Government
Nonideality-aware training makes memristive networks more robust to adversarial attacks
Joksas, Dovydas, Muñoz-González, Luis, Lupu, Emil, Mehonic, Adnan
Neural networks are now deployed in a wide number of areas from object classification to natural language systems. Implementations using analog devices like memristors promise better power efficiency, potentially bringing these applications to a greater number of environments. However, such systems suffer from more frequent device faults and overall, their exposure to adversarial attacks has not been studied extensively. In this work, we investigate how nonideality-aware training - a common technique to deal with physical nonidealities - affects adversarial robustness. We find that adversarial robustness is significantly improved, even with limited knowledge of what nonidealities will be encountered during test time.
Membership Inference Attacks Cannot Prove that a Model Was Trained On Your Data
Zhang, Jie, Das, Debeshee, Kamath, Gautam, Tramèr, Florian
We consider the problem of a training data proof, where a data creator or owner wants to demonstrate to a third party that some machine learning model was trained on their data. Training data proofs play a key role in recent lawsuits against foundation models trained on web-scale data. Many prior works suggest to instantiate training data proofs using membership inference attacks. We argue that this approach is fundamentally unsound: to provide convincing evidence, the data creator needs to demonstrate that their attack has a low false positive rate, i.e., that the attack's output is unlikely under the null hypothesis that the model was not trained on the target data. Yet, sampling from this null hypothesis is impossible, as we do not know the exact contents of the training set, nor can we (efficiently) retrain a large foundation model. We conclude by offering two paths forward, by showing that data extraction attacks and membership inference on special canary data can be used to create sound training data proofs.
Towards Robust Extractive Question Answering Models: Rethinking the Training Methodology
Tran, Son Quoc, Kretchmar, Matt
This paper proposes a novel training method to improve the robustness of Extractive Question Answering (EQA) models. Previous research has shown that existing models, when trained on EQA datasets that include unanswerable questions, demonstrate a significant lack of robustness against distribution shifts and adversarial attacks. Despite this, the inclusion of unanswerable questions in EQA training datasets is essential for ensuring real-world reliability. Our proposed training method includes a novel loss function for the EQA problem and challenges an implicit assumption present in numerous EQA datasets. Models trained with our method maintain in-domain performance while achieving a notable improvement on out-of-domain datasets. This results in an overall F1 score improvement of 5.7 across all testing sets. Furthermore, our models exhibit significantly enhanced robustness against two types of adversarial attacks, with a performance decrease of only about a third compared to the default models.
Multimodal Misinformation Detection by Learning from Synthetic Data with Multimodal LLMs
Zeng, Fengzhu, Li, Wenqian, Gao, Wei, Pang, Yan
Detecting multimodal misinformation, especially in the form of image-text pairs, is crucial. Obtaining large-scale, high-quality real-world fact-checking datasets for training detectors is costly, leading researchers to use synthetic datasets generated by AI technologies. However, the generalizability of detectors trained on synthetic data to real-world scenarios remains unclear due to the distribution gap. To address this, we propose learning from synthetic data for detecting real-world multimodal misinformation through two model-agnostic data selection methods that match synthetic and real-world data distributions. Experiments show that our method enhances the performance of a small MLLM (13B) on real-world fact-checking datasets, enabling it to even surpass GPT-4V~\cite{GPT-4V}.
Enhancing Temporal Sensitivity and Reasoning for Time-Sensitive Question Answering
Yang, Wanqi, Li, Yanda, Fang, Meng, Chen, Ling
Time-Sensitive Question Answering (TSQA) demands the effective utilization of specific temporal contexts, encompassing multiple time-evolving facts, to address time-sensitive questions. This necessitates not only the parsing of temporal information within questions but also the identification and understanding of time-evolving facts to generate accurate answers. However, current large language models still have limited sensitivity to temporal information and their inadequate temporal reasoning capabilities. In this paper, we propose a novel framework that enhances temporal awareness and reasoning through Temporal Information-Aware Embedding and Granular Contrastive Reinforcement Learning. Experimental results on four TSQA datasets demonstrate that our framework significantly outperforms existing LLMs in TSQA tasks, marking a step forward in bridging the performance gap between machine and human temporal understanding and reasoning.
Posterior Conformal Prediction
Zhang, Yao, Candès, Emmanuel J.
Conformal prediction is a popular technique for constructing prediction intervals with distribution-free coverage guarantees. The coverage is marginal, meaning it only holds on average over the entire population but not necessarily for any specific subgroup. This article introduces a new method, posterior conformal prediction (PCP), which generates prediction intervals with both marginal and approximate conditional validity for clusters (or subgroups) naturally discovered in the data. PCP achieves these guarantees by modelling the conditional conformity score distribution as a mixture of cluster distributions. Compared to other methods with approximate conditional validity, this approach produces tighter intervals, particularly when the test data is drawn from clusters that are well represented in the validation data. PCP can also be applied to guarantee conditional coverage on user-specified subgroups, in which case it achieves robust coverage on smaller subgroups within the specified subgroups. In classification, the theory underlying PCP allows for adjusting the coverage level based on the classifier's confidence, achieving significantly smaller sets than standard conformal prediction sets. We evaluate the performance of PCP on diverse datasets from socio-economic, scientific and healthcare applications.
Eight killed in Russian drone attacks on medical centre in Sumy, Ukraine
At least eight people have died in two consecutive Russian drone attacks on a medical centre in the northeast Ukrainian city of Sumy, Ukrainian officials have said. The first attack on Saturday morning killed one person, and it was followed by another attack while patients and staff were evacuating, Ukraine's Interior Minister Ihor Klymenko said. Ukraine's President Volodymyr Zelenskyy said on his Telegram channel that Russia had hit the hospital using Shahed drones, stating that eleven people were injured. Sumy lies just across the border from Russia's Kursk region where Kyiv launched a shock offensive on August 6, which it says is aimed partly at creating a "buffer zone" inside Russia. Regional prosecutors said the first attack in Sumy on Saturday took place at about 7:35am (04:35 GMT), hitting the hospital where there were 86 patients and 38 staff.
After meeting, Blinken says Beijing's talk of Ukraine peace 'doesn't add up'
U.S. Secretary of State Antony Blinken underscored strong U.S. concerns about China's support for Russia's defense industrial base in talks Friday with Chinese Foreign Minister Wang Yi, saying Beijing's talk of peace in Ukraine "doesn't add up." In a meeting with Wang on the sidelines of the U.N. General Assembly in New York, Blinken said he also raised China's "dangerous and destabilizing actions" in the South China Sea and discussed improving communication between their militaries. Blinken told a news conference he and Wang also discussed ways to disrupt the flow of drugs into the United States, and the risks posed by artificial intelligence.
DAVID MARCUS: Kamala Harris finally visits the border. Was George Orwell her travel agent?
Fox News correspondent Bill Melugin gives the latest on Vice President Kamala Harris' southern border visit on'Special Report.' It was George Orwell, in his seminal book "1984," which turned out to be about 40 years off, who wrote that eventually the state would make us believe that 2 2 5. Vice President Kamala Harris' incomprehensibly shameless photo op on the southern border might have dialed it up to a 6. There she was, our vice president, in front of the wall, and the barbed wire, ready to get serious about the problem she and "kind of" President Joe Biden created in the first place. I recalled a film in which Cheech and Chong said it was time to get serious about the band. This is like Oedipus saying, "Who did all this?"
Subject Data Auditing via Source Inference Attack in Cross-Silo Federated Learning
Li, Jiaxin, Arazzi, Marco, Nocera, Antonino, Conti, Mauro
Source Inference Attack (SIA) in Federated Learning (FL) aims to identify which client used a target data point for local model training. It allows the central server to audit clients' data usage. In cross-silo FL, a client (silo) collects data from multiple subjects (e.g., individuals, writers, or devices), posing a risk of subject information leakage. Subject Membership Inference Attack (SMIA) targets this scenario and attempts to infer whether any client utilizes data points from a target subject in cross-silo FL. However, existing results on SMIA are limited and based on strong assumptions on the attack scenario. Therefore, we propose a Subject-Level Source Inference Attack (SLSIA) by removing critical constraints that only one client can use a target data point in SIA and imprecise detection of clients utilizing target subject data in SMIA. The attacker, positioned on the server side, controls a target data source and aims to detect all clients using data points from the target subject. Our strategy leverages a binary attack classifier to predict whether the embeddings returned by a local model on test data from the target subject include unique patterns that indicate a client trains the model with data from that subject. To achieve this, the attacker locally pre-trains models using data derived from the target subject and then leverages them to build a training set for the binary attack classifier. Our SLSIA significantly outperforms previous methods on three datasets. Specifically, SLSIA achieves a maximum average accuracy of 0.88 over 50 target subjects. Analyzing embedding distribution and input feature distance shows that datasets with sparse subjects are more susceptible to our attack. Finally, we propose to defend our SLSIA using item-level and subject-level differential privacy mechanisms.