Skip to main content

Showing 1–21 of 21 results for author: Kwiatkowska, M

Searching in archive stat. Search in all archives.
.
  1. arXiv:2405.08498  [pdf, other

    cs.LG stat.ML

    Learning Decision Policies with Instrumental Variables through Double Machine Learning

    Authors: Daqian Shao, Ashkan Soleymani, Francesco Quinzan, Marta Kwiatkowska

    Abstract: A common issue in learning decision-making policies in data-rich settings is spurious correlations in the offline dataset, which can be caused by hidden confounders. Instrumental variable (IV) regression, which utilises a key unconfounded variable known as the instrument, is a standard technique for learning causal relationships between confounded action, outcome, and context variables. Most recen… ▽ More

    Submitted 28 June, 2024; v1 submitted 14 May, 2024; originally announced May 2024.

    Comments: Accepted at ICML 2024

  2. arXiv:2304.08278  [pdf, ps, other

    cs.AI stat.ML

    Compositional Probabilistic and Causal Inference using Tractable Circuit Models

    Authors: Benjie Wang, Marta Kwiatkowska

    Abstract: Probabilistic circuits (PCs) are a class of tractable probabilistic models, which admit efficient inference routines depending on their structural properties. In this paper, we introduce md-vtrees, a novel structural formulation of (marginal) determinism in structured decomposable PCs, which generalizes previously proposed classes such as probabilistic sentential decision diagrams. Crucially, we s… ▽ More

    Submitted 17 April, 2023; originally announced April 2023.

    Comments: 30 pages, AISTATS 2023

  3. arXiv:2205.06127  [pdf, ps, other

    cs.LG stat.ML

    Sample Complexity Bounds for Robustly Learning Decision Lists against Evasion Attacks

    Authors: Pascale Gourdeau, Varun Kanade, Marta Kwiatkowska, James Worrell

    Abstract: A fundamental problem in adversarial machine learning is to quantify how much training data is needed in the presence of evasion attacks. In this paper we address this issue within the framework of PAC learning, focusing on the class of decision lists. Given that distributional assumptions are essential in the adversarial setting, we work with probability distributions on the input data that satis… ▽ More

    Submitted 12 May, 2022; originally announced May 2022.

    Comments: To appear in the proceedings of International Joint Conference on Artificial Intelligence (2022)

  4. arXiv:2204.14170  [pdf, other

    cs.LG cs.AI stat.ML

    Tractable Uncertainty for Structure Learning

    Authors: Benjie Wang, Matthew Wicker, Marta Kwiatkowska

    Abstract: Bayesian structure learning allows one to capture uncertainty over the causal directed acyclic graph (DAG) responsible for generating given data. In this work, we present Tractable Uncertainty for STructure learning (TRUST), a framework for approximate posterior inference that relies on probabilistic circuits as the representation of our posterior belief. In contrast to sample-based posterior appr… ▽ More

    Submitted 1 July, 2022; v1 submitted 29 April, 2022; originally announced April 2022.

    Comments: ICML 2022 (long talk); 20 pages

  5. arXiv:2104.03180  [pdf, other

    cs.LG stat.ML

    Adversarial Robustness Guarantees for Gaussian Processes

    Authors: Andrea Patane, Arno Blaas, Luca Laurenti, Luca Cardelli, Stephen Roberts, Marta Kwiatkowska

    Abstract: Gaussian processes (GPs) enable principled computation of model uncertainty, making them attractive for safety-critical applications. Such scenarios demand that GP decisions are not only accurate, but also robust to perturbations. In this paper we present a framework to analyse adversarial robustness of GPs, defined as invariance of the model's decision to bounded perturbations. Given a compact su… ▽ More

    Submitted 7 April, 2021; originally announced April 2021.

    Comments: Submitted for publication

  6. Assessing Robustness of Text Classification through Maximal Safe Radius Computation

    Authors: Emanuele La Malfa, Min Wu, Luca Laurenti, Benjie Wang, Anthony Hartshorn, Marta Kwiatkowska

    Abstract: Neural network NLP models are vulnerable to small modifications of the input that maintain the original meaning but result in a different prediction. In this paper, we focus on robustness of text classification against word substitutions, aiming to provide guarantees that the model prediction does not change if a word is replaced with a plausible alternative, such as a synonym. As a measure of rob… ▽ More

    Submitted 7 October, 2020; v1 submitted 1 October, 2020; originally announced October 2020.

    Comments: 12 pages + appendix

    Journal ref: EMNLP-Findings2020

  7. arXiv:2005.00178  [pdf, other

    cs.LG stat.ML

    On the Benefits of Invariance in Neural Networks

    Authors: Clare Lyle, Mark van der Wilk, Marta Kwiatkowska, Yarin Gal, Benjamin Bloem-Reddy

    Abstract: Many real world data analysis problems exhibit invariant structure, and models that take advantage of this structure have shown impressive empirical performance, particularly in deep learning. While the literature contains a variety of methods to incorporate invariance into models, theoretical understanding is poor and there is no way to assess when one method should be preferred over another. In… ▽ More

    Submitted 30 April, 2020; originally announced May 2020.

  8. arXiv:2004.10281  [pdf, other

    cs.LG stat.ML

    Probabilistic Safety for Bayesian Neural Networks

    Authors: Matthew Wicker, Luca Laurenti, Andrea Patane, Marta Kwiatkowska

    Abstract: We study probabilistic safety for Bayesian Neural Networks (BNNs) under adversarial input perturbations. Given a compact set of input points, $T \subseteq \mathbb{R}^m$, we study the probability w.r.t. the BNN posterior that all the points in $T$ are mapped to the same region $S$ in the output space. In particular, this can be used to evaluate the probability that a network sampled from the BNN is… ▽ More

    Submitted 18 June, 2020; v1 submitted 21 April, 2020; originally announced April 2020.

    Comments: UAI 2020; 13 pages, 5 figures, 1 table

  9. arXiv:2003.06016  [pdf, other

    cs.LG cs.AI stat.ML

    Invariant Causal Prediction for Block MDPs

    Authors: Amy Zhang, Clare Lyle, Shagun Sodhani, Angelos Filos, Marta Kwiatkowska, Joelle Pineau, Yarin Gal, Doina Precup

    Abstract: Generalization across environments is critical to the successful application of reinforcement learning algorithms to real-world challenges. In this paper, we consider the problem of learning abstractions that generalize in block MDPs, families of environments with a shared latent state space and dynamics structure over that latent space, but varying observations. We leverage tools from causal infe… ▽ More

    Submitted 11 June, 2020; v1 submitted 12 March, 2020; originally announced March 2020.

    Comments: Accepted to ICML 2020. 16 pages, 8 figures

  10. arXiv:1912.00071  [pdf, other

    cs.LG stat.ML

    Safety Guarantees for Planning Based on Iterative Gaussian Processes

    Authors: Kyriakos Polymenakos, Luca Laurenti, Andrea Patane, Jan-Peter Calliess, Luca Cardelli, Marta Kwiatkowska, Alessandro Abate, Stephen Roberts

    Abstract: Gaussian Processes (GPs) are widely employed in control and learning because of their principled treatment of uncertainty. However, tracking uncertainty for iterative, multi-step predictions in general leads to an analytically intractable problem. While approximation methods exist, they do not come with guarantees, making it difficult to estimate their reliability and to trust their predictions. I… ▽ More

    Submitted 7 September, 2020; v1 submitted 29 November, 2019; originally announced December 2019.

    Comments: An earlier version of this work presented in NeurIPS-2019 Workshop on Safety and Robustness in Decision Making. A shorter (but otherwise equivalent) paper was accepted to the 59th Conference on Decision and Control (CDC2020)

  11. arXiv:1909.09884  [pdf, other

    cs.LG stat.ML

    Uncertainty Quantification with Statistical Guarantees in End-to-End Autonomous Driving Control

    Authors: Rhiannon Michelmore, Matthew Wicker, Luca Laurenti, Luca Cardelli, Yarin Gal, Marta Kwiatkowska

    Abstract: Deep neural network controllers for autonomous driving have recently benefited from significant performance improvements, and have begun deployment in the real world. Prior to their widespread adoption, safety guarantees are needed on the controller behaviour that properly take account of the uncertainty within the model as well as sensor noise. Bayesian neural networks, which assume a prior over… ▽ More

    Submitted 21 September, 2019; originally announced September 2019.

    Comments: 7 pages, 3 figures, submitted to ICRA 2020

  12. arXiv:1909.05822  [pdf, other

    cs.LG cs.CC stat.ML

    On the Hardness of Robust Classification

    Authors: Pascale Gourdeau, Varun Kanade, Marta Kwiatkowska, James Worrell

    Abstract: It is becoming increasingly important to understand the vulnerability of machine learning models to adversarial attacks. In this paper we study the feasibility of robust learning from the perspective of computational learning theory, considering both sample and computational complexity. In particular, our definition of robust learnability requires polynomial sample complexity. We start with two ne… ▽ More

    Submitted 12 September, 2019; originally announced September 2019.

    Comments: To appear in the proceedings of Neural Information Processing Systems Conference (2019)

  13. arXiv:1905.11876  [pdf, other

    stat.ML cs.LG

    Adversarial Robustness Guarantees for Classification with Gaussian Processes

    Authors: Arno Blaas, Andrea Patane, Luca Laurenti, Luca Cardelli, Marta Kwiatkowska, Stephen Roberts

    Abstract: We investigate adversarial robustness of Gaussian Process Classification (GPC) models. Given a compact subset of the input space $T\subseteq \mathbb{R}^d$ enclosing a test point $x^*$ and a GPC trained on a dataset $\mathcal{D}$, we aim to compute the minimum and the maximum classification probability for the GPC over all the points in $T$. In order to do so, we show how functions lower- and upper… ▽ More

    Submitted 11 March, 2020; v1 submitted 28 May, 2019; originally announced May 2019.

    Comments: 10 pages, 6 figures + Supplementary Material

  14. arXiv:1903.01980  [pdf, other

    cs.LG cs.CV stat.ML

    Statistical Guarantees for the Robustness of Bayesian Neural Networks

    Authors: Luca Cardelli, Marta Kwiatkowska, Luca Laurenti, Nicola Paoletti, Andrea Patane, Matthew Wicker

    Abstract: We introduce a probabilistic robustness measure for Bayesian Neural Networks (BNNs), defined as the probability that, given a test point, there exists a point within a bounded set such that the BNN prediction differs between the two. Such a measure can be used, for instance, to quantify the probability of the existence of adversarial examples. Building on statistical verification techniques for pr… ▽ More

    Submitted 5 March, 2019; originally announced March 2019.

    Comments: 9 pages, 6 figures

  15. arXiv:1811.06817  [pdf, other

    cs.LG cs.CV stat.ML

    Evaluating Uncertainty Quantification in End-to-End Autonomous Driving Control

    Authors: Rhiannon Michelmore, Marta Kwiatkowska, Yarin Gal

    Abstract: A rise in popularity of Deep Neural Networks (DNNs), attributed to more powerful GPUs and widely available datasets, has seen them being increasingly used within safety-critical domains. One such domain, self-driving, has benefited from significant performance improvements, with millions of miles having been driven with no human intervention. Despite this, crashes and erroneous behaviours still oc… ▽ More

    Submitted 16 November, 2018; originally announced November 2018.

    Comments: 7 pages, 6 figures

  16. arXiv:1809.06452  [pdf, other

    cs.LG stat.ML

    Robustness Guarantees for Bayesian Inference with Gaussian Processes

    Authors: Luca Cardelli, Marta Kwiatkowska, Luca Laurenti, Andrea Patane

    Abstract: Bayesian inference and Gaussian processes are widely used in applications ranging from robotics and control to biological systems. Many of these applications are safety-critical and require a characterization of the uncertainty associated with the learning model and formal guarantees on its predictions. In this paper we define a robustness measure for Bayesian inference against input perturbations… ▽ More

    Submitted 24 October, 2018; v1 submitted 17 September, 2018; originally announced September 2018.

  17. arXiv:1807.03571  [pdf, other

    cs.LG cs.AI stat.ML

    A Game-Based Approximate Verification of Deep Neural Networks with Provable Guarantees

    Authors: Min Wu, Matthew Wicker, Wenjie Ruan, Xiaowei Huang, Marta Kwiatkowska

    Abstract: Despite the improved accuracy of deep neural networks, the discovery of adversarial examples has raised serious safety concerns. In this paper, we study two variants of pointwise robustness, the maximum safe radius problem, which for a given input sample computes the minimum distance to an adversarial example, and the feature robustness problem, which aims to quantify the robustness of individual… ▽ More

    Submitted 6 March, 2019; v1 submitted 10 July, 2018; originally announced July 2018.

    Journal ref: Theoretical Computer Science 807 (2020) 298-329

  18. arXiv:1805.02242  [pdf, other

    cs.LG cs.CV stat.ML

    Reachability Analysis of Deep Neural Networks with Provable Guarantees

    Authors: Wenjie Ruan, Xiaowei Huang, Marta Kwiatkowska

    Abstract: Verifying correctness of deep neural networks (DNNs) is challenging. We study a generic reachability problem for feed-forward DNNs which, for a given set of inputs to the network and a Lipschitz-continuous function over its outputs, computes the lower and upper bound on the function values. Because the network and the function are Lipschitz continuous, all values in the interval between the lower… ▽ More

    Submitted 6 May, 2018; originally announced May 2018.

    Comments: This is the long version of the conference paper accepted in IJCAI-2018. Github: https://github.com/TrustAI/DeepGO

  19. arXiv:1805.00089  [pdf, other

    cs.LG cs.SE stat.ML

    Concolic Testing for Deep Neural Networks

    Authors: Youcheng Sun, Min Wu, Wenjie Ruan, Xiaowei Huang, Marta Kwiatkowska, Daniel Kroening

    Abstract: Concolic testing combines program execution and symbolic analysis to explore the execution paths of a software program. This paper presents the first concolic testing approach for Deep Neural Networks (DNNs). More specifically, we formalise coverage criteria for DNNs that have been studied in the literature, and then develop a coherent method for performing concolic testing to increase test covera… ▽ More

    Submitted 4 August, 2018; v1 submitted 30 April, 2018; originally announced May 2018.

  20. arXiv:1804.05805  [pdf, other

    cs.LG cs.CR cs.CV stat.ML

    Global Robustness Evaluation of Deep Neural Networks with Provable Guarantees for the $L_0$ Norm

    Authors: Wenjie Ruan, Min Wu, Youcheng Sun, Xiaowei Huang, Daniel Kroening, Marta Kwiatkowska

    Abstract: Deployment of deep neural networks (DNNs) in safety- or security-critical systems requires provable guarantees on their correct behaviour. A common requirement is robustness to adversarial perturbations in a neighbourhood around an input. In this paper we focus on the $L_0$ norm and aim to compute, for a trained DNN and an input, the maximal radius of a safe norm ball around the input within which… ▽ More

    Submitted 20 November, 2018; v1 submitted 16 April, 2018; originally announced April 2018.

    Comments: 42 Pages, Github: https://github.com/TrustAI/L0-TRE

  21. arXiv:1610.06940  [pdf, other

    cs.AI cs.LG stat.ML

    Safety Verification of Deep Neural Networks

    Authors: Xiaowei Huang, Marta Kwiatkowska, Sen Wang, Min Wu

    Abstract: Deep neural networks have achieved impressive experimental results in image classification, but can surprisingly be unstable with respect to adversarial perturbations, that is, minimal changes to the input image that cause the network to misclassify it. With potential applications including perception modules and end-to-end controllers for self-driving cars, this raises concerns about their safety… ▽ More

    Submitted 5 May, 2017; v1 submitted 21 October, 2016; originally announced October 2016.

    Comments: To appear as invited paper at CAV 2017