Goto

Collaborating Authors

 Government


Bag of Tricks for Adversarial Training

arXiv.org Machine Learning

Adversarial training (AT) is one of the most effective strategies for promoting model robustness. However, recent benchmarks show that most of the proposed improvements on AT are less effective than simply early stopping the training procedure. This counterintuitive fact motivates us to investigate the implementation details of tens of AT methods. Surprisingly, we find that the basic settings (e.g., weight decay, training schedule, etc.) used in these methods are highly inconsistent. In this work, we provide comprehensive evaluations on CIFAR-10, focusing on the effects of mostly overlooked training tricks and hyperparameters for adversarially trained models. Our empirical observations suggest that adversarial robustness is much more sensitive to some basic training settings than we thought. For example, a slightly different value of weight decay can reduce the model robust accuracy by more than 7%, which is probable to override the potential promotion induced by the proposed methods. Adversarial training (AT) has been one of the most effective defense strategies against adversarial attacks (Biggio et al., 2013; Szegedy et al., 2014; Goodfellow et al., 2015). Based on the primary AT frameworks like PGD-AT (Madry et al., 2018), many improvements have been proposed from different perspectives, and demonstrate promising results (detailed in Sec. 2). However, the recent benchmarks (Croce & Hein, 2020b; Chen & Gu, 2020) find that simply early stopping the training procedure of PGD-AT (Rice et al., 2020) can attain the gains from almost all the previously proposed improvements, including the state-of-the-art TRADES (Zhang et al., 2019b).


Mediating Artificial Intelligence Developments through Negative and Positive Incentives

arXiv.org Artificial Intelligence

The field of Artificial Intelligence (AI) is going through a period of great expectations, introducing a certain level of anxiety in research, business and also policy. This anxiety is further energised by an AI race narrative that makes people believe they might be missing out. Whether real or not, a belief in this narrative may be detrimental as some stake-holders will feel obliged to cut corners on safety precautions, or ignore societal consequences just to "win". Starting from a baseline model that describes a broad class of technology races where winners draw a significant benefit compared to others (such as AI advances, patent race, pharmaceutical technologies), we investigate here how positive (rewards) and negative (punishments) incentives may beneficially influence the outcomes. We uncover conditions in which punishment is either capable of reducing the development speed of unsafe participants or has the capacity to reduce innovation through over-regulation. Alternatively, we show that, in several scenarios, rewarding those that follow safety measures may increase the development speed while ensuring safe choices. Moreover, in {the latter} regimes, rewards do not suffer from the issue of over-regulation as is the case for punishment. Overall, our findings provide valuable insights into the nature and kinds of regulatory actions most suitable to improve safety compliance in the contexts of both smooth and sudden technological shifts.


Explaining AI as an Exploratory Process: The Peircean Abduction Model

arXiv.org Artificial Intelligence

Current discussions of "Explainable AI" (XAI) do not much consider the role of abduction in explanatory reasoning (see Mueller, et al., 2018). It might be worthwhile to pursue this, to develop intelligent systems that allow for the observation and analysis of abductive reasoning and the assessment of abductive reasoning as a learnable skill. Abductive inference has been defined in many ways. For example, it has been defined as the achievement of insight. Most often abduction is taken as a single, punctuated act of syllogistic reasoning, like making a deductive or inductive inference from given premises. In contrast, the originator of the concept of abduction---the American scientist/philosopher Charles Sanders Peirce---regarded abduction as an exploratory activity. In this regard, Peirce's insights about reasoning align with conclusions from modern psychological research. Since abduction is often defined as "inferring the best explanation," the challenge of implementing abductive reasoning and the challenge of automating the explanation process are closely linked. We explore these linkages in this report. This analysis provides a theoretical framework for understanding what the XAI researchers are already doing, it explains why some XAI projects are succeeding (or might succeed), and it leads to design advice.


Podcast: How Russia's everything company works with the Kremlin

MIT Technology Review

Russia's biggest technology company enjoys a level of dominance that is unparalleled by any one of its Western counterparts. Think Google mixed with equal parts Amazon, Spotify and Uber and you're getting close to the sprawling empire that is Yandex--a single, mega-corporation with its hands in everything from search to ecommerce to driverless cars. But being the crown jewel of Russia's silicon valley has its drawbacks. The country's government sees the internet as contested territory amid ever-present tensions with US and other Western interests. As such, it wants influence over how Yandex uses its massive trove of data on Russian citizens. Foreign investors, meanwhile, are more interested in how that data can be turned into growth and profit. For the September/October issue of MIT Technology Review, Moscow-based journalist Evan Gershkovich explains how Yandex's ability to walk a highwire between the Kremlin and Wall Street could potentially serve as a kind of template for Big Tech.


Humane AI requires a regulatory regime - Information Age

#artificialintelligence

Artificial intelligence (AI) is set to upend nearly every industry. It's a technology that will deliver astronomical gains in productivity, dramatic cost reductions, and tremendous advances in research and development. With AI set to increase global GDP by more than $15.7 trillion by 2030, it can be easy to assume that the technology can be nothing but an unfettered good. That would be a dangerous mistake. AI, like any technology, can have detrimental personal, societal, and economic effects: some common concerns include the fact it provides tools that can be exploited by criminals to compromise the cyber security of individuals and organisations, or that the predictive abilities of AI raise a swathe of privacy concerns.


Artificial Intelligence and ML in Cybersecurity: Is it Worth the Hype?

#artificialintelligence

The world is going digital at a pace faster than the blink of an eye. Artificial intelligence (AI) and machine learning (ML) have been heralded as a means of digital technology that can solve a wide range of problems in different industries and applications. This also includes the realm of cybersecurity. Capgemini's Reinventing Cybersecurity with Artificial Intelligence Report, which was published last year, found that 61% of enterprises say they cannot detect breach attempts today without using AI technologies. In a similar survey by Webroot, it was observed that 89% of IT professionals believe their company could be doing more to defend against cyberattacks.


Amsterdam and Helsinki launch algorithm registries to bring transparency to public deployments of AI

#artificialintelligence

Amsterdam and Helsinki today launched AI registries to detail how each city government uses algorithms to deliver services, some of the first major cities in the world to do so. An AI Register for each city was introduced in beta today as part of the Next Generation Internet Policy Summit, organized in part by the European Commission and the city of Amsterdam. The Amsterdam registry currently features a handful of algorithms, but it will be extended to include all algorithms following the collection of feedback at the virtual conference to lay out a European vision of the future of the internet, according to a city official. Each algorithm cited in the registry lists datasets used to train a model, a description of how an algorithm is used, how humans utilize the prediction, and how algorithms were assessed for potential bias or risks. The registry also provides citizens a way to give feedback on algorithms their local government uses and the name, city department, and contact information for the person responsible for the responsible deployment of a particular algorithm.


DARPA sets sights on making AI self-aware of complex time dimensions

#artificialintelligence

The Defense Advanced Research Projects Agency (DARPA) is setting its sights on developing an AI system with a detailed self-understanding of the time dimensions of its learned knowledge. DARPA's Time-Aware Machine Intelligence (TAMI) research program and incubator is looking to develop a new class of neural network architectures that incorporate an explicit time dimension as a fundamental building block for network knowledge representation," according to the TAMI program solicitation. The overall goal is to create an AI system that will be able to "think in and about time" when exercising its learned task knowledge in task performance. Current neural networks do not explicitly model the inherent time characteristics of their encoded knowledge. Consequently, state-of-the-art machine learning does not have the expressive capability to reason with encoded knowledge using time.


The state of artificial intelligence-based FDA-approved medical devices and algorithms: an online database

#artificialintelligence

At the beginning of the artificial intelligence (AI)/machine learning (ML) era, the expectations are high, and experts foresee that AI/ML shows potential for diagnosing, managing and treating a wide variety of medical conditions. However, the obstacles for implementation of AI/ML in daily clinical practice are numerous, especially regarding the regulation of these technologies. Therefore, we provide an insight into the currently available AI/ML-based medical devices and algorithms that have been approved by the US Food & Drugs Administration (FDA). We aimed to raise awareness of the importance of regulatory bodies, clearly stating whether a medical device is AI/ML based or not. Cross-checking and validating all approvals, we identified 64 AI/ML based, FDA approved medical devices and algorithms. Out of those, only 29 (45%) mentioned any AI/ML-related expressions in the official FDA announcement. The majority (85.9%) was approved by the FDA with a 510(k) clearance, while 8 (12.5%) received de novo pathway clearance and one (1.6%) premarket approval (PMA) clearance. Most of these technologies, notably 30 (46.9%), 16 (25.0%), and 10 (15.6%) were developed for the fields of Radiology, Cardiology and Internal Medicine/General Practice respectively. We have launched the first comprehensive and open access database of strictly AI/ML-based medical technologies that have been approved by the FDA. The database will be constantly updated.


What investment trends reveal about the global AI landscape

#artificialintelligence

It's a serious competitor and has made massive gains, but China's AI prowess is still often oversold. Our data suggest that America still leads in AI venture capital and other forms of private-market AI investment, and Chinese investors don't seem to be co-opting American AI startups in large numbers. Policymakers should focus on reinforcing the vibrant, open innovation ecosystem that fuels America's AI advantage, and take a deep breath before acting against China's technology transfer efforts and AI abuses. Action is necessary, but misunderstanding China's overall position in AI could lead to rushed or overbroad policies that do more harm than good. AI is a global wave, not a bipolar contest.