EAGER: Towards Adversarial Attack Resistant Machine Learning Systems
EAGER:迈向抗对抗性攻击的机器学习系统
基本信息
- 批准号:1953166
- 负责人:
- 金额:$ 30万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2020
- 资助国家:美国
- 起止时间:2020-02-15 至 2024-01-31
- 项目状态:已结题
- 来源:
- 关键词:
项目摘要
Machine learning based pattern classification and related advances like deep learning have demonstrated impressive capabilities in multiple application domains, ranging from computer vision to medical diagnosis. However, it has also been shown that it is relatively straight-forward to create adversarial inputs that can fool machine learning models. The goal of this project is to develop defenses for machine learning models that are robust even in the face of sophisticated and determined adversaries. This project will have broad impact on the security of machine learning systems, advance cross-disciplinary research, and promote participation of undergraduates and under-represented groups in computer engineering research and education.This project will pursue two lines of defenses designed to hinder gradient ascent techniques used in adversarial input generation. The first line of defense will add controlled noise to output confidence levels to deny an adversary access to the precise classification boundary, while seeking to preserve model accuracy. The second line of defense will pursue choosing a random model in a query step from a pool of multiple trained models which have similar classification accuracy but differ in internal parameters and confidence levels. To test effectiveness of defenses, this project will also develop a gray-box model for accelerating adversarial input generation from a black-box machine learning model.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
基于机器学习的模式分类和深度学习等相关进展在从计算机视觉到医疗诊断的多个应用领域都显示出了令人印象深刻的能力。然而,也有研究表明,创建可以愚弄机器学习模型的对抗性输入是相对直接的。这个项目的目标是为机器学习模型开发防御措施,即使面对复杂和坚定的对手也是稳健的。这个项目将对机器学习系统的安全性产生广泛的影响,促进跨学科研究,并促进本科生和未被充分代表的群体参与计算机工程研究和教育。该项目将寻求两条防线,旨在阻止在对抗性输入生成中使用的梯度上升技术。第一道防线将向输出置信度添加受控噪声,以拒绝对手访问精确的分类边界,同时寻求保持模型的准确性。第二道防线将追求在查询步骤中从具有相似分类精度但内部参数和置信度不同的多个训练模型池中选择随机模型。为了测试防御的有效性,该项目还将开发一个灰箱模型,用于从黑箱机器学习模型加速对手输入的生成。该奖项反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
项目成果
期刊论文数量(2)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Towards Adversarial Attack Resistant Deep Neural Networks
- DOI:
- 发表时间:2020
- 期刊:
- 影响因子:0
- 作者:Tiago A. O. Alves;S. Kundu
- 通讯作者:Tiago A. O. Alves;S. Kundu
Preventing DNN Model IP Theft via Hardware Obfuscation
通过硬件混淆防止 DNN 模型 IP 盗窃
- DOI:10.1109/jetcas.2021.3076151
- 发表时间:2021
- 期刊:
- 影响因子:4.6
- 作者:Goldstein, Brunno F.;Patil, Vinay C.;Ferreira, Victor C.;Nery, Alexandre S.;Franca, Felipe M.;Kundu, Sandip
- 通讯作者:Kundu, Sandip
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Sandip Kundu其他文献
Memory Scraping Attack on Xilinx FPGAs: Private Data Extraction from Terminated Processes
Xilinx FPGA 上的内存抓取攻击:从终止进程中提取私有数据
- DOI:
10.48550/arxiv.2405.13927 - 发表时间:
2024 - 期刊:
- 影响因子:0
- 作者:
Bharadwaj Madabhushi;Sandip Kundu;Daniel Holcomb - 通讯作者:
Daniel Holcomb
Robust tests for parity trees
- DOI:
10.1007/bf00938682 - 发表时间:
1990-10-01 - 期刊:
- 影响因子:1.300
- 作者:
Sandip Kundu;Sudhakar M. Reddy - 通讯作者:
Sudhakar M. Reddy
CORRELATION OF HbA1c WITH URINARY ACR, eGFR AND SERUM CREATININE IN TYPE 2 DIABETES MELLITUS
2 型糖尿病中 HbA1c 与尿 ACR、eGFR 和血清肌酐的相关性
- DOI:
10.14260/jemds/2017/507 - 发表时间:
2017 - 期刊:
- 影响因子:0
- 作者:
Sandip Kundu;I. Biswas;Nirmalya Roy;N. Basu - 通讯作者:
N. Basu
Test Challenges in Nanometer Technologies
- DOI:
10.1023/a:1012203009875 - 发表时间:
2001-06-01 - 期刊:
- 影响因子:1.300
- 作者:
