Government
Robust Deep Learning Ensemble against Deception
Deep neural network (DNN) models are known to be vulnerable to maliciously crafted adversarial examples and to out-of-distribution inputs drawn sufficiently far away from the training data. How to protect a machine learning model against deception of both types of destructive inputs remains an open challenge. This paper presents XEnsemble, a diversity ensemble verification methodology for enhancing the adversarial robustness of DNN models against deception caused by either adversarial examples or out-of-distribution inputs. XEnsemble by design has three unique capabilities. First, XEnsemble builds diverse input denoising verifiers by leveraging different data cleaning techniques. Second, XEnsemble develops a disagreement-diversity ensemble learning methodology for guarding the output of the prediction model against deception. Third, XEnsemble provides a suite of algorithms to combine input verification and output verification to protect the DNN prediction models from both adversarial examples and out of distribution inputs. Evaluated using eleven popular adversarial attacks and two representative out-of-distribution datasets, we show that XEnsemble achieves a high defense success rate against adversarial examples and a high detection success rate against out-of-distribution data inputs, and outperforms existing representative defense methods with respect to robustness and defensibility.
Fed+: A Family of Fusion Algorithms for Federated Learning
Yu, Pengqian, Wynter, Laura, Lim, Shiau Hong
We present a class of methods for federated learning, which we call Fed+, pronounced FedPlus. The class of methods encompasses and unifies a number of recent algorithms proposed for federated learning and permits easily defining many new algorithms. The principal advantage of this class of methods is to better accommodate the real-world characteristics found in federated learning training, such as the lack of IID data across the parties in the federation. We demonstrate the use and benefits of this class of algorithms on standard benchmark datasets and a challenging real-world problem where catastrophic failure has a serious impact, namely in financial portfolio management.
Sparsity Turns Adversarial: Energy and Latency Attacks on Deep Neural Networks
Krithivasan, Sarada, Sen, Sanchari, Raghunathan, Anand
Adversarial attacks have exposed serious vulnerabilities in Deep Neural Networks (DNNs) through their ability to force misclassifications through human-imperceptible perturbations to DNN inputs. We explore a new direction in the field of adversarial attacks by suggesting attacks that aim to degrade the computational efficiency of DNNs rather than their classification accuracy. Specifically, we propose and demonstrate sparsity attacks, which adversarial modify a DNN's inputs so as to reduce sparsity (or the presence of zero values) in its internal activation values. In resource-constrained systems, a wide range of hardware and software techniques have been proposed that exploit sparsity to improve DNN efficiency. The proposed attack increases the execution time and energy consumption of sparsity-optimized DNN implementations, raising concern over their deployment in latency and energy-critical applications. We propose a systematic methodology to generate adversarial inputs for sparsity attacks by formulating an objective function that quantifies the network's activation sparsity, and minimizing this function using iterative gradient-descent techniques. We launch both white-box and black-box versions of adversarial sparsity attacks on image recognition DNNs and demonstrate that they decrease activation sparsity by up to 1.82x. We also evaluate the impact of the attack on a sparsity-optimized DNN accelerator and demonstrate degradations up to 1.59x in latency, and also study the performance of the attack on a sparsity-optimized general-purpose processor. Finally, we evaluate defense techniques such as activation thresholding and input quantization and demonstrate that the proposed attack is able to withstand them, highlighting the need for further efforts in this new direction within the field of adversarial machine learning.
The Radicalization Risks of GPT-3 and Advanced Neural Language Models
McGuffie, Kris, Newhouse, Alex
In this paper, we expand on our previous research of the potential for abuse of generative language models by assessing GPT-3. Experimenting with prompts representative of different types of extremist narrative, structures of social interaction, and radical ideologies, we find that GPT-3 demonstrates significant improvement over its predecessor, GPT-2, in generating extremist texts. We also show GPT-3's strength in generating text that accurately emulates interactive, informational, and influential content that could be utilized for radicalizing individuals into violent far-right extremist ideologies and behaviors. While OpenAI's preventative measures are strong, the possibility of unregulated copycat technology represents significant risk for large-scale online radicalization and recruitment; thus, in the absence of safeguards, successful and efficient weaponization that requires little experimentation is likely. AI stakeholders, the policymaking community, and governments should begin investing as soon as possible in building social norms, public policy, and educational initiatives to preempt an influx of machine-generated disinformation and propaganda. Mitigation will require effective policy and partnerships across industry, government, and civil society.
Chasing Value as AI Transforms Health Care
Business leaders no longer think about artificial intelligence in terms of future impact--they're seeing the impact today. AI is appearing in all corners of business, transforming the way companies operate. Health care is no exception. Health care players are using AI to address significant inefficiencies and open up powerful new opportunities. These include everything from the delivery of remote health care services to the early diagnosis of disease and the hunt for new life-saving medicines.
AI Weekly: What ML practitioners are doing about climate change
A lot happened this week in the AI space. The Guardian wrote an article with GPT-3 and again demonstrated that no matter what OpenAI paid to train and create the language model, the free marketing might be worth more. After losing the JEDI cloud contract appeal with the Pentagon, Amazon appointed to its board Keith Alexander, who oversaw the National Security Agency mass surveillance revealed by Edward Snowden leaks in 2013. And Portland passed the strictest facial recognition bans in U.S. history, outlawing government and business use of the technology. However, AI Weekly attempts to reach into the zeitgeist and highlight the issues on people's minds. This week without question it's the smoke that has hung over the western United States and the underlying problem of climate change.
How does Artificial Intelligence Redefine Business Processes?
Artificial Intelligence (AI) emulates human intelligence process which involves extracting meaningful insights and patterns, predicting plausible future decisions made possible by the three major tenants of the technology which translates to Machine Learning (ML), Natural Language Processing (NLP) and Deep Learning (Neural Networks). AI has established encapsulating everything from rule-based machine learning to image classification whose applications range from preventing high-end cybersecurity threats to object recognition. Here are the use cases that explain the pursuit of AI in business parlance. Machine Learning and AI have reached users on every platform be it online or offline. Artificial Intelligence deploys Natural Language Processing (NLP) techniques to interpret words, data and apply contextual and reasoning algorithms to generate useful insights and provide relevant data for analysts to focus on growing data needs.
Twilight of the Human Hacker โ Center for Public Integrity
The Joint Operations Center inside Fort Meade in Maryland is a cathedral to cyber warfare. Part of a 380,000-square-foot, $520 million complex opened in 2018, the office is the nerve center for both the U.S. Cyber Command and the National Security Agency as they do cyber battle. Clusters of civilians and military troops work behind dozens of computer monitors beneath a bank of small chiclet windows dousing the room in light. Three 20-foot-tall screens are mounted on a wall below the windows. On most days, two of them are spitting out a constant feed from a secretive program known as "Project IKE." Join the Watchdog newsletter to hear about our latest ground-breaking investigation. The room looks no different than a standard government auditorium, but IKE represents a radical leap forward. If the Joint Operations Center is the physical embodiment of a new era in cyber warfare -- the art of using computer code to attack and defend targets ranging from tanks to email servers -- IKE is the brains. It tracks every keystroke made by the 200 fighters working on computers below the big screens and churns out predictions about the possibility of success on individual cyber missions. It can automatically run strings of programs and adjusts constantly as it absorbs information. IKE is a far cry from the prior decade of cyber operations, a period of manual combat that involved the most mundane of tools.
Jewish News
China's Defense Ministry on Sunday blasted a critical U.S. report on the country's military ambitions, saying it is the U.S. instead that poses the biggest threat to the international orderโฆ Oman welcomes Bahrain's decision to normalize relations with Israel and hopes it will contribute to Israeli-Palestinian peace, Oman state media said on Sunday. Pushing for new roads to reelection, President Donald Trump is going on the offense this weekend in Nevada, which hasn't supported a Republican presidential candidate since 2004. Housing and Construction Minister Rabbi Yaakov Litzman threatened Sunday to resign if the government implements a lockdown over the Yamim Nora'im. The United Arab Emirates' Mohamed Bin Zayed University of Artificial Intelligence and Israel's Weizmann Institute of Science have agreed to work together, UAE state news agency WAM said on Sunday.โฆ Hamas leader Ismail Haniyeh told Turkish media on Friday that Egypt is currently mediating a new prisoner exchange deal between Gaza Strip's rulers and Israel.
Google Is Using Machine Learning Techniques To Better Recognize Breaking News, And Its AI Systems Now Take Minutes To Detect Breaking News
Yesterday, Google wrote in a blog post that the company is using Artificial Intelligence and machine learning techniques to more quickly recognize breaking news around various crises such as natural disasters. According to Google's VP of search Pandu Nayak, the AI systems of Google now take minutes to recognize breaking stories. In comparison, the detection time of its systems was up to 40 minutes only a few years ago. Nayak wrote in the post that the company has improved its system to automatically recognize breaking news around crisis moments and make sure that the company is returning the most authentic information available. Likely, quicker breaking news detection will become more critical as the 2020 United States Presidential Election day nears and natural disasters across the globe unfold.