Source author record

Ivan Girardi

Ivan Girardi appears in the imported research catalog. Authorship, coauthor and topic links are available while profile ownership is still unclaimed.

ResearcherUnclaimed source record

Catalog footprint

What is connected

5works
4topics
4close collaborators

Actions

Connect this record

Log in to claim

Research graph

See the researcher in context

Open full explorer

Inspect adjacent papers, topics, institutions and collaborators without losing the researcher page.

Building this map preview

BZPEER is loading the nearby papers, people, topics and institutions for this page.

Published work

5 published item(s)

preprint2022arXiv

FAR: A General Framework for Attributional Robustness

Attribution maps are popular tools for explaining neural networks predictions. By assigning an importance value to each input dimension that represents its impact towards the outcome, they give an intuitive explanation of the decision process. However, recent work has discovered vulnerability of these maps to imperceptible adversarial changes, which can prove critical in safety-relevant domains such as healthcare. Therefore, we define a novel generic framework for attributional robustness (FAR) as general problem formulation for training models with robust attributions. This framework consist of a generic regularization term and training objective that minimize the maximal dissimilarity of attribution maps in a local neighbourhood of the input. We show that FAR is a generalized, less constrained formulation of currently existing training methods. We then propose two new instantiations of this framework, AAT and AdvAAT, that directly optimize for both robust attributions and predictions. Experiments performed on widely used vision datasets show that our methods perform better or comparably to current ones in terms of attributional robustness while being more generally applicable. We finally show that our methods mitigate undesired dependencies between attributional robustness and some training and estimation parameters, which seem to critically affect other competitor methods.

preprint2022arXiv

Fooling Explanations in Text Classifiers

State-of-the-art text classification models are becoming increasingly reliant on deep neural networks (DNNs). Due to their black-box nature, faithful and robust explanation methods need to accompany classifiers for deployment in real-life scenarios. However, it has been shown in vision applications that explanation methods are susceptible to local, imperceptible perturbations that can significantly alter the explanations without changing the predicted classes. We show here that the existence of such perturbations extends to text classifiers as well. Specifically, we introduceTextExplanationFooler (TEF), a novel explanation attack algorithm that alters text input samples imperceptibly so that the outcome of widely-used explanation methods changes considerably while leaving classifier predictions unchanged. We evaluate the performance of the attribution robustness estimation performance in TEF on five sequence classification datasets, utilizing three DNN architectures and three transformer architectures for each dataset. TEF can significantly decrease the correlation between unchanged and perturbed input attributions, which shows that all models and explanation methods are susceptible to TEF perturbations. Moreover, we evaluate how the perturbations transfer to other model architectures and attribution methods, and show that TEF perturbations are also effective in scenarios where the target model and explanation method are unknown. Finally, we introduce a semi-universal attack that is able to compute fast, computationally light perturbations with no knowledge of the attacked classifier nor explanation method. Overall, our work shows that explanations in text classifiers are very fragile and users need to carefully address their robustness before relying on them in critical applications.

preprint2014arXiv

Constraining Sterile Neutrinos Using Reactor Neutrino Experiments

Models of neutrino mixing involving one or more sterile neutrinos have resurrected their importance in the light of recent cosmological data. In this case, reactor antineutrino experiments offer an ideal place to look for signatures of sterile neutrinos due to their impact on neutrino flavor transitions. In this work, we show that the high-precision data of the Daya Bay experi\-ment constrain the 3+1 neutrino scenario imposing upper bounds on the relevant active-sterile mixing angle $\sin^2 2 θ_{14} \lesssim 0.06$ at 3$σ$ confidence level for the mass-squared difference $Δm^2_{41}$ in the range $(10^{-3},10^{-1}) \, {\rm eV^2}$. The latter bound can be improved by six years of running of the JUNO experiment, $\sin^22θ_{14} \lesssim 0.016$, although in the smaller mass range $ Δm^2_{41} \in (10^{-4} ,10^{-3}) \, {\rm eV}^2$. We have also investigated the impact of sterile neutrinos on precision measurements of the standard neutrino oscillation parameters $θ_{13}$ and $Δm^2_{31}$ (at Daya Bay and JUNO), $θ_{12}$ and $Δm^2_{21}$ (at JUNO), and most importantly, the neutrino mass hierarchy (at JUNO). We find that, except for the obvious situation where $Δm^2_{41}\sim Δm^2_{31}$, sterile states do not affect these measurements substantially.

preprint2014arXiv

Generalised Geometrical CP Violation in a $T^{\prime}$ Lepton Flavour Model

We analyse the interplay of generalised CP transformations and the non-Abelian discrete group $T^{\prime}$ and use the semi-direct product $G_f= T^{\prime}\rtimes H_{\text{CP}}$, as family symmetry acting in the lepton sector. The family symmetry is shown to be spontaneously broken in a geometrical manner. In the resulting flavour model, naturally small Majorana neutrino masses for the light active neutrinos are obtained through the type I see-saw mechanism. The known masses of the charged leptons, lepton mixing angles and the two neutrino mass squared differences are reproduced by the model with a good accuracy. The model allows for two neutrino mass spectra with normal ordering (NO) and one with inverted ordering (IO). For each of the three spectra the absolute scale of neutrino masses is predicted with relatively small uncertainty. The value of the Dirac CP violation (CPV) phase $δ$ in the lepton mixing matrix is predicted to be $δ\cong π/2~{\rm or}~ 3π/2$. Thus, the CP violating effects in neutrino oscillations are predicted to be maximal (given the values of the neutrino mixing angles) and experimentally observable. We present also predictions for the sum of the neutrino masses, for the Majorana CPV phases and for the effective Majorana mass in neutrinoless double beta decay. The predictions of the model can be tested in a variety of ongoing and future planned neutrino experiments.

preprint2013arXiv

Neutrinoless Double Beta Decay in the Presence of Light Sterile Neutrinos

We investigate the predictions for neutrinoless double beta ($(ββ)_{0 ν}$-) decay effective Majorana mass $\left| \langle \, m \, \rangle \right|$ in the 3+1 and 3+2 schemes with one and two additional sterile neutrinos with masses at the eV scale. The two schemes are suggested by the neutrino oscillation interpretation of the reactor neutrino and Gallium "anomalies" and of the data of the LSND and MiniBooNE experiments. We analyse in detail the possibility of a complete or partial cancellation between the different terms in $\left| \langle \, m \, \rangle \right|$, leading to a strong suppression of $\left| \langle \, m \, \rangle \right|$. We determine the regions of the relevant parameter spaces where such a suppression can occure. This allows us to derive the conditions under which the effective Majorana mass satisfies $\left| \langle \, m \, \rangle \right| > 0.01$ eV, which is the range planned to be exploited by the next generation of $(ββ)_{0 ν}$-experiments.