10,000 publications from this institution
Work on adversarial examples has shown that neural nets are surprisingly sensitive to adversarially chosen changes of small magnitude. In this paper, we show the opposite: neural nets could be surprisingly insensitive to adversarially chosen changes of large magnitude. We observe that this phenomenon can arise from the intrinsic properties of the ReLU activation function. As a result, two very different examples could share the same feature activation and therefore the same classification decision. We refer to this phenomenon as feature collision and the corresponding examples as colliding examples. We find that colliding examples are quite abundant: we empirically demonstrate the existence of polytopes of approximately colliding examples in the neighbourhood of practically any example.
Abstract not Available.
This document specifies an Internet standards track protocol for the Internet community, and requests discussion and suggestions for improvements.
A class of acknowledgment-based transmission control algorithms is considered. In the finite population case, we claim that algorithms based on backoff functions which increase faster than linearly but slower than exponentially are stable up to full channel capacity, whereas sublinear, exponential, and superexponential algorithms are not. In addition, comments are made about the nature of the quasistationary behavior in the infinite population case, and about how systems interpolate between the finite and infinite number of station cases. The treatment presented here is nonrigorous, consisting of approximate analytic arguments confirmed by detailed numerical simulations.