Ismail Alkhouri

dblp:241/7238 · also Ismail R. Alkhouri · DBLP profile ↗
← Back
21ranked-venue papers
12as first author
19since 2021 · last 2026
0000-0002-5754-5509ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 15 · 7 first-author · 14 since 2021Graphics, computer vision, multimedia, augmented reality and games · 8 · 3 first-author · 7 since 2021Systems, architecture and hardware · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 On the Dataless Training of Neural Networks
abstract
This paper surveys studies on the use of neural networks for optimization in the training-data-free setting. Specifically, we examine the dataless application of neural network architectures in optimization by re-parameterizing problems using fully connected (or MLP), convolutional, graph, and quadratic neural networks. Although MLPs have been used to solve linear programs a few decades ago, this approach has recently gained increasing attention due to its promising results across diverse applications, including those based on combinatorial optimization, inverse problems, and partial differential equations. The motivation for this setting stems from two key (possibly over-lapping) factors: (i) data-driven learning approaches are still underdeveloped and have yet to demonstrate strong results, as seen in combinatorial optimization, and (ii) the availability of training data is inherently limited, such as in medical image reconstruction and other scientific applications. In this paper, we define the dataless setting and categorize it into two variants based on how a problem instance—defined by a single datum—is encoded onto the neural network: (i) architecture-agnostic methods and (ii) architecture-specific methods. Additionally, we discuss similarities and clarify distinctions between the dataless neural network (dNN) settings and related concepts such as zero-shot learning, one-shot learning, lifting in optimization, and over-parameterization.
Alvaro Velasquez, Susmit Jha, Ismail Alkhouri
AAAI3
2026 Robust Physics-Based Deep MRI Reconstruction via Diffusion Purification
abstract
Deep learning (DL) supervised techniques have been extensively employed in magnetic resonance imaging (MRI) reconstruction, delivering notable performance enhancements over traditional non-DL methods. Nonetheless, these models have vulnerabilities during testing such as their susceptibility to worst-case or noise-based measurement perturbations, variations in training/testing settings like acceleration factors, contrast, $k$ -space sampling locations, and distribution shifts stemming from unseen lesions and different anatomies. This article addresses these robustness challenges by leveraging diffusion models (DMs). In particular, we present a robustification strategy that improves the resilience of DL-based MRI reconstruction methods by utilizing pretrained DMs as purifiers. We dub our method as robust DL-based MRI with diffusion purification (RODIO). In contrast to conventional robustification methods for DL-based MRI reconstruction, such as adversarial training (AT), our proposed approach eliminates the need to tackle a minimax optimization problem. It only necessitates efficient fine-tuning on purified examples. Our experimental results underscore the effectiveness of our approach in addressing the mentioned instabilities, outperforming standalone diffusion-based MRI reconstructors and leading robustification methods for deep supervised MRI reconstruction, including AT and randomized smoothing (RS). Our experiments demonstrate: 1) the adaptability of our approach across multiple DL-based supervised MRI reconstruction models; 2) compatibility with accelerated diffusion-based samplers; 3) robustness to data with unseen lesions; and 4) effectiveness when applied to unsupervised single-shot generative reconstructors.
Ismail Alkhouri, Shijun Liang 0001, Qing Qu 0001, Saiprasad Ravishankar
IEEE Trans. Neural Networks Learn. Syst.1
2025 Sequential Diffusion-Guided Deep Image Prior for Medical Image Reconstruction
abstract
Deep learning (DL) methods have been extensively applied to various image recovery problems, including magnetic resonance imaging (MRI) and computed tomography (CT) reconstruction. Beyond supervised models, other approaches have been recently explored including two key recent schemes: deep image prior (DIP) that is an unsupervised scan-adaptive method that leverages the network architecture as implicit regularization but can suffer from noise over-fitting, and diffusion models (DMs), where the sampling procedure of a pre-trained generative model is modified to allow sampling from the measurement-conditioned distribution through approximations. In this paper, we propose combining DIP and DMs for MRI and CT reconstruction, motivated by (i) the impact of the DIP network input and (ii) the use of DMs as diffusion purifiers (DPs). Specifically, we propose a sequential procedure that iteratively optimizes the DIP network with a DM-refined adaptive input using a loss with data consistency and autoencoding terms. We term the approach Sequential Diffusion-Guided DIP (uDiG-DIP). Our experimental results demonstrate that uDiG-DIP achieves superior reconstruction results compared to leading DM-based baselines and the original DIP for MRI and CT tasks.
Shijun Liang 0001, Ismail Alkhouri, Qing Qu 0001, Saiprasad Ravishankar
ICASSP2
2025 Differentiable Quadratic Optimization For the Maximum Independent Set Problem
abstract
Combinatorial Optimization (CO) addresses many important problems, including the challenging Maximum Independent Set (MIS) problem. Alongside exact and heuristic solvers, differentiable approaches have emerged, often using continuous relaxations of quadratic objectives. Noting that an MIS in a graph is a Maximum Clique (MC) in its complement, we propose a new quadratic formulation for MIS by incorporating an MC term, improving convergence and exploration. We show that every maximal independent set corresponds to a local minimizer, derive conditions with respect to the MIS size, and characterize stationary points. To tackle the non-convexity of the objective, we propose optimizing several initializations in parallel using momentum-based gradient descent, complemented by an efficient MIS checking criterion derived from our theory. We dub our method as parallelized Clique-Informed Quadratic Optimization for MIS (pCQO-MIS). Our experimental results demonstrate the effectiveness of the proposed method compared to exact, heuristic, sampling, and data-centric approaches. Notably, our method avoids the out-of-distribution tuning and reliance on (un)labeled data required by data-centric methods, while achieving superior MIS sizes and competitive run-time relative to their inference time. Additionally, a key advantage of pCQO-MIS is that, unlike exact and heuristic solvers, the run-time scales only with the number of nodes in the graph, not the number of edges. Our code is available at the GitHub repository: https://github.com/ledenmat/pCQO-mis-benchmark/tree/refactor.
Ismail Alkhouri, Cedric Le Denmat, Cunxi Yu, Jia Liu 0002, Alvaro Velasquez
ICML1
2025 SITCOM: Step-wise Triple-Consistent Diffusion Sampling For Inverse Problems
abstract
Diffusion models (DMs) are a class of generative models that allow sampling from a distribution learned over a training set. When applied to solving inverse problems, the reverse sampling steps are modified to approximately sample from a measurement-conditioned distribution. However, these modifications may be unsuitable for certain settings (e.g., presence of measurement noise) and non-linear tasks, as they often struggle to correct errors from earlier steps and generally require a large number of optimization and/or sampling steps. To address these challenges, we state three conditions for achieving measurement-consistent diffusion trajectories. Building on these conditions, we propose a new optimization-based sampling method that not only enforces standard data manifold measurement consistency and forward diffusion consistency, as seen in previous studies, but also incorporates our proposed step-wise and network-regularized backward diffusion consistency that maintains a diffusion trajectory by optimizing over the input of the pre-trained model at every sampling step. By enforcing these conditions (implicitly or explicitly), our sampler requires significantly fewer reverse steps. Therefore, we refer to our method as **S**tep-w**i**se **T**riple-**Co**nsistent Sa**m**pling (**SITCOM**). Compared to SOTA baselines, our experiments across several linear and non-linear tasks (with natural and medical images) demonstrate that SITCOM achieves competitive or superior results in terms of standard similarity metrics and run-time.
