课题基金 / 基金详情

CIF: Small: A Systematic Approach to Adversarial Machine Learning: Sparsity-based Defenses and Locally Linear Attacks

CIF: Small: A Systematic Approach to Adversarial Machine Learning: Sparsity-based Defenses and Locally Linear Attacks
CIF:小型:对抗性机器学习的系统方法:基于稀疏性的防御和局部线性攻击
批准号:
1909320
负责人:
Ramtin Pedarsani
金额:
$49.99万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-10-01 至 2023-09-30

项目摘要

项目成果

Ramtin Pedarsani的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Machine learning has made tremendous advances in the past decade, and is rapidly becoming embedded in our daily lives. We experience its power directly when we interact with voice assistants and automated translation engines, which are improving rapidly every year. Machine learning tools also enable many of the functionalities underlying search engines, e-commerce sites and social media. Thus, machine learning has become an essential component of cyberspace and our interactions with it, and is now poised to enter our physical space, for example, as a core component of perception for autonomous vehicles and drones. Much of the recent progress in machine learning has been in the area of multilayer, or deep, neural networks, which can be trained to learn complex relationships by leveraging the availability of large amounts of data and massive computing power. However, before we rely on such capabilities for safety-critical applications such as vehicular autonomy, we must ensure the robustness and security of deep networks. Recent research shows, for example, that deep networks can be induced to make errors (e.g., to misclassify images) by an adversary by adding tiny perturbations which would be imperceptible to humans. This project develops a systematic framework for defending against such adversarial perturbations, blending classical model-based techniques with the modern data-driven approach that characterizes machine learning practice today. The project will be validated through two key applications of deep learning: image classification and speech recognition.When the vulnerability of deep networks to adversarial perturbations was discovered a few years back, it was initially conjectured that this vulnerability is due to the complex and nonlinear nature of the neural networks. However, there is now general agreement that this vulnerability is actually due to the excessive linearity of deep networks. Motivated by this observation, this project aims to develop a systematic approach to study adversarial machine learning by utilizing the sparsity inherent in natural data for defense, and locally linear models of the network for attack. The proposed approach is based on exploiting signal sparsity to develop provably efficient defense mechanisms. In particular, the project first investigates a sparsifying frontend, designed to preserve desired input information while attenuating perturbations before they enter the neural network. This then leads to a defense mechanism based on sparsifying the neural network, with the goal of mitigating the impact of an adversarial perturbation as it flows up the network. The methodology brings together ideas from sparse signal processing, optimization, and machine learning, and aims to bridge the gap between systematic theoretical understanding and machine learning practice. The proposal has an extensive evaluation plan that focuses on two important real-world applications of adversarial machine learning: image classification and speech recognition.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(25)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1109/isit50566.2022.9834832
发表时间: 2022-01
期刊: 2022 IEEE International Symposium on Information Theory (ISIT)
影响因子: --
作者: [M. Beliaev;Payam Delgosha;Hamed Hassani;Ramtin Pedarsani]
通讯作者: M. Beliaev;Payam Delgosha;Hamed Hassani;Ramtin Pedarsani
Equal Improvability: A New Fairness Notion Considering the Long-term Impact
平等可改进性:考虑长期影响的新公平理念
DOI: --
发表时间: 2023
期刊: International Conference on Learning Representations (ICLR
影响因子: --
作者: [Guldogan, Ozgur, Zeng, Yuchen, Sohn, Jy-yong, Pedarsani, Ramtin, Lee, Kangwook]
通讯作者: Lee, Kangwook
Sharp Asymptotics and Optimal Performance for Inference in Binary Models
二元模型中推理的尖锐渐近性和最佳性能
DOI: --
发表时间: 2020
期刊: Proceedings of the Twenty Third International Conference on Artificial Intelligence and Statistics
影响因子: --
作者: [Taheri, Hossein, Pedarsani, Ramtin, Thrampoulidis, Christos]
通讯作者: Thrampoulidis, Christos
DOI: 10.1109/icip42928.2021.9506184
发表时间: 2021-09
期刊: 2021 IEEE International Conference on Image Processing (ICIP)
影响因子: --
作者: [Can Bakiskan;Metehan Cekic;Ahmet Dundar Sezer;Upamanyu Madhow]
通讯作者: Can Bakiskan;Metehan Cekic;Ahmet Dundar Sezer;Upamanyu Madhow
21
    NSF-NSERC: Fairness Fundamentals: Geometry-inspired Algorithms and Long-term Implications
    Collaborative Research: CIF: Small: Robust Machine Learning under Sparse Adversarial Attacks
    Collaborative Research: Mixed-Autonomy Traffic Networks: Routing Games and Learning Human Choice Models
    MLWiNS: Optimization and Coding Theory for Fast and Robust Wireless Distributed Learning
    国内基金
    海外基金
    昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
    • 批准号:
    • 项目类别:
      省市级项目
    • 资助金额:
      --
    • 批准年份:
      2024
    • 负责人:
    • 依托单位:
    tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
    • 批准号:
    • 项目类别:
      省市级项目
    • 资助金额:
      10.0万元
    • 批准年份:
      2022
    • 负责人:
      张祥忠
    • 依托单位:
    Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
    Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
    • 批准号:
      31972324
    • 项目类别:
      面上项目
    • 资助金额:
      58.0万元
    • 批准年份:
      2019
    • 负责人:
      高学文
    • 依托单位: