Academic papers, new techniques, benchmarks, and theoretical findings in AI/LLM security.
Researchers developed a dual-locking security method for protecting trained neural networks by combining two techniques: a PIN (personal identification number)-based watermark embedded in the network's bias coefficients, and a cryptographic key that scrambles the network's internal index vectors. When locked without the correct key, the network becomes nearly non-functional (dropping accuracy below 10%), but unlocking with the right key fully restores its performance while keeping the ownership watermark hidden inside the model.
This research proposes a new method for protecting data privacy in deep learning (training AI models on sensitive data) by adding Gaussian noise (random values from a bell-curve distribution) to ResNets (a type of neural network with skip connections). The method aims to provide differential privacy (a mathematical guarantee that an individual's data cannot be easily identified from the model's results) while maintaining better accuracy and speed than existing privacy-protection techniques like DPSGD (differentially private stochastic gradient descent, a slower privacy-focused training method).
GRACE-FL is a framework for federated learning (collaborative training where multiple devices learn together while keeping their data private) that reduces energy use and communication costs on resource-limited devices like smartphones or IoT sensors. The system adjusts each device's training settings based on how much battery or power it has available, so devices with more energy can do harder computational work while weaker devices do lighter work, and a special aggregation strategy (method for combining results) weights each device's contribution fairly based on its energy capacity.
This paper presents SUNG, a framework for offline-to-online reinforcement learning (RL), which is training an AI agent first on existing data and then improving it through live interactions. The framework addresses two main problems: limited exploration due to offline data constraints and distribution shift (when the agent encounters data patterns it wasn't trained on). SUNG uses uncertainty estimation via a VAE (variational autoencoder, a type of neural network that learns data patterns) to guide both exploration (trying new actions) and exploitation (using known good actions), achieving strong performance on standard benchmarks.
Deep model fusion is a technique that combines parameters or predictions from multiple deep learning models into one unified system to improve performance by reducing individual model biases and errors. The survey categorizes four main fusion approaches: weight average (averaging model parameters), mode connectivity (connecting models through optimized paths), alignment (matching corresponding units between models), and ensemble learning (combining model outputs during inference). However, applying this technique to large-scale models like LLMs (large language models, which are AI systems trained on massive amounts of text) faces challenges including high computational cost and interference between different types of models.
Researchers developed OR-SLZNet, a deep learning model that helps drones automatically identify safe landing zones by analyzing camera images in real time. The model assigns each pixel a safety score by combining visual features like color and texture with geometric information like flatness and slope, enabling drones to make quick landing decisions in emergencies or autonomous missions.
Deep neural networks can be fooled by adversarial attacks (small, carefully crafted changes to input data that cause incorrect predictions), but training them to resist these attacks usually requires large amounts of labeled data. This paper proposes margin-based interpolation, a technique that adjusts how strongly to attack training data based on each example's difficulty and reliability, and uses global epsilon scheduling (gradually increasing perturbation strength during training) to help models become robust while maintaining accuracy, even with limited labeled data.
This research studies how deep neuro-fuzzy systems (DNFS, a type of AI that combines deep learning with fuzzy logic, which handles uncertain or imprecise information) perform on medical images that contain noise (unwanted degradation that makes images unclear). The researchers tested the DNFS on seven different medical imaging datasets with six types of noise and adversarial attacks (deliberate perturbations designed to fool AI models), and found that the DNFS maintained better accuracy on noisy images compared to other state-of-the-art models, though both approaches remained vulnerable to adversarial attacks.
Scene Graph Generation (SGG, a method that identifies objects and their relationships in images) is limited by long-tailed bias, where the AI model performs well on common relationships but poorly on rare ones. This paper proposes a Grounded Cognition Method (GCM) that mimics human thinking by using techniques like Out Domain Knowledge Injection to broaden visual understanding, a Semantic Group Aware Synthesizer to organize relationship categories, modality erasure (removing one type of input at a time) to improve robustness, and a Shapley Enhanced Multimodal Counterfactual module to handle diverse contexts.
This paper presents mathematical approaches to solve Shape-from-Template (SfT, reconstructing a 3D object's shape from a single image using a known template) and Non-Rigid Structure-from-Motion (NRSfM, figuring out how a flexible object moves and its 3D structure from video). The researchers use Semi-Definite Programming (SDP, a mathematical optimization technique for solving certain types of problems) to find solutions that work with different types of object deformation models, requiring only point correspondences (matching points between images) rather than additional impractical assumptions.
This research addresses the problem of recognizing shapes that have been rotated at different angles in computer vision (the field of teaching computers to understand images). The authors propose a new method that focuses on analyzing the outline or contour points of shapes rather than individual pixels, and they use a special neural network module to identify geometric patterns in these contours while ignoring rotation. Their approach shows better results than previous methods, especially for complex shapes, and it works even when the contour data is slightly noisy or imperfect.
This research introduces TGDIP, a machine learning model that uses graph neural networks (GNNs, which are AI systems that learn patterns from data organized as connected networks) to predict how different drugs interact with each other. The model addresses two main problems: drug features becoming too similar to each other during processing, and irrelevant information being included when predicting interactions between drug pairs. TGDIP solves these issues using two techniques: contrastive learning (training the model by comparing similar and different examples) to keep drug features distinct, and an information bottleneck method (a process that filters out unnecessary data) to remove irrelevant information between drug pairs.
This research addresses challenges in federated learning (FL, a method where multiple institutions train an AI model together without sharing private data) by introducing FedDPO, which uses reinforcement learning (a type of AI that learns through trial and error feedback) to automatically adjust regularization terms (mathematical penalties that stabilize training) for each participant based on their unique data and system conditions. The approach also uses local batch normalization (a technique that normalizes data within each institution) to handle differences in how data is distributed across institutions, and testing on medical image classification tasks shows it outperforms existing methods.
This research addresses a problem where image de-raining AI models (systems that remove rain from photos) perform poorly on real-world rainy images because they are trained on limited datasets. The researchers propose a framework inspired by how human brains learn and remember, using generative adversarial networks (GANs, AI systems that generate synthetic images) to capture features of new rainy data and then train the de-raining model with both real and synthetic data, similar to how the brain replays memories to strengthen learning.
Researchers developed DIC-GAN, a generative adversarial network (GAN, an AI model that learns to create realistic data by having two competing neural networks) that reconstructs weather radar images from satellite data in regions where ground-based radar doesn't exist, such as deserts and oceans. The system uses dynamic identity convolution modules (specialized neural network layers that adjust their behavior based on input data) and a mixed loss function (a measure of how wrong the AI's predictions are, combining three different error metrics) to improve accuracy, especially for strong storm signals. Testing showed the model works better than existing methods and can generate radar images for areas without physical radar coverage.
HPE-Li++ is a new system that estimates human pose (the position and angles of body parts) using both Wi-Fi signals and camera data together, rather than relying only on camera images. The system uses a specialized neural network (a type of AI model) with adaptive kernel selection (a technique that automatically adjusts how the AI processes different parts of the input) to achieve accurate 3D skeletal pose detection while using very little computing power, making it practical for devices with limited resources.
This research proposes FGE-GAN (fuzzy graph evolutionary generative adversarial network, a deep learning model that uses fuzzy graphs to handle uncertainty in disease data) to predict Alzheimer's disease risk and identify disease pathways. The model treats Alzheimer's progression as the spread of fuzzy entropy (uncertain information) through interconnected disease factors, and experiments show it outperforms existing methods at predicting disease risk.
This research addresses the problem of incomplete knowledge graphs (databases of connected facts about entities) by proposing a new model called TEDD that predicts missing relationships between entities. The model combines both structural information from the graph and text information, and uses a specialized transformer technique (BERT, a language processing model) to reduce computational costs and handle entities that change over time in dynamic knowledge graphs.
This research paper argues that the real problem with machine learning classifiers isn't that robustness (resistance to adversarial attacks, where small malicious changes trick the AI) and accuracy are fundamentally opposed, but rather that continuous functions (smooth mathematical functions without jumps or breaks) cannot achieve both properties simultaneously. The authors propose that effective robust and accurate classifiers should use discontinuous functions (functions with breaks or sudden changes) instead, and show that understanding this continuity property is crucial for building, analyzing, and testing modern machine learning models.
This research presents ABAE-RTN, a deep learning framework that improves security in wireless radio networks by using adaptive beamforming (technology that focuses radio signals toward intended receivers) and autoencoders (neural networks that learn to compress and reconstruct data) to protect against eavesdropping. The system adds artificial noise to disrupt attackers while maintaining communication quality, and adjusts its signal patterns in real time to handle changing channel conditions. Testing shows it outperforms other AI approaches like LSTM (long short-term memory, a type of neural network good at processing sequences) in protecting wireless communications.