Ismail Alkhouri, Shijun Liang 0001, Cheng-Han Huang, Jimmy Dai, Qing Qu 0001, Saiprasad Ravishankar
ICML1
2025 UGoDIT: Unsupervised Group Deep Image Prior Via Transferable Weights
abstract
Recent advances in data-centric deep generative models have led to significant progress in solving inverse imaging problems. However, these models (e.g., diffusion models (DMs)) typically require large amounts of fully sampled (clean) training data, which is often impractical in medical and scientific settings such as dynamic imaging. On the other hand, training-data-free approaches like the Deep Image Prior (DIP) do not require clean ground-truth images but suffer from noise overfitting and can be computationally expensive as the network parameters need to be optimized for each measurement vector independently. Moreover, DIP-based methods often overlook the potential of learning a prior using a small number of sub-sampled measurements (or degraded images) available during training. In this paper, we propose **UGoDIT**—an **U**nsupervised **G**r**o**up **DI**P with **T**ransferable weights—designed for the low-data regime where only a very small number, $M$, of sub-sampled measurement vectors are available during training. Our method learns a set of transferable weights by optimizing a shared encoder and $M$ disentangled decoders. At test time, we reconstruct the unseen degraded image using a DIP network, where part of the parameters are fixed to the learned weights, while the remaining are optimized to enforce measurement consistency. We evaluate \our on both medical (multi-coil MRI) and natural (super resolution and non-linear deblurring) image recovery tasks under various settings. Compared to recent standalone DIP methods, \our provides accelerated convergence and notable improvement in reconstruction quality. Furthermore, our method achieves performance competitive with SOTA DM-based and supervised approaches, despite not requiring large amounts of clean training data. Our code is available at: https://github.com/sjames40/UGoDIT.
Shijun Liang 0001, Ismail Alkhouri, Siddhant Gautam, Qing Qu 0001, Saiprasad Ravishankar
NeurIPS2
2024 Improving Training Efficiency of Diffusion Models via Multi-Stage Framework and Tailored Multi-Decoder Architecture
abstract
Diffusion models, emerging as powerful deep generative tools, excel in various applications. They operate through a two-steps process: introducing noise into training samples and then employing a model to convert random noise into new samples (e.g., images). However, their remarkable generative performance is hindered by slow training and sampling. This is due to the necessity of tracking extensive forward and reverse diffusion trajectories, and employing a large model with numerous parameters across multiple timesteps (i.e., noise levels). To tackle these challenges, we present a multi-stage framework inspired by our empirical findings. These observations indicate the advantages of employing distinct parameters tailored to each timestep while retaining universal parameters shared across all time steps. Our approach involves segmenting the time interval into multiple stages where we employ custom multi-decoder U-net architecture that blends time-dependent models with a universally shared encoder. Our framework enables the efficient distribution of computational resources and mitigates inter-stage interference, which substantially improves training efficiency. Extensive numerical experiments affirm the effectiveness of our framework, showcasing significant training and sampling efficiency enhancements on three state-of-the-art diffusion models, including large-scale latent diffusion models. Furthermore, our ablation studies illustrate the impact of two important components in our framework: (i) a novel timestep clustering algorithm for stage division, and (ii) an innovative multi-decoder U-net architecture, seamlessly integrating universal and customized hyperparameters.
Yifu Lu, Ismail Alkhouri, Saiprasad Ravishankar, Dogyoon Song, Qing Qu 0001
CVPR3
2024 Diffusion-Based Adversarial Purification for Robust Deep Mri Reconstruction
abstract
Deep learning (DL) methods have been extensively employed in magnetic resonance imaging (MRI) reconstruction, demonstrating remarkable performance improvements compared to traditional non-DL methods. However, recent studies have uncovered the susceptibility of these models to carefully engineered adversarial perturbations. In this paper, we tackle this issue by leveraging diffusion models. Specifically, we introduce a defense strategy that enhances the robustness of DL-based MRI reconstruction methods through the utilization of pre-trained diffusion models as adversarial purifiers. Unlike conventional state-of-the-art adversarial defense methods (e.g., adversarial training), our proposed approach eliminates the need to solve a minimax optimization problem to train the image reconstruction model from scratch, and only requires fine-tuning on purified adversarial examples. Our experimental findings underscore the effectiveness of our proposed technique when benchmarked against leading defense methodologies for MRI reconstruction such as adversarial training and randomized smoothing.
Ismail Alkhouri, Shijun Liang 0001, Qing Qu 0001, Saiprasad Ravishankar
ICASSP1
2024 Image Reconstruction Via Autoencoding Sequential Deep Image Prior
abstract
Recently, Deep Image Prior (DIP) has emerged as an effective unsupervised one-shot learner, delivering competitive results across various image recovery problems. This method only requires the noisy measurements and a forward operator, relying solely on deep networks initialized with random noise to learn and restore the structure of the data. However, DIP is notorious for its vulnerability to overfitting due to the overparameterization of the network. Building upon insights into the impact of the DIP input and drawing inspiration from the gradual denoising process in cutting-edge diffusion models, we introduce Autoencoding Sequential DIP (aSeqDIP) for image reconstruction. This method progressively denoises and reconstructs the image through a sequential optimization of network weights. This is achieved using an input-adaptive DIP objective, combined with an autoencoding regularization term. Compared to diffusion models, our method does not require training data and outperforms other DIP-based methods in mitigating noise overfitting while maintaining a similar number of parameter updates as Vanilla DIP. Through extensive experiments, we validate the effectiveness of our method in various image reconstruction tasks, such as MRI and CT reconstruction, as well as in image restoration tasks like image denoising, inpainting, and non-linear deblurring.
Ismail Alkhouri, Shijun Liang 0001, Evan Bell, Qing Qu 0001, Saiprasad Ravishankar
NeurIPS1
2024 Controller synthesis for linear temporal logic and steady-state specifications
Alvaro Velasquez, Ismail Alkhouri, Andre Beckus, Ashutosh Trivedi 0001, George Atia
Auton. Agents Multi Agent Syst.2
2024 Imperceptible Attacks on Fault Detection and Diagnosis Systems in Smart Buildings
abstract
Automated fault detection and diagnosis systems are critical to safe and efficient operation of smart buildings. A significant amount of building data can be collected and analyzed to detect building component failures. Attacks against such data that are contaminated with small additive disturbances (i.e., adversarial perturbation attacks) could dreadfully impact the performance of such systems while maintaining a high level of imperceptibility. The vulnerability studies of such data attacks is lacking. Specifically, most existing detection and classification models have flat structures, regarded as single-stage classifiers (SSCs), are prone to adversarial data perturbation attacks. In this article, we present a coarse-to-fine hierarchical fault detection and multilevel diagnosis (HFDD) model, and formulate a mathematical program to derive targeted attacks on the model with respect to a prespecified target diagnosis level. Two algorithms are developed based on convex relaxations of the formulated program for nontargeted attacks. An alternating direction method of multipliers-based solver is developed for the convex programs. Extensive experiments are conducted using two real-world datasets of measurements from air handling units and chillers, demonstrating the feasibility of the proposed attacks with regard to misclassification rate and imperceptibility of the attack. We also show that the HFDD is more robust to disturbances than SSC-based fault detection and multilevel diagnosis systems.
Ismail Alkhouri, Akram S. Awad, Qun Zhou 0002, George Atia
IEEE Trans. Ind. Informatics1
2023 A Non-Targeted Attack Approach for the Coarse Misclassification Problem
abstract
The evaluation of classifiers' robustness against adversarial attacks is typically performed through metrics based on the minimal perturbation required for misclassification. The conventional method of generating these perturbations relies on setting a limit on the maximum allowed perturbation (restricted attack method) and a non-targeted attack formulation. This approach, however, disregards any relationships between classes. Our paper introduces a novel, non-targeted, bound-restricted method for achieving coarse misclassification, so that the perturbed feature is classified outside its true coarse class. We present an efficient, single-step solution to the coarse misclassification problem and analyze its computational requirements. Our experiments showcase the superiority of our method, surpassing state-of-the-art in terms of both the perceptibility of adversarial examples and runtime.
