Goto

Collaborating Authors

 Government


On the Adversarial Risk of Test Time Adaptation: An Investigation into Realistic Test-Time Data Poisoning

arXiv.org Artificial Intelligence

Test-time adaptation (TTA) updates the model weights during the inference stage using testing data to enhance generalization. Existing studies have shown that when TTA is updated with crafted adversarial test samples, also known as test-time poisoned data, the performance on benign samples can deteriorate. Nonetheless, the perceived adversarial risk may be overstated if the poisoned data is generated under overly strong assumptions. We then propose an effective and realistic attack method that better produces poisoned samples without access to benign samples, and derive an effective in-distribution attack objective. Our benchmarks of existing attack methods reveal that the TTA methods are more robust than previously believed. In addition, we analyze effective defense strategies to help develop adversarially robust TTA methods. Test-time adaptation (TTA) emerges as an effective measure to counter distribution shift at inference stage (Wang et al., 2020; Liu et al., 2021; Su et al., 2022; Song et al., 2023). Successful TTA methods leverage the testing data samples for self-training (Wang et al., 2020; Su et al., 2024b), distribution alignment Su et al. (2022); Liu et al. (2021) or prompt tuning (Gao et al., 2022). Consequently, this task is also referred to as Test-Time Data Poisoning (TTDP). The pioneering work DIA (Wu et al., 2023) introduced a poisoning approach by crafting malicious data with access to all benign samples within a minibatch, leveraging realtime model weights for explicit gradient computing, i.e., a white-box attack.


Teuken-7B-Base & Teuken-7B-Instruct: Towards European LLMs

arXiv.org Artificial Intelligence

We present two multilingual LLMs designed to embrace Europe's linguistic diversity by supporting all 24 official languages of the European Union. Trained on a dataset comprising around 60% non-English data and utilizing a custom multilingual tokenizer, our models address the limitations of existing LLMs that predominantly focus on English or a few high-resource languages. We detail the models' development principles, i.e., data composition, tokenizer optimization, and training methodologies. The models demonstrate competitive performance across multilingual benchmarks, as evidenced by their performance on European versions of ARC, HellaSwag, MMLU, and TruthfulQA.


Data-adaptive Differentially Private Prompt Synthesis for In-Context Learning

arXiv.org Machine Learning

Large Language Models (LLMs) rely on the contextual information embedded in examples/demonstrations to perform in-context learning (ICL). To mitigate the risk of LLMs potentially leaking private information contained in examples in the prompt, we introduce a novel data-adaptive differentially private algorithm called AdaDPSyn to generate synthetic examples from the private dataset and then use these synthetic examples to perform ICL. The objective of AdaDPSyn is to adaptively adjust the noise level in the data synthesis mechanism according to the inherent statistical properties of the data, thereby preserving high ICL accuracy while maintaining formal differential privacy guarantees. A key innovation in AdaDPSyn is the Precision-Focused Iterative Radius Reduction technique, which dynamically refines the aggregation radius - the scope of data grouping for noise addition - based on patterns observed in data clustering, thereby minimizing the amount of additive noise. We conduct extensive experiments on standard benchmarks and compare AdaDPSyn with DP few-shot generation algorithm (Tang et al., 2023). The experiments demonstrate that AdaDPSyn not only outperforms DP few-shot generation, but also maintains high accuracy levels close to those of non-private baselines, providing an effective solution for ICL with privacy protection.


Mitigating Suboptimality of Deterministic Policy Gradients in Complex Q-functions

arXiv.org Machine Learning

In reinforcement learning, off-policy actor-critic approaches like DDPG and TD3 are based on the deterministic policy gradient. Herein, the Q-function is trained from off-policy environment data and the actor (policy) is trained to maximize the Q-function via gradient ascent. We observe that in complex tasks like dexterous manipulation and restricted locomotion, the Q-value is a complex function of action, having several local optima or discontinuities. This poses a challenge for gradient ascent to traverse and makes the actor prone to get stuck at local optima. To address this, we introduce a new actor architecture that combines two simple insights: (i) use multiple actors and evaluate the Q-value maximizing action, and (ii) learn surrogates to the Q-function that are simpler to optimize with gradient-based methods. We evaluate tasks such as restricted locomotion, dexterous manipulation, and large discrete-action space recommender systems and show that our actor finds optimal actions more frequently and outperforms alternate actor architectures.


Drone swarms targeting US military bases are operated by 'mother ship' UFO, claims top Pentagon official

Daily Mail - Science & tech

A retired, senior Pentagon official has confirmed that UFO'mother ships' were spotted'releasing swarms of smaller craft' -- adding further mystery to the still-unexplained intrusions over multiple US military bases. His statements come amid the release of 50 pages of Air Force records related to provocative'drone' incursions, that one general calls'Close Encounters at Langley.' For at least 17 nights last December, swarms of noisy, small UFOs were seen at dusk'moving at rapid speeds' and displaying'flashing red, green, and white lights' penetrating the highly restricted airspace above Langley Air Force Base in Virginia. Senior ex-Pentagon security official Chris Mellon told DailyMail.com'Two of the notable aspects,' he said, 'are the fact our drone signal-jamming devices have proven ineffective and these craft are making no effort to remain concealed.'


Drone attack on Israel puts spotlight on Iron Dome's limitations

BBC News

Here in northern Israel we hear booms at regular intervals as Iron Dome intercept rockets that Hezbollah fires from southern Lebanon. Israel says it hits more than 90% of its targets. But Iron Dome works because Hezbollah's rockets are crude โ€“ and it's possible to calculate where it's rockets will go at take-off and then intercept them. Stopping drones is more complicated. And has in this war become a recurring problem.


Westminster's reliance on Elon Musk's X is 'totally wrong', says Labour MP

The Guardian

Westminster needs to wean itself off X, a close ally of Keir Starmer has said, as he suggested that Elon Musk was deliberately manipulating its algorithm to boost his own political and personal interests. Josh Simons, the MP for Makerfield and former head of the Starmerite thinktank Labour Together, said he believed the British political class was dangerously addicted to the platform, formerly known as Twitter. Simons maintains an active X profile, but says he is keen not to "overuse" it. His comments reflect a growing concern among Labour MPs about the impact of X after the summer's riots, during which misinformation spread rapidly on the platform. But they also threaten to exacerbate tensions between the government and the company, with Musk continuing to attack Starmer over ministers' response to the violence.


Navy parachutist crash-lands on mother and teenager during San Francisco performance: video

FOX News

Two people reportedly are injured after a Navy parachutist crash-landed during a performance in San Francisco. The accident happened Sunday at Marina Green after one of the six members of the Navy Leap Frogs parachute team appeared to miss the landing zone, according to KTVU. Footage taken of the incident shows a Navy parachutist with a banner attached to him crashing into a crowd of spectators. The mother and her child who were struck both suffered minor injuries, with the mother being taken to a hospital for further evaluation, the station added. "Our thoughts are with the individual and their family. Safety is our number one priority," the Navy told KTVU in a statement.


Hezbollah drone attack on Israeli base kills 4 soldiers

Al Jazeera

Hezbollah has carried out its deadliest attack against Israel since the latest escalation in fighting began, sending a'swarm' of drones to a military base and killing at least four soldiers. Here's what we know about the attack.


South Korea on alert as North 'to blow up border roads' amid drones dispute

Al Jazeera

South Korea's military has announced it is "fully ready" to respond amid reports that North Korean troops have been deployed to the border and are getting ready to blow up roads connecting the two nations along the heavily militarised dividing line. Tensions have escalated in recent days as the nuclear-armed North accused Seoul of flying drones over its capital to drop propaganda leaflets filled with "inflammatory rumours and rubbish", and warned that if another drone was detected, it would consider it "a declaration of war". South Korean military spokesman Lee Sung-jun told reporters in Seoul on Monday they are in "full readiness" against the possibility of "a provocation" after Pyongyang ordered artillery units along the border to open fire in case of an escalation. South Korean state news agency Yonhap also quoted Lee as saying the military found that the North is installing screens along the roads "to make preparations for the explosions". "It is possible for [North Korea's explosions] to take place as early as today [Monday]," he said.