Government
Efficient Project Gradient Descent for Ensemble Adversarial Attack
Wu, Fanyou, Gazo, Rado, Haviarova, Eva, Benes, Bedrich
Recent advances show that deep neural networks are not robust to deliberately crafted adversarial examples which many are generated by adding human imperceptible perturbation to clear input. Consider $l_2$ norms attacks, Project Gradient Descent (PGD) and the Carlini and Wagner (C\&W) attacks are the two main methods, where PGD control max perturbation for adversarial examples while C\&W approach treats perturbation as a regularization term optimized it with loss function together. If we carefully set parameters for any individual input, both methods become similar. In general, PGD attacks perform faster but obtains larger perturbation to find adversarial examples than the C\&W when fixing the parameters for all inputs. In this report, we propose an efficient modified PGD method for attacking ensemble models by automatically changing ensemble weights and step size per iteration per input. This method generates smaller perturbation adversarial examples than PGD method while remains efficient as compared to C\&W method. Our method won the first place in IJCAI19 Targeted Adversarial Attack competition.
Machine Learning Prediction of Accurate Atomization Energies of Organic Molecules from Low-Fidelity Quantum Chemical Calculations
Ward, Logan, Blaiszik, Ben, Foster, Ian, Assary, Rajeev S., Narayanan, Badri, Curtiss, Larry
Recent studies illustrate how machine learning (ML) can be used to bypass a core challenge of molecular modeling: the tradeoff between accuracy and computational cost. Here, we assess multiple ML approaches for predicting the atomization energy of organic molecules. Our resulting models learn the difference between low-fidelity, B3LYP, and high-accuracy, G4MP2, atomization energies, and predict the G4MP2 atomization energy to 0.005 eV (mean absolute error) for molecules with less than 9 heavy atoms and 0.012 eV for a small set of molecules with between 10 and 14 heavy atoms. Our two best models, which have different accuracy/speed tradeoffs, enable the efficient prediction of G4MP2-level energies for large molecules and are available through a simple web interface.
Kernelized Capsule Networks
Killian, Taylor, Goodwin, Justin, Brown, Olivia, Son, Sung-Hyun
Capsule Networks attempt to represent patterns in images in a way that preserves hierarchical spatial relationships. Additionally, research has demonstrated that these techniques may be robust against adversarial perturbations. We present an improvement to training capsule networks with added robustness via non-parametric kernel methods. The representations learned through the capsule network are used to construct covariance kernels for Gaussian processes (GPs). We demonstrate that this approach achieves comparable prediction performance to Capsule Networks while improving robustness to adversarial perturbations and providing a meaningful measure of uncertainty that may aid in the detection of adversarial inputs.
Reliable Classification Explanations via Adversarial Attacks on Robust Networks
Woods, Walt, Chen, Jack, Teuscher, Christof
Neural Networks (NNs) have been found vulnerable to a class of imperceptible attacks, called adversarial examples, which arbitrarily alter the output of the network. These attacks have called the validity of NNs into question, particularly on sensitive problems such as medical imaging or fraud detection. We further argue that the fields of explainable AI and Human-In-The-Loop (HITL) algorithms are impacted by adversarial attacks, as attacks result in perturbations outside of the salient regions highlighted by state-of-the-art techniques such as LIME or Grad-CAM. This work accomplishes three things which greatly reduce the impact of adversarial examples, and pave the way for future HITL workflows: we propose a novel regularization technique inspired by the Lipschitz constraint which greatly improves an NN's resistance to adversarial examples; we propose a collection of novel network and training changes to complement the proposed regularization technique, including a Half-Huber activation function and an integrator-based controller for regularization strength; and we demonstrate that networks trained with this technique may be deliberately attacked to generate rich explanations. Our techniques led to networks more robust than the previous state of the art: using the Accuracy-Robustness Area (ARA), our most robust ImageNet classification network scored 42.2% top-1 accuracy on unmodified images and demonstrated an attack ARA of 0.0053, an ARA 2.4x greater than the previous state-of-the-art at the same level of accuracy on clean data, achieved with a network one-third the size. A far-reaching benefit of this technique is its ability to intuitively demonstrate decision boundaries to a human observer, allowing for improved debugging of NN decisions, and providing a means for improving the underlying model.
Quantum Machine Learning
Presenter: Harry Rhys Davies, Applied AI Lead, Tech Nation Level: Introductory Abstract: As part of the UK Government's AI Sector Deal, Tech Nation is launching the UK's first peer-to-peer, growth programme for applied AI companies that aim to solve real-world problems. Applied AI 1.0, sponsored by the UK Government's Office for Artificial Intelligence, will kick-off this September and is inspired by Tech Nation's successful Future Fifty, Upscale and Fintech programmes. The free, non-residential, six-month programme will first and foremost function as practical network for founders that facilitates peer-to-peer learning across the C-suite (CEO, CTO, COO and more) through values of honesty, intimacy and trust, as well as providing opportunities to learn from later-stage founders, meet investors and potential clients, and join us on an international trip. Title: The Autodidact's Guide to Building an AI Application Presenter: Armaghan Ahmed Level: Introductory Abstract: An intro-level walkthrough for those interested in AI on a practical way to learn about the field by using ML in a side-project. Title: Quantum Machine Learning Presenter: Viacheslav Burenkov Level: Introductory to Intermediate Abstract: Machine learning is becoming increasingly popular in today's world, improving and creating new businesses across a broad range of industries, including healthcare, financial services, self-driving cars, and many others.
Universal Basic Income, Automation and the Future of Jobs
The nature of work has changed dramatically since the 1950s. In that glorious post-war period, work was primarily a man's purview, while women did so-called "invisible" work - taking care of children, maintaining the home and cooking. It wasn't unusual for a man to retire 40 years laterfrom the same employer he started with. That employer picked up the worker's health and life insurance, and some employers even paid school tuition for their workers' children. There was a sense of continuity.
US Military funds mind-reading helmet that may let soldiers TELEPATHICALLY control robots or drones
US military research body DARPA is funding a project to create a mind-reading helmet that could let soldiers fly drones and control robots telepathically. Led by Texas-based researchers, the project will start by trying to read the vision of one person and transfer it into the brain of someone who is visually impaired. The helmet works by using both light and magnetic fields to interact with specially-reprogrammed neurons in the brain of the wearer. The Magnetic, Optical and Acoustic Neural Access (MOANA) project is exploring a minimally invasive, nonsurgical approach to connect human brains with a machine via a special helmet. Users will undergo gene therapy that will make certain neurons absorb light when firing.
Speculation grows in Japan that Diet session will be extended to enable double election
Speculation within the ruling Liberal Democratic Party over a possible extension of the current regular Diet session, a move that could result in a double election this summer, has grown ahead of the scheduled end of the 150-day session on June 26. The speculation has grown because the government is moving to submit a bill to revise the law on national strategic special zones in order to realize "super cities" where cutting-edge technologies such as artificial intelligence will be fully utilized. It's believed that it will be difficult to pass the legislation during the ongoing session without an extension. The move and the possible extension is apparently aimed at setting the stage for Prime Minister Shinzo Abe to dissolve the House of Representatives and arrange an election for the same date as that of a triennial election this summer for the House of Councilors. Opposition parties, as well as Komeito, the coalition partner of the LDP, are cautious over the possibility of a double election.
Machine Learning And Artificial Intelligence In Cybersecurity: Hype Versus Reality
When it comes to training AI/ML models, a popular debate is whether "supervised" or "unsupervised" learning should be used. Supervised learning is based on labeled data and features extracted to derive a prediction model. For malware, this means human experts classify each sample in the data set as good or bad, and feature-engineering is performed to determine what attributes of the malware are relevant to the prediction model prior to training. Unsupervised learning gleans patterns and determines structure from data that is not labeled or categorized. Unsupervised learning proponents claim that it is not limited by the boundaries of human classification and remains free from feature-selection bias.
New tool helps travelers avoid airlines that use facial recognition technology
A new tool launched by privacy activists offers to help travelers avoid increasingly invasive facial recognition technologies in airports. Activist groups Fight for the Future, Demand Progress and CREDO on Wednesday unveiled a new website called AirlinePrivacy.com, The site also helps customers to directly book flights with airlines that don't use facial recognition technologies. Airlines' use of facial recognition technology is raising fresh questions about privacy and data security, advocates have argued. Instead of verifying passengers' details by scanning a boarding pass, the technology – which is provided by government agencies – scans passengers' face and sends that information to border control to verify identity and flight details.