SaTC: CORE: Small: Attack-Agnostic Defenses against Adversarial Inputs in Learning Systems
SaTC: CORE: Small: Attack-Agnostic Defenses against Adversarial Inputs in Learning Systems
批准号:
1718787
负责人:
Ting Wang
金额:
$49.83万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2017
资助国家:
美国
项目状态:
已结题
起止时间:
2017-08-15 至 2019-11-30
中文摘要
深度学习技术有望彻底改变人们的生活和工作方式。然而,深度学习系统天生就容易受到敌意输入的影响,这些输入是恶意制作的样本,用于触发深度神经网络的不当行为,从而在安全关键应用中导致灾难性后果。防御此类攻击的根本挑战来自于它们的自适应和可变性质:敌意输入是针对深层神经网络量身定做的,而精心设计的策略因具体攻击而有很大差异。这个项目开发了EagleEye,这是一个通用的攻击不可知的防御框架,它(I)有效地对抗不可见的攻击变体,(Ii)保留深度神经网络的预测能力,(Iii)补充现有的防御机制,以及(Iv)提供对深度学习输出中的潜在风险的全面诊断。特别是,EagleEye利用了大多数攻击背后的一组不变属性,包括“最小化原则”:为了最大限度地避免攻击,通过对合法输入应用最小可能的扭曲来生成对抗性输入。通过以有原则的方式利用这些特性,EagleEye有效地区分敌意输入(完整性检查),甚至发现它们的正确输出(真相恢复)。具体的研究任务包括:(I)识别合法和敌意输入的内在不同属性(区分因素),(Ii)基于这些区分因素开发攻击不可知的敌意输入检测方法,以及(Iii)分析敌手为逃避此类防御而可能采取的对策。这项研究不仅促进了深度学习驱动的系统和服务的采用,而且对总体上设计和实现健壮的机器学习系统也有启发作用。在这个项目中开发的新理论和系统被整合到本科和研究生教育中,并用于提高公众对机器学习安全重要性的认识。有关该项目的更多信息,请访问项目主页:http://x-machine.github.io/project/eagleeye
英文摘要
Deep learning technologies hold great promise to revolutionize the way people live and work. However, deep learning systems are inherently vulnerable to adversarial inputs, which are maliciously crafted samples to trigger deep neural networks to misbehave, leading to disastrous consequences in security-critical applications. The fundamental challenges of defending against such attacks stem from their adaptive and variable nature: adversarial inputs are tailored to target deep neural networks, while crafting strategies vary greatly with concrete attacks. This project develops EagleEye, a universal, attack-agnostic defense framework that (i) works effectively against unseen attack variants, (ii) preserves predictive power of deep neural networks, (iii) complements existing defense mechanisms, and (iv) provides comprehensive diagnosis about potential risks in deep learning outputs.In particular, EagleEye leverages a set of invariant properties underlying most attacks, including the "minimality principle": to maximize attack evasiveness, an adversarial input is generated by applying the minimum possible distortion to a legitimate input. By exploiting such properties in a principled manner, EagleEye effectively discriminates adversarial inputs (integrity checking) and even uncovers their correct outputs (truth recovery). The specific research tasks include: (i) identifying inherently distinct properties (differentiators) of legitimate and adversarial inputs, (ii) developing attack-agnostic adversarial input detection methods based on these differentiators, and (iii) analyzing possible countermeasures by adversaries to evade such defenses. This research not only facilitates the adoption of deep learning-powered systems and services, but also enlightens designing and implementing robust machine learning systems in general. New theories and systems developed in this project are integrated into undergraduate and graduate education and used to raise public awareness of the importance of machine learning security. More information about this project can be found at the project homepage: http://x-machine.github.io/project/eagleeye
期刊论文(8)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
--
发表时间:
2020-10
期刊:
影响因子:
--
作者:
[Yuwei Li;S. Ji;Yuan Chen;Sizhuang Liang;Wei-Han Lee;Yueyao Chen;Chenyang Lyu-;Chunming Wu;R. Be]
通讯作者:
Yuwei Li;S. Ji;Yuan Chen;Sizhuang Liang;Wei-Han Lee;Yueyao Chen;Chenyang Lyu-;Chunming Wu;R. Be
DOI:
10.1109/dsaa.2018.00039
发表时间:
2018-10
期刊:
2018 IEEE 5th International Conference on Data Science and Advanced Analytics (DSAA)
影响因子:
--
作者:
[Xinyang Zhang-;Yujie Ji;Chanh Nguyen;Ting Wang]
通讯作者:
Xinyang Zhang-;Yujie Ji;Chanh Nguyen;Ting Wang
Integration of Static and Dynamic Code Stylometry Analysis for Programmer De-anonymization
集成静态和动态代码风格分析以实现程序员去匿名化
DOI:
10.1145/3270101.3270110
发表时间:
2018
期刊:
Proceedings of the 11th ACM Workshop on Artificial Intelligence and Security
影响因子:
--
作者:
[Wang, Ningfei, Ji, Shouling, Wang, Ting]
通讯作者:
Wang, Ting
DOI:
10.1145/3270101.3270104
发表时间:
2018-01
期刊:
Proceedings of the 11th ACM Workshop on Artificial Intelligence and Security
影响因子:
--
作者:
[Binbin Zhao;Haiqin Weng;S. Ji;Jianhai Chen;Ting Wang;Qinming He;Reheem Beyah]
通讯作者:
Binbin Zhao;Haiqin Weng;S. Ji;Jianhai Chen;Ting Wang;Qinming He;Reheem Beyah
DOI:
10.1145/3243734.3278528
发表时间:
2018-10
期刊:
Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
[Yujie Ji;Ting Wang]
通讯作者:
Yujie Ji;Ting Wang
共 7 条
CAREER: Trustworthy Machine Learning from Untrusted Models
-
批准号:2405136
-
项目类别:Continuing Grant
-
资助金额:$50.99万
-
财政年份:2023
-
负责人:Ting Wang
-
依托单位:
Collaborative Research: PPoSS: LARGE: Principles and Infrastructure of Extreme Scale Edge Learning for Computational Screening and Surveillance for Health Care
-
批准号:2406572
-
项目类别:Continuing Grant
-
资助金额:$94.27万
-
财政年份:2023
-
负责人:Ting Wang
-
依托单位:
Collaborative Research: PPoSS: LARGE: Principles and Infrastructure of Extreme Scale Edge Learning for Computational Screening and Surveillance for Health Care
-
批准号:2119331
-
项目类别:Continuing Grant
-
资助金额:$94.27万
-
财政年份:2021
-
负责人:Ting Wang
-
依托单位:
SaTC: CORE: Small: Attack-Agnostic Defenses against Adversarial Inputs in Learning Systems
-
批准号:1953813
-
项目类别:Standard Grant
-
资助金额:$38.62万
-
财政年份:2019
-
负责人:Ting Wang
-
依托单位:
III: Small: Usable Interpretability
-
批准号:1910546
-
项目类别:Continuing Grant
-
资助金额:$49.56万
-
财政年份:2019
-
负责人:Ting Wang
-
依托单位:
CAREER: Trustworthy Machine Learning from Untrusted Models
-
批准号:1953893
-
项目类别:Continuing Grant
-
资助金额:$50.99万
-
财政年份:2019
-
负责人:Ting Wang
-
依托单位:
III: Small: Usable Interpretability
-
批准号:1951729
-
项目类别:Continuing Grant
-
资助金额:$49.56万
-
财政年份:2019
-
负责人:Ting Wang
-
依托单位:
CAREER: Trustworthy Machine Learning from Untrusted Models
-
批准号:1846151
-
项目类别:Continuing Grant
-
资助金额:$50.99万
-
财政年份:2019
-
负责人:Ting Wang
-
依托单位:
CRII: SaTC: Re-Envisioning Contextual Services and Mobile Privacy in the Era of Deep Learning
-
批准号:1566526
-
项目类别:Standard Grant
-
资助金额:$16.87万
-
财政年份:2016
-
负责人:Ting Wang
-
依托单位:
Engineering Initiation Award: Effects of Curvature, Pressure, Gradient, and Freestream Turbulence on Reynolds Analogy in Transitional Boundary Layer Flow
-
批准号:8708843
-
项目类别:Standard Grant
-
资助金额:$7.0万
-
财政年份:1987
-
负责人:Ting Wang
-
依托单位:
国内基金
海外基金
登录
查看更多内容
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
-
批准号:82371765
-
项目类别:面上项目
-
资助金额:50万元
-
批准年份:2023
-
负责人:谭广云
-
依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
-
批准号:22303037
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2023
-
负责人:鲁俊波
-
依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
-
批准号:--
-
项目类别:--
-
资助金额:52万元
-
批准年份:2022
-
负责人:孙丙军
-
依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:叶成林
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:--
-
项目类别:--
-
资助金额:55万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:82072415
-
项目类别:面上项目
-
资助金额:55.0万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
-
批准号:92053110
-
项目类别:重大研究计划
-
资助金额:70.0万元
-
批准年份:2020
-
负责人:彭鹏
-
依托单位:
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
-
批准号:81902805
-
项目类别:青年科学基金项目
-
资助金额:20.5万元
-
批准年份:2019
-
负责人:刘菲
-
依托单位:
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
-
批准号:41973063
-
项目类别:面上项目
-
资助金额:65.0万元
-
批准年份:2019
-
负责人:周游
-
依托单位:
CORDEX-CORE区域气候模拟与预估研讨会
-
批准号:41981240365
-
项目类别:国际(地区)合作与交流项目
-
资助金额:1.5万元
-
批准年份:2019
-
负责人:陈威霖
-
依托单位: