Goto

Collaborating Authors

 Government


PatchZero: Defending against Adversarial Patch Attacks by Detecting and Zeroing the Patch

arXiv.org Artificial Intelligence

Adversarial patch attacks mislead neural networks by injecting adversarial pixels within a local region. Patch attacks can be highly effective in a variety of tasks and physically realizable via attachment (e.g. a sticker) to the real-world objects. Despite the diversity in attack patterns, adversarial patches tend to be highly textured and different in appearance from natural images. We exploit this property and present PatchZero, a general defense pipeline against white-box adversarial patches without retraining the downstream classifier or detector. Specifically, our defense detects adversaries at the pixel-level and "zeros out" the patch region by repainting with mean pixel values. We further design a two-stage adversarial training scheme to defend against the stronger adaptive attacks. PatchZero achieves SOTA defense performance on the image classification (ImageNet, RESISC45), object detection (PASCAL VOC), and video classification (UCF101) tasks with little degradation in benign performance. In addition, PatchZero transfers to different patch shapes and attack types.


Identifying a Training-Set Attack's Target Using Renormalized Influence Estimation

arXiv.org Artificial Intelligence

Targeted training-set attacks inject malicious instances into the training set to cause a trained model to mislabel one or more specific test instances. This work proposes the task of target identification, which determines whether a specific test instance is the target of a training-set attack. Target identification can be combined with adversarial-instance identification to find (and remove) the attack instances, mitigating the attack with minimal impact on other predictions. Rather than focusing on a single attack method or data modality, we build on influence estimation, which quantifies each training instance's contribution to a model's prediction. We show that existing influence estimators' poor practical performance often derives from their over-reliance on training instances and iterations with large losses. Our renormalized influence estimators fix this weakness; they far outperform the original estimators at identifying influential groups of training examples in both adversarial and non-adversarial settings, even finding up to 100% of adversarial training instances with no clean-data false positives. Target identification then simplifies to detecting test instances with anomalous influence values. We demonstrate our method's effectiveness on backdoor and poisoning attacks across various data domains, including text, vision, and speech, as well as against a gray-box, adaptive attacker that specifically optimizes the adversarial instances to evade our method. Our source code is available at https://github.com/ZaydH/target_identification.


Selective Annotation Makes Language Models Better Few-Shot Learners

arXiv.org Artificial Intelligence

Many recent approaches to natural language tasks are built on the remarkable abilities of large language models. Large language models can perform in-context learning, where they learn a new task from a few task demonstrations, without any parameter updates. This work examines the implications of in-context learning for the creation of datasets for new natural language tasks. Departing from recent in-context learning methods, we formulate an annotation-efficient, two-step framework: selective annotation that chooses a pool of examples to annotate from unlabeled data in advance, followed by prompt retrieval that retrieves task examples from the annotated pool at test time. Based on this framework, we propose an unsupervised, graph-based selective annotation method, voke-k, to select diverse, representative examples to annotate. Extensive experiments on 10 datasets (covering classification, commonsense reasoning, dialogue, and text/code generation) demonstrate that our selective annotation method improves the task performance by a large margin. On average, vote-k achieves a 12.9%/11.4% relative gain under an annotation budget of 18/100, as compared to randomly selecting examples to annotate. Compared to state-of-the-art supervised finetuning approaches, it yields similar performance with 10-100x less annotation cost across 10 tasks. We further analyze the effectiveness of our framework in various scenarios: language models with varying sizes, alternative selective annotation methods, and cases where there is a test data domain shift. We hope that our studies will serve as a basis for data annotations as large language models are increasingly applied to new tasks. Our code is available at https://github.com/HKUNLP/icl-selective-annotation.


Opportunities for Data Science Innovation in the Policing Sector

#artificialintelligence

According to Peter K. Manning, in Anglo-American societies, the purpose of the police is to "sustain politically defined order and ordering via tracking, surveillance, coercion and arrest" (2014: p.6). Consisting of several authoritatively coordinated and legitimate organizations (ibid.), the policing sector serves governments in protecting their communities, preventing crime and disorder, and ensuring justice (The Policy Circle, 2022). The police's position as acting in the communities' interest suggests that their functions are heavily dependent on public trust and societal consensus concerning social justice and fairness (Manning, 2014). While there are large numbers of police officers employed in Australia (67,200 in 2021), a number which is expected to increase in the future (Australian Industry and Skills Committee, 2022), Ransley & Mazerolle (2009) have argued that trends in public governance and regulation have caused the increased pluralization and privatisation of policing efforts. Nowadays, the policing sector thus constitutes a large network of private, public and welfare organizations geared at controlling and preventing crimes (ibid.). In this essay, I will thus focus on data science opportunities for a variety of stakeholders involved in ensuring public security and order.


