Goto

Collaborating Authors

 Government


Cybersecurity tool uses machine learning, honeypots to stop attacks

#artificialintelligence

In recent months, the FBI issued a high-impact cybersecurity warning in response to increasing attacks on government targets. Government officials have warned major cities such hacks are a disturbing trend likely to continue. Purdue University researchers may help stop some of those threats with a tool designed to alert organizations to cyberattacks. The system is called LIDAR โ€“ which stands for lifelong, intelligent, diverse, agile and robust. "The name for this architecture for network security really defines its significant attributes," said Aly El Gamal, an assistant professor of electrical and computer engineering in Purdue's College of Engineering.


Scalable Quantitative Verification For Deep Neural Networks

arXiv.org Machine Learning

Verifying security properties of deep neural networks (DNNs) is becoming increasingly important. This paper introduces a new quantitative verification framework for DNNs that can decide, with user-specified confidence, whether a given logical property {\psi} defined over the space of inputs of the given DNN holds for less than a user-specified threshold, {\theta}. We present new algorithms that are scalable to large real-world models as well as proven to be sound. Our approach requires only black-box access to the models. Further, it certifies properties of both deterministic and non-deterministic DNNs. We implement our approach in a tool called PROVERO. We apply PROVERO to the problem of certifying adversarial robustness. In this context, PROVERO provides an attack-agnostic measure of robustness for a given DNN and a test input. First, we find that this metric has a strong statistical correlation with perturbation bounds reported by 2 of the most prominent white-box attack strategies today. Second, we show that PROVERO can quantitatively certify robustness with high confidence in cases where the state-of-the-art qualitative verification tool (ERAN) fails to produce conclusive results. Thus, quantitative verification scales easily to large DNNs.


TensorShield: Tensor-based Defense Against Adversarial Attacks on Images

arXiv.org Machine Learning

Recent studies have demonstrated that machine learning approaches like deep neural networks (DNNs) are easily fooled by adversarial attacks. Subtle and imperceptible perturbations of the data are able to change the result of deep neural networks. Leveraging vulnerable machine learning methods raises many concerns especially in domains where security is an important factor. Therefore, it is crucial to design defense mechanisms against adversarial attacks. For the task of image classification, unnoticeable perturbations mostly occur in the high-frequency spectrum of the image. In this paper, we utilize tensor decomposition techniques as a preprocessing step to find a low-rank approximation of images which can significantly discard high-frequency perturbations. Recently a defense framework called Shield could "vaccinate" Convolutional Neural Networks (CNN) against adversarial examples by performing random-quality JPEG compressions on local patches of images on the ImageNet dataset. Our tensor-based defense mechanism outperforms the SLQ method from Shield by 14% against FastGradient Descent (FGSM) adversarial attacks, while maintaining comparable speed.


Robust Stochastic Bandit Algorithms under Probabilistic Unbounded Adversarial Attack

arXiv.org Machine Learning

The multi-armed bandit formalism has been extensively studied under various attack models, in which an adversary can modify the reward revealed to the player. Previous studies focused on scenarios where the attack value either is bounded at each round or has a vanishing probability of occurrence. These models do not capture powerful adversaries that can catastrophically perturb the revealed reward. This paper investigates the attack model where an adversary attacks with a certain probability at each round, and its attack value can be arbitrary and unbounded if it attacks. Furthermore, the attack value does not necessarily follow a statistical distribution. We propose a novel sample median-based and exploration-aided UCB algorithm (called med-E-UCB) and a median-based $\epsilon$-greedy algorithm (called med-$\epsilon$-greedy). Both of these algorithms are provably robust to the aforementioned attack model. More specifically we show that both algorithms achieve $\mathcal{O}(\log T)$ pseudo-regret (i.e., the optimal regret without attacks). We also provide a high probability guarantee of $\mathcal{O}(\log T)$ regret with respect to random rewards and random occurrence of attacks. These bounds are achieved under arbitrary and unbounded reward perturbation as long as the attack probability does not exceed a certain constant threshold. We provide multiple synthetic simulations of the proposed algorithms to verify these claims and showcase the inability of existing techniques to achieve sublinear regret. We also provide experimental results of the algorithm operating in a cognitive radio setting using multiple software-defined radios.


