Government
Robustness of Generalized Learning Vector Quantization Models against Adversarial Attacks
Saralajew, Sascha, Holdijk, Lars, Rees, Maike, Villmann, Thomas
Adversarial attacks and the development of (deep) neural networks robust against them are currently two widely researched topics. The robustness of Learning Vector Quantization (LVQ) models against adversarial attacks has however not yet been studied to the same extend. We therefore present an extensive evaluation of three LVQ models: Generalized LVQ, Generalized Matrix LVQ and Generalized Tangent LVQ. The evaluation suggests that both Generalized LVQ and Generalized Tangent LVQ have a high base robustness, on par with the current state-of-the-art in robust neural network methods. In contrast to this, Generalized Matrix LVQ shows a high susceptibility to adversarial attacks, scoring consistently behind all other models. Additionally, our numerical evaluation indicates that increasing the number of prototypes per class improves the robustness of the models.
The Spatially-Conscious Machine Learning Model
Kiely, Timothy J., Bastian, Nathaniel D.
Successfully predicting gentrification could have many social and commercial applications; however, real estate sales are difficult to predict because they belong to a chaotic system comprised of intrinsic and extrinsic characteristics, perceived value, and market speculation. Using New York City real estate as our subject, we combine modern techniques of data science and machine learning with traditional spatial analysis to create robust real estate prediction models for both classification and regression tasks. We compare several cutting edge machine learning algorithms across spatial, semi-spatial and non-spatial feature engineering techniques, and we empirically show that spatially-conscious machine learning models outperform non-spatial models when married with advanced prediction techniques such as feed-forward artificial neural networks and gradient boosting machine models.
Natural and Adversarial Error Detection using Invariance to Image Transformations
Bahat, Yuval, Irani, Michal, Shakhnarovich, Gregory
We propose an approach to distinguish between correct and incorrect image classifications. Our approach can detect misclassifications which either occurunintentionally ("natural errors"), or due to intentional adversarial attacks ("adversarial errors"),both in a single unified framework. Our approach is based on the observation that correctly classified images tend to exhibit robust and consistent classifications under certain image transformations (e.g., horizontal flip, small image translation, etc.). In contrast, incorrectly classified images (whether due to adversarial errors or natural errors)tend to exhibit large variations in classification resultsunder such transformations. Our approach does not require any modifications or retraining of the classifier, hence can be applied to any pre-trained classifier. We further use state of the art targeted adversarial attacks to demonstrate that even when the adversary has full knowledge of our method, the adversarial distortion needed for bypassing our detector is no longer imperceptible tothe human eye. Our approach obtains state-of-the-art results compared to previous adversarial detectionmethods, surpassing them by a large margin.
Optimal Adversarial Attack on Autoregressive Models
We investigate optimal adversarial attacks against time series forecast made by autoregressive models. In our setting, the environment evolves according to a potentially nonlinear dynamical system. A linear autoregressive model observes the current environment state and predicts its future values. But an adversary can modify the environment state and hence indirectly manipulate the autoregressive model forecasts. The adversary wants to drive the forecasts towards some adversarial targets while minimizing environment modification. We pose this attack problem as optimal control. When the environment dynamics is linear, we provide a closed-form solution to the optimal attack using Linear Quadratic Regulator (LQR). Otherwise, we propose an approximate attack based on Model Predictive Control (MPC) and iterative LQR (iLQR). Our paper thus connects adversarial learning with control theory. We demonstrate the advantage of our methods empirically.
Maximum Likelihood Estimation and Graph Matching in Errorfully Observed Networks
Arroyo, Jesรบs, Sussman, Daniel L., Priebe, Carey E., Lyzinski, Vince
Given a pair of graphs with the same number of vertices, the inexact graph matching problem consists in finding a correspondence between the vertices of these graphs that minimizes the total number of induced edge disagreements. We study this problem from a statistical framework in which one of the graphs is an errorfully observed copy of the other. We introduce a corrupting channel model, and show that in this model framework, the solution to the graph matching problem is a maximum likelihood estimator. Necessary and sufficient conditions for consistency of this MLE are presented, as well as a relaxed notion of consistency in which a negligible fraction of the vertices need not be matched correctly. The results are used to study matchability in several families of random graphs, including edge independent models, random regular graphs and small-world networks. We also use these results to introduce measures of matching feasibility, and experimentally validate the results on simulated and real-world networks.
