Government
The Malicious Use of Artificial Intelligence: Forecasting, Prevention, and Mitigation
Brundage, Miles, Avin, Shahar, Clark, Jack, Toner, Helen, Eckersley, Peter, Garfinkel, Ben, Dafoe, Allan, Scharre, Paul, Zeitzoff, Thomas, Filar, Bobby, Anderson, Hyrum, Roff, Heather, Allen, Gregory C., Steinhardt, Jacob, Flynn, Carrick, hÉigeartaigh, Seán Ó, Beard, SJ, Belfield, Haydn, Farquhar, Sebastian, Lyle, Clare, Crootof, Rebecca, Evans, Owain, Page, Michael, Bryson, Joanna, Yampolskiy, Roman, Amodei, Dario
This report surveys the landscape of potential security threats from malicious uses of AI, and proposes ways to better forecast, prevent, and mitigate these threats. After analyzing the ways in which AI may influence the threat landscape in the digital, physical, and political domains, we make four high-level recommendations for AI researchers and other stakeholders. We also suggest several promising areas for further research that could expand the portfolio of defenses, or make attacks less effective or harder to execute. Finally, we discuss, but do not conclusively resolve, the long-term equilibrium of attackers and defenders.
AI expert Marietje Schaake: 'The way we think about technology is shaped by the tech companies themselves'
Marietje Schaake is a former Dutch member of the European parliament. She is now the international policy director at Stanford University Cyber Policy Center and international policy fellow at Stanford's Institute for Human-Centred Artificial Intelligence. Her new book is entitled The Tech Coup: How to Save Democracy from Silicon Valley. In terms of power and political influence, what are the main differences between big tech and previous incarnations of big business? The difference is the role that these tech companies play in so many aspects of people's lives: in the state, the economy, geopolitics.
China's lone-wolf attacks pose challenge for Xi's security state
Chinese leader Xi Jinping has built a sprawling security system to prevent violent forces from destabilizing society. A new wave of deadly attacks is putting pressure on officials to expand that surveillance state. China was stunned this month by its deadliest act of public violence since a string of terrorism strikes rocked the remote Xinjiang region in 2014. Dozens were hospitalized and 35 killed by the bloody car-ramming in Zhuhai city that was the culmination of a spate of violence this year -- mostly stabbings -- which have sparked nationwide anxiety. Xi responded to spouts of ethnic violence a decade ago by installing a network of facial recognition cameras, tightening Internet controls and expanding a national resident database.
Why are drones flying near US airbases in England?
Airspace around US airbases in Norfolk and Suffolk has been under scrutiny following multiple recent drone incursions. Those responsible for the aircraft have yet to be found and nearby residents have questioned how and why the incidents have been allowed to happen. Drone incursions were initially reported at three US airbases – RAF Mildenhall and RAF Lakenheath in Suffolk, and RAF Feltwell in Norfolk – between 20 and 22 November, and the aircraft has since reappeared. In the village of Beck Row, Suffolk, which is situated next to RAF Mildenhall, residents reported brightly lit aerial vehicles hovering above their houses and over the base itself.
Artificial intelligence changes across the US
Fox News chief political anchor Bret Baier has the latest on regulatory uncertainty amid AI development on'Special Report.' An increasing number of companies are using artificial intelligence (AI) for everyday tasks. Much of the technology is helping with productivity and keeping the public safer. However, some industries are pushing back against certain aspects of AI. And some industry leaders are working to balance the good and the bad.
The Well: a Large-Scale Collection of Diverse Physics Simulations for Machine Learning
Ohana, Ruben, McCabe, Michael, Meyer, Lucas, Morel, Rudy, Agocs, Fruzsina J., Beneitez, Miguel, Berger, Marsha, Burkhart, Blakesley, Dalziel, Stuart B., Fielding, Drummond B., Fortunato, Daniel, Goldberg, Jared A., Hirashima, Keiya, Jiang, Yan-Fei, Kerswell, Rich R., Maddu, Suryanarayana, Miller, Jonah, Mukhopadhyay, Payel, Nixon, Stefan S., Shen, Jeff, Watteaux, Romain, Blancard, Bruno Régaldo-Saint, Rozet, François, Parker, Liam H., Cranmer, Miles, Ho, Shirley
Machine learning based surrogate models offer researchers powerful tools for accelerating simulation-based workflows. However, as standard datasets in this space often cover small classes of physical behavior, it can be difficult to evaluate the efficacy of new approaches. To address this gap, we introduce the Well: a large-scale collection of datasets containing numerical simulations of a wide variety of spatiotemporal physical systems. The Well draws from domain experts and numerical software developers to provide 15TB of data across 16 datasets covering diverse domains such as biological systems, fluid dynamics, acoustic scattering, as well as magneto-hydrodynamic simulations of extra-galactic fluids or supernova explosions. These datasets can be used individually or as part of a broader benchmark suite. To facilitate usage of the Well, we provide a unified PyTorch interface for training and evaluating models. We demonstrate the function of this library by introducing example baselines that highlight the new challenges posed by the complex dynamics of the Well.
