Goto

Collaborating Authors

 Government


Traceback of Data Poisoning Attacks in Neural Networks

arXiv.org Artificial Intelligence

In adversarial machine learning, new defenses against attacks on deep learning systems are routinely broken soon after their release by more powerful attacks. In this context, forensic tools can offer a valuable complement to existing defenses, by tracing back a successful attack to its root cause, and offering a path forward for mitigation to prevent similar attacks in the future. In this paper, we describe our efforts in developing a forensic traceback tool for poison attacks on deep neural networks. We propose a novel iterative clustering and pruning solution that trims "innocent" training samples, until all that remains is the set of poisoned data responsible for the attack. Our method clusters training samples based on their impact on model parameters, then uses an efficient data unlearning method to prune innocent clusters. We empirically demonstrate the efficacy of our system on three types of dirty-label (backdoor) poison attacks and three types of clean-label poison attacks, across domains of computer vision and malware classification. Our system achieves over 98.4% precision and 96.8% recall across all attacks. We also show that our system is robust against four anti-forensics measures specifically designed to attack it.


Truthful AI: Developing and governing AI that does not lie

arXiv.org Artificial Intelligence

In many contexts, lying -- the use of verbal falsehoods to deceive -- is harmful. While lying has traditionally been a human affair, AI systems that make sophisticated verbal statements are becoming increasingly prevalent. This raises the question of how we should limit the harm caused by AI "lies" (i.e. falsehoods that are actively selected for). Human truthfulness is governed by social norms and by laws (against defamation, perjury, and fraud). Differences between AI and humans present an opportunity to have more precise standards of truthfulness for AI, and to have these standards rise over time. This could provide significant benefits to public epistemics and the economy, and mitigate risks of worst-case AI futures. Establishing norms or laws of AI truthfulness will require significant work to: (1) identify clear truthfulness standards; (2) create institutions that can judge adherence to those standards; and (3) develop AI systems that are robustly truthful. Our initial proposals for these areas include: (1) a standard of avoiding "negligent falsehoods" (a generalisation of lies that is easier to assess); (2) institutions to evaluate AI systems before and after real-world deployment; and (3) explicitly training AI systems to be truthful via curated datasets and human interaction. A concerning possibility is that evaluation mechanisms for eventual truthfulness standards could be captured by political interests, leading to harmful censorship and propaganda. Avoiding this might take careful attention. And since the scale of AI speech acts might grow dramatically over the coming decades, early truthfulness standards might be particularly important because of the precedents they set.


Bayesian logistic regression for online recalibration and revision of risk prediction models with performance guarantees

arXiv.org Machine Learning

After deploying a clinical prediction model, subsequently collected data can be used to fine-tune its predictions and adapt to temporal shifts. Because model updating carries risks of over-updating/fitting, we study online methods with performance guarantees. We introduce two procedures for continual recalibration or revision of an underlying prediction model: Bayesian logistic regression (BLR) and a Markov variant that explicitly models distribution shifts (MarBLR). We perform empirical evaluation via simulations and a real-world study predicting COPD risk. We derive "Type I and II" regret bounds, which guarantee the procedures are non-inferior to a static model and competitive with an oracle logistic reviser in terms of the average loss. Both procedures consistently outperformed the static model and other online logistic revision methods. In simulations, the average estimated calibration index (aECI) of the original model was 0.828 (95%CI 0.818-0.938). Online recalibration using BLR and MarBLR improved the aECI, attaining 0.265 (95%CI 0.230-0.300) and 0.241 (95%CI 0.216-0.266), respectively. When performing more extensive logistic model revisions, BLR and MarBLR increased the average AUC (aAUC) from 0.767 (95%CI 0.765-0.769) to 0.800 (95%CI 0.798-0.802) and 0.799 (95%CI 0.797-0.801), respectively, in stationary settings and protected against substantial model decay. In the COPD study, BLR and MarBLR dynamically combined the original model with a continually-refitted gradient boosted tree to achieve aAUCs of 0.924 (95%CI 0.913-0.935) and 0.925 (95%CI 0.914-0.935), compared to the static model's aAUC of 0.904 (95%CI 0.892-0.916). Despite its simplicity, BLR is highly competitive with MarBLR. MarBLR outperforms BLR when its prior better reflects the data. BLR and MarBLR can improve the transportability of clinical prediction models and maintain their performance over time.


Dynamical Wasserstein Barycenters for Time-series Modeling

arXiv.org Machine Learning

Many time series can be modeled as a sequence of segments representing high-level discrete states, such as running and walking in a human activity application. Flexible models should describe the system state and observations in stationary ``pure-state'' periods as well as transition periods between adjacent segments, such as a gradual slowdown between running and walking. However, most prior work assumes instantaneous transitions between pure discrete states. We propose a dynamical Wasserstein barycentric (DWB) model that estimates the system state over time as well as the data-generating distributions of pure states in an unsupervised manner. Our model assumes each pure state generates data from a multivariate normal distribution, and characterizes transitions between states via displacement-interpolation specified by the Wasserstein barycenter. The system state is represented by a barycentric weight vector which evolves over time via a random walk on the simplex. Parameter learning leverages the natural Riemannian geometry of Gaussian distributions under the Wasserstein distance, which leads to improved convergence speeds. Experiments on several human activity datasets show that our proposed DWB model accurately learns the generating distribution of pure states while improving state estimation for transition periods compared to the commonly used linear interpolation mixture models.