The World's Fastest Supercomputer Breaks an AI Record
Along America's west coast, the world's most valuable companies are racing to make artificial intelligence smarter. Google and Facebook have boasted of experiments using billions of photos and thousands of high-powered processors. Late last year, a project in eastern Tennessee quietly exceeded the scale of any corporate AI lab. It was run by the US government. The record-setting project involved the world's most powerful supercomputer, Summit, at Oak Ridge National Lab.
Mars is more porous than we thought, Nasa's Curiosity rover finds in breakthrough study
Mars is more porous and less compacted than we thought, scientists have found in a breakthrough study that used data from Nasa's Curiosity rover in unusual ways. The researchers used non-science engineering data to understand the red planet's surface and measure how dense the rocks are in the 96-mile-wide Gale Crater. The discovery is not only a breakthrough in our understanding of Mars's surface, but gives researchers studying it a brand new way of exploring the planet as the Curiosity rover continues to drive around on it. Scientists made the discovery by taking data from engineering sensors that are on board Curiosity. They are accelerometers and gyroscopes, of the kind used to tell a smartphone where it is pointing.
China and the US are dominating the global artificial intelligence race
China and the United States are leading the way in the quest to dominate the world of artificial intelligence, a study by the United Nations has found. It found US tech giants IBM and Microsoft had the largest AI portfolios, with 8,920 and 5,930 different patents, respectively. China however, accounted for 17 of the top 20 academic institutions involved in patenting AI and was particularly strong in the fast growing area of'deep learning'. This process was recently used to create a'self-aware' robot that is capable of imagining itself. Other machines have complex speech recognition systems.
Could Chinese Telecom Giant Huawei Put U.S. Cyber-Security At Risk?
A new 5G network is being created now, which will not only offer faster downloading on cell phones. It will provide the kind of connectivity we need in the era of the Internet of Things - driverless cars, Internet-connected medical devices, smart TVs and virtual assistants. But there are dangers that could be lurking in the equipment needed to build the new network. The Chinese telecommunications equipment giant Huawei is dominating the creation of 5G networks around the world. For years, classified intelligence reports from the U.S. have warned that China would one day use Huawei to penetrate American networks for cyber-espionage or cyberattacks. In the U.S., the National Security Agency has banned AT&T and Verizon from using Huawei products in America's 5G network. And last month, the U.S. had a top executive from Huawei arrested in Canada so she could be extradited to the U.S. The growing cyberthreat posed by China was stressed in the Worldwide Threat Assessment - a report from the U.S. intelligence community - that was released this week. And all this is part of the backdrop for this week's trade negotiations between the U.S. and China. My guest David Sanger is the author of a book about cyberwar and cyber-sabotage called "The Perfect Weapon." Let's start with the 5G network. And how will it affect our phones, our devices and all our interconnectivity? DAVID SANGER: Well, at its simplest, the 5G network is an increase in speed and range for what you see on your cell phone. So 5G means just fifth generation. The hope is that when you're using your phone or some other device over Wi-Fi, you'll get no lag time and that you'll get near instantaneous download of data, webpages and so forth.
How Data Changed the World TechNative
The latest iteration of this new era revolves around data, both collecting it and analyzing it in ways never before possible. Big Data, as it's often called, is changing the world, and these changes are substantial. Here is how data is impacting society and what changes to expect in the future. The availability of robust scientific data in the latter half of the 20th century revolutionized how doctors treated diseases and provided better outcomes for patients. However, the ever-increasing flow of new data has made it nearly impossible for doctors and even large medical organizations to make sense of what the best and latest information is saying.