Liberia plans biometric voter registry with enrollment beginning in December

#artificialintelligence

NEC Chairperson Davidetta Browne Lansanah said during a press conference that portable tablets with fingerprint scanners will be used to capture thumbprints for a biometric voter registry, The New Dawn Liberia reports. The biometrics could also be used for deduplication and the prevention of impersonation. Facial images will also be collected, and the NEC will attempt to reduce the volume of incorrect voter data in the system. Following deduplication, biometric voter registry cards will be issued from registration centers. A biometric voter registration initiative is slated to start on December 15, 2022, and conclude on March 17, 2023.


EE Times Europe - Why Automotive Cybersecurity Is Important

#artificialintelligence

Cybersecurity is becoming a fundamental concern for the development of autonomous vehicle (AV) systems, as attacks can have serious consequences for autonomous electric vehicles and can put human lives at risk. Software attacks include data-driven decisions negatively impacting the autonomy of EVs and compromising the benefits of autonomous cars. AVs have seen many recent advances, with the integration of technologies like edge computing, private 5G, and high-performance processing units. In autonomous EVs, edge computing helps process the high volume of data at the edge to reduce latency and help vehicles make data-driven decisions in real time. Edge sensors deployed in vehicles have the scarcity of resources but require high computational power to process data.


We are the artist: Generative AI and the future of art

#artificialintelligence

Were you unable to attend Transform 2022? Check out all of the summit sessions in our on-demand library now! Before writing a single word of this article, I created the image above using a new type of AI software that produces "generative artwork." The process took about 15 minutes and did not involve paints or canvases. I simply entered a few lines of text to describe the image that I wanted โ€“ a robot holding a paintbrush and standing at an easel.


The super-rich 'preppers' planning to save themselves from the apocalypse

The Guardian

As a humanist who writes about the impact of digital technology on our lives, I am often mistaken for a futurist. The people most interested in hiring me for my opinions about technology are usually less concerned with building tools that help people live better lives in the present than they are in identifying the Next Big Thing through which to dominate them in the future. I don't usually respond to their inquiries. Why help these guys ruin what's left of the internet, much less civilisation? Still, sometimes a combination of morbid curiosity and cold hard cash is enough to get me on a stage in front of the tech elite, where I try to talk some sense into them about how their businesses are affecting our lives out here in the real world. That's how I found myself accepting an invitation to address a group mysteriously described as "ultra-wealthy stakeholders", out in the middle of the desert. A limo was waiting for me at the airport.


China is preparing for a full-spectrum AI war. India is still 15 years behind

#artificialintelligence

In his new book The Last War: How AI Will Shape India's Final Showdown With China, Pravin Sawhney, the editor of FORCE magazine, disquietingly forebodes a grim scenario for 2024: "If India and China were to fight a war in the near future, India faces the prospect of losing the war within 10 days. China could take Arunachal Pradesh and Ladakh with a minimum loss of life, and there is very little that India could do about it." Is it the imagination of a defence analyst running wild? Far from it -- such scenarios have been predicted by other analysts too. A US military blog, Mad Scientist, which looks at the future of warfare, visualised a similar scenario for 2035 in February 2020, wherein China, in collusion with Pakistan, defeats India in Jammu and Kashmir and Ladakh.


Can Text-to-Image AI Learn Ethics --or Is the Future Doomed?

#artificialintelligence

Text-to-image AI generation tools have entered their wild wild west phase. The sweeping trend which Open AI's DALL.E 2 started with great caution has drastically turned into a world where anything goes. Last week, London and Los Altos-based startup Stability.ai Comparable in quality to DALL.E 2 and Midjourney, the implications of the step taken by Stability.ai Moreover, Stable Diffusion, unlike its predecessors, has next to no restrictions barring users from generating images with inappropriate content or prominent personalities.