and Zhiqiang Ge. 2023. Adversarial Attacks on Regression Sys- tems via Gradient Optimization.IEEE Transactions on Systems, Man, and Cybernet- ics: Systems 53, 12 (2023), 7827–7839. https://doi.org/10.1109/TSMC.2023.3302838
2023
-
[42]
Larcker and Anastasia A
David F. Larcker and Anastasia A. Zakolyukina. 2012. Detecting Decep- tive Discussions in Conference Calls. Journal of Accounting Research 50, 2 (2012), 495–540. https://doi.org/10.1111/j.1475-679X.2012.00450.x _eprint: https://onlinelibrary.wiley.com/doi/pdf/10.1111/j.1475-67...
2012 arXiv
-
[43]
Chang Liu, Bo Li, Yevgeniy Vorobeychik, and Alina Oprea. 2017. Robust Linear Regression Against Training Data Poisoning. In Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security. ACM, New York, NY, USA, 91–102. https://doi.org/10.1145/3128572.3140447 Ser...
2017
-
[44]
Fred Lu, Francis Ferraro, and Edward Raff. 2022. Continuously Generalized Ordinal Regression for Linear and Deep Models. InSIAM International Conference on Data Mining (SDM22) . http://arxiv.org/abs/2202.07005 arXiv: 2202.07005
2022 arXiv
-
[45]
Wanting Lu and Xiaokang Zhao. 2020. Research and improvement of fraud identification model of Chinese A-share listed companies based on M-score. Journal of Financial Crime 28, 2 (Jan. 2020), 566–579. https://doi.org/10.1108/JFC- 12-2019-0164 Publisher: Emerald Publishing Limited
2020 doi
-
[46]
Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018. Towards Deep Learning Models Resistant to Adversarial Attacks. In International Conference on Learning Representations (ICLR) . https: //openreview.net/forum?id=rJzIBfZAb arXiv: 1802.10217
2018 arXiv
-
[47]
Anay Mehrotra, Manolis Zampetakis, Paul Kassianik, Blaine Nelson, Hyrum Anderson, Yaron Singer, and Amin Karbasi. 2024. Tree of Attacks: Jail- breaking Black-Box LLMs Automatically. In Advances in Neural Informa- tion Processing Systems , A. Globerson, L. Mackey, D. Belgrave, ...
2024
-
[48]
Gregory S. Miller. 2006. The Press as a Watchdog for Accounting Fraud.Journal of Accounting Research 44, 5 (2006), 1001–1033. https://doi.org/10.1111/j.1475-679X. 2006.00224.x _eprint: https://onlinelibrary.wiley.com/doi/pdf/10.1111/j.1475- 679X.2006.00224.x
2006 arXiv
-
[49]
Niluh Putu Dian Rosalina Handayani Narsa, Lesta Mega Evi Afifa, and Okta- viani Ari Wardhaningrum. 2023. Fraud triangle and earnings management based on the modified M-score: A study on manufacturing company in Indonesia. Heliyon 9, 2 (Feb. 2023), e13649. https://doi.org/10.10...
2023 doi
-
[50]
Andrew Y. Ng. 2004. Feature selection, L1 vs. L2 regularization, and rotational invariance. Twenty-first international conference on Machine learning - ICML ’04 (2004), 78. https://doi.org/10.1145/1015330.1015435 Publisher: ACM Press Place: New York, New York, USA ISBN: 1581138285
2004
-
[51]
Nguyen and Edward Raff
Andre T. Nguyen and Edward Raff. 2019. Adversarial Attacks, Regression, and Numerical Stability Regularization. In The AAAI 2019 Workshop on Engineering Dependable and Secure Machine Learning Systems. arXiv. https://doi.org/10.48550/ arXiv.1812.02885 arXiv:1812.02885 [cs, stat]
-
[52]
Fabio Pierazzi, Feargus Pendlebury, Jacopo Cortellazzi, and Lorenzo Cavallaro
-
[53]
Piotroski
Joseph D. Piotroski. 2000. Value Investing: The Use of Historical Financial Statement Information to Separate Winners from Losers. Journal of Accounting Research 38 (2000), 1–41. https://doi.org/10.2307/2672906 Publisher: [Accounting Research Center, Booth School of Business, ...
2000 doi
-
[54]
Yao Qin, Nicholas Carlini, Garrison Cottrell, Ian Goodfellow, and Colin Raffel
-
[55]
Edward Raff, Michel Benaroch, and Andrew L. Farris. 2023. You Don’t Need Robust Machine Learning to Manage Adversarial Attack Risks. arXiv:2306.09951 [cs.LG] https://arxiv.org/abs/2306.09951
2023 arXiv
-
[56]
Edward Raff, Amol Khanna, and Fred Lu. 2023. Scaling Up Differentially Pri- vate LASSO Regularized Logistic Regression via Faster Frank-Wolfe Iterations. In Advances in Neural Information Processing Systems, A. Oh, T. Naumann, A. Glober- son, K. Saenko, M. Hardt, and S. Levine...
2023
-
[57]
Nguyen, and Edward Raff
Arash Rahnama, Andre T. Nguyen, and Edward Raff. 2020. Robust Design of Deep Neural Networks against Adversarial Attacks based on Lyapunov Theory. In The IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR) . 8178–8187. http://arxiv.org/abs/1911.04636 arXiv: 1...
2020 arXiv
-
[58]
Martínez-Romero, and Teresa Mariño-Garrido
Alicia Ramírez-Orellana, María J. Martínez-Romero, and Teresa Mariño-Garrido
-
[59]
Ribeiro and Thomas B
Antônio H. Ribeiro and Thomas B. Schön. 2023. Overparameterized Linear Regression Under Adversarial Attacks. IEEE Transactions on Signal Processing 71 (2023), 601–614. https://doi.org/10.1109/TSP.2023.3246228
2023
-
[60]
Rebecca L. Rosner. 2003. Earnings Manipulation in Failing Firms. Contemporary Accounting Research 20, 2 (2003), 361–408. https://doi.org/10.1506/8EVN-9KRB- 3AE4-EE81 _eprint: https://onlinelibrary.wiley.com/doi/pdf/10.1506/8EVN-9KRB- 3AE4-EE81
2003 doi
-
[61]
Donald B. Rubin. 1984. Bayesianly Justifiable and Relevant Frequency Calcu- lations for the Applied Statistician. The Annals of Statistics 12, 4 (Dec. 1984), 1151–1172. https://doi.org/10.1214/aos/1176346785 Publisher: Institute of Math- ematical Statistics
1984
-
[62]
Zakeya Sanad. 2021. Machine Learning and Earnings Management Detection. In The Big Data-Driven Digital Economy: Artificial and Computational Intelligence , Abdalmuttaleb M. A. Musleh Al-Sartawi (Ed.). Springer International Publishing, Cham, 77–83. https://doi.org/10.1007/978-...
2021 doi
-
[63]
Wharton Research Data Services. [n. d.]. Wharton Research Data Services. https: //wrds-www.wharton.upenn.edu/pages/
-
[64]
European Journal of Family Business 7, 1 (Jan 2017), 41–53
Measuring fraud and earnings management by a case of study: Evidence from an international family business. European Journal of Family Business 7, 1 (Jan 2017), 41–53. https://doi.org/10.1016/j.ejfb.2017.10.001
2017 doi
-
[65]
Charalambos T. Spathis. 2002. Detecting false financial statements using pub- lished data: some evidence from Greece. Managerial Auditing Journal 17, 4 (Jan. 2002), 179–191. https://doi.org/10.1108/02686900210424321 Publisher: MCB UP Ltd
2002 doi
-
[66]
Hervé Stolowy and Gaétan Breton. 2004. Accounts Manipulation: A Literature Review and Proposed Conceptual Framework. Review of Accounting and Finance 3, 1 (Jan. 2004), 5–92. https://doi.org/10.1108/eb043395 Publisher: Emerald Group Publishing Limited
2004 doi
-
[67]
Phoenix Neale Williams and Ke Li. 2023. Black-Box Sparse Adversarial Attack via Multi-Objective Optimisation. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition . 12291–12301
2023
-
[68]
Skyler Wu, Fred Lu, Edward Raff, and James Holt. 2024. Stabilizing Linear Passive-Aggressive Online Learning with Weighted Reservoir Sampling. In The Thirty-eighth Annual Conference on Neural Information Processing Systems . https: //openreview.net/forum?id=FNOBf6JM7r
2024
-
[69]
Zhaoyuan Yang, Zhiwei Xu, Jing Zhang, Richard Hartley, and Peter Tu. 2024. Adversarial Purification with the Manifold Hypothesis. Proceedings of the AAAI Conference on Artificial Intelligence 38, 15 (Mar. 2024), 16379–16387. https: //doi.org/10.1609/aaai.v38i15.29574
2024 doi
-
[70]
Simko, J.S
P.J. Simko, J.S. Wallace, and J. Comprix. 2020. Financial accounting for executives and MBAs. Cambridge Business Publishers. https://books.google.com/books? id=u-2NzQEACAAJ
2020
-
[76]
Hui Zou and Trevor Hastie. 2005. Regularization and variable selection via the elastic net. Journal of the Royal Statistical Society, Series B 67, 2 (April 2005), 301–320. https://doi.org/10.1111/j.1467-9868.2005.00503.x
2005
-
[2019]
InProceedings of the 36th International Conference on Machine Learning (Proceedings of Machine Learning Research, Vol
Imperceptible, Robust, and Targeted Adversarial Examples for Automatic Speech Recognition. InProceedings of the 36th International Conference on Machine Learning (Proceedings of Machine Learning Research, Vol. 97), Kamalika Chaudhuri and Ruslan Salakhutdinov (Eds.). PMLR, 5231...
-
[2020]
In 2020 IEEE Symposium on Security and Privacy (SP)
Intriguing Properties of Adversarial ML Attacks in the Problem Space. In 2020 IEEE Symposium on Security and Privacy (SP) . IEEE, 1332–1349. https: //doi.org/10.1109/SP40000.2020.00073
2020
-
[2024]
In 11th IEEE International Conference on Data Science and Advanced Analytics, DSAA 2024
More Options for Prelabor Rupture of Membranes, A Bayesian Analysis. In 11th IEEE International Conference on Data Science and Advanced Analytics, DSAA 2024. https://www.arxiv.org/abs/2408.10876 Best Paper Award
2024 arXiv
-
[2025]
In Proceedings of the Computer Vision and Pattern Recognition Conference (CVPR)
Stop Walking in Circles! Bailing Out Early in Projected Gradient Descent. In Proceedings of the Computer Vision and Pattern Recognition Conference (CVPR) . 6373–6382
Reviewed August 6, 2026 · model on record in the stance chip above.
Discussion (0). Sign in to comment.