EDBT 2026 Demo / reviewers in the wild / expert
Ambar Pal
dblp:170/0102
· DBLP profile ↗
8ranked-venue papers
5as first author
4since 2021 · last 2025
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 5 · 3 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5 · 2 first-author · 2 since 2021Theory of computation · 1 · 1 first-author · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Artificial intelligence
5 papers |
Trustworthy machine learning · 57% Deep learning architectures and training · 20% Learning theory · 7% | |
| Theoretical computer science
1 paper |
Algorithmic game theory and mechanism design · 100% |
Topics — the 13 heaviest of 13, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Machine learning › Trustworthy machine learning › robustness
adversarial robustness |
1.1 | 2 | 2023 | Adversarial Examples Might be Avoidable: The Role of Data Concentration in Adversarial Robustness · NeurIPS 2023 A Game Theoretic Analysis of Additive Adversarial Attacks and Defenses · NeurIPS 2020 |
Machine learning › Trustworthy machine learning
robustness |
0.9 | 1 | 2025 | Disentangling Safe and Unsafe Image Corruptions via Anisotropy and Locality · CVPR 2025 |
Machine learning › Trustworthy machine learning › robustness
adversarial examples |
0.7 | 1 | 2023 | Adversarial Examples Might be Avoidable: The Role of Data Concentration in Adversarial Robustness · NeurIPS 2023 |
Machine learning › Trustworthy machine learning › robustness
certified robustness |
0.7 | 1 | 2023 | Adversarial Examples Might be Avoidable: The Role of Data Concentration in Adversarial Robustness · NeurIPS 2023 |
Machine learning › Trustworthy machine learning › adversarial machine learning
adversarial defense |
0.4 | 1 | 2020 | A Game Theoretic Analysis of Additive Adversarial Attacks and Defenses · NeurIPS 2020 |
Machine learning › Deep learning architectures and training › regularization
dropout |
0.4 | 1 | 2020 | On the Regularization Properties of Structured Dropout · CVPR 2020 |
Knowledge, reasoning and agents › Multi-agent systems › game theory
game-theoretic equilibrium |
0.4 | 1 | 2020 | A Game Theoretic Analysis of Additive Adversarial Attacks and Defenses · NeurIPS 2020 |
Machine learning › Deep learning architectures and training
regularization |
0.4 | 1 | 2020 | On the Regularization Properties of Structured Dropout · CVPR 2020 |
Machine learning › Learning theory › statistical learning theory
regularization theory |
0.4 | 1 | 2020 | On the Regularization Properties of Structured Dropout · CVPR 2020 |
Machine learning › Deep learning architectures and training › regularization › dropout
structured dropout |
0.4 | 1 | 2020 | On the Regularization Properties of Structured Dropout · CVPR 2020 |
Algorithmic game theory and mechanism design › solution concepts in games › equilibrium concepts
nash equilibrium |
0.4 | 1 | 2020 | A Game Theoretic Analysis of Additive Adversarial Attacks and Defenses · NeurIPS 2020 |
Knowledge, reasoning and agents › Knowledge representation and reasoning
external knowledge |
0.3 | 1 | 2017 | An Empirical Evaluation of Visual Question Answering for Novel Objects · CVPR 2017 |
Computer vision › Vision and language
visual question answering |
0.3 | 1 | 2017 | An Empirical Evaluation of Visual Question Answering for Novel Objects · CVPR 2017 |
Methods — techniques the papers use, named apart from their topics
projected displacement · 0.9adversarial perturbation analysis · 0.9randomized smoothing · 0.9generalization bounds · 0.9fast gradient method · 0.9polyhedral certification · 0.7low-dimensional subspace structure · 0.7stochastic gradient descent · 0.4spectral k-support norm · 0.4multimodal learning · 0.3
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Disentangling Safe and Unsafe Image Corruptions via Anisotropy and LocalityabstractState-of-the-art machine learning systems are vulnerable to small perturbations to their input, where "small" is defined according to a threat model that assigns a positive threat to each perturbation. Most prior works define a task-agnostic, isotropic, and global threat, like the ℓpnorm, where the magnitude of the perturbation fully determines the degree of the threat and neither the direction of the attack nor its position in space matter. However, common corruptions in computer vision, such as blur, compression, or occlusions, are not well captured by such threat models. This paper proposes a novel threat model called ProjectedDisplacement (PD) to study robustness beyond existing isotropic and global threat models. The proposed threat model