TWC: Medium: Collaborative: Efficient Repair of Learning Systems via Machine Unlearning
TWC: Medium: Collaborative: Efficient Repair of Learning Systems via Machine Unlearning
批准号:
1854000
负责人:
Yinzhi Cao
金额:
$44.9万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2018
资助国家:
美国
项目状态:
已结题
起止时间:
2018-09-05 至 2022-08-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Today individuals and organizations leverage machine learning systems to adjust room temperature, provide recommendations, detect malware, predict earthquakes, forecast weather, maneuver vehicles, and turn Big Data into insights. Unfortunately, these systems are prone to a variety of malicious attacks with potentially disastrous consequences. For example, an attacker might trick an Intrusion Detection System into ignoring the warning signs of a future attack by injecting carefully crafted samples into the training set for the machine learning model (i.e., "polluting" the model). This project is creating an approach to machine unlearning and the necessary algorithms, techniques, and systems to efficiently and effectively repair a learning system after it has been compromised. Machine unlearning provides a last resort against various attacks on learning systems, and is complementary to other existing defenses. The key insight in machine unlearning is that most learning systems can be converted into a form that can be updated incrementally without costly retraining from scratch. For instance, several common learning techniques (e.g., naive Bayesian classifier) can be converted to the non-adaptive statistical query learning form, which depends only on a constant number of summations, each of which is a sum of some efficiently computable transformation of the training data samples. To repair a compromised learning system in this form, operators add or remove the affected training sample and re-compute the trained model by updating a constant number of summations. This approach yields huge speedup -- the asymptotic speedup over retraining is equal to the size of the training set. With unlearning, operators can efficiently correct a polluted learning system by removing the injected sample from the training set, strengthen an evaded learning system by adding evasive samples to the training set, and prevent system inference attacks by forgetting samples stolen by the attacker so that no future attacks can infer anything about the samples.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
CICI: TCR: Transitioning Differentially Private Federated Learning to Enable Collaborative, Intelligent, Fair Skin Disease Diagnostics on Medical Imaging Cyberinfrastructure
-
批准号:2319742
-
项目类别:Standard Grant
-
资助金额:$120.0万
-
财政年份:2024
-
负责人:Yinzhi Cao
-
依托单位:
Collaborative Research: DASS: Assessing the Relationship Between Privacy Regulations and Software Development to Improve Rulemaking and Compliance
-
批准号:2317185
-
项目类别:Standard Grant
-
资助金额:$25.0万
-
财政年份:2023
-
负责人:Yinzhi Cao
-
依托单位:
SaTC: CORE: Small: Studying and Measuring the Consequence of Prototype Pollution Vulnerabilities Automatically via Joint Taintflow Analysis
-
批准号:2154404
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2022
-
负责人:Yinzhi Cao
-
依托单位:
CAREER: Mining and Exploiting Web Vulnerabilities of Prototype-based Programming Languages via Object Property Graph
-
批准号:2046361
-
项目类别:Continuing Grant
-
资助金额:$56.05万
-
财政年份:2021
-
负责人:Yinzhi Cao
-
依托单位:
Collaborative Research: CNS Core: Medium: Cross-Layer Design of Video Analytics for the Internet of Things
-
批准号:1955487
-
项目类别:Standard Grant
-
资助金额:$37.5万
-
财政年份:2020
-
负责人:Yinzhi Cao
-
依托单位:
CNS Core: Small: Lease-based, Utilitarian Mobile System Design to Enable Energy-Efficient Apps
-
批准号:1910133
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2019
-
负责人:Yinzhi Cao
-
依托单位:
SaTC: CORE: Small: Preventing Web Side-channel Attacks via Atomic Determinism
-
批准号:1812870
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2018
-
负责人:Yinzhi Cao
-
依托单位:
SaTC: CORE: Small: Preventing Web Side-channel Attacks via Atomic Determinism
-
批准号:1854001
-
项目类别:Standard Grant
-
资助金额:$50.0万
-
财政年份:2018
-
负责人:Yinzhi Cao
-
依托单位:
TWC: Medium: Collaborative: Efficient Repair of Learning Systems via Machine Unlearning
-
批准号:1563843
-
项目类别:Standard Grant
-
资助金额:$59.99万
-
财政年份:2016
-
负责人:Yinzhi Cao
-
依托单位:
EAGER: Real-time Enforcement of Content Security Policy upon Real-world Websites
-
批准号:1646662
-
项目类别:Standard Grant
-
资助金额:$9.47万
-
财政年份:2016
-
负责人:Yinzhi Cao
-
依托单位:
海外基金