Government
Improving Transferability of Adversarial Examples with Input Diversity
Xie, Cihang, Zhang, Zhishuai, Wang, Jianyu, Zhou, Yuyin, Ren, Zhou, Yuille, Alan
Though convolutional neural networks have achieved state-of-the-art performance on various vision tasks, they are extremely vulnerable to adversarial examples, which are obtained by adding human-imperceptible perturbations to the original images. Adversarial examples can thus be used as an useful tool to evaluate and select the most robust models in safety-critical applications. However, most of the existing adversarial attacks only achieve relatively low success rates under the challenging black-box setting, where the attackers have no knowledge of the model structure and parameters. To this end, we propose to improve the transferability of adversarial examples by creating diverse input patterns. Instead of only using the original images to generate adversarial examples, our method applies random transformations to the input images at each iteration. Extensive experiments on ImageNet show that the proposed attack method can generate adversarial examples that transfer much better to different networks than existing baselines. To further improve the transferability, we (1) integrate the recently proposed momentum method into the attack process; and (2) attack an ensemble of networks simultaneously. By evaluating our method against top defense submissions and official baselines from NIPS 2017 adversarial competition, this enhanced attack reaches an average success rate of 73.0%, which outperforms the top 1 attack submission in the NIPS competition by a large margin of 6.6%. We hope that our proposed attack strategy can serve as a benchmark for evaluating the robustness of networks to adversaries and the effectiveness of different defense methods in future. The code is public available at https://github.com/cihangxie/DI-2-FGSM.
Learning non-Gaussian Time Series using the Box-Cox Gaussian Process
A Gaussian process (GP) [1] is a prior distribution over functions with a support that includes a wide class of phenomena via the design of its mean and covariance functions, the parameters of which provide meaningful interpretation of the process at hand. Beyond regression [2], GPs have been extensively used in the last two decades for classification [3], density estimation [4], filter design [5], model identification [6] and optimisation [7]. In general terms, all these generative models have two stages: The latent process is modelled as a GP and the observation is modelled (conditional to the latent process) as a non-Gaussian variable. This class of models is referred to as GP with non-Gaussian likelihood, or as Generalised GPs. These usually consider likelihood functions from the exponential family such as the Laplace, Poisson, beta and gamma distributions [8]. A well-known example is the GP classification model, where the classes are represented by the output of an activation neuron into which a latent GP is fed. A slightly different approach to non-Gaussian models, which is not constrained to the exponential family, is the warped GP (WGP, [9]). The WGP models non-Gaussian data by assuming that there is a transformation ฯ such that the observations can be passed through ฯ to yield a GP, therefore, the likelihood function of this model is not designed directly but, rather, induced by the transformation (a.k.a.
Security Analysis and Enhancement of Model Compressed Deep Learning Systems under Adversarial Attacks
Liu, Qi, Liu, Tao, Liu, Zihao, Wang, Yanzhi, Jin, Yier, Wen, Wujie
DNN is presenting human-level performance for many complex intelligent tasks in real-world applications. However, it also introduces ever-increasing security concerns. For example, the emerging adversarial attacks indicate that even very small and often imperceptible adversarial input perturbations can easily mislead the cognitive function of deep learning systems (DLS). Existing DNN adversarial studies are narrowly performed on the ideal software-level DNN models with a focus on single uncertainty factor, i.e. input perturbations, however, the impact of DNN model reshaping on adversarial attacks, which is introduced by various hardware-favorable techniques such as hash-based weight compression during modern DNN hardware implementation, has never been discussed. In this work, we for the first time investigate the multi-factor adversarial attack problem in practical model optimized deep learning systems by jointly considering the DNN model-reshaping (e.g. HashNet based deep compression) and the input perturbations. We first augment adversarial example generating method dedicated to the compressed DNN models by incorporating the software-based approaches and mathematical modeled DNN reshaping. We then conduct a comprehensive robustness and vulnerability analysis of deep compressed DNN models under derived adversarial attacks. A defense technique named "gradient inhibition" is further developed to ease the generating of adversarial examples thus to effectively mitigate adversarial attacks towards both software and hardware-oriented DNNs. Simulation results show that "gradient inhibition" can decrease the average success rate of adversarial attacks from 87.99% to 4.77% (from 86.74% to 4.64%) on MNIST (CIFAR-10) benchmark with marginal accuracy degradation across various DNNs.
