arXiv ScienceSearch

arXiv subjects

Marco Melis

Publications and source records attributed to Marco Melis.

15 recordsLinked to original sources

The Great Impersonation: $\mathcal{W}$-Solitons as Prototypical Black Hole Microstates

We analyze a new class of static, smooth geometries in five-dimensional supergravity, dubbed $\mathcal{W}$-solitons. They carry the same mass and charges as four-dimensional Reissner-Nordström-like black holes but replace the horizon with a Kaluza-Klein bubble supported by electromagnetic flux. These solutions provide analytically tractable prototypes of black hole microstates in supergravity, including a new, relevant neutral configuration involving a massless axion field. Focusing on photon scattering and scalar perturbations, we compute their key observables, aiming to identify mesoscopic observables. We find that $\mathcal{W}$-solitons feature a single photon sphere, qualitatively similar to that of the black hole but with quantitative differences. They have only short-lived quasinormal modes~(QNMs), as black holes, while long-lived echo modes seen in other ultracompact horizonless objects are absent. As a result, the ringdown closely resembles that of a black hole while still showing sizable deviations. The latter are at the ${\mathcal{O}}(10\%)$ level, compatible with the recent measurement of GW250114 and potentially falsifiable in the near future. Finally, we show that $\mathcal{W}$-solitons are stable under scalar perturbations. Our results underscore the qualitative similarities between $\mathcal{W}$-solitons and black holes, reinforcing their relevance as smooth black hole microstate prototypes.

gr-qc

Black hole spectroscopy and nonlinear echoes in Einstein-Maxwell-scalar theory

In the context of Einstein-Maxwell-scalar theory with a nonminimal coupling between the electromagnetic and scalar field, we study linear (non)radial perturbations and nonlinear radial dynamics of spherically symmetric black holes. In a certain region of the parameter space, this theory admits hairy black holes with a stable photon sphere. This has a counterpart in the effective potential of linear perturbations, featuring multiple maxima and minima. The corresponding quasinormal mode spectrum contains long-lived modes trapped in the potential cavity and the time-domain linear response displays echoes, as previously observed for horizonless compact objects. Interestingly, the black-hole dynamics in this theory can be studied at the nonlinear level. By performing fully-fledged 1+1 simulations, we show that echoes are present even when the nonlinearities are significant. To our knowledge, this is the first example of echoes appearing in a consistent theory beyond a linearized analysis. In a follow-up work we will study whether this feature is also present in the post-merger signal from black hole collisions in this theory.

gr-qc

Extreme mass ratio inspirals around topological stars

We study a point scalar charge in circular orbit around a topological star, a regular, horizonless soliton emerging from dimensional compactification of Einstein-Maxwell theory in five dimensions, which could describe qualitative properties of microstate geometries for astrophysical black holes. This is the first step towards studying extreme mass-ratio inspirals around these objects. We show that when the particle probes the spacetime close to the object, the scalar-wave flux deviates significantly from the corresponding black hole case. Furthermore, as the topological star approaches the black-hole limit, the inspiral can resonantly excite its long-lived modes, resulting in sharp features in the emitted flux. Although such resonances are too narrow to produce detectable dephasing, we estimate that a year-long inspiral down to the innermost stable circular orbit could accumulate a significant dephasing for most configurations relative to the black hole case. While a full parameter-estimation analysis is needed, the generically large deviations are likely to be within the sensitivity reach of future space-based gravitational-wave detectors.

gr-qc

Nonradial stability of topological stars

Topological stars are regular, horizonless solitons arising from dimensional compactification of Einstein-Maxwell theory in five dimensions, which could describe qualitative properties of microstate geometries for astrophysical black holes. They also provide a compelling realization of ultracompact objects arising from a well-defined theory and display all the phenomenological features typically associated with black hole mimickers, including a (stable) photon sphere, long-lived quasinormal modes, and echoes in the ringdown. By completing a thorough linear stability analysis, we provide strong numerical evidence that these solutions are stable against nonradial perturbations with zero Kaluza-Klein momentum.

gr-qc

Spectroscopy of magnetized black holes and topological stars

We study the linear response of four dimensional magnetized black holes and regular topological stars arising from dimensional compactification of Einstein-Maxwell theory in five dimensions. We consider both radial and nonradial perturbations and study the stability of these solutions, both in the frequency and in the time domain. Due to the presence of magnetic fluxes in the background, axial (i.e., odd-parity) gravitational perturbations are coupled to polar (i.e., even-parity) electromagnetic perturbations (Type-I sector) whereas polar gravitational and scalar perturbations are coupled to axial electromagnetic ones (Type-II sector). We provide a comprehensive analytical and numerical study of the radial perturbations and of the Type I sector, finding no evidence of linear instabilities (besides the already known Gregory-Laflamme instability of black strings occurring only in a certain range of the parameters), even despite the fact that the effective potential for radial perturbations of topological stars is negative and divergent near the inner boundary. Ultracompact topological stars exhibit long-lived trapped modes that give rise to echoes in the time-domain response. Their prompt response is very similar to that of the corresponding black hole with comparable charge-to-mass ratio. This provides a concrete realization of ultracompact objects arising from a well-defined theory. The numerical analysis of the Type-II sector will appear in a companion paper.

gr-qc

Gauge-invariant coefficients in perturbative quantum gravity

Heat kernel methods are useful for studying properties of quantum gravity. We recompute here the first three heat kernel coefficients in perturbative quantum gravity with cosmological constant to ascertain which ones are correctly reported in the literature. They correspond to the counterterms needed to renormalize the one-loop effective action in four dimensions. They may be evaluated at arbitrary dimensions $D$, in which case they identify only a subset of the divergences appearing in the effective action for $D\geq 6$. Generically, these coefficients depend on the gauge-fixing choice adopted in quantizing the Einstein-Hilbert action. However, they become gauge-invariant once evaluated on-shell, i.e. using Einstein's field equations with cosmological constant. We identify them and use them as a benchmark for checking alternative approaches to perturbative quantum gravity. One such approach describes the graviton in first-quantization through the use of the action of the ${\cal N}=4$ spinning particle, characterized by four supersymmetries on the worldline and a set of worldline gauge invariances. This description has been used for computing the gauge-invariant coefficients as well. We verify their correctness at $D=4$, but find a mismatch at arbitrary $D$ when comparing with the benchmark fixed earlier. We interpret this result as signaling that the path integral quantization of the ${\cal N}=4$ spinning particle should be amended. We perform this task by fixing the correct counterterm that must be used in the worldline path integral quantization of the ${\cal N}=4$ spinning particle to make it consistent in arbitrary dimensions.

hep-th

secml: A Python Library for Secure and Explainable Machine Learning

We present \texttt{secml}, an open-source Python library for secure and explainable machine learning. It implements the most popular attacks against machine learning, including test-time evasion attacks to generate adversarial examples against deep neural networks and training-time poisoning attacks against support vector machines and many other algorithms. These attacks enable evaluating the security of learning algorithms and the corresponding defenses under both white-box and black-box threat models. To this end, \texttt{secml} provides built-in functions to compute security evaluation curves, showing how quickly classification performance decreases against increasing adversarial perturbations of the input data. \texttt{secml} also includes explainability methods to help understand why adversarial attacks succeed against a given model, by visualizing the most influential features and training prototypes contributing to each decision. It is distributed under the Apache License 2.0 and hosted at \url{https://github.com/pralab/secml}.

cs.LG

Do Gradient-based Explanations Tell Anything About Adversarial Robustness to Android Malware?

While machine-learning algorithms have demonstrated a strong ability in detecting Android malware, they can be evaded by sparse evasion attacks crafted by injecting a small set of fake components, e.g., permissions and system calls, without compromising intrusive functionality. Previous work has shown that, to improve robustness against such attacks, learning algorithms should avoid overemphasizing few discriminant features, providing instead decisions that rely upon a large subset of components. In this work, we investigate whether gradient-based attribution methods, used to explain classifiers' decisions by identifying the most relevant features, can be used to help identify and select more robust algorithms. To this end, we propose to exploit two different metrics that represent the evenness of explanations, and a new compact security measure called Adversarial Robustness Metric. Our experiments conducted on two different datasets and five classification algorithms for Android malware detection show that a strong connection exists between the uniformity of explanations and adversarial robustness. In particular, we found that popular techniques like Gradient*Input and Integrated Gradients are strongly correlated to security when applied to both linear and nonlinear detectors, while more elementary explanation techniques like the simple Gradient do not provide reliable information about the robustness of such classifiers.

cs.LG

FADER: Fast Adversarial Example Rejection

Deep neural networks are vulnerable to adversarial examples, i.e., carefully-crafted inputs that mislead classification at test time. Recent defenses have been shown to improve adversarial robustness by detecting anomalous deviations from legitimate training samples at different layer representations - a behavior normally exhibited by adversarial attacks. Despite technical differences, all aforementioned methods share a common backbone structure that we formalize and highlight in this contribution, as it can help in identifying promising research directions and drawbacks of existing methods. The first main contribution of this work is the review of these detection methods in the form of a unifying framework designed to accommodate both existing defenses and newer ones to come. In terms of drawbacks, the overmentioned defenses require comparing input samples against an oversized number of reference prototypes, possibly at different representation layers, dramatically worsening the test-time efficiency. Besides, such defenses are typically based on ensembling classifiers with heuristic methods, rather than optimizing the whole architecture in an end-to-end manner to better perform detection. As a second main contribution of this work, we introduce FADER, a novel technique for speeding up detection-based methods. FADER overcome the issues above by employing RBF networks as detectors: by fixing the number of required prototypes, the runtime complexity of adversarial examples detectors can be controlled. Our experiments outline up to 73x prototypes reduction compared to analyzed detectors for MNIST dataset and up to 50x for CIFAR10 dataset respectively, without sacrificing classification accuracy on both clean and adversarial data.

cs.LG

Deep Neural Rejection against Adversarial Examples

Despite the impressive performances reported by deep neural networks in different application domains, they remain largely vulnerable to adversarial examples, i.e., input samples that are carefully perturbed to cause misclassification at test time. In this work, we propose a deep neural rejection mechanism to detect adversarial examples, based on the idea of rejecting samples that exhibit anomalous feature representations at different network layers. With respect to competing approaches, our method does not require generating adversarial examples at training time, and it is less computationally demanding. To properly evaluate our method, we define an adaptive white-box attack that is aware of the defense mechanism and aims to bypass it. Under this worst-case setting, we empirically show that our approach outperforms previously-proposed methods that detect adversarial examples by only analyzing the feature representation provided by the output network layer.

cs.CV

Why Do Adversarial Attacks Transfer? Explaining Transferability of Evasion and Poisoning Attacks

Transferability captures the ability of an attack against a machine-learning model to be effective against a different, potentially unknown, model. Empirical evidence for transferability has been shown in previous work, but the underlying reasons why an attack transfers or not are not yet well understood. In this paper, we present a comprehensive analysis aimed to investigate the transferability of both test-time evasion and training-time poisoning attacks. We provide a unifying optimization framework for evasion and poisoning attacks, and a formal definition of transferability of such attacks. We highlight two main factors contributing to attack transferability: the intrinsic adversarial vulnerability of the target model, and the complexity of the surrogate model used to optimize the attack. Based on these insights, we define three metrics that impact an attack's transferability. Interestingly, our results derived from theoretical analysis hold for both evasion and poisoning attacks, and are confirmed experimentally using a wide range of linear and non-linear classifiers and datasets.

cs.LG

Explaining Black-box Android Malware Detection

Machine-learning models have been recently used for detecting malicious Android applications, reporting impressive performances on benchmark datasets, even when trained only on features statically extracted from the application, such as system calls and permissions. However, recent findings have highlighted the fragility of such in-vitro evaluations with benchmark datasets, showing that very few changes to the content of Android malware may suffice to evade detection. How can we thus trust that a malware detector performing well on benchmark data will continue to do so when deployed in an operating environment? To mitigate this issue, the most popular Android malware detectors use linear, explainable machine-learning models to easily identify the most influential features contributing to each decision. In this work, we generalize this approach to any black-box machine- learning model, by leveraging a gradient-based approach to identify the most influential local features. This enables using nonlinear models to potentially increase accuracy without sacrificing interpretability of decisions. Our approach also highlights the global characteristics learned by the model to discriminate between benign and malware applications. Finally, as shown by our empirical analysis on a popular Android malware detection task, it also helps identifying potential vulnerabilities of linear and nonlinear models against adversarial manipulations.

cs.LG

Super-sparse Learning in Similarity Spaces

In several applications, input samples are more naturally represented in terms of similarities between each other, rather than in terms of feature vectors. In these settings, machine-learning algorithms can become very computationally demanding, as they may require matching the test samples against a very large set of reference prototypes. To mitigate this issue, different approaches have been developed to reduce the number of required reference prototypes. Current reduction approaches select a small subset of representative prototypes in the space induced by the similarity measure, and then separately train the classification function on the reduced subset. However, decoupling these two steps may not allow reducing the number of prototypes effectively without compromising accuracy. We overcome this limitation by jointly learning the classification function along with an optimal set of virtual prototypes, whose number can be either fixed a priori or optimized according to application-specific criteria. Creating a super-sparse set of virtual prototypes provides much sparser solutions, drastically reducing complexity at test time, at the expense of a slightly increased complexity during training. A much smaller set of prototypes also results in easier-to-interpret decisions. We empirically show that our approach can reduce up to ten times the complexity of Support Vector Machines, LASSO and ridge regression at test time, without almost affecting their classification accuracy.

cs.CV

Is Deep Learning Safe for Robot Vision? Adversarial Examples against the iCub Humanoid

Deep neural networks have been widely adopted in recent years, exhibiting impressive performances in several application domains. It has however been shown that they can be fooled by adversarial examples, i.e., images altered by a barely-perceivable adversarial noise, carefully crafted to mislead classification. In this work, we aim to evaluate the extent to which robot-vision systems embodying deep-learning algorithms are vulnerable to adversarial examples, and propose a computationally efficient countermeasure to mitigate this threat, based on rejecting classification of anomalous inputs. We then provide a clearer understanding of the safety properties of deep networks through an intuitive empirical analysis, showing that the mapping learned by such networks essentially violates the smoothness assumption of learning algorithms. We finally discuss the main limitations of this work, including the creation of real-world adversarial examples, and sketch promising research directions.

cs.LG

Yes, Machine Learning Can Be More Secure! A Case Study on Android Malware Detection

To cope with the increasing variability and sophistication of modern attacks, machine learning has been widely adopted as a statistically-sound tool for malware detection. However, its security against well-crafted attacks has not only been recently questioned, but it has been shown that machine learning exhibits inherent vulnerabilities that can be exploited to evade detection at test time. In other words, machine learning itself can be the weakest link in a security system. In this paper, we rely upon a previously-proposed attack framework to categorize potential attack scenarios against learning-based malware detection tools, by modeling attackers with different skills and capabilities. We then define and implement a set of corresponding evasion attacks to thoroughly assess the security of Drebin, an Android malware detector. The main contribution of this work is the proposal of a simple and scalable secure-learning paradigm that mitigates the impact of evasion attacks, while only slightly worsening the detection rate in the absence of attack. We finally argue that our secure-learning approach can also be readily applied to other malware detection tasks.

cs.CR