Invariant Measures in Time-Delay Coordinates for Unique Dynamical System Identification
Botvinick-Greenhouse, Jonah, Martin, Robert, Yang, Yunan
Invariant measures are widely used to compare chaotic dynamical systems, as they offer robustness to noisy data, uncertain initial conditions, and irregular sampling. However, large classes of systems with distinct transient dynamics can still exhibit the same asymptotic statistical behavior, which poses challenges when invariant measures alone are used to perform system identification. Motivated by Takens' seminal embedding theory, we propose studying invariant measures in time-delay coordinates, which exhibit enhanced sensitivity to the underlying dynamics. Our first result demonstrates that a single invariant measure in time-delay coordinates can be used to perform system identification up to a topological conjugacy. This result already surpasses the capabilities of invariant measures in the original state coordinate. Continuing to explore the power of delay-coordinates, we eliminate all ambiguity from the conjugacy relation by showing that unique system identification can be achieved using additional invariant measures in time-delay coordinates constructed from different observables. Our findings improve the effectiveness of invariant measures in system identification and broaden the scope of measure-theoretic approaches to modeling dynamical systems.
GloCOM: A Short Text Neural Topic Model via Global Clustering Context
Nguyen, Quang Duc, Nguyen, Tung, Nguyen, Duc Anh, Van, Linh Ngo, Dinh, Sang, Nguyen, Thien Huu
Uncovering hidden topics from short texts is challenging for traditional and neural models due to data sparsity, which limits word co-occurrence patterns, and label sparsity, stemming from incomplete reconstruction targets. Although data aggregation offers a potential solution, existing neural topic models often overlook it due to time complexity, poor aggregation quality, and difficulty in inferring topic proportions for individual documents. In this paper, we propose a novel model, GloCOM (Global Clustering COntexts for Topic Models), which addresses these challenges by constructing aggregated global clustering contexts for short documents, leveraging text embeddings from pre-trained language models. GloCOM can infer both global topic distributions for clustering contexts and local distributions for individual short texts. Additionally, the model incorporates these global contexts to augment the reconstruction loss, effectively handling the label sparsity issue. Extensive experiments on short text datasets show that our approach outperforms other state-of-the-art models in both topic quality and document representations.
Dynamics Modeling using Visual Terrain Features for High-Speed Autonomous Off-Road Driving
Gibson, Jason, Alavilli, Anoushka, Tevere, Erica, Theodorou, Evangelos A., Spieler, Patrick
Rapid autonomous traversal of unstructured terrain is essential for scenarios such as disaster response, search and rescue, or planetary exploration. As a vehicle navigates at the limit of its capabilities over extreme terrain, its dynamics can change suddenly and dramatically. For example, high-speed and varying terrain can affect parameters such as traction, tire slip, and rolling resistance. To achieve effective planning in such environments, it is crucial to have a dynamics model that can accurately anticipate these conditions. In this work, we present a hybrid model that predicts the changing dynamics induced by the terrain as a function of visual inputs. We leverage a pre-trained visual foundation model (VFM) DINOv2, which provides rich features that encode fine-grained semantic information. To use this dynamics model for planning, we propose an end-to-end training architecture for a projection distance independent feature encoder that compresses the information from the VFM, enabling the creation of a lightweight map of the environment at runtime. We validate our architecture on an extensive dataset (hundreds of kilometers of aggressive off-road driving) collected across multiple locations as part of the DARPA Robotic Autonomy in Complex Environments with Resiliency (RACER) program. https://www.youtube.com/watch?v=dycTXxEosMk
Exact Certification of (Graph) Neural Networks Against Label Poisoning
Sabanayagam, Mahalakshmi, Gosch, Lukas, Günnemann, Stephan, Ghoshdastidar, Debarghya
Machine learning models are highly vulnerable to label flipping, i.e., the adversarial modification (poisoning) of training labels to compromise performance. Thus, deriving robustness certificates is important to guarantee that test predictions remain unaffected and to understand worst-case robustness behavior. However, for Graph Neural Networks (GNNs), the problem of certifying label flipping has so far been unsolved. We change this by introducing an exact certification method, deriving both sample-wise and collective certificates. Our method leverages the Neural Tangent Kernel (NTK) to capture the training dynamics of wide networks enabling us to reformulate the bilevel optimization problem representing label flipping into a Mixed-Integer Linear Program (MILP). We apply our method to certify a broad range of GNN architectures in node classification tasks. Thereby, concerning the worst-case robustness to label flipping: $(i)$ we establish hierarchies of GNNs on different benchmark graphs; $(ii)$ quantify the effect of architectural choices such as activations, depth and skip-connections; and surprisingly, $(iii)$ uncover a novel phenomenon of the robustness plateauing for intermediate perturbation budgets across all investigated datasets and architectures. While we focus on GNNs, our certificates are applicable to sufficiently wide NNs in general through their NTK. Thus, our work presents the first exact certificate to a poisoning attack ever derived for neural networks, which could be of independent interest.