arXiv Science⌕ Search

arXiv subjects

Dawei Yang

Publications and source records attributed to Dawei Yang.

At least 91 records · Page 5Linked to original sources

Adversarial Objects Against LiDAR-Based Autonomous Driving Systems

Deep neural networks (DNNs) are found to be vulnerable against adversarial examples, which are carefully crafted inputs with a small magnitude of perturbation aiming to induce arbitrarily incorrect predictions. Recent studies show that adversarial examples can pose a threat to real-world security-critical applications: a "physical adversarial Stop Sign" can be synthesized such that the autonomous driving cars will misrecognize it as others (e.g., a speed limit sign). However, these image-space adversarial examples cannot easily alter 3D scans of widely equipped LiDAR or radar on autonomous vehicles. In this paper, we reveal the potential vulnerabilities of LiDAR-based autonomous driving detection systems, by proposing an optimization based approach LiDAR-Adv to generate adversarial objects that can evade the LiDAR-based detection system under various conditions. We first show the vulnerabilities using a blackbox evolution-based algorithm, and then explore how much a strong adversary can do, using our gradient-based approach LiDAR-Adv. We test the generated adversarial objects on the Baidu Apollo autonomous driving platform and show that such physical systems are indeed vulnerable to the proposed attacks. We also 3D-print our adversarial objects and perform physical experiments to illustrate that such vulnerability exists in the real world. Please find more visualizations and results on the anonymous website: https://sites.google.com/view/lidar-adv.

cs.CR↗

MeshAdv: Adversarial Meshes for Visual Recognition

Highly expressive models such as deep neural networks (DNNs) have been widely applied to various applications. However, recent studies show that DNNs are vulnerable to adversarial examples, which are carefully crafted inputs aiming to mislead the predictions. Currently, the majority of these studies have focused on perturbation added to image pixels, while such manipulation is not physically realistic. Some works have tried to overcome this limitation by attaching printable 2D patches or painting patterns onto surfaces, but can be potentially defended because 3D shape features are intact. In this paper, we propose meshAdv to generate "adversarial 3D meshes" from objects that have rich shape features but minimal textural variation. To manipulate the shape or texture of the objects, we make use of a differentiable renderer to compute accurate shading on the shape and propagate the gradient. Extensive experiments show that the generated 3D meshes are effective in attacking both classifiers and object detectors. We evaluate the attack under different viewpoints. In addition, we design a pipeline to perform black-box attack on a photorealistic renderer with unknown rendering parameters.

cs.CR↗

Randomization Inference for Peer Effects

Many previous causal inference studies require no interference, that is, the potential outcomes of a unit do not depend on the treatments of other units. However, this no-interference assumption becomes unreasonable when a unit interacts with other units in the same group or cluster. In a motivating application, a university in China admits students through two channels: the college entrance exam (also known as Gaokao) and recommendation (often based on Olympiads in various subjects). The university randomly assigns students to dorms, each of which hosts four students. Students within the same dorm live together and have extensive interactions. Therefore, it is likely that peer effects exist and the no-interference assumption does not hold. It is important to understand peer effects, because they give useful guidance for future roommate assignment to improve the performance of students. We define peer effects using potential outcomes. We then propose a randomization-based inference framework to study peer effects with arbitrary numbers of peers and peer types. Our inferential procedure does not assume any parametric model on the outcome distribution. Our analysis gives useful practical guidance for policy makers of the university in China.

stat.ME↗

Empirical measures of partially hyperbolic attractors

In this paper, we study the limit measures of the empirical measures of Lebesgue almost every point in the basin of a partially hyperbolic attractor. They are strongly related to a notion named Gibbs u-state, which can be defined in a large class of diffeomorphisms with less regularity and which is the same as Pesin-Sinai's notion for partially hyperbolic attractors of $C^{1+α}$ diffeomorphisms. In particular, we prove that for partially hyperbolic $C^{1+α}$ diffeomorphisms with one-dimensional center, and for Lebesgue almost every point: (1) the center Lyapunov exponent is well defined, but (2) the sequence of empirical measures may not converge. We also give some consequences on SRB measures and large deviations.

math.DS↗

Homoclinic tangencies and singular hyperbolicity for three-dimensional vector fields

We prove that any vector field on a three-dimensional compact manifold can be approximated in the C1-topology by one which is singular hyperbolic or by one which exhibits a homoclinic tangency associated to a regular hyperbolic periodic orbit. This answers a conjecture by Palis. During the proof we obtain several other results with independent interest: a compactification of the rescaled sectional Poincaré flow and a generalization of Mañé-Pujals-Sambarino theorem for three-dimensional C2 vector fields with singularities.

math.DS↗

Decorrelated Batch Normalization

Batch Normalization (BN) is capable of accelerating the training of deep models by centering and scaling activations within mini-batches. In this work, we propose Decorrelated Batch Normalization (DBN), which not just centers and scales activations but whitens them. We explore multiple whitening techniques, and find that PCA whitening causes a problem we call stochastic axis swapping, which is detrimental to learning. We show that ZCA whitening does not suffer from this problem, permitting successful learning. DBN retains the desirable qualities of BN and further improves BN's optimization efficiency and generalization ability. We design comprehensive experiments to show that DBN can improve the performance of BN on multilayer perceptrons and convolutional neural networks. Furthermore, we consistently improve the accuracy of residual networks on CIFAR-10, CIFAR-100, and ImageNet.

cs.CV↗

On the abundance of SRB measures

We prove the abundance of Sinai-Ruelle-Bowen measures for diffeomorphisms away from ones with a homoclinic tangency. This is motivated by conjectures of Palis on the existence of physical (Sinai-Ruelle-Bowen) measures for global dynamics. The main novelty in this paper is that we have to deeply study Gibbs $cu$-states in different levels. Note that we have to use random perturbations to give some upper bound of the level of Gibbs $cu$-states.

math.DS↗

Shape from Shading through Shape Evolution

In this paper, we address the shape-from-shading problem by training deep networks with synthetic images. Unlike conventional approaches that combine deep learning and synthetic imagery, we propose an approach that does not need any external shape dataset to render synthetic images. Our approach consists of two synergistic processes: the evolution of complex shapes from simple primitives, and the training of a deep network for shape-from-shading. The evolution generates better shapes guided by the network training, while the training improves by using the evolved shapes. We show that our approach achieves state-of-the-art performance on a shape-from-shading benchmark.

cs.CV↗

On the growth rate of periodic orbits for vector fields

We establish the relationship between the growth rate of periodic orbits and the topological entropy for $C^1$ generic vector fields: this extends a classical result of Katok for $C^{1+α}(α>0)$ surface diffeomorphisms to $C^1$ generic vector fields of any dimension. The main difficulty comes from the existence of singularities and the shear of the flow.

math.DS↗

Single-Image Depth Perception in the Wild

This paper studies single-image depth perception in the wild, i.e., recovering depth from a single image taken in unconstrained settings. We introduce a new dataset "Depth in the Wild" consisting of images in the wild annotated with relative depth between pairs of random points. We also propose a new algorithm that learns to estimate metric depth using annotations of relative depth. Compared to the state of the art, our algorithm is simpler and performs better. Experiments show that our algorithm, combined with existing RGB-D data and our new relative depth annotations, significantly improves single-image depth perception in the wild.

cs.CV↗

SRB measures for diffeomorphisms with continuous invariant splittings

We study the existence of SRB measures of C 2 diffeomorphisms for attractors whose bundles admit Holder continuous invariant (non-dominated) splittings. We prove the existence when one subbundle has the non-uniform expanding property on a set with positive Lebesgue measure and the other subbundle admits non-positive Lyapunov exponents on a total probability set.

math.DS↗

Hyperbolicity versus non-hyperbolic ergodic measures inside homoclinic classes

We prove that, for $C^1$-generic diffeomorphisms, if a homoclinic class is not hyperbolic, then there is a non-hyperbolic ergodic measure supported on it. This proves a conjecture by Díaz and Gorodetski [28]. We also discuss the conjectured existence of periodic points with different stable dimension in the class.

math.DS↗

On the density of singular hyperbolic three-dimensional vector fields: a conjecture of Palis

In this note we announce a result for vector fields on three-dimensional manifolds: those who are singular hyperbolic or exhibit a homoclinic tangency form a dense subset of the space of $C^1$-vector fields. This answers a conjecture by Palis. The argument uses an extension for local fibered flows of Mañé and Pujals-Sambarino's theorems about the uniform contraction of one-dimensional dominated bundles. Sur la densité de l'hyperbolicité singulière pour les champs de vecteurs en dimension trois : une conjecture de Palis Dans cette note, nous annonçons un résultat portant sur les champs de vecteurs des variétés de dimension $3$ : ceux qui vérifient l'hyperbolicité singulière ou qui possèdent une tangence homocline forment un sous-ensemble dense de l'espace des champs de vecteurs $C^1$. Ceci répond à une conjecture de Palis. La démonstration utilise une généralisation pour les flots fibrés locaux des théorèmes de Mañé et Pujals-Sambarino traitant de la contraction uniforme de fibrés unidimensionnels dominés.

math.DS↗

On the finiteness of uniform sinks

We study the finiteness of uniform sinks for flow. Precisely, we prove that, for $α>0$ $T>0$, if a vector field $X$ has only hyperbolic singularities or sectionally dissipative singularities, then $X$ can have only finitely many $(α,T)$-uniform sinks. This is a generalized version of a theorem of Liao

math.DS↗