SaTC: CORE: Small: Collaborative: When Adversarial Learning Meets Differential Privacy: Theoretical Foundation and Applications
SaTC: CORE: Small: Collaborative: When Adversarial Learning Meets Differential Privacy: Theoretical Foundation and Applications
批准号:
1935928
负责人:
Hai Phan
金额:
$25.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2020
资助国家:
美国
项目状态:
已结题
起止时间:
2020-07-01 至 2024-06-30
中文摘要
机器学习的普及暴露了软件系统中新的严重漏洞,在软件系统中,部署的深度神经网络可被利用来揭示私人训练数据中的敏感信息,并使模型错误分类。然而,现有的学习算法在理论和实践上都没有被设计成对这种隐私和完整性攻击同时具有健壮性。在现场试验中,这种缺乏保护和有效性的情况会显著降低基于机器学习的系统的性能,并使敏感数据面临高风险,从而使服务提供商面临基于HIPAA/HITECH法律和相关法规的法律诉讼。该项目旨在开发第一个框架来推进和无缝集成关键技术,包括对抗性学习、隐私保护和认证防御,提供针对隐私和完整性攻击的严密和可靠的保护,同时保持深度神经网络的高模型实用性。该系统正在为可扩展的、复杂的和常用的机器学习框架而开发,为行业和教育环境提供根本影响。该项目的最终目标是构建对抗性学习中隐私保护的核心基础,以更好地解决模型效用、隐私损失和认证防御之间的权衡。因此,该团队通过引入一套新的严格理论来解决模型效用和隐私损失之间的权衡,从理论上将对抗性学习和隐私保护联系起来。为了进一步加强系统的安全性,该小组将进行一类新的攻击,以发现以前未知和未受保护的漏洞,包括数据实例之间高度敏感和隐藏的关联结构,这些结构将被用来放大现有的模型攻击。在这一努力的基础上,将自动识别和保护易受攻击的特征和相关性,从而在给定模型训练和推理的情况下,实现统一的健壮和隐私保护学习。最后,该团队将优化模型效用、隐私损失和认证防御之间的权衡。该项目预计将为关键隐私保护技术奠定理论和实践基础,以保护用户在模型攻击下的对抗性学习中的个人和高度敏感数据。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
The pervasiveness of machine learning exposes new and severe vulnerabilities in software systems, where deployed deep neural networks can be exploited to reveal sensitive information in private training data, and to make the models misclassify. However, existing learning algorithms have not been designed to be simultaneously robust to such privacy and integrity attacks, in both theory and practice. In field trials, such lack of protection and efficacy significantly degrades the performance of machine learning-based systems, and puts sensitive data at high risk, thereby exposing service providers to legal action based on HIPAA/HITECH law and related regulations. This project aims to develop the first framework to advance and seamlessly integrate key techniques, including adversarial learning, privacy preserving, and certified defenses, offering tight and reliable protection against both privacy and integrity attacks, while retaining high model utility in deep neural networks. The system is being developed for scalable, complex, and commonly used machine learning frameworks, providing a fundamental impact to both industry and educational environments.An ultimate goal of this project is to build a core foundation of privacy preservation in adversarial learning, to better address the trade-off between model utility, privacy loss, and certified defenses. Accordingly, the team theoretically connects adversarial learning and privacy preservation by introducing a new set of rigorous theories to address the trade-off between model utility and privacy loss. To further strengthen the safety of the system, the team will conduct a new class of attacks towards discovering previously unknown and unprotected vulnerabilities, including highly sensitive and hidden correlation structures among data instances, which will be used to amplify existing model attacks. Based upon that effort, vulnerable features and correlations will be automatically identified and protected, towards unified robust and privacy preserving learning, given both model training and inference. Finally, the team will optimize the trade-off among model utility, privacy loss, and certified defenses. The project is expected to lay a theoretical and practical foundation of key privacy-preserving techniques to protect users' personal and highly sensitive data in adversarial learning under model attacks.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(6)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.48550/arxiv.2302.12685
发表时间:
2023-02
期刊:
ArXiv
影响因子:
--
作者:
[Truc D. T. Nguyen;Phung Lai;K. Tran;Nhathai Phan;M. Thai]
通讯作者:
Truc D. T. Nguyen;Phung Lai;K. Tran;Nhathai Phan;M. Thai
DOI:
10.48550/arxiv.2212.04454
发表时间:
2022-12
期刊:
影响因子:
--
作者:
[Truc D. T. Nguyen;Phung Lai;Nhathai Phan;M. Thai]
通讯作者:
Truc D. T. Nguyen;Phung Lai;Nhathai Phan;M. Thai
DOI:
10.1109/bigdata55660.2022.10020501
发表时间:
2022-11
期刊:
2022 IEEE International Conference on Big Data (Big Data)
影响因子:
--
作者:
[Khang Tran;Phung Lai;Nhathai Phan;Issa M. Khalil;Yao Ma;Abdallah Khreishah;M. Thai;Xintao Wu]
通讯作者:
Khang Tran;Phung Lai;Nhathai Phan;Issa M. Khalil;Yao Ma;Abdallah Khreishah;M. Thai;Xintao Wu
Continual Learning with Differential Privacy
具有差异隐私的持续学习
DOI:
10.1007/978-3-030-92310-5_39
发表时间:
2021
期刊:
International Conference on Neural Information Processing
影响因子:
--
作者:
[Desai, Pradnya, Lai, Phung, Phan, NhatHai, Thai, My T.]
通讯作者:
Thai, My T.
Lifelong DP: Consistently Bounded Differential Privacy in Lifelong Machine Learning
终身 DP:终身机器学习中始终有界的差分隐私
DOI:
--
发表时间:
2022
期刊:
Conference on Lifelong Learning Agents. PMLR.
影响因子:
--
作者:
[Lai, Phung, Hu, Han, Phan, NhatHai, Jin, Ruoming, Thai, My T., Chen, An]
通讯作者:
Chen, An
共 6 条
EAGER: Collaborative Research: Understanding Human Behaviors and Mental Health using Federated Machine Learning on Smart Phones
-
批准号:2041096
-
项目类别:Standard Grant
-
资助金额:$7.5万
-
财政年份:2020
-
负责人:Hai Phan
-
依托单位:
CRII: SaTC: PrivateNet - Preserving Differential Privacy in Deep Learning under Model Attacks
-
批准号:1850094
-
项目类别:Standard Grant
-
资助金额:$17.4万
-
财政年份:2019
-
负责人:Hai Phan
-
依托单位:
国内基金
海外基金
登录
查看更多内容
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
-
批准号:82371765
-
项目类别:面上项目
-
资助金额:50万元
-
批准年份:2023
-
负责人:谭广云
-
依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
-
批准号:22303037
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2023
-
负责人:鲁俊波
-
依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
-
批准号:--
-
项目类别:--
-
资助金额:52万元
-
批准年份:2022
-
负责人:孙丙军
-
依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:叶成林
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:--
-
项目类别:--
-
资助金额:55万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:82072415
-
项目类别:面上项目
-
资助金额:55.0万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
-
批准号:92053110
-
项目类别:重大研究计划
-
资助金额:70.0万元
-
批准年份:2020
-
负责人:彭鹏
-
依托单位:
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
-
批准号:81902805
-
项目类别:青年科学基金项目
-
资助金额:20.5万元
-
批准年份:2019
-
负责人:刘菲
-
依托单位:
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
-
批准号:41973063
-
项目类别:面上项目
-
资助金额:65.0万元
-
批准年份:2019
-
负责人:周游
-
依托单位:
CORDEX-CORE区域气候模拟与预估研讨会
-
批准号:41981240365
-
项目类别:国际(地区)合作与交流项目
-
资助金额:1.5万元
-
批准年份:2019
-
负责人:陈威霖
-
依托单位: