CAREER: Trustworthy Machine Learning from Untrusted Models
CAREER: Trustworthy Machine Learning from Untrusted Models
批准号:
1953893
负责人:
Ting Wang
金额:
$50.99万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-08-15 至 2023-12-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Many of today's machine learning (ML)-based systems are not built from scratch, but are "composed" from an array of pre-trained, third-party models. Paralleling other forms of software reuse, reusing models can both speed up and simplify the development of ML-based systems. However, a lack of standardization, regulation, and verification of third-party ML models raises security concerns. In particular, ML models are subject to adversarial attacks in which third-party attackers or model providers themselves might embed hidden behaviors that are triggered by pre-specified inputs. This project aims at understanding the security threats incurred by reusing third-party models as building blocks of ML systems and developing tools to help developers mitigate such threats throughout the lifecycle of ML systems. Outcomes from the project will improve ML security in applications from self-driving cars to authentication in the short term while promoting more principled practices of building and operating ML systems in the long run.One major type of threat incurred by reusing third-party models is model reuse attacks, in which maliciously crafted models ("adversarial models") force host ML systems to malfunction on targeted inputs ("triggers") in a highly predictable manner. This project develops rigorous yet practical methods to proactively detect and remediate such backdoor vulnerabilities. First, it will empirically and analytically investigate the necessary conditions and invariant patterns of model reuse attacks. Second, leveraging these insights, it will develop a chain of mitigation tools that detect potential backdoors, pinpoint triggers, and provide mechanisms to fortify adversarial models against these attacks. Third, it will establish a unified theory of adversarial models and adversarial inputs to deepen more general understanding of adversarial ML. Finally, it will implement all the proposed techniques and system designs in the form of a prototype testbed, which provides a unique research facility for investigating a range of attack and defense techniques. New theories and techniques developed in this project will be integrated into undergraduate and graduate education and used to raise public awareness of the importance of ML security.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(36)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
Transfer Attacks Revisited: A Large-Scale Empirical Study in Real Computer Vision Settings
重新审视传输攻击:真实计算机视觉设置中的大规模实证研究
DOI:
10.1109/sp46214.2022.9833783
发表时间:
2022
期刊:
2022 IEEE Symposium on Security and Privacy
影响因子:
--
作者:
[Mao, Yuhao, Fu, Chong, Wang, Saizhuo, Ji, Shouling, Zhang, Xuhong, Liu, Zhenguang, Zhou, Jun, Liu, Alex X., Beyah, Raheem, Wang, Ting]
通讯作者:
Wang, Ting
DOI:
--
发表时间:
2022
期刊:
影响因子:
--
作者:
[Jianfeng Li;Hao Zhou;Shuohan Wu;Xiapu Luo;Ting Wang;Xian Zhan;Xiaobo Ma]
通讯作者:
Jianfeng Li;Hao Zhou;Shuohan Wu;Xiapu Luo;Ting Wang;Xian Zhan;Xiaobo Ma
Adversarial CAPTCHAs
对抗性验证码
DOI:
10.1109/tcyb.2021.3071395
发表时间:
2019-01
期刊:
{IEEE} Trans. Cybern.
影响因子:
--
作者:
[Chenghui Shi, Xiaogang Xu, Shouling Ji, Kai Bu, Jianhai Chen, Raheem Beyah, Ting Wang]
通讯作者:
Ting Wang
DOI:
--
发表时间:
2021
期刊:
影响因子:
--
作者:
[Pengfei Jing;Qiyi Tang;Yue Du;Lei Xue;Xiapu Luo;Ting Wang;Sen Nie;Shi Wu]
通讯作者:
Pengfei Jing;Qiyi Tang;Yue Du;Lei Xue;Xiapu Luo;Ting Wang;Sen Nie;Shi Wu
DOI:
10.1145/3544548.3581082
发表时间:
2023-02
期刊:
Proceedings of the 2023 CHI Conference on Human Factors in Computing Systems
影响因子:
--
作者:
[Yuan Sun;Qiurong Song;Xinning Gui;Fenglong Ma;Ting Wang]
通讯作者:
Yuan Sun;Qiurong Song;Xinning Gui;Fenglong Ma;Ting Wang
共 35 条
CAREER: Trustworthy Machine Learning from Untrusted Models
-
批准号:2405136
-
项目类别:Continuing Grant
-
资助金额:$50.99万
-
财政年份:2023
-
负责人:Ting Wang
-
依托单位:
Collaborative Research: PPoSS: LARGE: Principles and Infrastructure of Extreme Scale Edge Learning for Computational Screening and Surveillance for Health Care
-
批准号:2406572
-
项目类别:Continuing Grant
-
资助金额:$94.27万
-
财政年份:2023
-
负责人:Ting Wang
-
依托单位:
Collaborative Research: PPoSS: LARGE: Principles and Infrastructure of Extreme Scale Edge Learning for Computational Screening and Surveillance for Health Care
-
批准号:2119331
-
项目类别:Continuing Grant
-
资助金额:$94.27万
-
财政年份:2021
-
负责人:Ting Wang
-
依托单位:
SaTC: CORE: Small: Attack-Agnostic Defenses against Adversarial Inputs in Learning Systems
-
批准号:1953813
-
项目类别:Standard Grant
-
资助金额:$38.62万
-
财政年份:2019
-
负责人:Ting Wang
-
依托单位:
III: Small: Usable Interpretability
-
批准号:1910546
-
项目类别:Continuing Grant
-
资助金额:$49.56万
-
财政年份:2019
-
负责人:Ting Wang
-
依托单位:
III: Small: Usable Interpretability
-
批准号:1951729
-
项目类别:Continuing Grant
-
资助金额:$49.56万
-
财政年份:2019
-
负责人:Ting Wang
-
依托单位:
CAREER: Trustworthy Machine Learning from Untrusted Models
-
批准号:1846151
-
项目类别:Continuing Grant
-
资助金额:$50.99万
-
财政年份:2019
-
负责人:Ting Wang
-
依托单位:
SaTC: CORE: Small: Attack-Agnostic Defenses against Adversarial Inputs in Learning Systems
-
批准号:1718787
-
项目类别:Standard Grant
-
资助金额:$49.83万
-
财政年份:2017
-
负责人:Ting Wang
-
依托单位:
CRII: SaTC: Re-Envisioning Contextual Services and Mobile Privacy in the Era of Deep Learning
-
批准号:1566526
-
项目类别:Standard Grant
-
资助金额:$16.87万
-
财政年份:2016
-
负责人:Ting Wang
-
依托单位:
Engineering Initiation Award: Effects of Curvature, Pressure, Gradient, and Freestream Turbulence on Reynolds Analogy in Transitional Boundary Layer Flow
-
批准号:8708843
-
项目类别:Standard Grant
-
资助金额:$7.0万
-
财政年份:1987
-
负责人:Ting Wang
-
依托单位:
海外基金