课题基金 / 基金详情

EAGER: Toward Attack-Resilient Statistical Inference

EAGER: Toward Attack-Resilient Statistical Inference
EAGER:迈向抗攻击统计推断
批准号:
2224150
负责人:
Jinsub Kim
金额:
$25.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2022
资助国家:
美国
项目状态:
未结题
起止时间:
2022-07-01 至 2025-06-30

项目摘要

项目成果

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Classical techniques and theories for statistical inference had been developed under the assumption that there is no adversarial attempt to manipulate the input data. Such a nature renders most existing statistical inference techniques unreliable and the associated theories irrelevant when they are deployed to an adversarial environment. This existing gap is a matter of great concern because many modern statistical inference tasks in mission-critical systems (e.g., the nation's power grids) and safety-critical systems (e.g., autonomous driving systems) are relying on sensor data that could be vulnerable to falsification by an adversary. For instance, an adversary can launch a spoofing attack to manipulate lidar or vision sensor data in an autonomous driving system such that the object detection algorithm will fail to detect certain obstacle in front of the car. Despite recent advances in robust statistical inference, there still is no general theory that characterizes optimal inference rules in the presence of data falsification or the fundamental limit of performing inference using falsified data. This project is aimed at addressing this gap by developing fundamental theory and optimal methods for robust inference in the presence of data falsification by an adversary. The project will advance the state-of-the-art in robust statistics, robust sensing, and security of machine learning. Furthermore, the project will contribute to the national security by generating the outcomes that can be applied to significantly improve resilience of safety-critical and mission-critical systems of the nation against data falsification attacks. The technical objectives of the project are to investigate fundamental limits of performing hypothesis testing and estimation in the presence of adversarial data falsification and to develop robust inference methods, supported by theoretical analyses, to mitigate the impact of data falsification. The developed theory and methods will be further extended to develop a novel framework to train an attack-resilient machine learning model. In pursuing these objectives, a game-theoretic formulation will be employed to rigorously model the complex interplay between the defender designing a robust inference method and the adversary optimizing the data falsification strategy against the defender's design of the inference method. Techniques from optimization, game theory, and probability theory will be leveraged to derive optimal robust inference methods for the game-theoretic formulation and analyze their properties. Furthermore, power system state estimation in the presence of falsified meter measurements will be considered as a case study, and a robust power system state estimator will be developed and evaluated in a rigorous game-theoretic setup.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
Forensics for Adversarial Machine Learning Through Attack Mapping Identification
通过攻击映射识别进行对抗性机器学习取证
DOI: 10.1109/icassp49357.2023.10095092
发表时间: 2023
期刊: and Signal Processing (ICASSP
影响因子: --
作者: [Yan, Allen, Kim, Jinsub, Raich, Raviv]
通讯作者: Raich, Raviv
国内基金
海外基金
Toward a general theory of intermittent aeolian and fluvial nonsuspended sediment transport
  • 批准号:
    --
  • 项目类别:
    --
  • 资助金额:
    55万元
  • 批准年份:
    2022
  • 负责人:
    Thomas Pahtz
  • 依托单位: