Government
On the Duality Between Sharpness-Aware Minimization and Adversarial Training
Zhang, Yihao, He, Hangzhou, Zhu, Jingyu, Chen, Huanran, Wang, Yifei, Wei, Zeming
Adversarial Training (AT), which adversarially perturb the input samples during training, has been acknowledged as one of the most effective defenses against adversarial attacks, yet suffers from inevitably decreased clean accuracy. Instead of perturbing the samples, Sharpness-Aware Minimization (SAM) perturbs the model weights during training to find a more flat loss landscape and improve generalization. However, as SAM is designed for better clean accuracy, its effectiveness in enhancing adversarial robustness remains unexplored. In this work, considering the duality between SAM and AT, we investigate the adversarial robustness derived from SAM. Intriguingly, we find that using SAM alone can improve adversarial robustness. To understand this unexpected property of SAM, we first provide empirical and theoretical insights into how SAM can implicitly learn more robust features, and conduct comprehensive experiments to show that SAM can improve adversarial robustness notably without sacrificing any clean accuracy, shedding light on the potential of SAM to be a substitute for AT when accuracy comes at a higher priority. Code is available at https://github.com/weizeming/SAM_AT.
Self-Consistency Training for Density-Functional-Theory Hamiltonian Prediction
Zhang, He, Liu, Chang, Wang, Zun, Wei, Xinran, Liu, Siyuan, Zheng, Nanning, Shao, Bin, Liu, Tie-Yan
Predicting the mean-field Hamiltonian matrix in density functional theory is a fundamental formulation to leverage machine learning for solving molecular science problems. Yet, its applicability is limited by insufficient labeled data for training. In this work, we highlight that Hamiltonian prediction possesses a self-consistency principle, based on which we propose self-consistency training, an exact training method that does not require labeled data. It distinguishes the task from predicting other molecular properties by the following benefits: (1) it enables the model to be trained on a large amount of unlabeled data, hence addresses the data scarcity challenge and enhances generalization; (2) it is more efficient than running DFT to generate labels for supervised training, since it amortizes DFT calculation over a set of queries. We empirically demonstrate the better generalization in data-scarce and out-of-distribution scenarios, and the better efficiency over DFT labeling. These benefits push forward the applicability of Hamiltonian prediction to an ever-larger scale.
RetrievalQA: Assessing Adaptive Retrieval-Augmented Generation for Short-form Open-Domain Question Answering
Zhang, Zihan, Fang, Meng, Chen, Ling
Adaptive retrieval-augmented generation (ARAG) aims to dynamically determine the necessity of retrieval for queries instead of retrieving indiscriminately to enhance the efficiency and relevance of the sourced information. However, previous works largely overlook the evaluation of ARAG approaches, leading to their effectiveness being understudied. This work presents a benchmark, RetrievalQA, comprising 1,271 short-form questions covering new world and long-tail knowledge. The knowledge necessary to answer the questions is absent from LLMs; therefore, external information must be retrieved to answer correctly. This makes RetrievalQA a suitable testbed to evaluate existing ARAG methods. We observe that calibration-based methods heavily rely on threshold tuning, while vanilla prompting is inadequate for guiding LLMs to make reliable retrieval decisions. Based on our findings, we propose Time-Aware Adaptive Retrieval (TA-ARE), a simple yet effective method that helps LLMs assess the necessity of retrieval without calibration or additional training. The dataset and code will be available at https://github.com/hyintell/RetrievalQA
Gaussian Copula Models for Nonignorable Missing Data Using Auxiliary Marginal Quantiles
Feldman, Joseph, Reiter, Jerome P., Kowal, Daniel R.
We present an approach for modeling and imputation of nonignorable missing data under Gaussian copulas. The analyst posits a set of quantiles of the marginal distributions of the study variables, for example, reflecting information from external data sources or elicited expert opinion. When these quantiles are accurately specified, we prove it is possible to consistently estimate the copula correlation and perform multiple imputation in the presence of nonignorable missing data. We develop algorithms for estimation and imputation that are computationally efficient, which we evaluate in simulation studies of multiple imputation inferences. We apply the model to analyze associations between lead exposure levels and end-of-grade test scores for 170,000 students in North Carolina. These measurements are not missing at random, as children deemed at-risk for high lead exposure are more likely to be measured. We construct plausible marginal quantiles for lead exposure using national statistics provided by the Centers for Disease Control and Prevention. Complete cases and missing at random analyses appear to underestimate the relationships between certain variables and end-of-grade test scores, while multiple imputation inferences under our model support stronger adverse associations between lead exposure and educational outcomes.
Reparameterization invariance in approximate Bayesian inference
Roy, Hrittik, Miani, Marco, Ek, Carl Henrik, Hennig, Philipp, Pförtner, Marvin, Tatzel, Lukas, Hauberg, Søren
Current approximate posteriors in Bayesian neural networks (BNNs) exhibit a crucial limitation: they fail to maintain invariance under reparameterization, i.e. BNNs assign different posterior densities to different parametrizations of identical functions. This creates a fundamental flaw in the application of Bayesian principles as it breaks the correspondence between uncertainty over the parameters with uncertainty over the parametrized function. In this paper, we investigate this issue in the context of the increasingly popular linearized Laplace approximation. Specifically, it has been observed that linearized predictives alleviate the common underfitting problems of the Laplace approximation. We develop a new geometric view of reparametrizations from which we explain the success of linearization. Moreover, we demonstrate that these reparameterization invariance properties can be extended to the original neural network predictive using a Riemannian diffusion process giving a straightforward algorithm for approximate posterior sampling, which empirically improves posterior fit.
Conformal Validity Guarantees Exist for Any Data Distribution (and How to Find Them)
Prinster, Drew, Stanton, Samuel, Liu, Anqi, Saria, Suchi
As artificial intelligence (AI) / machine learning (ML) gain widespread adoption, practitioners are increasingly seeking means to quantify and control the risk these systems incur. This challenge is especially salient when such systems have autonomy to collect their own data, such as in black-box optimization and active learning, where their actions induce sequential feedback-loop shifts in the data distribution. Conformal prediction is a promising approach to uncertainty and risk quantification, but prior variants' validity guarantees have assumed some form of ``quasi-exchangeability'' on the data distribution, thereby excluding many types of sequential shifts. In this paper we prove that conformal prediction can theoretically be extended to \textit{any} joint data distribution, not just exchangeable or quasi-exchangeable ones. Although the most general case is exceedingly impractical to compute, for concrete practical applications we outline a procedure for deriving specific conformal algorithms for any data distribution, and we use this procedure to derive tractable algorithms for a series of AI/ML-agent-induced covariate shifts. We evaluate the proposed algorithms empirically on synthetic black-box optimization and active learning tasks.
Employees Say OpenAI and Google DeepMind Are Hiding Dangers from the Public
A group of current and former employees at leading AI companies OpenAI and Google DeepMind published a letter on Tuesday warning against the dangers of advanced AI as they allege companies are prioritizing financial gains while avoiding oversight. Thirteen employees, eleven of which are current or former employees of OpenAI, the company behind ChatGPT, signed the letter entitled: "A Right to Warn about Advanced Artificial Intelligence." The two other signatories are current and former employees of Google DeepMind. The coalition cautions that AI systems are powerful enough to pose serious harms without proper regulation. "These risks range from the further entrenchment of existing inequalities, to manipulation and misinformation, to the loss of control of autonomous AI systems potentially resulting in human extinction," the letter says.
Microsoft announces layoffs and restructuring in its mixed reality division
Microsoft is laying off employees working on mixed reality as part of a restructuring of the division, CNBC has reported. The company will continue to sell the HoloLens 2 augmented reality (AR) headset, a key device produced by that department. "Earlier today we announced a restructuring of the Microsoft's Mixed Reality organization," a spokesperson told CNBC in an email. "We remain fully committed to the Department of Defense's IVAS program and will continue to deliver cutting edge technology to support our soldiers. In addition, we will continue to invest in W365 to reach the broader Mixed Reality hardware ecosystem. We will continue to sell HoloLens 2 while supporting existing HoloLens 2 customers and partners."
AI Is Your Coworker Now. Can You Trust It?
Generative AI tools such as OpenAI's ChatGPT and Microsoft's Copilot are rapidly evolving, fueling concerns that the technology could open the door to multiple privacy and security issues, particularly in the workplace. In May, privacy campaigners dubbed Microsoft's new Recall tool a potential "privacy nightmare" due to its ability to take screenshots of your laptop every few seconds. The feature has caught the attention of UK regulator the Information Commissioner's Office, which is asking Microsoft to reveal more about the safety of the product launching soon in its Copilot PCs. Concerns are also mounting over OpenAI's ChatGPT, which has demonstrated screenshotting abilities in its soon-to-launch macOS app that privacy experts say could result in the capture of sensitive data. The US House of Representatives has banned the use of Microsoft's Copilot among staff members after it was deemed by the Office of Cybersecurity to be a risk to users due to "the threat of leaking House data to non-House approved cloud services." Meanwhile, market analyst Gartner has cautioned that "using Copilot for Microsoft 365 exposes the risks of sensitive data and content exposure internally and externally."
Kamala, Dems talk about Trump 'weaponizing' DOJ. But guess who got there first?
Vice President Kamala Harris recently warned donors in San Diego that Donald Trump has "threatened to weaponize the Department of Justice against his political enemies" if elected. Does our clueless vice president not get that half the country believes the Biden-Harris White House has been doing exactly that for over three years? While Joe Biden prattles on about threats to democracy, his Department of Justice has created the ultimate threat to democracy -- ruthlessly waging war on MAGA Republicans, Catholics, pro-life advocates, parents' groups -- anyone and everyone who does not buy into their progressive agenda. It is not just the outrageous legal persecution of the former president – the four dubious cases brought against Trump, each less credible than the last. It is not just Trump's conviction on flimsy charges brought by a politically-motivated district attorney and overseen by a clearly conflicted judge. DOJ CLAIMS IT CAN'T RELEASE BIDEN-HUR INTERVIEW DUE TO THREAT OF AI DEEPFAKES It is also the pursuit and prosecution of Trump allies including Peter Navarro, Roger Stone, Paul Manafort, Rick Gates, George Papadopoulos, Allen Weisselberg and Steve Bannon, all of whom have been sentenced to time in prison.