Ambar Pal

dblp:170/0102 · DBLP profile ↗
← Back
8ranked-venue papers
5as first author
4since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 5 · 3 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5 · 2 first-author · 2 since 2021Theory of computation · 1 · 1 first-author · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Artificial intelligence
5 papers
Trustworthy machine learning · 57% Deep learning architectures and training · 20% Learning theory · 7%
Theoretical computer science
1 paper
Algorithmic game theory and mechanism design · 100%

Topics — the 13 heaviest of 13, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Machine learning › Trustworthy machine learning › robustness
adversarial robustness
1.122023
Adversarial Examples Might be Avoidable: The Role of Data Concentration in Adversarial Robustness · NeurIPS 2023
A Game Theoretic Analysis of Additive Adversarial Attacks and Defenses · NeurIPS 2020
Machine learning › Trustworthy machine learning
robustness
0.912025
Disentangling Safe and Unsafe Image Corruptions via Anisotropy and Locality · CVPR 2025
Machine learning › Trustworthy machine learning › robustness
adversarial examples
0.712023
Adversarial Examples Might be Avoidable: The Role of Data Concentration in Adversarial Robustness · NeurIPS 2023
Machine learning › Trustworthy machine learning › robustness
certified robustness
0.712023
Adversarial Examples Might be Avoidable: The Role of Data Concentration in Adversarial Robustness · NeurIPS 2023
Machine learning › Trustworthy machine learning › adversarial machine learning
adversarial defense
0.412020
A Game Theoretic Analysis of Additive Adversarial Attacks and Defenses · NeurIPS 2020
Machine learning › Deep learning architectures and training › regularization
dropout
0.412020
On the Regularization Properties of Structured Dropout · CVPR 2020
Knowledge, reasoning and agents › Multi-agent systems › game theory
game-theoretic equilibrium
0.412020
A Game Theoretic Analysis of Additive Adversarial Attacks and Defenses · NeurIPS 2020
Machine learning › Deep learning architectures and training
regularization
0.412020
On the Regularization Properties of Structured Dropout · CVPR 2020
Machine learning › Learning theory › statistical learning theory
regularization theory
0.412020
On the Regularization Properties of Structured Dropout · CVPR 2020
Machine learning › Deep learning architectures and training › regularization › dropout
structured dropout
0.412020
On the Regularization Properties of Structured Dropout · CVPR 2020
Algorithmic game theory and mechanism design › solution concepts in games › equilibrium concepts
nash equilibrium
0.412020
A Game Theoretic Analysis of Additive Adversarial Attacks and Defenses · NeurIPS 2020
Knowledge, reasoning and agents › Knowledge representation and reasoning
external knowledge
0.312017
An Empirical Evaluation of Visual Question Answering for Novel Objects · CVPR 2017
Computer vision › Vision and language
visual question answering
0.312017
An Empirical Evaluation of Visual Question Answering for Novel Objects · CVPR 2017

