Collaborative Research: CIF: Small: Robust Machine Learning under Sparse Adversarial Attacks
协作研究:CIF:小型:稀疏对抗攻击下的鲁棒机器学习
基本信息
- 批准号:2236483
- 负责人:
- 金额:$ 30万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2023
- 资助国家:美国
- 起止时间:2023-06-01 至 2026-05-31
- 项目状态:未结题
- 来源:
- 关键词:
项目摘要
Machine-learning algorithms have proved successful in many applications, such as detecting handwriting, converting speech to text, detecting traffic signals for autonomous vehicles, or predicting a patient's diagnosis from medical data. A machine-learning model is usually "trained" to perform the designated task. This training is done by feeding many data samples to the model and using algorithms to adjust the model parameters so that its output is consistent with the provided training output most of the time. There are many challenges to performing this task reliably and efficiently. Recent research has shown that making small changes to the data points can lead to misdetection. Therefore, it is critical to make learning models robust against such data perturbations, especially in safety-critical applications such as autonomous driving. This project aims to achieve this for a specific category of data perturbations called "sparse attacks." Sparse-attack scenarios are those in which perturbations occur in only a few coordinates of the data, such as a few pixels in an image. Despite their importance and various real-world applications, sparse attacks have not been widely studied from a theoretical perspective. The goal of this project is to develop a theoretical framework for robust machine learning in the presence of adversarial perturbations that are bounded in L0 norm, or so-called sparse attacks. There have been significant theoretical studies on non-sparse adversarial attacks, but such fundamental understanding has been lacking for the sparse setting. This is partly due to the challenges in the L0 setting, namely, the L0 ball being non-convex and highly non-smooth. The first goal of this project is to study the fundamental limits of robust classification for stylized mathematical models. This will be done by proposing defense methods that are provably robust against L0 attacks, as well as proving converse results. Ideally, one aims to establish tight achievability and converse bounds asymptotically to fully characterize the optimal robust classifier. Motivated by practical considerations, the performance of the proposed defense methods in other scenarios will also be studied. In particular, this project explores the generalization properties of the proposed robust hypothesis class in order to study the effect of finite samples when the data distribution is unknown. Furthermore, the project consists of an evaluation plan to implement the developed defense mechanisms and analyze its performance in terms of learning a model which is robust against sparse attacks.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
机器学习算法已被证明在许多应用中是成功的,例如检测手写、将语音转换为文本、检测自动驾驶车辆的交通信号或从医疗数据预测患者的诊断。机器学习模型通常被“训练”来执行指定的任务。这种训练是通过向模型提供许多数据样本并使用算法来调整模型参数来完成的,以便其输出在大多数情况下与所提供的训练输出一致。要可靠有效地执行此任务,存在许多挑战。最近的研究表明,对数据点进行微小的更改可能会导致错误检测。因此,使学习模型对这种数据扰动具有鲁棒性至关重要,特别是在自动驾驶等安全关键型应用中。这个项目的目标是实现这一特定类别的数据扰动称为“稀疏攻击”。稀疏攻击场景是指扰动仅发生在数据的几个坐标中,例如图像中的几个像素。尽管它们的重要性和各种现实世界的应用,稀疏攻击还没有从理论的角度进行广泛的研究。该项目的目标是开发一个理论框架,用于在存在L0范数有界的对抗扰动或所谓的稀疏攻击的情况下进行鲁棒机器学习。关于非稀疏对抗性攻击已经有了重要的理论研究,但对于稀疏环境缺乏这种基本的理解。这部分是由于L0设置中的挑战,即,L0球是非凸的且高度非光滑的。这个项目的第一个目标是研究程式化数学模型的鲁棒分类的基本限制。这将通过提出可证明对L0攻击具有鲁棒性的防御方法以及证明匡威结果来实现。理想情况下,我们的目标是建立严格的可扩展性和匡威界渐近充分表征最佳的鲁棒分类器。出于实际考虑,还将研究所提出的防御方法在其他情况下的性能。特别是,这个项目探讨了建议的鲁棒假设类的泛化特性,以研究有限样本的数据分布未知时的效果。此外,该项目还包括一个评估计划,以实施开发的防御机制,并分析其在学习模型方面的性能,该模型对稀疏攻击具有鲁棒性。该奖项反映了NSF的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估而被认为值得支持。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
数据更新时间:{{ journalArticles.updateTime }}
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
数据更新时间:{{ journalArticles.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ monograph.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ sciAawards.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ conferencePapers.updateTime }}
{{ item.title }}
- 作者:
{{ item.author }}
数据更新时间:{{ patent.updateTime }}
Ramtin Pedarsani其他文献
Asynchronous and noncoherent neighbor discovery for the IoT using sparse-graph codes
使用稀疏图代码的物联网异步和非相干邻居发现
- DOI:
- 发表时间:
2017 - 期刊:
- 影响因子:0
- 作者:
Kabir Chandrasekher;Kangwook Lee;P. Kairouz;Ramtin Pedarsani;K. Ramchandran - 通讯作者:
K. Ramchandran
Control and Management of Urban Traffic Networks with Mixed Autonomy
- DOI:
- 发表时间:
2020 - 期刊:
- 影响因子:8.7
- 作者:
Ramtin Pedarsani - 通讯作者:
Ramtin Pedarsani
Optimality of Least-squares for Classification in Gaussian-Mixture Models
高斯混合模型中分类的最小二乘最优性
- DOI:
- 发表时间:
2020 - 期刊:
- 影响因子:0
- 作者:
Hossein Taheri;Ramtin Pedarsani;Christos Thrampoulidis - 通讯作者:
Christos Thrampoulidis
Capacity-approaching PhaseCode for low-complexity compressive phase retrieval
用于低复杂度压缩相位检索的接近容量的 PhaseCode
- DOI:
- 发表时间:
2014 - 期刊:
- 影响因子:0
- 作者:
Ramtin Pedarsani;Kangwook Lee;K. Ramchandran - 通讯作者:
K. Ramchandran
Robust scheduling for flexible processing networks
灵活处理网络的鲁棒调度
- DOI:
10.1017/apr.2017.14 - 发表时间:
2016 - 期刊:
- 影响因子:1.2
- 作者:
Ramtin Pedarsani;J. Walrand;Y. Zhong - 通讯作者:
Y. Zhong
Ramtin Pedarsani的其他文献
{{
item.title }}
{{ item.translation_title }}
- DOI:
{{ item.doi }} - 发表时间:
{{ item.publish_year }} - 期刊:
- 影响因子:{{ item.factor }}
- 作者:
{{ item.authors }} - 通讯作者:
{{ item.author }}
{{ truncateString('Ramtin Pedarsani', 18)}}的其他基金
NSF-NSERC: Fairness Fundamentals: Geometry-inspired Algorithms and Long-term Implications
NSF-NSERC:公平基础:几何启发的算法和长期影响
- 批准号:
2342253 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
Collaborative Research: Mixed-Autonomy Traffic Networks: Routing Games and Learning Human Choice Models
合作研究:混合自主交通网络:路由博弈和学习人类选择模型
- 批准号:
1952920 - 财政年份:2020
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
MLWiNS: Optimization and Coding Theory for Fast and Robust Wireless Distributed Learning
MLWiNS:快速、稳健的无线分布式学习的优化和编码理论
- 批准号:
2003035 - 财政年份:2020
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
CIF: Small: A Systematic Approach to Adversarial Machine Learning: Sparsity-based Defenses and Locally Linear Attacks
CIF:小型:对抗性机器学习的系统方法:基于稀疏性的防御和局部线性攻击
- 批准号:
1909320 - 财政年份:2019
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
CRII: CIF: Next-Generation Group Testing for Neighbor Discovery in the IoT via Sparse-Graph Codes
CRII:CIF:通过稀疏图代码在物联网中进行邻居发现的下一代组测试
- 批准号:
1755808 - 财政年份:2018
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
相似国自然基金
Research on Quantum Field Theory without a Lagrangian Description
- 批准号:24ZR1403900
- 批准年份:2024
- 资助金额:0.0 万元
- 项目类别:省市级项目
Cell Research
- 批准号:31224802
- 批准年份:2012
- 资助金额:24.0 万元
- 项目类别:专项基金项目
Cell Research
- 批准号:31024804
- 批准年份:2010
- 资助金额:24.0 万元
- 项目类别:专项基金项目
Cell Research (细胞研究)
- 批准号:30824808
- 批准年份:2008
- 资助金额:24.0 万元
- 项目类别:专项基金项目
Research on the Rapid Growth Mechanism of KDP Crystal
- 批准号:10774081
- 批准年份:2007
- 资助金额:45.0 万元
- 项目类别:面上项目
相似海外基金
Collaborative Research: CIF: Medium: Snapshot Computational Imaging with Metaoptics
合作研究:CIF:Medium:Metaoptics 快照计算成像
- 批准号:
2403122 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
Collaborative Research: CIF-Medium: Privacy-preserving Machine Learning on Graphs
合作研究:CIF-Medium:图上的隐私保护机器学习
- 批准号:
2402815 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
Collaborative Research: CIF: Small: Mathematical and Algorithmic Foundations of Multi-Task Learning
协作研究:CIF:小型:多任务学习的数学和算法基础
- 批准号:
2343599 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
Collaborative Research: CIF: Small: Mathematical and Algorithmic Foundations of Multi-Task Learning
协作研究:CIF:小型:多任务学习的数学和算法基础
- 批准号:
2343600 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
Collaborative Research: CIF-Medium: Privacy-preserving Machine Learning on Graphs
合作研究:CIF-Medium:图上的隐私保护机器学习
- 批准号:
2402817 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
Collaborative Research: CIF-Medium: Privacy-preserving Machine Learning on Graphs
合作研究:CIF-Medium:图上的隐私保护机器学习
- 批准号:
2402816 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
Collaborative Research: NSF-AoF: CIF: Small: AI-assisted Waveform and Beamforming Design for Integrated Sensing and Communication
合作研究:NSF-AoF:CIF:小型:用于集成传感和通信的人工智能辅助波形和波束成形设计
- 批准号:
2326622 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
Collaborative Research: CIF: Medium: Snapshot Computational Imaging with Metaoptics
合作研究:CIF:Medium:Metaoptics 快照计算成像
- 批准号:
2403123 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
Collaborative Research: NSF-AoF: CIF: Small: AI-assisted Waveform and Beamforming Design for Integrated Sensing and Communication
合作研究:NSF-AoF:CIF:小型:用于集成传感和通信的人工智能辅助波形和波束成形设计
- 批准号:
2326621 - 财政年份:2024
- 资助金额:
$ 30万 - 项目类别:
Standard Grant
Collaborative Research: CIF: Small: Versatile Data Synchronization: Novel Codes and Algorithms for Practical Applications
合作研究:CIF:小型:多功能数据同步:实际应用的新颖代码和算法
- 批准号:
2312872 - 财政年份:2023
- 资助金额:
$ 30万 - 项目类别:
Standard Grant