Ismail Alkhouri, Alvaro Velasquez, George Atia
IJCNN1
2023 Optimal Deterministic Controller Synthesis from Steady-State Distributions
Alvaro Velasquez, Ismail Alkhouri, K. Subramani 0001, Piotr Wojciechowski 0002, George Atia
J. Autom. Reason.2
2022 Synthesis of Adversarial Samples in Two-Stage Classifiers
abstract
Adversarial attacks can drastically reduce the accuracy and confidence level of classifiers while being imperceptible. Existing studies on the topic have largely focused on one-stage classifiers. In this paper, we study the robustness of two Two-Stage Hierarchical Classifier models, the flat and top-down hierarchical classifiers, termed FHC and TDHC respectively, to targeted and confidence reduction attacks. We formulate feasibility programs based on similarity and distance measures for the one-shot synthesis of adversarial examples, and devise a generative approach to the solution. In this approach, the adjustable parameters of a generative network are iteratively updated by optimizing loss functions for the dual objective of (i) low attack perceptibility and (ii) small distance from desired soft predictions. We demonstrate the performance of the proposed approach in terms of imperceptibilty and measures of attack success, and show it compares favorably with state-of-the-art techniques.
Ismail Alkhouri, Alvaro Velasquez, George Atia
ICASSP1
2022 A differentiable approach to the maximum independent set problem using dataless neural networks
Ismail Alkhouri, George Atia, Alvaro Velasquez
Neural Networks1
2021 Dynamic Automaton-Guided Reward Shaping for Monte Carlo Tree Search
abstract
Reinforcement learning and planning have been revolutionized in recent years, due in part to the mass adoption of deep convolutional neural networks and the resurgence of powerful methods to refine decision-making policies. However, the problem of sparse reward signals and their representation remains pervasive in many domains. While various rewardshaping mechanisms and imitation learning approaches have been proposed to mitigate this problem, the use of humanaided artificial rewards introduces human error, sub-optimal behavior, and a greater propensity for reward hacking. In this paper, we mitigate this by representing objectives as automata in order to define novel reward shaping functions over this structured representation. In doing so, we address the sparse rewards problem within a novel implementation of Monte Carlo Tree Search (MCTS) by proposing a reward shaping function which is updated dynamically to capture statistics on the utility of each automaton transition as it pertains to satisfying the goal of the agent. We further demonstrate that such automaton-guided reward shaping can be utilized to facilitate transfer learning between different environments when the objective is the same.
Alvaro Velasquez, Brett Bissey, Lior Barak, Andre Beckus, Ismail Alkhouri, Daniel Melcer, George Atia
AAAI5
2021 Adversarial Attacks on Coarse-to-Fine Classifiers
abstract
Adversarial attacks have exposed the vulnerability of one-stage classifiers to carefully crafted perturbations which were shown to drastically alter their predictions while remaining imperceptible. In this paper, we examine the susceptibility of coarse-to-fine hierarchical classifiers to such types of attacks. We formulate convex programs to generate perturbations attacking these models and propose a generic solution based on the Alternating Direction Method of Multipliers (ADMM). We evaluate the performance of the proposed models using the degradation in classification accuracy and imperceptibility measures in comparison to perturbations generated to fool one-stage classifiers.