Randomer Forests
Tomita, Tyler M., Browne, James, Shen, Cencheng, Priebe, Carey E., Burns, Randal, Maggioni, Mauro, Vogelstein, Joshua T.
Ensemble methods -- particularly those based on decision trees -- have recently demonstrated superior performance in a variety of machine learning settings. Specifically, Random Forest (RF) was found to outperform >100 other methods in several manuscripts, and gradient boosting trees have been a crucial component of several recent Kaggle competition victories. Building off these successes and recent advances in sparse learning and random matrix theory, we propose a novel ensemble tree method called "Randomer Forest" (RerF). The key intuition behind RerF is that we can use sparse linear combinations at each decision node rather than just one feature (as in RF) or all of them (as in Rotation Forests). RerF significantly outperforms other methods on a standard benchmark suite containing 105 problems with varying dimension, sample size, and number of classes. Moreover, we provide an implementation that scales as or more efficiently than other available packages. Via a combination of basic principles, theory, and extensive numerical experiments, we demonstrate why, when, and how RerF achieves its performance properties.
The healing power of AI
Artificial intelligence originally aspired to replace doctors. Researchers imagined robots that could ask you questions, run the answers through an algorithm that would learn with experience and tell whether you had the flu or a cold. However, those promises largely failed, as artificial intelligent algorithms were too rudimentary to perform those functions. Particularly tricky was the variability between people, which caused basic machine learning algorithms to miss the patterns. Eventually though, a subset of AI called deep learning became sensitive enough to recognize speech from voice data.
Trump's talk with video game execs recalls Senate's concern that rock was possible root of teen problems
In the wake of the Parkland school shooting, President Trump is meeting with video game executives and members of congress to discuss the role of simulated violence and the impact on America's youth. They called it the "Filthy 15." Fifteen songs from 15 bands or artists that the Parents Music Resource Center found offensive due to explicit content. The PMRC's leaders were Susan Baker, wife of then-Treasury Secretary James Baker, and Tipper Gore. Gore was wife of then-Sen. The acts in question were Prince, AC/DC, Cyndi Lauper, Madonna, Def Leppard, Motley Crue, Black Sabbath, Sheena Easton and Vanity.
Cabinet to investigate societal impact of new technologies
Robotics, artificial intelligence, virtual and augmented reality and other new technologies can both strengthen and undermine key values such as privacy, non-discrimination, human dignity (such as when care tasks are carried out by robots), human rights and the right to due process, says the Rathenau Institute. At the same time, these technologies offer new social and commercial opportunities, potential gains in efficiency and quality, and educational benefits. The government has therefore decided to commission more research into the societal effects of technological developments and to establish an inter-ministerial working group to study this issue. And the budget of the Data Protection Authority will be almost doubled. The cabinet made these decisions following proposals put forward jointly by Minister of the Interior and Kingdom Relations Kajsa Ollongren and her ministry's state secretary Raymond Knops, State Secretary for Economic Affairs and Climate Policy Mona Keijzer, Minister of Justice and Security Ferdinand Grapperhaus and Minister for Legal Protection Sander Dekker.
Future of Humanity Institute
This report examines the intersection of two subjects, China and artificial intelligence, both of which are already difficult enough to comprehend on their own. It provides context for China's AI strategy with respect to past science and technology plans, and it also connects the consistent and new features of China's AI approach to the drivers of AI development (e.g. In addition, it benchmarks China's current AI capabilities by developing a novel index to measure any country's AI potential and highlights the potential implications of China's AI dream for issues of AI safety, national security, economic development, and social governance. The author, Jeffrey Ding, writes, "The hope is that this report can serve as a foundational document for further policy discussion and research on the topic of China's approach to AI." The report draws from the author's translations of Chinese texts on AI policy, a compilation of metrics on China's AI capabilities compared to other countries, and conversations with those who have consulted with Chinese companies and institutions involved in shaping the AI scene. To access the report, click here.
A new fiscal policy for a world of accelerated change and artificial intelligence
In the decade since the Great Recession, governments have used fiscal policy to prop up flagging domestic demand. This response has been considered appropriate because the shock was seen as temporary. But this attention to demand-side weaknesses may have distracted governments from attending to supply-side gaps that have been widening with the acceleration of technological change and artificial intelligence. Policymakers should start paying more attention to what's called structural fiscal policies, that is, changes in both public spending and tax collection to aid the expansion of the productive potential of economies. As laborsaving technologies flood the market, delays in doing this could mean that workers pay a stiff price, while consumers do not realize many of the benefits.