CIF: Small: A Systematic Approach to Adversarial Machine Learning: Sparsity-based Defenses and Locally Linear Attacks
CIF: Small: A Systematic Approach to Adversarial Machine Learning: Sparsity-based Defenses and Locally Linear Attacks
批准号:
1909320
负责人:
Ramtin Pedarsani
金额:
$49.99万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-10-01 至 2023-09-30
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Machine learning has made tremendous advances in the past decade, and is rapidly becoming embedded in our daily lives. We experience its power directly when we interact with voice assistants and automated translation engines, which are improving rapidly every year. Machine learning tools also enable many of the functionalities underlying search engines, e-commerce sites and social media. Thus, machine learning has become an essential component of cyberspace and our interactions with it, and is now poised to enter our physical space, for example, as a core component of perception for autonomous vehicles and drones. Much of the recent progress in machine learning has been in the area of multilayer, or deep, neural networks, which can be trained to learn complex relationships by leveraging the availability of large amounts of data and massive computing power. However, before we rely on such capabilities for safety-critical applications such as vehicular autonomy, we must ensure the robustness and security of deep networks. Recent research shows, for example, that deep networks can be induced to make errors (e.g., to misclassify images) by an adversary by adding tiny perturbations which would be imperceptible to humans. This project develops a systematic framework for defending against such adversarial perturbations, blending classical model-based techniques with the modern data-driven approach that characterizes machine learning practice today. The project will be validated through two key applications of deep learning: image classification and speech recognition.When the vulnerability of deep networks to adversarial perturbations was discovered a few years back, it was initially conjectured that this vulnerability is due to the complex and nonlinear nature of the neural networks. However, there is now general agreement that this vulnerability is actually due to the excessive linearity of deep networks. Motivated by this observation, this project aims to develop a systematic approach to study adversarial machine learning by utilizing the sparsity inherent in natural data for defense, and locally linear models of the network for attack. The proposed approach is based on exploiting signal sparsity to develop provably efficient defense mechanisms. In particular, the project first investigates a sparsifying frontend, designed to preserve desired input information while attenuating perturbations before they enter the neural network. This then leads to a defense mechanism based on sparsifying the neural network, with the goal of mitigating the impact of an adversarial perturbation as it flows up the network. The methodology brings together ideas from sparse signal processing, optimization, and machine learning, and aims to bridge the gap between systematic theoretical understanding and machine learning practice. The proposal has an extensive evaluation plan that focuses on two important real-world applications of adversarial machine learning: image classification and speech recognition.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(25)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1109/isit50566.2022.9834832
发表时间:
2022-01
期刊:
2022 IEEE International Symposium on Information Theory (ISIT)
影响因子:
--
作者:
[M. Beliaev;Payam Delgosha;Hamed Hassani;Ramtin Pedarsani]
通讯作者:
M. Beliaev;Payam Delgosha;Hamed Hassani;Ramtin Pedarsani
Equal Improvability: A New Fairness Notion Considering the Long-term Impact
平等可改进性:考虑长期影响的新公平理念
DOI:
--
发表时间:
2023
期刊:
International Conference on Learning Representations (ICLR
影响因子:
--
作者:
[Guldogan, Ozgur, Zeng, Yuchen, Sohn, Jy-yong, Pedarsani, Ramtin, Lee, Kangwook]
通讯作者:
Lee, Kangwook
Sharp Asymptotics and Optimal Performance for Inference in Binary Models
二元模型中推理的尖锐渐近性和最佳性能
DOI:
--
发表时间:
2020
期刊:
Proceedings of the Twenty Third International Conference on Artificial Intelligence and Statistics
影响因子:
--
作者:
[Taheri, Hossein, Pedarsani, Ramtin, Thrampoulidis, Christos]
通讯作者:
Thrampoulidis, Christos
DOI:
10.1109/icip42928.2021.9506184
发表时间:
2021-09
期刊:
2021 IEEE International Conference on Image Processing (ICIP)
影响因子:
--
作者:
[Can Bakiskan;Metehan Cekic;Ahmet Dundar Sezer;Upamanyu Madhow]
通讯作者:
Can Bakiskan;Metehan Cekic;Ahmet Dundar Sezer;Upamanyu Madhow
DOI:
10.1109/jsait.2022.3182355
发表时间:
2022-06
期刊:
IEEE Journal on Selected Areas in Information Theory
影响因子:
--
作者:
[Farzan Farnia;Amirhossein Reisizadeh;Ramtin Pedarsani;A. Jadbabaie]
通讯作者:
Farzan Farnia;Amirhossein Reisizadeh;Ramtin Pedarsani;A. Jadbabaie
共 21 条
NSF-NSERC: Fairness Fundamentals: Geometry-inspired Algorithms and Long-term Implications
-
批准号:2342253
-
项目类别:Standard Grant
-
资助金额:$44.0万
-
财政年份:2024
-
负责人:Ramtin Pedarsani
-
依托单位:
Collaborative Research: CIF: Small: Robust Machine Learning under Sparse Adversarial Attacks
-
批准号:2236483
-
项目类别:Standard Grant
-
资助金额:$30.0万
-
财政年份:2023
-
负责人:Ramtin Pedarsani
-
依托单位:
Collaborative Research: Mixed-Autonomy Traffic Networks: Routing Games and Learning Human Choice Models
-
批准号:1952920
-
项目类别:Standard Grant
-
资助金额:$18.0万
-
财政年份:2020
-
负责人:Ramtin Pedarsani
-
依托单位:
MLWiNS: Optimization and Coding Theory for Fast and Robust Wireless Distributed Learning
-
批准号:2003035
-
项目类别:Standard Grant
-
资助金额:$30.0万
-
财政年份:2020
-
负责人:Ramtin Pedarsani
-
依托单位:
CRII: CIF: Next-Generation Group Testing for Neighbor Discovery in the IoT via Sparse-Graph Codes
-
批准号:1755808
-
项目类别:Standard Grant
-
资助金额:$17.49万
-
财政年份:2018
-
负责人:Ramtin Pedarsani
-
依托单位:
国内基金
海外基金
登录
查看更多内容
昼夜节律性small RNA在血斑形成时间推断中的法医学应用研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:
-
依托单位:
tRNA-derived small RNA上调YBX1/CCL5通路参与硼替佐米诱导慢性疼痛的机制研究
-
批准号:
-
项目类别:省市级项目
-
资助金额:10.0万元
-
批准年份:2022
-
负责人:张祥忠
-
依托单位:
Small RNA调控I-F型CRISPR-Cas适应性免疫性的应答及分子机制
-
批准号:32000033
-
项目类别:青年科学基金项目
-
资助金额:24.0万元
-
批准年份:2020
-
负责人:林平
-
依托单位:
Small RNAs调控解淀粉芽胞杆菌FZB42生防功能的机制研究
-
批准号:31972324
-
项目类别:面上项目
-
资助金额:58.0万元
-
批准年份:2019
-
负责人:高学文
-
依托单位:
变异链球菌small RNAs连接LuxS密度感应与生物膜形成的机制研究
-
批准号:81900988
-
项目类别:青年科学基金项目
-
资助金额:21.0万元
-
批准年份:2019
-
负责人:毛梦莹
-
依托单位:
肠道细菌关键small RNAs在克罗恩病发生发展中的功能和作用机制
-
批准号:31870821
-
项目类别:面上项目
-
资助金额:56.0万元
-
批准年份:2018
-
负责人:陈江宁
-
依托单位:
基于small RNA 测序技术解析鸽分泌鸽乳的分子机制
-
批准号:31802058
-
项目类别:青年科学基金项目
-
资助金额:26.0万元
-
批准年份:2018
-
负责人:麻慧
-
依托单位:
Small RNA介导的DNA甲基化调控的水稻草矮病毒致病机制
-
批准号:31772128
-
项目类别:面上项目
-
资助金额:60.0万元
-
批准年份:2017
-
负责人:吴建国
-
依托单位:
基于small RNA-seq的针灸治疗桥本甲状腺炎的免疫调控机制研究
-
批准号:81704176
-
项目类别:青年科学基金项目
-
资助金额:20.0万元
-
批准年份:2017
-
负责人:赵继梦
-
依托单位:
水稻OsSGS3与OsHEN1调控small RNAs合成及其对抗病性的调节
-
批准号:91640114
-
项目类别:重大研究计划
-
资助金额:85.0万元
-
批准年份:2016
-
负责人:何祖华
-
依托单位: