课题基金 / 基金详情

SaTC: CORE: Small: Attack-Agnostic Defenses against Adversarial Inputs in Learning Systems

SaTC: CORE: Small: Attack-Agnostic Defenses against Adversarial Inputs in Learning Systems
SaTC:核心:小:针对学习系统中的对抗性输入的与攻击无关的防御
批准号:
1718787
负责人:
Ting Wang
金额:
$49.83万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2017
资助国家:
美国
项目状态:
已结题
起止时间:
2017-08-15 至 2019-11-30

项目摘要

项目成果

Ting Wang的其他基金

相似基金

相关文献

中文摘要
翻译
深度学习技术有望彻底改变人们的生活和工作方式。然而,深度学习系统天生就容易受到敌意输入的影响,这些输入是恶意制作的样本,用于触发深度神经网络的不当行为,从而在安全关键应用中导致灾难性后果。防御此类攻击的根本挑战来自于它们的自适应和可变性质:敌意输入是针对深层神经网络量身定做的,而精心设计的策略因具体攻击而有很大差异。这个项目开发了EagleEye,这是一个通用的攻击不可知的防御框架,它(I)有效地对抗不可见的攻击变体,(Ii)保留深度神经网络的预测能力,(Iii)补充现有的防御机制,以及(Iv)提供对深度学习输出中的潜在风险的全面诊断。特别是,EagleEye利用了大多数攻击背后的一组不变属性,包括“最小化原则”:为了最大限度地避免攻击,通过对合法输入应用最小可能的扭曲来生成对抗性输入。通过以有原则的方式利用这些特性,EagleEye有效地区分敌意输入(完整性检查),甚至发现它们的正确输出(真相恢复)。具体的研究任务包括:(I)识别合法和敌意输入的内在不同属性(区分因素),(Ii)基于这些区分因素开发攻击不可知的敌意输入检测方法,以及(Iii)分析敌手为逃避此类防御而可能采取的对策。这项研究不仅促进了深度学习驱动的系统和服务的采用,而且对总体上设计和实现健壮的机器学习系统也有启发作用。在这个项目中开发的新理论和系统被整合到本科和研究生教育中,并用于提高公众对机器学习安全重要性的认识。有关该项目的更多信息,请访问项目主页:http://x-machine.github.io/project/eagleeye
英文摘要
Deep learning technologies hold great promise to revolutionize the way people live and work. However, deep learning systems are inherently vulnerable to adversarial inputs, which are maliciously crafted samples to trigger deep neural networks to misbehave, leading to disastrous consequences in security-critical applications. The fundamental challenges of defending against such attacks stem from their adaptive and variable nature: adversarial inputs are tailored to target deep neural networks, while crafting strategies vary greatly with concrete attacks. This project develops EagleEye, a universal, attack-agnostic defense framework that (i) works effectively against unseen attack variants, (ii) preserves predictive power of deep neural networks, (iii) complements existing defense mechanisms, and (iv) provides comprehensive diagnosis about potential risks in deep learning outputs.In particular, EagleEye leverages a set of invariant properties underlying most attacks, including the "minimality principle": to maximize attack evasiveness, an adversarial input is generated by applying the minimum possible distortion to a legitimate input. By exploiting such properties in a principled manner, EagleEye effectively discriminates adversarial inputs (integrity checking) and even uncovers their correct outputs (truth recovery). The specific research tasks include: (i) identifying inherently distinct properties (differentiators) of legitimate and adversarial inputs, (ii) developing attack-agnostic adversarial input detection methods based on these differentiators, and (iii) analyzing possible countermeasures by adversaries to evade such defenses. This research not only facilitates the adoption of deep learning-powered systems and services, but also enlightens designing and implementing robust machine learning systems in general. New theories and systems developed in this project are integrated into undergraduate and graduate education and used to raise public awareness of the importance of machine learning security. More information about this project can be found at the project homepage: http://x-machine.github.io/project/eagleeye
期刊论文(8)
专著(0)
科研奖励(0)
会议论文
DOI: --
发表时间: 2020-10
期刊:
影响因子: --
作者: [Yuwei Li;S. Ji;Yuan Chen;Sizhuang Liang;Wei-Han Lee;Yueyao Chen;Chenyang Lyu-;Chunming Wu;R. Be]
通讯作者: Yuwei Li;S. Ji;Yuan Chen;Sizhuang Liang;Wei-Han Lee;Yueyao Chen;Chenyang Lyu-;Chunming Wu;R. Be
DOI: 10.1109/dsaa.2018.00039
发表时间: 2018-10
期刊: 2018 IEEE 5th International Conference on Data Science and Advanced Analytics (DSAA)
影响因子: --
作者: [Xinyang Zhang-;Yujie Ji;Chanh Nguyen;Ting Wang]
通讯作者: Xinyang Zhang-;Yujie Ji;Chanh Nguyen;Ting Wang
Integration of Static and Dynamic Code Stylometry Analysis for Programmer De-anonymization
集成静态和动态代码风格分析以实现程序员去匿名化
DOI: 10.1145/3270101.3270110
发表时间: 2018
期刊: Proceedings of the 11th ACM Workshop on Artificial Intelligence and Security
影响因子: --
作者: [Wang, Ningfei, Ji, Shouling, Wang, Ting]
通讯作者: Wang, Ting
DOI: 10.1145/3270101.3270104
发表时间: 2018-01
期刊: Proceedings of the 11th ACM Workshop on Artificial Intelligence and Security
影响因子: --
作者: [Binbin Zhao;Haiqin Weng;S. Ji;Jianhai Chen;Ting Wang;Qinming He;Reheem Beyah]
通讯作者: Binbin Zhao;Haiqin Weng;S. Ji;Jianhai Chen;Ting Wang;Qinming He;Reheem Beyah
共 7 条
    CAREER: Trustworthy Machine Learning from Untrusted Models
    • 批准号:
      2405136
    • 项目类别:
      Continuing Grant
    • 资助金额:
      $50.99万
    • 财政年份:
      2023
    • 负责人:
      Ting Wang
    • 依托单位:
    Collaborative Research: PPoSS: LARGE: Principles and Infrastructure of Extreme Scale Edge Learning for Computational Screening and Surveillance for Health Care
    • 批准号:
      2406572
    • 项目类别:
      Continuing Grant
    • 资助金额:
      $94.27万
    • 财政年份:
      2023
    • 负责人:
      Ting Wang
    • 依托单位:
    Collaborative Research: PPoSS: LARGE: Principles and Infrastructure of Extreme Scale Edge Learning for Computational Screening and Surveillance for Health Care
    SaTC: CORE: Small: Attack-Agnostic Defenses against Adversarial Inputs in Learning Systems
    国内基金
    海外基金
    胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
    • 批准号:
      82371765
    • 项目类别:
      面上项目
    • 资助金额:
      50万元
    • 批准年份:
      2023
    • 负责人:
      谭广云
    • 依托单位:
    锕系元素5f-in-core的GTH赝势和基组的开发
    • 批准号:
      22303037
    • 项目类别:
      青年科学基金项目
    • 资助金额:
      30万元
    • 批准年份:
      2023
    • 负责人:
      鲁俊波
    • 依托单位:
    基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
    • 批准号:
      --
    • 项目类别:
      --
    • 资助金额:
      52万元
    • 批准年份:
      2022
    • 负责人:
      孙丙军
    • 依托单位:
    鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
    • 批准号:
      --
    • 项目类别:
      青年科学基金项目
    • 资助金额:
      30万元
    • 批准年份:
      2022
    • 负责人:
      叶成林
    • 依托单位: