Upgrade & Secure Your Future with DevOps, SRE, DevSecOps, MLOps!

We spend hours on Instagram and YouTube and waste money on coffee and fast food, but won’t spend 30 minutes a day learning skills to boost our careers.
Master in DevOps, SRE, DevSecOps & MLOps!

Learn from Guru Rajesh Kumar and double your salary in just one year.

Get Started Now!

Google’s AI detects adversarial attacks against image classifiers

Source: venturebeat.com

Defenses against adversarial attacks, which in the context of AI refer to techniques that fool models through malicious input, are increasingly being broken by “defense-aware” attacks. In fact, most state-of-the-art methods claiming to detect adversarial attacks have been counteracted shortly after their publication. To break the cycle, researchers at the University of California, San Diego and Google Brain, including Turing Award winner Geoffrey Hinton, recently described in a preprint paper an approach that deflects attacks in the computer vision domain. Their framework either detects attacks accurately or, for undetected attacks, pressures the attackers to produce images that resemble the target class of images.

The proposed architecture comprises (1) a network that classifies various input images from a data set and (2) a network that reconstructs the inputs conditioned on parameters of a predicted capsule. Several years ago, Hinton and several students devised an architecture called CapsNet, a discriminately trained and multilayer AI system. It and other capsule networks make sense of objects in images by interpreting sets of their parts geometrically. Sets of mathematical functions (capsules) responsible for analyzing various object properties (like position, size, and hue) are tacked onto a type of AI model often used to analyze visuals. Several of the capsules’ predictions are reused to form representations of parts, and since these representations remain intact throughout analyses, capsule systems can leverage them to identify objects even when the positions of parts are swapped or transformed.

Another unique thing about capsule systems? They route with attention. As with all deep neural networks, capsules’ functions are arranged in interconnected layers that transmit “signals” from input data and slowly adjust the synaptic strength — weights — of each connection. (That’s how they extract features and learn to make predictions.) But where capsules are concerned, the weightings are calculated dynamically according to previous-layer functions’ ability to predict the next layer’s outputs.

Three reconstruction-based detection methods are used together by the capsule network to detect standard adversarial attacks. The first — Global Threshold Detector — exploits the fact that when input images are adversarially perturbed, the classification given to the input may be incorrect, but the reconstruction is often blurry. Local Best Detector identifies “clean” images from their reconstruction error; when the input is a clean image, the reconstruction error from the winning capsule is smaller than that of the losing capsules. As for the last technique, called Cycle-Consistency Detector, it flags inputs as adversarial examples if they aren’t classified in the same class as the reconstruction of the winning capsule.

The team reports that in experiments they were able to detect standard adversarial attacks based on three different distance metrics with a low False Positive Rate on SVHN and CIFAR-10. “A large percentage of the undetected attacks are deflected by our model to resemble the adversarial target class [and] stop being adversarial any more,” they wrote. “These attack images can no longer be called ‘adversarial’ because our network classifies them the same way as humans do.”

Related Posts

How to Choose the Best Free Blogging Platform Easily

INTRODUCTION In an era dominated by short-form videos and fast-paced social feeds, long-form content remains the bedrock of deep connections, authority, and organic search traffic. Blogging continues Read More

Read More

The Rise of Quiet Publishing: How Calm Writing Tools Change Content Creation

INTRODUCTION In an era dominated by fast-moving social media feeds and fleeting algorithmic attention, long-form writing remains the bedrock of deep ideas, authentic storytelling, and professional credibility. Read More

Read More

Top 10 Federated Learning Platforms

Introduction Federated Learning Platforms enable organizations to collaboratively train AI and machine learning models across multiple decentralized data sources without moving or exposing raw data. In plain Read More

Read More

Comparing Heart Surgery Options, Costs, and Leading Hospitals

INTRODUCTION When dealing with complex cardiovascular conditions, choosing the right medical institution is one of the most critical health decisions you will ever make. The quality of Read More

Read More

Top 10 AI ESG Data Extraction Tools: Features, Pros, Cons & Comparison

Introduction AI ESG Data Extraction Tools use artificial intelligence, machine learning, natural language processing (NLP), document intelligence, and automation technologies to collect, extract, classify, and organize environmental, Read More

Read More

Top 10 AI Carbon Accounting Automation Tools: Features, Pros, Cons & Comparison

Introduction AI Carbon Accounting Automation Tools use artificial intelligence, machine learning, natural language processing, data automation, and sustainability analytics to help organizations measure, track, calculate, and report Read More

Read More
Subscribe
Notify of
guest
0 Comments
Oldest
Newest Most Voted
0
Would love your thoughts, please comment.x
()
x