Neural Tangent Kernel Eigenvalues Accurately Predict Generalization

arXiv.org Machine Learning

Finding a quantitative theory of neural network generalization has long been a central goal of deep learning research. We extend recent results to demonstrate that, by examining the eigensystem of a neural network's "neural tangent kernel", one can predict its generalization performance when learning arbitrary functions. Our theory accurately predicts not only test mean-squared-error but all first- and second-order statistics of the network's learned function. Furthermore, using a measure quantifying the "learnability" of a given target function, we prove a new "no-free-lunch" theorem characterizing a fundamental tradeoff in the inductive bias of wide neural networks: improving a network's generalization for a given target function must worsen its generalization for orthogonal functions. We further demonstrate the utility of our theory by analytically predicting two surprising phenomena - worse-than-chance generalization on hard-to-learn functions and nonmonotonic error curves in the small data regime - which we subsequently observe in experiments. Though our theory is derived for infinite-width architectures, we find it agrees with networks as narrow as width 20, suggesting it is predictive of generalization in practical neural networks. Code replicating our results is available at https://github.com/james-simon/eigenlearning.


White House proposes tech 'bill of rights' to limit AI harms

#artificialintelligence

Top science advisers to President Joe Biden are calling for a new "bill of rights" to guard against powerful new artificial intelligence technology. The White House's Office of Science and Technology Policy on Friday launched a fact-finding mission to look at facial recognition and other biometric tools used to identify people or assess their emotional or mental states and character. Biden's chief science adviser, Eric Lander, and the deputy director for science and society, Alondra Nelson, also published an opinion piece in Wired magazine detailing the need to develop new safeguards against faulty and harmful uses of AI that can unfairly discriminate against people or violate their privacy. "Enumerating the rights is just a first step," they wrote. "What might we do to protect them? Possibilities include the federal government refusing to buy software or technology products that fail to respect these rights, requiring federal contractors to use technologies that adhere to this'bill of rights,' or adopting new laws and regulations to fill gaps."


The Air Force's First Software Chief Stepped Down--But He Won't Be Quiet

#artificialintelligence

As he settles into post-government life, Nicolas Chaillan still expects to call out the foreign competitors and domestic roadblocks that he says increasingly endanger U.S. security and informed his decision to publicly resign as the Air Force's first chief software officer. "Right now, the urgency is spending time with my kids first, and waking up America before it is too late. Because otherwise, there's just no point," Chaillan told Nextgov in an interview Tuesday. "Otherwise I need to invest in a bunker." A computer coder by the age of seven, Chaillan started his own companies in France at 15.


Artificial intelligence is becoming a 'force multiplier' -- for good and bad

#artificialintelligence

AI safety issues are becoming increasingly important. Google DeepMind and Faculty, both based in London, are devoting considerable resources to this area. But Anthropic, a San Francisco-based startup research company spun out of OpenAI, and some academic labs, including the Future of Humanity Institute in Oxford, are building expert teams in this field. "There is so little scrutiny over building very, very powerful software systems," says Hogarth. "We can plausibly have systems that exceed human capabilities in 30 years but there are fewer than 200 people in the world working on oversight and regulation."


Scientists develop an exoskeleton to help amputees walk with much less effort

Daily Mail - Science & tech

An exoskeleton that lets amputees feel like they are'walking with two normal legs' has been developed by scientists using battery-powered electric motors. The powerful exoskeleton, which wraps around the wearer's waist and leg, was developed by a team of engineers at the University of Utah in Salt Lake City. It has been designed for above-the-knee amputees and uses battery-powered electric motors and embedded microprocessors to reduce walking effort. The 5.4lb frame is made of carbon-fibre material, plastic composites and aluminium and can walk for miles between charges, according to its creators. Those wearing it saw a 15.6 per cent reduction in their metabolic rate, equivalent to taking off a 26-pound backpack while out on a long walk, the team said.


Clearview scraped '10bn' selfies for facial recognition

#artificialintelligence

In brief Clearview AI says it has scraped more than 10 billion photographs from people's public social media accounts for its controversial facial-recognition tool. The startup's CEO Hoan Ton-That also told Wired his engineers were working on new features to make blurry images sharper and to make it possible to recognize people even if they were wearing masks. Its software, often peddled to law enforcement agencies, provides face matching – you show it a still from CCTV, it finds the online profiles of that person – and the larger its database, the more faces it can identify. The latest steps show Clearview has ignored pressure from Facebook, Google, YouTube, and Twitter, which urged the upstart to stop downloading people's selfies last year. Clearview said it also only operates in the US.