measures the threat of a perturbation via its alignment with unsafe directions, defined as directions in the input space along which a perturbation of sufficient magnitude changes the ground truth class label. Unsafe directions are identified locally for each input based on observed training data. In this way, the PD-threat model exhibits anisotropy and locality. Experiments on Imagenet-1k data indicate that, for any input, the set of perturbations with small PD threat includes safe perturbations of large ℓpnorm that preserve the true label, such as noise, blur and compression, while simultaneously excluding unsafe perturbations that alter the true label. Unlike perceptual threat models based on embeddings of large-vision models, the PD-threat model can be readily computed for arbitrary classification tasks without pre-training or finetuning. Further additional task information such as sensitivity to image regions or concept hierarchies can be easily integrated into the assessment of threat and thus the PD threat model presents practitioners with a flexible, task-driven threat specification that alleviates the limitations of ℓp-threat models. Ramchandran Muthukumar, Ambar Pal, Jeremias Sulam, René Vidal |
CVPR | 2 |
| 2024 | A Fast Algorithm for Computing a Planar Support for Non-Piercing RectanglesabstractFor a hypergraph ℋ = (X,ℰ) a support is a graph G on X such that for each E ∈ ℰ, the induced subgraph of G on the elements in E is connected. If G is planar, we call it a planar support. A set of axis parallel rectangles ℛ forms a non-piercing family if for any R₁, R₂ ∈ ℛ, R₁⧵R₂ is connected. Given a set P of n points in ℝ² and a set ℛ of m non-piercing axis-aligned rectangles, we give an algorithm for computing a planar support for the hypergraph (P,ℛ) in O(nlog² n + (n+m)log m) time, where each R ∈ ℛ defines a hyperedge consisting of all points of P contained in R. Ambar Pal, Rajiv Raman 0001, Saurabh Ray, Karamjeet Singh 0002 |
ISAAC | 1 |
| 2023 | Adversarial Examples Might be Avoidable: The Role of Data Concentration in Adversarial RobustnessabstractThe susceptibility of modern machine learning classifiers to adversarial examples has motivated theoretical results suggesting that these might be unavoidable. However, these results can be too general to be applicable to natural data distributions. Indeed, humans are quite robust for tasks involving vision. This apparent conflict motivates a deeper dive into the question: Are adversarial examples truly unavoidable?
In this work, we theoretically demonstrate that a key property of the data distribution -- concentration on small-volume subsets of the input space -- determines whether a robust classifier exists. We further demonstrate that, for a data distribution concentrated on a union of low-dimensional linear subspaces, utilizing structure in data naturally leads to classifiers that enjoy data-dependent polyhedral robustness guarantees, improving upon methods for provable certification in certain regimes. Ambar Pal, Jeremias Sulam, René Vidal |
NeurIPS | 1 |
| 2021 | Identifying Physically Realizable Triggers for Backdoored Face Recognition NetworksabstractBackdoor attacks embed a hidden functionality into deep neural networks, causing the network to display anomalous behavior when activated by a predetermined pattern in the input (Trigger), while behaving well otherwise on public test data. Recent works have shown that backdoored face recognition (FR) systems can respond to natural-looking triggers like a particular pair of sunglasses. Such attacks pose a serious threat to the applicability of FR systems in high-security applications. We propose a novel technique to (1) detect whether an FR network is compromised with a natural, physically realizable trigger, and (2) identify such triggers given a compromised network. We demonstrate the effectiveness of our methods with a compromised FR network, where we are able to identify the trigger (e.g. green-sunglasses or redbowtie) with a top-5 accuracy of 74%, whereas a naïve brute force baseline achieves 56% accuracy. Ankita Raj, Ambar Pal, Chetan Arora 0001 |
ICIP | 2 |
| 2020 | On the Regularization Properties of Structured DropoutabstractDropout and its extensions (e.g. DropBlock and DropConnect) are popular heuristics for training neural networks, which have been shown to improve generalization performance in practice. However, a theoretical understanding of their optimization and regularization properties remains elusive. Recent work shows that in the case of single hidden-layer linear networks, Dropout is a stochastic gradient descent method for minimizing a regularized loss, and that the regularizer induces solutions that are low-rank and balanced. In this work we show that for single hidden-layer linear networks, DropBlock induces spectral k-support norm regularization, and promotes solutions that are low-rank and have factors with equal norm. We also show that the global minimizer for DropBlock can be computed in closed form, and that DropConnect is equivalent to Dropout. We then show that some of these results can be extended to a general class of Dropout-strategies, and, with some assumptions, to deep non-linear networks when Dropout is applied to the last layer. We verify our theoretical claims and assumptions experimentally with commonly used network architectures. Ambar Pal, Connor Lane, René Vidal, Benjamin D. Haeffele |
CVPR | 1 |
| 2020 | A Game Theoretic Analysis of Additive Adversarial Attacks and DefensesabstractResearch in adversarial learning follows a cat and mouse game between attackers and defenders where attacks are proposed, they are mitigated by new defenses, and subsequently new attacks are proposed that break earlier defenses, and so on. However, it has remained unclear as to whether there are conditions under which no better attacks or defenses can be proposed. In this paper, we propose a game-theoretic framework for studying attacks and defenses which exist in equilibrium. Under a locally linear decision boundary model for the underlying binary classifier, we prove that the Fast Gradient Method attack and a Randomized Smoothing defense form a Nash Equilibrium. We then show how this equilibrium defense can be approximated given finitely many samples from a data-generating distribution, and derive a generalization bound for the performance of our approximation. Ambar Pal, René Vidal |
NeurIPS | 1 |
| 2018 | Making Deep Neural Network Fooling PracticalabstractWith the success of deep neural networks (DNNs), the robustness of such models under adversarial or fooling attacks has become extremely important. It has been shown that a simple perturbation of the image, invisible to a human observer, is sufficient to fool a deep network. Building on top of such work, methods have been proposed to generate adversarial samples which are robust to natural perturbations (camera noise, rotation, shift, scaling etc.). In this paper, we review multiple such fooling algorithms and show that the generated adversarial samples exhibit distributions largely different from the true distribution of the training samples, and thus are easily detectable by a simple meta classifier. We argue that for truly practical DNN fooling, not only should the adversarial samples be robust against various distortions, but must also follow the training set distribution and be undetectable from such meta classifiers. Finally we propose a new adversarial sample generation technique that outperforms commonly known methods when evaluated simultaneously on robustness and detectability. Ambar Pal, Chetan Arora 0001 |
ICIP | 1 |
| 2017 | An Empirical Evaluation of Visual Question Answering for Novel ObjectsabstractWe study the problem of answering questions about images in the harder setting, where the test questions and corresponding images contain novel objects, which were not queried about in the training data. Such setting is inevitable in real world–owing to the heavy tailed distribution of the visual categories, there would be some objects which would not be annotated in the train set. We show that the performance of two popular existing methods drop significantly (21–28%) when evaluated on novel objects cf. known objects. We propose methods which use large existing external corpora of (i) unlabeled text, i.e. books, and (ii) images tagged with classes, to achieve novel object based visual question answering. We systematically study both, an oracle case where the novel objects are known textually, as well as a fully automatic case without any explicit knowledge of the novel objects, but with the minimal assumption that the novel objects are semantically related to the existing objects in training. The proposed methods for novel object based visual question answering are modular and can potentially be used with many visual question answering architectures. We show consistent improvements with the two popular architectures and give qualitative analysis of the cases where the model does well and of those where it fails to bring improvements. Santhosh K. Ramakrishnan, Ambar Pal, Anurag Mittal |
CVPR | 2 |