课题基金 / 基金详情

CAREER: Towards Trustworthy Machine Learning via Learning Trustworthy Representations: An Information-Theoretic Framework

CAREER: Towards Trustworthy Machine Learning via Learning Trustworthy Representations: An Information-Theoretic Framework
职业:通过学习可信表示实现可信机器学习:信息理论框架
批准号:
2339686
负责人:
Binghui Wang
金额:
$54.8万
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2024
资助国家:
美国
项目状态:
未结题
起止时间:
2024-04-01 至 2029-03-31

项目摘要

项目成果

Binghui Wang的其他基金

相似基金

相关文献

中文摘要
翻译
这个项目的目标是使机器学习(ML)变得值得信赖。ML,特别是使用深度神经网络的深度学习,在计算机视觉、自然语言处理、生物学和数学等多个研究领域和学科取得了令人瞩目的突破。然而,在过去的十年里,大量的研究表明,ML模型容易受到隐私和安全攻击。例如,电子邮件垃圾邮件过滤器可能会受到数据中毒攻击的影响,即攻击者通过向ML模型提供虚假数据来混淆ML模型,从而允许攻击者发送包含恶意软件或其他安全威胁的恶意电子邮件而不被注意。攻击者还可以向模型发出重复请求,查看结果以重建用于构建ML模型的数据;例如,在健康领域,成功的数据重建攻击可能会暴露患者的私人医疗详细信息。已经提出了许多防御方法来缓解这些攻击,但它们面临着几个限制:它们在具有严格保密要求的现实世界应用程序中往往无效,或者不可接受地降低模型的性能。此外,大多数防御都是针对特定的学习方法或攻击类型,这使得处理多个并发攻击变得困难,并且对不同类型的模型和数据的泛化能力很差。这个项目的目标是通过设计一个基于信息论的可信学习框架来解决这些限制。该项目的成果将推动最先进的可信ML和信息理论隐私方法的发展,同时促进国家对ML和网络安全专业人员日益增长的需求。为此,该团队将设计一个实用、准确、灵活和可推广的信息理论可信表征学习框架,并提供健壮性和隐私保证。这项工作将围绕三个方面展开。推力1将设计新颖的信息论表示学习方法,以抵御常见的隐私攻击,包括成员关系推理、属性推理和数据重构攻击。推力2将设计新颖的信息论表示学习方法来抵御常见的安全攻击,包括测试时间逃避攻击、训练时间中毒攻击以及训练和测试时间后门攻击。推力3将推广推力1和推力2,以处理不同的攻击类型(例如,多个隐私/安全攻击或其组合)、数据类型(例如,时空数据、多模式数据)和学习类型(例如,联合学习、图学习、自我监督学习)。建议的框架将在几个领域的数据集和学习任务上进行评估,包括计算机视觉、自然语言处理、多媒体和网络。该团队将开发一个开源工具包,让学术界、工业界和政府的其他研究人员广泛使用这些技术。推广和教育活动,包括夏令营、讲座、讲座、教程和研讨会,将促进K-12、本科生和研究生的参与,重点是为STEM中代表性不足的群体提供机会。该奖项反映了NSF的法定使命,并通过使用基金会的智力价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
The objective of this project is to enable machine learning (ML) to be trustworthy. ML, especially deep learning that uses deep neural networks, has made remarkable breakthroughs in various research domains and disciplines including computer vision, natural language processing, biology, and math, to name a few. However, in the past decade, extensive work has shown ML models are vulnerable to privacy and security attacks. For example, email spam filters can be compromised by data poisoning attacks, where attackers confuse ML models by feeding them bogus data, allowing adversaries to send malicious emails containing malware or other security threats without being noticed. Attackers can also make repeated requests to models, looking at the results in order to reconstruct the data used to build ML models; in health domains, for instance, successful data reconstruction attacks might expose private medical details about patients. Many defense methods have been proposed to mitigate these attacks, but they face several limitations: they often aren’t effective in real-world applications with strict confidentiality requirements, or unacceptably degrade the performance of the models. Further, most defenses are aimed at particular learning methods or attack types, making it hard to deal with multiple concurrent attacks, and generalizing poorly to different types of models and data. This project’s goal is to address these limitations by designing a trustworthy learning framework based on information theory. The outcomes of the project will advance the state-of-the-art trustworthy ML and information-theoretic approaches to privacy, while contributing to the growing national need for professionals in ML and cybersecurity.To do this, the team will design a practical, accurate, flexible, and generalizable information-theoretic trustworthy representation learning framework with robustness and privacy guarantees. The work will be structured around three thrusts. Thrust 1 will design novel information-theoretic representation learning methods against common privacy attacks, including membership inference, property inference, and data reconstruction attacks. Thrust 2 will design novel information-theoretic representation learning methods against common security attacks, including test-time evasion attacks, training-time poisoning attacks, and training- and test-time backdoor attacks. Thrust 3 will generalize Thrust 1 and Thrust 2 to handle diverse attack types (e.g., multiple privacy/security attacks or their combination), data types (e.g., spatial-temporal data, multimodal data), and learning types (e.g., federated learning, graph learning, self-supervised learning). The proposed framework will be evaluated on datasets and learning tasks from several domains, including computer vision, natural language processing, multimedia, and networking. The team will develop an open-source toolkit to make the techniques widely available to other researchers in academia, industry, and government. Outreach and educational activities, including summer camps, talks, lectures, tutorials, and workshops, will promote the participation of K-12, undergraduate, and graduate students, with a focus on providing opportunities for people from groups underrepresented in STEM.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Collaborative Research: SHF: Small: LEGAS: Learning Evolving Graphs At Scale
  • 批准号:
    2331302
  • 项目类别:
    Standard Grant
  • 资助金额:
    $29.13万
  • 财政年份:
    2024
  • 负责人:
    Binghui Wang
  • 依托单位:
CRII: SaTC: Towards Understanding the Robustness of Graph Neural Networks against Graph Perturbations
  • 批准号:
    2241713
  • 项目类别:
    Standard Grant
  • 资助金额:
    $17.5万
  • 财政年份:
    2023
  • 负责人:
    Binghui Wang
  • 依托单位:
CRII: SaTC: Discerning the Upgradeability of Smart Contracts in Blockchains From a Security Perspective
  • 批准号:
    2245627
  • 项目类别:
    Standard Grant
  • 资助金额:
    $17.48万
  • 财政年份:
    2023
  • 负责人:
    Binghui Wang
  • 依托单位:
海外基金