Methods — techniques the papers use, named apart from their topics

projected displacement · 0.9adversarial perturbation analysis · 0.9randomized smoothing · 0.9generalization bounds · 0.9fast gradient method · 0.9polyhedral certification · 0.7low-dimensional subspace structure · 0.7stochastic gradient descent · 0.4spectral k-support norm · 0.4multimodal learning · 0.3
YearPublicationVenuePosition
2025 Disentangling Safe and Unsafe Image Corruptions via Anisotropy and Locality
abstract
State-of-the-art machine learning systems are vulnerable to small perturbations to their input, where "small" is defined according to a threat model that assigns a positive threat to each perturbation. Most prior works define a task-agnostic, isotropic, and global threat, like the ℓpnorm, where the magnitude of the perturbation fully determines the degree of the threat and neither the direction of the attack nor its position in space matter. However, common corruptions in computer vision, such as blur, compression, or occlusions, are not well captured by such threat models. This paper proposes a novel threat model called ProjectedDisplacement (PD) to study robustness beyond existing isotropic and global threat models. The proposed threat model measures the threat of a perturbation via its alignment with unsafe directions, defined as directions in the input space along which a perturbation of sufficient magnitude changes the ground truth class label. Unsafe directions are identified locally for each input based on observed training data. In this way, the PD-threat model exhibits anisotropy and locality. Experiments on Imagenet-1k data indicate that, for any input, the set of perturbations with small PD threat includes safe perturbations of large ℓpnorm that preserve the true label, such as noise, blur and compression, while simultaneously excluding unsafe perturbations that alter the true label. Unlike perceptual threat models based on embeddings of large-vision models, the PD-threat model can be readily computed for arbitrary classification tasks without pre-training or finetuning. Further additional task information such as sensitivity to image regions or concept hierarchies can be easily integrated into the assessment of threat and thus the PD threat model presents practitioners with a flexible, task-driven threat specification that alleviates the limitations of ℓp-threat models.
Ramchandran Muthukumar, Ambar Pal, Jeremias Sulam, René Vidal
CVPR2
2024 A Fast Algorithm for Computing a Planar Support for Non-Piercing Rectangles
abstract
For a hypergraph ℋ = (X,ℰ) a support is a graph G on X such that for each E ∈ ℰ, the induced subgraph of G on the elements in E is connected. If G is planar, we call it a planar support. A set of axis parallel rectangles ℛ forms a non-piercing family if for any R₁, R₂ ∈ ℛ, R₁⧵R₂ is connected. Given a set P of n points in ℝ² and a set ℛ of m non-piercing axis-aligned rectangles, we give an algorithm for computing a planar support for the hypergraph (P,ℛ) in O(nlog² n + (n+m)log m) time, where each R ∈ ℛ defines a hyperedge consisting of all points of P contained in R.
Ambar Pal, Rajiv Raman 0001, Saurabh Ray, Karamjeet Singh 0002
ISAAC1
2023 Adversarial Examples Might be Avoidable: The Role of Data Concentration in Adversarial Robustness
abstract
The susceptibility of modern machine learning classifiers to adversarial examples has motivated theoretical results suggesting that these might be unavoidable. However, these results can be too general to be applicable to natural data distributions. Indeed, humans are quite robust for tasks involving vision. This apparent conflict motivates a deeper dive into the question: Are adversarial examples truly unavoidable? In this work, we theoretically demonstrate that a key property of the data distribution -- concentration on small-volume subsets of the input space -- determines whether a robust classifier exists. We further demonstrate that, for a data distribution concentrated on a union of low-dimensional linear subspaces, utilizing structure in data naturally leads to classifiers that enjoy data-dependent polyhedral robustness guarantees, improving upon methods for provable certification in certain regimes.
Ambar Pal, Jeremias Sulam, René Vidal
NeurIPS1
2021 Identifying Physically Realizable Triggers for Backdoored Face Recognition Networks
abstract
Backdoor attacks embed a hidden functionality into deep neural networks, causing the network to display anomalous behavior when activated by a predetermined pattern in the input (Trigger), while behaving well otherwise on public test data. Recent works have shown that backdoored face recognition (FR) systems can respond to natural-looking triggers like a particular pair of sunglasses. Such attacks pose a serious threat to the applicability of FR systems in high-security applications. We propose a novel technique to (1) detect whether an FR network is compromised with a natural, physically realizable trigger, and (2) identify such triggers given a compromised network. We demonstrate the effectiveness of our methods with a compromised FR network, where we are able to identify the trigger (e.g. green-sunglasses or redbowtie) with a top-5 accuracy of 74%, whereas a naïve brute force baseline achieves 56% accuracy.
Ankita Raj, Ambar Pal, Chetan Arora 0001
ICIP2
2020 On the Regularization Properties of Structured Dropout
abstract
Dropout and its extensions (e.g. DropBlock and DropConnect) are popular heuristics for training neural networks, which have been shown to improve generalization performance in practice. However, a theoretical understanding of their optimization and regularization properties remains elusive. Recent work shows that in the case of single hidden-layer linear networks, Dropout is a stochastic gradient descent method for minimizing a regularized loss, and that the regularizer induces solutions that are low-rank and balanced. In this work we show that for single hidden-layer linear networks, DropBlock induces spectral k-support norm regularization, and promotes solutions that are low-rank and have factors with equal norm. We also show that the global minimizer for DropBlock can be computed in closed form, and that DropConnect is equivalent to Dropout. We then show that some of these results can be extended to a general class of Dropout-strategies, and, with some assumptions, to deep non-linear networks when Dropout is applied to the last layer. We verify our theoretical claims and assumptions experimentally with commonly used network architectures.
Ambar Pal, Connor Lane, René Vidal, Benjamin D. Haeffele
CVPR1
2020 A Game Theoretic Analysis of Additive Adversarial Attacks and Defenses
abstract
Research in adversarial learning follows a cat and mouse game between attackers and defenders where attacks are proposed, they are mitigated by new defenses, and subsequently new attacks are proposed that break earlier defenses, and so on. However, it has remained unclear as to whether there are conditions under which no better attacks or defenses can be proposed. In this paper, we propose a game-theoretic framework for studying attacks and defenses which exist in equilibrium. Under a locally linear decision boundary model for the underlying binary classifier, we prove that the Fast Gradient Method attack and a Randomized Smoothing defense form a Nash Equilibrium. We then show how this equilibrium defense can be approximated given finitely many samples from a data-generating distribution, and derive a generalization bound for the performance of our approximation.
Ambar Pal, René Vidal
NeurIPS1
2018 Making Deep Neural Network Fooling Practical
abstract
With the success of deep neural networks (DNNs), the robustness of such models under adversarial or fooling attacks has become extremely important. It has been shown that a simple perturbation of the image, invisible to a human observer, is sufficient to fool a deep network. Building on top of such work, methods have been proposed to generate adversarial samples which are robust to natural perturbations (camera noise, rotation, shift, scaling etc.). In this paper, we review multiple such fooling algorithms and show that the generated adversarial samples exhibit distributions largely different from the true distribution of the training samples, and thus are easily detectable by a simple meta classifier. We argue that for truly practical DNN fooling, not only should the adversarial samples be robust against various distortions, but must also follow the training set distribution and be undetectable from such meta classifiers. Finally we propose a new adversarial sample generation technique that outperforms commonly known methods when evaluated simultaneously on robustness and detectability.
Ambar Pal, Chetan Arora 0001
ICIP1
2017 An Empirical Evaluation of Visual Question Answering for Novel Objects
abstract
We study the problem of answering questions about images in the harder setting, where the test questions and corresponding images contain novel objects, which were not queried about in the training data. Such setting is inevitable in real world–owing to the heavy tailed distribution of the visual categories, there would be some objects which would not be annotated in the train set. We show that the performance of two popular existing methods drop significantly (21–28%) when evaluated on novel objects cf. known objects. We propose methods which use large existing external corpora of (i) unlabeled text, i.e. books, and (ii) images tagged with classes, to achieve novel object based visual question answering. We systematically study both, an oracle case where the novel objects are known textually, as well as a fully automatic case without any explicit knowledge of the novel objects, but with the minimal assumption that the novel objects are semantically related to the existing objects in training. The proposed methods for novel object based visual question answering are modular and can potentially be used with many visual question answering architectures. We show consistent improvements with the two popular architectures and give qualitative analysis of the cases where the model does well and of those where it fails to bring improvements.
Santhosh K. Ramakrishnan, Ambar Pal, Anurag Mittal
CVPR2