Conditional Self-Attention for Query-based Summarization

arXiv.org Artificial Intelligence

Self-attention mechanisms have achieved great success on a variety of NLP tasks due to its flexibility of capturing dependency between arbitrary positions in a sequence. For problems such as query-based summarization (Qsumm) and knowledge graph reasoning where each input sequence is associated with an extra query, explicitly modeling such conditional contextual dependencies can lead to a more accurate solution, which however cannot be captured by existing self-attention mechanisms. In this paper, we propose \textit{conditional self-attention} (CSA), a neural network module designed for conditional dependency modeling. CSA works by adjusting the pairwise attention between input tokens in a self-attention module with the matching score of the inputs to the given query. Thereby, the contextual dependencies modeled by CSA will be highly relevant to the query. We further studied variants of CSA defined by different types of attention. Experiments on Debatepedia and HotpotQA benchmark datasets show CSA consistently outperforms vanilla Transformer and previous models for the Qsumm problem.


European Commission to release new paper on AI, facial recognition

#artificialintelligence

The Irish Times reports the European Commission will publish a new position paper on artificial intelligence across the bloc next week. While the paper does not include a pitch for a previously proposed facial-recognition moratorium, the commission is set to allow member states, via an independent assessor, to decipher how and when they will permit the use of facial recognition. Meanwhile, Euractiv reports that Clearview AI aims to expand services across the European market.


A Conversation with Steve Durbin โ€“ Gigaom

#artificialintelligence

Right this moment's main minds discuss AI with host Byron Reese Hearken to this episode or learn the total transcript at www.VoicesinAI.com Byron Reese: That is Voices in AI dropped at you by GigaOm, and I'm Byron Reese. Right this moment our visitor is Steve Durbin. His principal areas of focus embody technique, info know-how, cybersecurity and the rising safety risk panorama throughout the company and private surroundings. He runs his firm because the managing director, which he has been doing for nearly a decade. Welcome to the present, Steve.


A Texas jury found him guilty of murder. A computer algorithm proved his innocence.

#artificialintelligence

Nearly a decade into his life sentence for murder, Lydell Grant was escorted out of a Texas prison in November with his hands held high, free on bail, all thanks to DNA re-examined by a software program. "The last nine years, man, I felt like an animal in a cage," Grant, embracing his mother and brother, told the crush of reporters awaiting him in Houston. "Especially knowing that I didn't do it." Now, Grant, 42, is on a fast-track to exoneration after a judge recommended in December that Texas' highest criminal court vacate his conviction. His attorneys are hopeful a ruling is made in the coming weeks.


How the Pentagon's AI team can benefit civilian agencies

#artificialintelligence

The General Services Administration expects that its new partnership with the Pentagon's Joint Artificial Intelligence Center will ultimately lead to significant benefits for civilian agencies. The GSA is working with JAIC, which was established last year to speed up AI adoption across the Pentagon, to accelerate the center's process by adding AI into acquisition work, which GSA officials said they hope to turn around and offer civilian government. "We're able to utilize a lot of that educational material [and] best practices that they're getting and scale it up, standardize it in a sense so it can be spread among civilian agencies," said Omid Ghaffari-Tabrizi, acquisition lead at the GSA Centers of Excellence, speaking Dec. 5 at the GovernmentCIO AI and RPA in Government conference. "All of the AI that we're procuring for them, we're also hoping to procure for ourselves," Ghaffari-Tabrizi added. One frustration with the acquisition process is the time it takes from the start of the project to the end.


AI a new and 'frightening' battlefield in cyber war, experts warn

#artificialintelligence

Unbeknownst to the CEO of a company who was interviewed on TV last year, a hacking group that was trailing the CEO taped the interview and then taught a computer to perfectly imitate the CEO's voice -- so it could then give credible instructions for a wire transfer of funds to a third party. This "voice phishing" hack brought to light the growing abilities of artificial intelligence-based technologies to perpetuate cyber-attacks and cyber-crime. Using new AI-based software, hackers have imitated the voices of a number of senior company officials around the world and thereby given out instructions to perform transactions for them, such as money transfers. The software can learn how to perfectly imitate a voice after just 20 minutes of listening to it and can then speak with that voice and say things that the hacker types into the software. Get The Start-Up Israel's Daily Start-Up by email and never miss our top stories Free Sign Up Some of these attempts were foiled, but other hackers were successful in getting their hands on money.