Ismail Alkhouri, George Atia
ICASSP1
2021 Targeted Attacks in Hierarchical Settings via Convex Programming
abstract
Adversarial attacks were shown to drastically degrade the performance of one-stage classifiers while being undetectable. In this paper, we examine the susceptibility of both flat and top-down hierarchical classifiers, abbreviated FHCs and TDHCs respectively, to targeted adversarial attacks. Convex programs are formulated to generate input perturbations geared at altering their output predictions according to pre-specified targets (e.g., changing the prediction of a ‘cat’ to a ‘car’ rather than a ‘dog’ or some other pet). A competitive solver based on the Alternating Direction Method of Multipliers (ADMM) is developed and is shown to outperform state-of-the-art solvers. The attacks developed for FHCs and TDHCs are evaluated based on their success rate and imperceptibility. It is shown that FHCs are inherently more robust than TDHCs to said attacks in the sense that fooling their coarse classification generally requires higher levels of perturbation.
Ismail Alkhouri, George Atia
IJCNN1
2021 Steady-State Planning in Expected Reward Multichain MDPs
abstract
The planning domain has experienced increased interest in the formal synthesis of decision-making policies. This formal synthesis typically entails finding a policy which satisfies formal specifications in the form of some well-defined logic. While many such logics have been proposed with varying degrees of expressiveness and complexity in their capacity to capture desirable agent behavior, their value is limited when deriving decision-making policies which satisfy certain types of asymptotic behavior in general system models. In particular, we are interested in specifying constraints on the steady-state behavior of an agent, which captures the proportion of time an agent spends in each state as it interacts for an indefinite period of time with its environment. This is sometimes called the average or expected behavior of the agent and the associated planning problem is faced with significant challenges unless strong restrictions are imposed on the underlying model in terms of the connectivity of its graph structure. In this paper, we explore this steady-state planning problem that consists of deriving a decision-making policy for an agent such that constraints on its steady-state behavior are satisfied. A linear programming solution for the general case of multichain Markov Decision Processes (MDPs) is proposed and we prove that optimal solutions to the proposed programs yield stationary policies with rigorous guarantees of behavior.
George Atia, Andre Beckus, Ismail Alkhouri, Alvaro Velasquez
J. Artif. Intell. Res.3
2020 Steady-State Policy Synthesis in Multichain Markov Decision Processes
abstract
The formal synthesis of automated or autonomous agents has elicited strong interest from the artificial intelligence community in recent years. This problem space broadly entails the derivation of decision-making policies for agents acting in an environment such that a formal specification of behavior is satisfied. Popular formalisms for such specifications include the quintessential Linear Temporal Logic (LTL) and Computation Tree Logic (CTL) which reason over infinite sequences and trees, respectively, of states. However, the related and relevant problem of reasoning over the frequency with which states are visited infinitely and enforcing behavioral specifications on the same has received little attention. That problem, known as Steady-State Policy Synthesis (SSPS) or steady-state control, is the focus of this paper. Prior related work has been mostly confined to unichain Markov Decision Processes (MDPs), while a tractable solution to the general multichain setting heretofore remains elusive. In this paper, we provide a solution to the latter within the context of multichain MDPs over a class of policies that account for all possible transitions in the given MDP. The solution policy is derived from a novel linear program (LP) that encodes constraints on the limiting distributions of the Markov chain induced by said policy. We establish a one-to-one correspondence between the feasible solutions of the LP and the stationary distributions of the induced Markov chains. The derived policy is shown to maximize the reward among the constrained class of stationary policies and to satisfy the specification constraints even when it does not exercise all possible transitions.
George Atia, Andre Beckus, Ismail Alkhouri, Alvaro Velasquez
IJCAI3
2020 Adversarial Perturbation Attacks on GLRT-Based Detectors
abstract
Existing work on adversarial attacks on classification tasks has focused on classifiers that make use of simple hypothesis testing models. In this work, we study the vulnerability of composite classifiers employing generalized likelihood ratio tests to adversarial perturbation attacks. We derive imperceptible adversarial attacks for a multiple composite hypothesis testing setting using gradient methods. The work considers scenarios where the attacker has access to the ground truth class. The classification performance, with and without perturbation, is characterized based on the notions of posterior sensitivity and specificity.
Ismail Alkhouri, George Atia, Wasfy B. Mikhael
ISCAS1