EAGER: Invisible Shield: Can Compression Harden Deep Neural Networks Universally Against Adversarial Attacks?

EAGER:隐形盾牌:压缩能否使深层神经网络普遍抵御对抗性攻击?

基本信息

  • 批准号:
    2011260
  • 负责人:
  • 金额:
    $ 14.92万
  • 依托单位:
  • 依托单位国家:
    美国
  • 项目类别:
    Standard Grant
  • 财政年份:
    2019
  • 资助国家:
    美国
  • 起止时间:
    2019-11-07 至 2021-08-31
  • 项目状态:
    已结题

项目摘要

Deep neural networks (DNNs) are finding applications in wide-ranging applications such as image recognition, medical diagnosis and self-driving cars. However, DNNs suffer from a security threat: decisions can be misled by adversarial inputs crafted by adding human-imperceptible perturbations into normal inputs during training of DNN model. Defending against adversarial attacks is challenging due to multiple attack vectors, unknown adversary's strategies and cost. This project investigates a compression/decompression-based defense strategy to protect DNNs against any attack, with low cost and high accuracy. The project aims to create a new paradigm of safeguarding DNNs from a radically different perspective by using signal compression with a focus on integrating defenses into compression of the inputs and DNN models. The research tasks include: (i) developing defensive compression for visual/audio inputs to maximize defense efficiency without compromising testing accuracy; (ii) developing defensive model compression, and novel gradient masking/obfuscating methods without involving retraining, to universally harden DNN models; and (iii) conducting attack-defense evaluations through algorithm-level simulation and live platform experimentation.Any success from this EAGER project will be useful to research community interested in deep learning, hardware- and cyber- security, and multimedia. This project enhances economic opportunities by promoting wider applications of deep learning into realistic systems, and gives special attention to educating women and students from traditionally under-represented/under-served groups in Florida International University (FIU).The project repository will be stored on a publicly accessible server at FIU (http://web.eng.fiu.edu/wwen/). Data will be maintained for at least 5 years after the project period.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
深度神经网络(DNN)正在寻找在大型应用中的应用,例如图像识别,医疗诊断和自动驾驶汽车。但是,DNN遭受了安全威胁的困扰:通过在训练DNN模型期间,通过将人类侵蚀性的扰动添加到正常输入中,可以通过将人类侵蚀性扰动添加到正常输入中而误导决策。由于多个攻击媒介,未知的对手的策略和成本,防御对抗攻击的防御是具有挑战性的。该项目调查了一种基于压缩/减压的防御策略,以保护DNN免受任何攻击,较低的成本和高精度。该项目旨在通过使用信号压缩来从根本不同的角度创建一个新的保护DNN范式,重点是将防御范围集成到输入和DNN模型的压缩中。研究任务包括:(i)为视觉/音频输入开发防御性压缩,以最大程度地提高防御效率,而不会损害测试精度; (ii)开发防御模型压缩,以及新颖的梯度掩盖/混淆方法,而无需涉及重新训练,以普遍硬化DNN模型; (iii)通过算法级别的仿真和实时平台实验进行攻击防御评估。该渴望项目的成功对对深度学习,硬件和网络安全以及多媒体感兴趣的研究社区都有用。该项目通过促进深度学习在现实系统中的广泛应用来增强经济机会,并特别关注佛罗里达国际大学(FIU)传统上代表性不足/服务不足的群体的妇女和学生。该项目存储库将存储在FIU的公共访问服务器上(http://web.eng.eng.eng.fiu.fiu.edu.edu.edu.edu/wewween/wewwesn/- 该奖项反映了NSF的法定任务,并被认为是值得通过基金会的知识分子优点和更广泛的审查标准来评估,这将在项目期间结束后至少维持5年。

项目成果

期刊论文数量(7)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)
Efficient Implementation of Finite Field Arithmetic for Binary Ring-LWE Post-Quantum Cryptography Through a Novel Lookup-Table-Like Method
通过新颖的类查找表方法有效实现二元环 LWE 后量子密码学的有限域算法
Model Compression Hardens Deep Neural Networks: A New Perspective to Prevent Adversarial Attacks
An Image Enhancing Pattern-based Sparsity for Real-time Inference on Mobile Devices
  • DOI:
    10.1007/978-3-030-58601-0_37
  • 发表时间:
    2020-01
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Xiaolong Ma;Wei Niu;Tianyun Zhang;Sijia Liu;Fu-Ming Guo;Sheng Lin;Hongjia Li;Xiang Chen;Jian Tang;Kaisheng Ma;Bin Ren;Yanzhi Wang
  • 通讯作者:
    Xiaolong Ma;Wei Niu;Tianyun Zhang;Sijia Liu;Fu-Ming Guo;Sheng Lin;Hongjia Li;Xiang Chen;Jian Tang;Kaisheng Ma;Bin Ren;Yanzhi Wang
StegoNet: Turn Deep Neural Network into a Stegomalware
Stealing Your Data from Compressed Machine Learning Models
从压缩的机器学习模型中窃取数据
{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

数据更新时间:{{ journalArticles.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ monograph.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ sciAawards.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ conferencePapers.updateTime }}

{{ item.title }}
  • 作者:
    {{ item.author }}

数据更新时间:{{ patent.updateTime }}

Wujie Wen其他文献

EFENDING DNN A DVERSARIAL A TTACKS WITH P RUNING AND L OGITS A UGMENTATION
通过剪枝和逻辑增强来防御 DNN 对抗攻击
  • DOI:
  • 发表时间:
    2018
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Shaokai Ye;Siyue Wang;Xiao Wang;Bo Yuan;Wujie Wen;X. Lin
  • 通讯作者:
    X. Lin
AdaPI: Facilitating DNN Model Adaptivity for Efficient Private Inference in Edge Computing
AdaPI:促进 DNN 模型适应性,以实现边缘计算中的高效私有推理
  • DOI:
  • 发表时间:
    2024
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Tong Zhou;Jiahui Zhao;Yukui Luo;Xi Xie;Wujie Wen;Caiwen Ding;Xiaolin Xu
  • 通讯作者:
    Xiaolin Xu
FlexLevel NAND Flash Storage System Design to Reduce LDPC Latency
FlexLevel NAND 闪存存储系统设计可减少 LDPC 延迟
Deep-evasion: Turn deep neural network into evasive self-contained cyber-physical malware: poster
深度规避:将深度神经网络变成规避的独立网络物理恶意软件:海报
Error Characterization and Correction Techniques for Reliable STT-RAM Designs
  • DOI:
  • 发表时间:
    2015-09
  • 期刊:
  • 影响因子:
    0
  • 作者:
    Wujie Wen
  • 通讯作者:
    Wujie Wen

Wujie Wen的其他文献

{{ item.title }}
{{ item.translation_title }}
  • DOI:
    {{ item.doi }}
  • 发表时间:
    {{ item.publish_year }}
  • 期刊:
  • 影响因子:
    {{ item.factor }}
  • 作者:
    {{ item.authors }}
  • 通讯作者:
    {{ item.author }}

{{ truncateString('Wujie Wen', 18)}}的其他基金

CAREER: Dependable and Secure Machine Learning Acceleration from Untrusted Hardware
职业:来自不受信任的硬件的可靠且安全的机器学习加速
  • 批准号:
    2238873
  • 财政年份:
    2023
  • 资助金额:
    $ 14.92万
  • 项目类别:
    Continuing Grant
SPX: Collaborative Research: Scalable Neural Network Paradigms to Address Variability in Emerging Device based Platforms for Large Scale Neuromorphic Computing
SPX:协作研究:可扩展神经网络范式,以解决基于新兴设备的大规模神经形态计算平台的可变性
  • 批准号:
    2401544
  • 财政年份:
    2023
  • 资助金额:
    $ 14.92万
  • 项目类别:
    Standard Grant
Collaborative Research: SaTC: CORE: Medium: Accelerating Privacy-Preserving Machine Learning as a Service: From Algorithm to Hardware
协作研究:SaTC:核心:中:加速保护隐私的机器学习即服务:从算法到硬件
  • 批准号:
    2247891
  • 财政年份:
    2023
  • 资助金额:
    $ 14.92万
  • 项目类别:
    Continuing Grant
CAREER: Dependable and Secure Machine Learning Acceleration from Untrusted Hardware
职业:来自不受信任的硬件的可靠且安全的机器学习加速
  • 批准号:
    2349538
  • 财政年份:
    2023
  • 资助金额:
    $ 14.92万
  • 项目类别:
    Continuing Grant
Collaborative Research: SaTC: CORE: Medium: Accelerating Privacy-Preserving Machine Learning as a Service: From Algorithm to Hardware
协作研究:SaTC:核心:中:加速保护隐私的机器学习即服务:从算法到硬件
  • 批准号:
    2348733
  • 财政年份:
    2023
  • 资助金额:
    $ 14.92万
  • 项目类别:
    Continuing Grant
SHF: Small: Collaborative Research: Retraining-free Concurrent Test and Diagnosis in Emerging Neural Network Accelerators
SHF:小型:协作研究:新兴神经网络加速器中的免再训练并发测试和诊断
  • 批准号:
    2011236
  • 财政年份:
    2019
  • 资助金额:
    $ 14.92万
  • 项目类别:
    Standard Grant
SPX: Collaborative Research: Scalable Neural Network Paradigms to Address Variability in Emerging Device based Platforms for Large Scale Neuromorphic Computing
SPX:协作研究:可扩展神经网络范式,以解决基于新兴设备的大规模神经形态计算平台的可变性
  • 批准号:
    1919182
  • 财政年份:
    2019
  • 资助金额:
    $ 14.92万
  • 项目类别:
    Standard Grant
SPX: Collaborative Research: Scalable Neural Network Paradigms to Address Variability in Emerging Device based Platforms for Large Scale Neuromorphic Computing
SPX:协作研究:可扩展神经网络范式,以解决基于新兴设备的大规模神经形态计算平台的可变性
  • 批准号:
    2006748
  • 财政年份:
    2019
  • 资助金额:
    $ 14.92万
  • 项目类别:
    Standard Grant
SHF: Small: Collaborative Research: Retraining-free Concurrent Test and Diagnosis in Emerging Neural Network Accelerators
SHF:小型:协作研究:新兴神经网络加速器中的免再训练并发测试和诊断
  • 批准号:
    1910022
  • 财政年份:
    2019
  • 资助金额:
    $ 14.92万
  • 项目类别:
    Standard Grant
EAGER: Invisible Shield: Can Compression Harden Deep Neural Networks Universally Against Adversarial Attacks?
EAGER:隐形盾牌:压缩能否使深层神经网络普遍抵御对抗性攻击?
  • 批准号:
    1840813
  • 财政年份:
    2018
  • 资助金额:
    $ 14.92万
  • 项目类别:
    Standard Grant

相似国自然基金

计算压裂泵头体寿命的“无形边界”新方法
  • 批准号:
  • 批准年份:
    2021
  • 资助金额:
    58 万元
  • 项目类别:
    面上项目
计算压裂泵头体寿命的“无形边界”新方法
  • 批准号:
    52174018
  • 批准年份:
    2021
  • 资助金额:
    58.00 万元
  • 项目类别:
    面上项目
控股股东股权质押对公司无形资本的影响研究
  • 批准号:
    72072147
  • 批准年份:
    2020
  • 资助金额:
    48 万元
  • 项目类别:
    面上项目
嗜吞噬细胞无形体劫持宿主细胞分泌途径机制的阐明
  • 批准号:
  • 批准年份:
    2020
  • 资助金额:
    35 万元
  • 项目类别:
    地区科学基金项目
化无形为有形:基于机器学习方法的无形资产测度与定价研究
  • 批准号:
  • 批准年份:
    2020
  • 资助金额:
    24 万元
  • 项目类别:
    青年科学基金项目

相似海外基金

Invisible diversity of reef-building corals: visualization, estimation of causes and prediction of the future
造礁珊瑚的无形多样性:可视化、原因估计和未来预测
  • 批准号:
    23H00529
  • 财政年份:
    2023
  • 资助金额:
    $ 14.92万
  • 项目类别:
    Grant-in-Aid for Scientific Research (A)
Invisible Labour: Women's Experimental Art in East-Central Europe, 1970-1989
无形的劳动:中东欧女性的实验艺术,1970-1989
  • 批准号:
    2882025
  • 财政年份:
    2023
  • 资助金额:
    $ 14.92万
  • 项目类别:
    Studentship
Practical Research to Promote Self-Understanding in Children with Invisible Disabilities; Focusing on Low Vision Children
促进隐形残疾儿童自我理解的实践研究;
  • 批准号:
    23K02568
  • 财政年份:
    2023
  • 资助金额:
    $ 14.92万
  • 项目类别:
    Grant-in-Aid for Scientific Research (C)
Development of 320x256 pixel metamaterial infrared image sensors for visualizing invisible gases
开发用于可视化不可见气体的 320x256 像素超材料红外图像传感器
  • 批准号:
    23H01883
  • 财政年份:
    2023
  • 资助金额:
    $ 14.92万
  • 项目类别:
    Grant-in-Aid for Scientific Research (B)
CRII: RI: Modeling and Understanding the Invisible World in Thermal Modality
CRII:RI:用热模态建模和理解无形世界
  • 批准号:
    2334246
  • 财政年份:
    2023
  • 资助金额:
    $ 14.92万
  • 项目类别:
    Standard Grant
{{ showInfoDetail.title }}

作者:{{ showInfoDetail.author }}

知道了