EAGER: Invisible Shield: Can Compression Harden Deep Neural Networks Universally Against Adversarial Attacks?
EAGER: Invisible Shield: Can Compression Harden Deep Neural Networks Universally Against Adversarial Attacks?
批准号:
2011260
负责人:
Wujie Wen
金额:
$14.92万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2019
资助国家:
美国
项目状态:
已结题
起止时间:
2019-11-07 至 2021-08-31
中文摘要
深度神经网络(DNN)在图像识别、医疗诊断和自动驾驶汽车等领域得到了广泛的应用。然而,DNN面临着安全威胁:在DNN模型的训练过程中,通过在正常输入中添加人的不可察觉的扰动而产生的敌意输入会误导决策。由于攻击载体多、对手的策略和成本未知,防御对手攻击具有挑战性。该项目研究了一种基于压缩/解压缩的防御策略,以低成本和高精度保护DNN免受任何攻击。该项目旨在通过使用信号压缩,从根本不同的角度创建保护DNN的新范例,重点是将防御整合到输入和DNN模型的压缩中。研究任务包括:(I)开发视频/音频输入的防御性压缩,在不影响测试精度的情况下最大限度地提高防御效率;(Ii)开发防御性模型压缩,以及新的不涉及再训练的梯度掩蔽/混淆方法,以普遍强化DNN模型;以及(Iii)通过算法级模拟和现场平台实验进行攻防评估。这一迫切需要的项目的任何成功都将有助于研究对深度学习、硬件和网络安全以及多媒体感兴趣的社区。这个项目通过促进深度学习在现实系统中的更广泛应用来增加经济机会,并特别关注教育来自佛罗里达国际大学传统上代表性不足/服务不足群体的妇女和学生。项目储存库将存储在佛罗里达国际大学(http://web.eng.fiu.edu/wwen/).)的可公开访问的服务器上数据将在项目期结束后至少保存5年。这一奖励反映了NSF的法定使命,并通过使用基金会的智力优势和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Deep neural networks (DNNs) are finding applications in wide-ranging applications such as image recognition, medical diagnosis and self-driving cars. However, DNNs suffer from a security threat: decisions can be misled by adversarial inputs crafted by adding human-imperceptible perturbations into normal inputs during training of DNN model. Defending against adversarial attacks is challenging due to multiple attack vectors, unknown adversary's strategies and cost. This project investigates a compression/decompression-based defense strategy to protect DNNs against any attack, with low cost and high accuracy. The project aims to create a new paradigm of safeguarding DNNs from a radically different perspective by using signal compression with a focus on integrating defenses into compression of the inputs and DNN models. The research tasks include: (i) developing defensive compression for visual/audio inputs to maximize defense efficiency without compromising testing accuracy; (ii) developing defensive model compression, and novel gradient masking/obfuscating methods without involving retraining, to universally harden DNN models; and (iii) conducting attack-defense evaluations through algorithm-level simulation and live platform experimentation.Any success from this EAGER project will be useful to research community interested in deep learning, hardware- and cyber- security, and multimedia. This project enhances economic opportunities by promoting wider applications of deep learning into realistic systems, and gives special attention to educating women and students from traditionally under-represented/under-served groups in Florida International University (FIU).The project repository will be stored on a publicly accessible server at FIU (http://web.eng.fiu.edu/wwen/). Data will be maintained for at least 5 years after the project period.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(7)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
Efficient Implementation of Finite Field Arithmetic for Binary Ring-LWE Post-Quantum Cryptography Through a Novel Lookup-Table-Like Method
通过新颖的类查找表方法有效实现二元环 LWE 后量子密码学的有限域算法
DOI:
--
发表时间:
2021
期刊:
Proc. ACM/IEEE 58th Design Automation Conference (DAC
影响因子:
--
作者:
[Xie, Jiafeng, He, Pengzhou, Wen, Wujie]
通讯作者:
Wen, Wujie
DOI:
10.1109/tnnls.2021.3089128
发表时间:
2021-06-25
期刊:
IEEE TRANSACTIONS ON NEURAL NETWORKS AND LEARNING SYSTEMS
影响因子:
10.4
作者:
[Liu, Qi, Wen, Wujie]
通讯作者:
Wen, Wujie
DOI:
10.1007/978-3-030-58601-0_37
发表时间:
2020-01
期刊:
ArXiv
影响因子:
--
作者:
[Xiaolong Ma;Wei Niu;Tianyun Zhang;Sijia Liu;Fu-Ming Guo;Sheng Lin;Hongjia Li;Xiang Chen;Jian Tang;Kaisheng Ma;Bin Ren;Yanzhi Wang]
通讯作者:
Xiaolong Ma;Wei Niu;Tianyun Zhang;Sijia Liu;Fu-Ming Guo;Sheng Lin;Hongjia Li;Xiang Chen;Jian Tang;Kaisheng Ma;Bin Ren;Yanzhi Wang
DOI:
10.1145/3427228.3427268
发表时间:
2020-12
期刊:
Proceedings of the 36th Annual Computer Security Applications Conference
影响因子:
--
作者:
[Tao Liu;Zihao Liu;Qi Liu;Wujie Wen;Wenyao Xu;Ming Li]
通讯作者:
Tao Liu;Zihao Liu;Qi Liu;Wujie Wen;Wenyao Xu;Ming Li
DOI:
10.1145/3400302.3415726
发表时间:
2020-11
期刊:
2020 IEEE/ACM International Conference On Computer Aided Design (ICCAD)
影响因子:
--
作者:
[Qi Liu;Wujie Wen;Yanzhi Wang]
通讯作者:
Qi Liu;Wujie Wen;Yanzhi Wang
共 7 条
SPX: Collaborative Research: Scalable Neural Network Paradigms to Address Variability in Emerging Device based Platforms for Large Scale Neuromorphic Computing
-
批准号:2401544
-
项目类别:Standard Grant
-
资助金额:$35.55万
-
财政年份:2023
-
负责人:Wujie Wen
-
依托单位:
CAREER: Dependable and Secure Machine Learning Acceleration from Untrusted Hardware
-
批准号:2238873
-
项目类别:Continuing Grant
-
资助金额:$60.0万
-
财政年份:2023
-
负责人:Wujie Wen
-
依托单位:
Collaborative Research: SaTC: CORE: Medium: Accelerating Privacy-Preserving Machine Learning as a Service: From Algorithm to Hardware
-
批准号:2247891
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2023
-
负责人:Wujie Wen
-
依托单位:
CAREER: Dependable and Secure Machine Learning Acceleration from Untrusted Hardware
-
批准号:2349538
-
项目类别:Continuing Grant
-
资助金额:$60.0万
-
财政年份:2023
-
负责人:Wujie Wen
-
依托单位:
Collaborative Research: SaTC: CORE: Medium: Accelerating Privacy-Preserving Machine Learning as a Service: From Algorithm to Hardware
-
批准号:2348733
-
项目类别:Continuing Grant
-
资助金额:$40.0万
-
财政年份:2023
-
负责人:Wujie Wen
-
依托单位:
SHF: Small: Collaborative Research: Retraining-free Concurrent Test and Diagnosis in Emerging Neural Network Accelerators
-
批准号:2011236
-
项目类别:Standard Grant
-
资助金额:$23.5万
-
财政年份:2019
-
负责人:Wujie Wen
-
依托单位:
SPX: Collaborative Research: Scalable Neural Network Paradigms to Address Variability in Emerging Device based Platforms for Large Scale Neuromorphic Computing
-
批准号:1919182
-
项目类别:Standard Grant
-
资助金额:$35.55万
-
财政年份:2019
-
负责人:Wujie Wen
-
依托单位:
SPX: Collaborative Research: Scalable Neural Network Paradigms to Address Variability in Emerging Device based Platforms for Large Scale Neuromorphic Computing
-
批准号:2006748
-
项目类别:Standard Grant
-
资助金额:$35.55万
-
财政年份:2019
-
负责人:Wujie Wen
-
依托单位:
SHF: Small: Collaborative Research: Retraining-free Concurrent Test and Diagnosis in Emerging Neural Network Accelerators
-
批准号:1910022
-
项目类别:Standard Grant
-
资助金额:$23.5万
-
财政年份:2019
-
负责人:Wujie Wen
-
依托单位:
EAGER: Invisible Shield: Can Compression Harden Deep Neural Networks Universally Against Adversarial Attacks?
-
批准号:1840813
-
项目类别:Standard Grant
-
资助金额:$25.0万
-
财政年份:2018
-
负责人:Wujie Wen
-
依托单位:
海外基金