Sandip Kundu;Sujit T. Zachariah;Sanjay Sengupta;Rajesh Galivanche - 通讯作者:
Rajesh Galivanche
Novel betaines/mesoionic compounds via a simple and convenient MCR in aqueous micellar system: synthesis of thiazolo[2,3-a]isoquinolin-4-ium derivatives
在水性胶束体系中通过简单方便的MCR制备新型甜菜碱/介离子化合物:噻唑并[2,3-a]异喹啉-4-鎓衍生物的合成
- DOI:
- 发表时间:
2014 - 期刊:
- 影响因子:0
- 作者:
A. Maity;Debanjan Chakraborty;A. Hazra;Yogesh P. Bharitkar;Sandip Kundu;P. Maulik;N. B. Mondal - 通讯作者:
N. B. Mondal
Sandip Kundu的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Sandip Kundu', 18)}}的其他基金
SaTC: CORE: Small: Emerging Security Challenges and a Solution Framework for FPGA-accelerated Cloud Computing
SaTC:CORE:小型:新兴安全挑战和 FPGA 加速云计算的解决方案框架
- 批准号:
2247059 - 财政年份:2023
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
A Design Framework for Improving Reliability, Debug and Security of Multi-Core Systems
提高多核系统可靠性、调试和安全性的设计框架
- 批准号:
0903191 - 财政年份:2009
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
Improving Reliability and Availability of Chip Multiprocessors
提高芯片多处理器的可靠性和可用性
- 批准号:
0811467 - 财政年份:2008
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
SGER: Dynamic hardware adaptation of high performance CMPs for managing thermal hotspots
SGER:高性能 CMP 的动态硬件适配,用于管理热点
- 批准号:
0649824 - 财政年份:2006
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
相似海外基金
Sexual offence interviewing: Towards victim-survivor well-being and justice
性犯罪面谈:为了受害者-幸存者的福祉和正义
- 批准号:
DE240100109 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Discovery Early Career Researcher Award
Unlocking the sensory secrets of predatory wasps: towards predictive tools for managing wasps' ecosystem services in the Anthropocene
解开掠食性黄蜂的感官秘密:开发用于管理人类世黄蜂生态系统服务的预测工具
- 批准号:
NE/Y001397/1 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Research Grant
Development of programmable nanomachines towards the enzymatic synthesis of peptide oligonucleotide conjugates
开发用于肽寡核苷酸缀合物酶促合成的可编程纳米机器
- 批准号:
EP/X019624/1 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Fellowship
Postdoctoral Fellowship: STEMEdIPRF: Towards a Diverse Professoriate: Experiences that Inform Underrepresented Scholars' Perceptions of Value Alignment and Career Decisions
博士后奖学金:STEMEdIPRF:走向多元化的教授职称:为代表性不足的学者对价值调整和职业决策的看法提供信息的经验
- 批准号:
2327411 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
CAREER: Adaptive Deep Learning Systems Towards Edge Intelligence
职业:迈向边缘智能的自适应深度学习系统
- 批准号:
2338512 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
CAREER: Towards highly efficient UV emitters with lattice engineered substrates
事业:采用晶格工程基板实现高效紫外线发射器
- 批准号:
2338683 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
ASCENT: Heterogeneously Integrated and AI-Empowered Millimeter-Wave Wide-Bandgap Transmitter Array towards Energy- and Spectrum-Efficient Next-G Communications
ASCENT:异构集成和人工智能支持的毫米波宽带隙发射机阵列,实现节能和频谱高效的下一代通信
- 批准号:
2328281 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
Collaborative Research: Maritime to Inland Transitions Towards ENvironments for Convection Initiation (MITTEN CI)
合作研究:海洋到内陆向对流引发环境的转变(MITTEN CI)
- 批准号:
2349935 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
Collaborative Research: Maritime to Inland Transitions Towards ENvironments for Convection Initiation (MITTEN CI)
合作研究:海洋到内陆向对流引发环境的转变(MITTEN CI)
- 批准号:
2349934 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Continuing Grant
NSF-BSF: Towards a Molecular Understanding of Dynamic Active Sites in Advanced Alkaline Water Oxidation Catalysts
NSF-BSF:高级碱性水氧化催化剂动态活性位点的分子理解
- 批准号:
2400195 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Standard Grant