EAGER: Toward Attack-Resilient Statistical Inference
EAGER: Toward Attack-Resilient Statistical Inference
批准号:
2224150
负责人:
Jinsub Kim
金额:
$25.0万
依托单位:
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2022
资助国家:
美国
项目状态:
未结题
起止时间:
2022-07-01 至 2025-06-30
中文摘要
统计推断的经典技术和理论是在没有人为操纵输入数据的假设下发展起来的。这种性质使得大多数现有的统计推断技术在部署到敌对环境时不可靠,相关理论也不相关。这种现有的差距是一个非常令人担忧的问题,因为许多关键任务系统(例如国家电网)和安全关键系统(例如自动驾驶系统)中的现代统计推断任务依赖于传感器数据,这些数据很容易被对手伪造。例如,攻击者可以发起欺骗攻击,操纵自动驾驶系统中的激光雷达或视觉传感器数据,使物体检测算法无法检测到汽车前方的某些障碍物。尽管最近在稳健统计推断方面取得了进展,但仍然没有一般的理论来描述在数据伪造的情况下的最佳推理规则,或者使用伪造的数据进行推理的基本限制。该项目旨在通过发展在对手伪造数据的情况下进行稳健推理的基本理论和最佳方法来解决这一差距。该项目将推进最先进的鲁棒统计、鲁棒传感和机器学习安全性。此外,该项目将通过产生可用于显著提高国家关键安全和关键任务系统抵御数据伪造攻击的弹性的结果,为国家安全做出贡献。该项目的技术目标是调查在存在对抗性数据伪造的情况下进行假设检验和估计的基本限制,并在理论分析的支持下开发强大的推理方法,以减轻数据伪造的影响。将进一步扩展已开发的理论和方法,以开发一个新的框架来训练具有攻击弹性的机器学习模型。为了实现这些目标,将采用博弈论公式严格模拟防御方设计稳健推理方法和对手针对防御方设计的推理方法优化数据伪造策略之间的复杂相互作用。将利用优化、博弈论和概率论的技术,为博弈论公式推导出最优的鲁棒推理方法,并分析其性质。此外,电力系统状态估计在伪造的仪表测量将被视为一个案例研究,并将开发一个鲁棒电力系统状态估计器,并在严格的博弈论设置中进行评估。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Classical techniques and theories for statistical inference had been developed under the assumption that there is no adversarial attempt to manipulate the input data. Such a nature renders most existing statistical inference techniques unreliable and the associated theories irrelevant when they are deployed to an adversarial environment. This existing gap is a matter of great concern because many modern statistical inference tasks in mission-critical systems (e.g., the nation's power grids) and safety-critical systems (e.g., autonomous driving systems) are relying on sensor data that could be vulnerable to falsification by an adversary. For instance, an adversary can launch a spoofing attack to manipulate lidar or vision sensor data in an autonomous driving system such that the object detection algorithm will fail to detect certain obstacle in front of the car. Despite recent advances in robust statistical inference, there still is no general theory that characterizes optimal inference rules in the presence of data falsification or the fundamental limit of performing inference using falsified data. This project is aimed at addressing this gap by developing fundamental theory and optimal methods for robust inference in the presence of data falsification by an adversary. The project will advance the state-of-the-art in robust statistics, robust sensing, and security of machine learning. Furthermore, the project will contribute to the national security by generating the outcomes that can be applied to significantly improve resilience of safety-critical and mission-critical systems of the nation against data falsification attacks. The technical objectives of the project are to investigate fundamental limits of performing hypothesis testing and estimation in the presence of adversarial data falsification and to develop robust inference methods, supported by theoretical analyses, to mitigate the impact of data falsification. The developed theory and methods will be further extended to develop a novel framework to train an attack-resilient machine learning model. In pursuing these objectives, a game-theoretic formulation will be employed to rigorously model the complex interplay between the defender designing a robust inference method and the adversary optimizing the data falsification strategy against the defender's design of the inference method. Techniques from optimization, game theory, and probability theory will be leveraged to derive optimal robust inference methods for the game-theoretic formulation and analyze their properties. Furthermore, power system state estimation in the presence of falsified meter measurements will be considered as a case study, and a robust power system state estimator will be developed and evaluated in a rigorous game-theoretic setup.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(1)
专著(0)
科研奖励(0)
会议论文
Forensics for Adversarial Machine Learning Through Attack Mapping Identification
通过攻击映射识别进行对抗性机器学习取证
DOI:
10.1109/icassp49357.2023.10095092
发表时间:
2023
期刊:
and Signal Processing (ICASSP
影响因子:
--
作者:
[Yan, Allen, Kim, Jinsub, Raich, Raviv]
通讯作者:
Raich, Raviv
国内基金
海外基金
Toward a general theory of intermittent aeolian and fluvial nonsuspended sediment transport
-
批准号:--
-
项目类别:--
-
资助金额:55万元
-
批准年份:2022
-
负责人:Thomas Pahtz
-
依托单位: