Goto

Collaborating Authors

 Government


Resisting Adversarial Attacks using Gaussian Mixture Variational Autoencoders

arXiv.org Machine Learning

Susceptibility of deep neural networks to adversarial attacks poses a major theoretical and practical challenge. All efforts to harden classifiers against such attacks have seen limited success. Two distinct categories of samples to which deep networks are vulnerable, "adversarial samples" and "fooling samples", have been tackled separately so far due to the difficulty posed when considered together. In this work, we show how one can address them both under one unified framework. We tie a discriminative model with a generative model, rendering the adversarial objective to entail a conflict. Our model has the form of a variational autoencoder, with a Gaussian mixture prior on the latent vector. Each mixture component of the prior distribution corresponds to one of the classes in the data. This enables us to perform selective classification, leading to the rejection of adversarial samples instead of misclassification. Our method inherently provides a way of learning a selective classifier in a semi-supervised scenario as well, which can resist adversarial attacks. We also show how one can reclassify the rejected adversarial samples.


PeerNets: Exploiting Peer Wisdom Against Adversarial Attacks

arXiv.org Machine Learning

Deep learning systems have become ubiquitous in many aspects of our lives. Unfortunately, it has been shown that such systems are vulnerable to adversarial attacks, making them prone to potential unlawful and harmful uses. Designing deep neural networks that are robust to adversarial attacks is a fundamental step in making such systems safer and deployable in a broader variety of applications (e.g., autonomous driving), but more importantly is a necessary step to design novel and more advanced architectures built on new computational paradigms rather than marginally modifying existing ones. In this paper we introduce PeerNets, a novel family of convolutional networks alternating classical Euclidean convolutions with graph convolutions to harness information from a graph of peer samples. This results in a form of non-local forward propagation in the model, where latent features are conditioned on the global structure induced by the data graph, that is up to 3 more robust to a variety of white-and black-box adversarial attacks compared to conventional architectures with almost no drop in accuracy.


Defending Against Model Stealing Attacks Using Deceptive Perturbations

arXiv.org Machine Learning

Machine learning models are vulnerable to simple model stealing attacks if the adversary can obtain output labels for chosen inputs. To protect against these attacks, it has been proposed to limit the information provided to the adversary by omitting probability scores, significantly impacting the utility of the provided service. In this work, we illustrate how a service provider can still provide useful, albeit misleading, class probability information, while significantly limiting the success of the attack. Our defense forces the adversary to discard the class probabilities, requiring significantly more queries before they can train a model with comparable performance. We evaluate several attack strategies, model architectures, and hyperparameters under varying adversarial models, and evaluate the efficacy of our defense against the strongest adversary. Finally, we quantify the amount of noise injected into the class probabilities to mesure the loss in utility, e.g., adding 1.74 nats per query on CIFAR-10 and 3.27 on MNIST. Our extensive evaluation shows our defense can degrade the accuracy of the stolen model at least 20%, or require 4x more queries while keeping the accuracy of the protected model almost intact.


Analysis of Fast Structured Dictionary Learning

arXiv.org Machine Learning

Sparsity-based models and techniques have been exploited in many signal processing and imaging applications. Data-driven methods based on dictionary and transform learning enable learning rich image features from data, and can outperform analytical models. In particular, alternating optimization algorithms for dictionary learning have been popular. In this work, we focus on alternating minimization for a specific structured unitary operator learning problem, and provide a convergence analysis. While the algorithm converges to the critical points of the problem generally, our analysis establishes under mild assumptions, the local linear convergence of the algorithm to the underlying generating model of the data. Analysis and numerical simulations show that our assumptions hold well for standard probabilistic data models. In practice, the algorithm is robust to initialization.


Greedy Attack and Gumbel Attack: Generating Adversarial Examples for Discrete Data

arXiv.org Machine Learning

Robustness to adversarial perturbation has become an extremely important criterion for applications of machine learning in security-sensitive domains such as spam detection [25], fraud detection [6], criminal justice [3], malware detection [13], and financial markets [27]. Systematic methods for generating adversarial examples by small perturbations of original input data, also known as "attack," have been developed to operationalize this criterion and to drive the development of more robust learning systems [4, 26, 7]. Most of the work in this area has focused on differentiable models with continuous input spaces [26, 7, 14, 14]. In this setting, the proposed attack strategies add a gradient-based perturbation to the original input. It has been shown that such perturbations can result in a dramatic decrease in the predictive accuracy of the model. Thus this line of research has demonstrated the vulnerability of deep neural networks to adversarial examples in tasks like image classification and speech recognition. We focus instead on adversarial attacks on models with discrete input data, such as text data, where each feature of an input sample has a categorical domain. While gradient-based approaches are not directly applicable to this setting, variations of gradient-based approaches have been shown effective in differentiable models. For example, Li et al. [15] proposed to locate the top features with the largest gradient magnitude of their embedding, and Papernot et al. [20] proposed to modify randomly selected features of an input through perturbing each feature by signs of the gradient, and project them onto the closest vector in the embedding space.


Trump Crony Proves Widespread Voter Fraud Doesn't Exist

Slate

Did voter fraud swing New Hampshire away from Donald Trump in the 2016 election? Absolutely not, according to an exhaustive investigation conducted by the state's attorney general and secretary of state, which, counter to Trump's persistent allegations, turned up no evidence of "serious voter fraud." Instead, the inquiry provided further evidence that the tools Republicans use to detect voter fraud are fatally flawed, churning out a huge number of false positives. And while the New Hampshire investigation ultimately debunked Trump's paranoia, it came perilously close to disenfranchising thousands of lawful voters. Republicans have seized upon New Hampshire as the putative epicenter of American voter fraud for two reasons.


SOCOM needs Google's artificial intelligence -- here's why SOFREP

#artificialintelligence

Earlier this month, Google employees made a stir in Silicon Valley when a number of them chose to resign from their positions in protest after their company agreed to work with the Defense Department on a new artificial intelligence initiative. Overwhelmingly, the media presented this gesture as an ethical stand -- with tech professionals doing their part to stem the tide of Terminator robots roving a nearby battle space, making complex decisions about who lives and who dies with seemingly no human supervision. These departing Googlers, then, were heroes -- begging society to ask hard questions about what we're capable of doing and whether we should do it at all. Of course, the reality of the situation didn't quite sync up with the dramatic headlines and lofty narratives presented in petitions and Op-eds. The truth of the matter is, Project Maven is indeed a Google partnered artificial intelligence endeavor, but it never aimed to make decisions about pulling any triggers.


Trump, 'Roseanne,' Arkady Babchenko: Your Wednesday Evening Briefing

#artificialintelligence

It recently won a share of the contract for the Maven program, which uses artificial intelligence to interpret video images and could be used for drone strikes. By reviewing emails and documents and interviewing about a dozen insiders at Google, our reporters got a detailed picture of how the news fractured its work force, fueling heated staff meetings and prompting employees with moral objections to resign. Executives now face this dilemma: Proceeding with defense contracts could drive away brainy experts in artificial intelligence; rejecting such work would deprive the company of a potentially huge business.


Future Tense Newsletter: Amazon Isn't Just Tracking What's in Your Shopping Cart

Slate

Future Tense is a partnership of Slate, New America, and Arizona State University that examines emerging technologies, public policy, and society. Amazon's object and facial recognition software, which the company claims offers real-time detection across tens of millions of mugs, including "up to 100 faces in challenging crowded photos." After its launch in late 2016, Amazon Web Services started marketing the visual surveillance tool (which it dubbed "Rekognition") to law enforcement agencies around the country--including partnering directly with the police department in Orlando and a sheriff's department in Oregon. But now, as April Glaser reports, civil rights groups are pushing back. Last week, a coalition including the ACLU, Human Rights Watch, and the Council on American-Islamic Relations, sent an open letter expressing their "profound concerns" that governments could easily abuse the technology to target communities of color, undocumented immigrants, and political protestors.


For Some Hard-To-Find Tumors, Doctors See Promise In Artificial Intelligence

#artificialintelligence

A team at Johns Hopkins Medicine in Baltimore is developing a tumor-detecting algorithm for detecting pancreatic cancer. But first, they have to train computers to distinguish between organs. A team at Johns Hopkins Medicine in Baltimore is developing a tumor-detecting algorithm for detecting pancreatic cancer. But first, they have to train computers to distinguish between organs. Artificial intelligence, which is bringing us everything from self-driving cars to personalized ads on the web, is also invading the world of medicine.