课题基金 / 基金详情

Mathematics of Adversarial Attacks

Mathematics of Adversarial Attacks
对抗性攻击的数学
批准号:
EP/V046527/1
负责人:
Desmond Higham
金额:
$25.75万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2021
资助国家:
英国
项目状态:
已结题
起止时间:
2021 至 --

项目摘要

项目成果

Desmond Higham的其他基金

相似基金

相关文献

中文摘要
翻译
这一建议建立在两个观察结果的基础上:1.实证实验表明,即使是最复杂和最受推崇的人工智能(AI)工具也可能被精心构建的例子愚弄。例如,给出一张狗的图片,我们可以用一种人眼看不到的方式来改变图片,但会让人工智能系统改变主意,将图片归类为鸡。这种“对抗性攻击”可能会取得惊人的成功,它们显然会对安全、安保和道德产生影响。2.尽管许多数学科学家正在为人工智能和深度学习领域令人兴奋和快速发展的研究做出贡献,但到目前为止,主要的理论焦点一直是逼近能力(我们能否建立满足所需特性列表的系统?)和优化(微调网络细节的最佳方式是什么?)。围绕对抗性攻击有一个迫切的、尚未满足的可操作理解需求:它们是不可避免的吗?它们是可识别的吗?它们是否可以概括为其他形式的攻击?这激发了提案的主题:必然性、可识别性和可扩展性。以下是我们将解决的三种类型的问题:a)任何人工智能系统都不可避免地容易受到对抗性攻击(在这种情况下,我们应该分配资源来识别攻击,而不是试图消除它们)?b)典型的现代人工智能硬件速度快,但精确度较低(例如,每次计算只能携带3位数);这种不精确会被新形式的对抗性攻击所利用吗?C)人工智能系统对恶意干预的安全性如何?恶意干预不是攻击输入数据,而是对系统中的参数进行秘密更改?我们将首次从数学(数值分析和近似理论)领域开发和扩展高度相关的想法,以产生概念和工具,使我们能够理解人工智能技术的基本限制,并确定这些限制何时被暴露;从而有助于安全、可解释性和问责问题。该提案将涉及一名博士后研究助理,他将在一个高需求领域获得宝贵的技能。此外,由于信任、隐私和安全问题是该项目的核心问题,因此公共参与活动被纳入计划中。创造持久影响的一个关键途径是开发实际案例研究,突出我们开发的理论。这将涉及创建使用行业标准人工智能平台和数据集的计算机代码:这是一项需要编码和数据科学方面的专业技能的活动,将雇用一名合格的软件工程师来完成这项任务。总体而言,这个项目产生的想法将通过使用目前被忽视的计算数学技术来改变我们对人工智能系统的理解。此外,通过表明人工智能的核心存在计算和应用数学家可以解决的挑战,我们计划改变这一重要的数学-计算机科学接口上研究互动的规模和质量。
英文摘要
This proposal is built on two observations:1. Empirical experiments have shown that even the most sophisticated and highly-regarded artificial intelligence (AI) tools can be fooled by carefully constructed examples. For example, given a picture of a dog, we can change the picture in a way that is imperceptible to the human eye but makes the AI system change its mind and categorize the picture as a chicken. Such *adversarial attacks* can be shockingly successful, and they clearly have implications for safety, security and ethics. 2. Although many mathematical scientists are contributing to the exciting and fast-moving body of research in AI and deep learning, the main theoretical focus so far has been on approximation power (can we build systems that satisfy a desired list of properties?) and optimization (what is the best way to fine-tune the network details?).There is an urgent, unmet need for actionable understanding around adversarial attacks: are they inevitable, are they identifiable, and are they generalizable to other forms of attack?This motivates the themes of the proposal: Inevitability, Identifiability, and Escalation.Here are three examples of the types of questions that we will address:A) Is it inevitable that any AI system will be susceptible to adversarial attack (in which case we should assign resources to identifying attacks rather than attempting to eliminate them)?B) Typical modern AI hardware is fast but has low accuracy (e.g., each computation may carry only 3 digits); can such imprecision be exploited by new forms of adversarial attack? C) How secure are AI systems to malicious interventions that, rather than attacking the input data, make covert alterations to the parameters in the system? We will, for the first time, develop and extend highly relevant ideas from the field of mathematics (numerical analysis and approximation theory) to produce concepts and tools that allow us to appreciate fundamental limitations of AI technology, and identify when these limitations are being exposed; thereby contributing to issues of security, interpretability and accountability. The proposal will involve a post-doctoral research assistant, who will gain valuable skills in a high-demand area. Also, because issues of trust, privacy and security are central to this project, public engagement activities are built in to the plans. A key route to creating lasting impact is the development of practical case studies that highlight the theory that we develop. This will involve the creation of computer code that uses industry-standard AI platforms and data sets: it is an activity that requires specialist skills in coding and data science, and a qualified software engineer will be employed for this task. Overall, the ideas emerging from this project will transform our understanding of AI systems by using currently overlooked techniques from computational mathematics. Furthermore, by showing that there are challenges at the heart of AI that can be tackled by computational and applied mathematicians, we plan to transform the scale and quality of research interaction at this important mathematics-computer science interface.
期刊论文(9)
专著(0)
科研奖励(0)
会议论文
DOI: 10.1093/imamat/hxad027
发表时间: 2021-06
期刊: ArXiv
影响因子: --
作者: [I. Tyukin;D. Higham;Eliyas Woldegeorgis;Alexander N Gorban]
通讯作者: I. Tyukin;D. Higham;Eliyas Woldegeorgis;Alexander N Gorban
DOI: 10.1016/j.laa.2022.08.022
发表时间: 2022-09-26
期刊: LINEAR ALGEBRA AND ITS APPLICATIONS
影响因子: 1.1
作者: [Arrigo, Francesca, Higham, Desmond J., Wood, Ryan]
通讯作者: Wood, Ryan
DOI: 10.48550/arxiv.2308.15092
发表时间: 2023-08
期刊: ArXiv
影响因子: --
作者: [D. Higham]
通讯作者: D. Higham
Adversarial ink: componentwise backward error attacks on deep learning
对抗性墨水:深度学习的组件式后向错误攻击
DOI: 10.1093/imamat/hxad017
发表时间: 2023
期刊: IMA Journal of Applied Mathematics
影响因子: 1.2
作者: [Beerens L]
通讯作者: Beerens L
共 6 条
    Disease Spread at High Order
    • 批准号:
      EP/W011093/1
    • 项目类别:
      Research Grant
    • 资助金额:
      $9.06万
    • 财政年份:
      2022
    • 负责人:
      Desmond Higham
    • 依托单位:
    Data Analytics for Future Cities
    • 批准号:
      EP/M00158X/2
    • 项目类别:
      Fellowship
    • 资助金额:
      $8.57万
    • 财政年份:
      2019
    • 负责人:
      Desmond Higham
    • 依托单位:
    Data Analytics for Future Cities
    • 批准号:
      EP/M00158X/1
    • 项目类别:
      Fellowship
    • 资助金额:
      $81.97万
    • 财政年份:
      2015
    • 负责人:
      Desmond Higham
    • 依托单位:
    MOLTEN: Mathematics Of Large Technological Evolving Networks
    • 批准号:
      EP/I016058/1
    • 项目类别:
      Research Grant
    • 资助金额:
      $23.06万
    • 财政年份:
      2011
    • 负责人:
      Desmond Higham
    • 依托单位:
    海外基金