CAREER: Protecting Deep Learning Systems against Hardware-Oriented Vulnerabilities

职业:保护深度学习系统免受面向硬件的漏洞的影响

基本信息

  • 批准号:
    2047384
  • 负责人:
  • 金额:
    $ 50万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Continuing Grant
  • 财政年份:
    2021
  • 资助国家:
    美国
  • 起止时间:
    2021-05-01 至 2024-04-30
  • 项目状态:
    已结题

项目摘要

Artificial intelligence (AI) has recently approached or even surpassed human-level performance in many applications. However, the successful deployment of AI requires sufficient robustness against adversarial attacks of all types and in all phases of the model life cycle. Although much progress has been made in enhancing the robustness of AI algorithms, there is a lack of systematic studies on hardware-oriented vulnerabilities and countermeasures, which also opens up demand for AI security education. Given this pressing need, this project aims at exploring novel hardware-oriented adversarial AI concepts and developing fundamental defensive strategies against such vulnerabilities to protect next-generation AI systems. This project has four thrusts. In Thrust 1, this project will exploit new adversarial attacks on deep neural network systems, featuring the design of an algorithm-hardware collaborative backdoor attack. Then in Thrust 2, it will develop methodologies that incorporate the hardware aspect into defense for enhancing adversarial robustness against vulnerabilities in the untrusted semiconductor supply chain. Subsequently, in Thrust 3, this project will develop novel signature embedding frameworks to protect the integrity of deep neural network models in the untrusted model building supply chain and finally in Thrust 4, it will model recovery strategies as an innovative approach to mitigate hardware-oriented fault attacks in the untrusted user-space.This project will yield novel methodologies for ensuring trust in AI systems from both the algorithm and hardware perspectives to meet the future needs of commercial products and national defense. In addition, it will catalyze advances in emerging AI applications across a broad range of sectors, including healthcare, autonomous vehicles, and Internet of things (IoT), triggering widespread implementation of AI in mobile and edge devices. New theories and techniques developed in this project will be integrated into undergraduate and graduate education and used to raise public awareness and promote understanding of the importance of AI security.Data, code and results generated in this project will be stored when appropriate in the research database managed by the Holcombe Department of Electrical and Computer Engineering at Clemson University. All data will be retained for at least five years after the end of this project or at least five years after publications, whichever is later. Longer periods will apply when questions arise from inquiries or investigations with respect to research. The project repository will be maintained under http://ylao.people.clemson.edu/hardware_AI_securityThis award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
人工智能(AI)最近在许多应用中接近甚至超过了人类水平的性能。然而,人工智能的成功部署需要在模型生命周期的所有阶段对所有类型的对抗性攻击具有足够的鲁棒性。虽然在增强人工智能算法的鲁棒性方面取得了很大进展,但缺乏对面向硬件的漏洞和对策的系统研究,这也开启了人工智能安全教育的需求。鉴于这一迫切需求,该项目旨在探索新的面向硬件的对抗性人工智能概念,并针对这些漏洞开发基本的防御策略,以保护下一代人工智能系统。这个项目有四个重点。在Thrust 1中,该项目将对深度神经网络系统进行新的对抗性攻击,其特点是设计算法-硬件协作后门攻击。然后在Thrust 2中,它将开发将硬件方面纳入防御的方法,以增强对抗不可信半导体供应链中漏洞的对抗鲁棒性。随后,在Thrust 3中,该项目将开发新颖的签名嵌入框架,以保护不可信模型构建供应链中深度神经网络模型的完整性,最后在Thrust 4中,它将恢复策略建模为一种创新方法,以减轻不受信任用户中面向硬件的故障攻击,该项目将产生新的方法,从算法和硬件的角度确保人工智能系统的信任,以满足商业产品和国防的未来需求。此外,它还将促进医疗保健、自动驾驶汽车和物联网(IoT)等广泛领域新兴人工智能应用的发展,引发人工智能在移动的和边缘设备中的广泛应用。该项目开发的新理论和技术将被整合到本科生和研究生教育中,并用于提高公众意识,促进对人工智能安全重要性的理解。该项目产生的数据,代码和结果将在适当时存储在由克莱姆森大学电气和计算机工程系管理的研究数据库中。所有数据将在本项目结束后至少保留五年,或在出版后至少保留五年,以较晚者为准。如果因研究方面的询问或调查而产生问题,则适用更长的期限。项目库将在http://ylao.people.clemson.edu/hardware_AI_securityThis奖下维护,反映了NSF的法定使命,并被认为值得通过使用基金会的知识价值和更广泛的影响审查标准进行评估来支持。

项目成果

期刊论文数量(12)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Genetic-based Joint Dynamic Pruning and Learning Algorithm to Boost DNN Performance
NNTesting: Neural Network Fault Attacks Detection Using Gradient-Based Test Vector Generation
CLPA: Clean-Label Poisoning Availability Attacks Using Generative Adversarial Nets
  • DOI:
    10.1609/aaai.v36i8.20902
  • 发表时间:
    2022-06
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Bingyin Zhao;Yingjie Lao
  • 通讯作者:
    Bingyin Zhao;Yingjie Lao
DeepHardMark: Towards Watermarking Neural Network Hardware
  • DOI:
    10.1609/aaai.v36i4.20367
  • 发表时间:
    2022-06
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Joseph Clements;Yingjie Lao
  • 通讯作者:
    Joseph Clements;Yingjie Lao
In Pursuit of Preserving the Fidelity of Adversarial Images
追求保持对抗性图像的保真度
  • DOI:
    10.1109/icassp43922.2022.9747529
  • 发表时间:
    2022
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Clements, Joseph;Lao, Yingjie
  • 通讯作者:
    Lao, Yingjie
{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Yingjie Lao其他文献

On the Construction of Composite Finite Fields for Hardware Obfuscation
硬件混淆的复合有限域构造
  • DOI:
    10.1109/tc.2019.2901483
  • 发表时间:
    2019
  • 期刊:
  • 影响因子:
    3.7
  • 作者:
    Xinmiao Zhang;Yingjie Lao
  • 通讯作者:
    Yingjie Lao
Integral Sampler and Polynomial Multiplication Architecture for Lattice-based Cryptography
用于基于格的密码学的积分采样器和多项式乘法架构
Pipelined High-Throughput NTT Architecture for Lattice-Based Cryptography
用于基于格的密码学的流水线高吞吐量 NTT 架构
An In-Place FFT Architecture for Real-Valued Signals
适用于实值信号的就地 FFT 架构
Sailfish: A Dependency-Aware and Resource Efficient Scheduling for Low Latency in Clouds
Sailfish:云中低延迟的依赖感知和资源高效调度

Yingjie Lao的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Yingjie Lao', 18)}}的其他基金

Collaborative Research: SHF: Small: Efficient and Scalable Privacy-Preserving Neural Network Inference based on Ciphertext-Ciphertext Fully Homomorphic Encryption
合作研究:SHF:小型:基于密文-密文全同态加密的高效、可扩展的隐私保护神经网络推理
  • 批准号:
    2412357
  • 财政年份:
    2024
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant
CAREER: Protecting Deep Learning Systems against Hardware-Oriented Vulnerabilities
职业:保护深度学习系统免受面向硬件的漏洞的影响
  • 批准号:
    2426299
  • 财政年份:
    2024
  • 资助金额:
    $ 50万
  • 项目类别:
    Continuing Grant
Collaborative Research: SaTC: CORE: Small: Towards Secure and Trustworthy Tree Models
协作研究:SaTC:核心:小型:迈向安全可信的树模型
  • 批准号:
    2413046
  • 财政年份:
    2024
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant
Collaborative Research: SaTC: CORE: Small: Towards Secure and Trustworthy Tree Models
协作研究:SaTC:核心:小型:迈向安全可信的树模型
  • 批准号:
    2247620
  • 财政年份:
    2023
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant
Collaborative Research: SHF: Small: Efficient and Scalable Privacy-Preserving Neural Network Inference based on Ciphertext-Ciphertext Fully Homomorphic Encryption
合作研究:SHF:小型:基于密文-密文全同态加密的高效、可扩展的隐私保护神经网络推理
  • 批准号:
    2243052
  • 财政年份:
    2023
  • 资助金额:
    $ 50万
  • 项目类别:
    Standard Grant

相似国自然基金

高功率光纤激光深熔焊接熔池/羽辉的微束高速保护气流 主动调控方法研究
  • 批准号:
    2024JJ8002
  • 批准年份:
    2024
  • 资助金额:
    0.0 万元
  • 项目类别:
    省市级项目
基于天然深共晶溶剂@海藻酸钙(NADES@CA)共晶凝胶囊泡的酵母高保活技术及其低温冷冻保护机制探究
  • 批准号:
    32302274
  • 批准年份:
    2023
  • 资助金额:
    30 万元
  • 项目类别:
    青年科学基金项目
circRNA-MYLK/miRNA-195调控SIRT3/OGG1/DNA甲基化在意外深低温心跳骤停ECPB控制再灌注时的脑保护作用
  • 批准号:
  • 批准年份:
    2021
  • 资助金额:
    57 万元
  • 项目类别:
    面上项目
“冬眠诱导因子”及lncRNA Tug1/miR-223 crosstalk信号通路在深低温停循环脑保护的应用机制研究
  • 批准号:
    82000437
  • 批准年份:
    2020
  • 资助金额:
    24 万元
  • 项目类别:
    青年科学基金项目
附子多糖在深低温保存过程中对血管保护机制的多层次研究
  • 批准号:
    81960824
  • 批准年份:
    2019
  • 资助金额:
    34.0 万元
  • 项目类别:
    地区科学基金项目
香蕉地机械化深松土机耦合过程解析及其高效减阻优化
  • 批准号:
    51865007
  • 批准年份:
    2018
  • 资助金额:
    40.0 万元
  • 项目类别:
    地区科学基金项目
意外深低温心跳骤停ECPB复苏时NHE1/SIRT3/CypD通路调控mPTP开放对神经系统的保护作用及机制研究
  • 批准号:
    81871515
  • 批准年份:
    2018
  • 资助金额:
    57.0 万元
  • 项目类别:
    面上项目
MiR-223调控IGF-1通路在深低温停循环脑保护中的作用及机制研究
  • 批准号:
    81601709
  • 批准年份:
    2016
  • 资助金额:
    18.0 万元
  • 项目类别:
    青年科学基金项目
急性主动脉夹层手术中低温停循环对凝血系统影响的机制研究
  • 批准号:
    81600362
  • 批准年份:
    2016
  • 资助金额:
    17.5 万元
  • 项目类别:
    青年科学基金项目

相似海外基金

Protecting aquifers in the race to net-zero carbon emissions
在净零碳排放竞赛中保护含水层
  • 批准号:
    IM230100831
  • 财政年份:
    2024
  • 资助金额:
    $ 50万
  • 项目类别:
    Mid-Career Industry Fellowships
Rare Event Simulation: Protecting vital infrastructure from flood extremes
罕见事件模拟:保护重要基础设施免受极端洪水影响
  • 批准号:
    DP240101365
  • 财政年份:
    2024
  • 资助金额:
    $ 50万
  • 项目类别:
    Discovery Projects
Protecting oyster aquaculture from heatwaves and flooding rains
保护牡蛎养殖免受热浪和洪水的影响
  • 批准号:
    DE240100272
  • 财政年份:
    2024
  • 资助金额:
    $ 50万
  • 项目类别:
    Discovery Early Career Researcher Award
BIOFIN - Protecting and Restoring Biodiversity using mainstream Finance
BIOFIN - 利用主流金融保护和恢复生物多样性
  • 批准号:
    10092956
  • 财政年份:
    2024
  • 资助金额:
    $ 50万
  • 项目类别:
    EU-Funded
Protecting children's health through forecast based anticipatory action (PROCHAIN)
通过基于预测的预期行动保护儿童健康 (PROCHAIN)
  • 批准号:
    NE/Y005112/1
  • 财政年份:
    2024
  • 资助金额:
    $ 50万
  • 项目类别:
    Research Grant
Protecting Women from Economic shocks to fight HIV in Africa (POWER)
保护非洲妇女免受经济冲击,抗击艾滋病毒 (POWER)
  • 批准号:
    MR/Y003837/1
  • 财政年份:
    2024
  • 资助金额:
    $ 50万
  • 项目类别:
    Fellowship
CAREER: Protecting Deep Learning Systems against Hardware-Oriented Vulnerabilities
职业:保护深度学习系统免受面向硬件的漏洞的影响
  • 批准号:
    2426299
  • 财政年份:
    2024
  • 资助金额:
    $ 50万
  • 项目类别:
    Continuing Grant
Protecting spermatogonial stem cells from chemotherapy-induced damage for fertility preservation in childhood cancer
保护精原干细胞免受化疗引起的损伤,以保存儿童癌症的生育能力
  • 批准号:
    MR/Y011783/1
  • 财政年份:
    2024
  • 资助金额:
    $ 50万
  • 项目类别:
    Fellowship
CAREER: Protecting Microbes to Protect Plants
职业:保护微生物以保护植物
  • 批准号:
    2339379
  • 财政年份:
    2024
  • 资助金额:
    $ 50万
  • 项目类别:
    Continuing Grant
NESP MaC Project 4.12 – Protecting valuable shoreline mangroves of northern Australia 2024-2026 (JCU)
NESP MaC 项目 4.12 — 保护澳大利亚北部宝贵的海岸线红树林 2024-2026 (JCU)
  • 批准号:
    global : 2ebc304d-a407-4f14-bb7b-bd38a8590de5
  • 财政年份:
    2024
  • 资助金额:
    $ 50万
  • 项目类别:
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了