본문

서브메뉴

Towards Secure and Safe AI-enabled Systems Through Optimizations
Towards Secure and Safe AI-enabled Systems Through Optimizations
Towards Secure and Safe AI-enabled Systems Through Optimizations

상세정보

자료유형  
 학위논문 서양
최종처리일시  
20250211152050
ISBN  
9798342108003
DDC  
150
저자명  
Tao, Guanhong.
서명/저자  
Towards Secure and Safe AI-enabled Systems Through Optimizations
발행사항  
[Sl] : Purdue University, 2024
발행사항  
Ann Arbor : ProQuest Dissertations & Theses, 2024
형태사항  
213 p
주기사항  
Source: Dissertations Abstracts International, Volume: 86-05, Section: B.
주기사항  
Advisor: Zhang, Xiangyu;Li, Ninghui;Xue, Yexiang;Tan, Lin.
학위논문주기  
Thesis (Ph.D.)--Purdue University, 2024.
초록/해제  
요약Artificial intelligence (AI) is increasingly integrated into critical systems across various sectors, including public surveillance, autonomous driving, and malware detection. Despite their impressive performance and promise, the security and safety of AI-enabled systems remain significant concerns. Like conventional systems that have software bugs or vulnerabilities, applications leveraging AI are also susceptible to such issues. Malicious behaviors can be intentionally injected into AI models by adversaries, creating a backdoor. These models operate normally with benign inputs but consistently misclassify samples containing an attacker-inserted trigger, known as a backdoor attack.However, backdoors can not only be injected by an attacker but may also naturally exist in normally trained models. One can find backdoor triggers in benign models that cause any inputs with the trigger to be misclassified, a phenomenon termed natural backdoors. Regardless of whether they are injected or natural, backdoors can take various forms, which increases the difficulty of identifying such vulnerabilities. This challenge is exacerbated when access to AI models is limited.This dissertation introduces an optimization-based technique that reverse-engineers trigger patterns exploited by backdoors, whether injected or natural. It formulates how backdoor triggers modify inputs down to the pixel level to approximate their potential forms. The intended changes in output predictions guide the reverse-engineering process, which involves computing the input gradient or sampling possible perturbations when model access is limited. Although various types of backdoors exist, this dissertation demonstrates that they can be effectively clustered into two categories based on their methods of input manipulation. The development of practical reverse-engineering approaches is based on this fundamental classification, leading to the successful identification of backdoor vulnerabilities in AI models.To alleviate such security threats, this dissertation introduces a novel hardening technique that enhances the robustness of models against adversary exploitation. It sheds light on the existence of backdoors, which can often be attributed to the small distance between two classes. Based on this analysis, a class distance hardening method is proposed to proactively enlarge the distance between every pair of classes in a model. This method is effective in eliminating both injected and natural backdoors in a variety of forms.This dissertation aims to highlight both existing and newly identified security and safety challenges in AI systems. It introduces novel formulations of backdoor trigger patterns and provides a fundamental understanding of backdoor vulnerabilities, paving the way for the development of safer and more secure AI systems.
일반주제명  
Success
일반주제명  
Systems science
기타저자  
Purdue University.
기본자료저록  
Dissertations Abstracts International. 86-05B.
전자적 위치 및 접속  
로그인 후 원문을 볼 수 있습니다.

MARC

 008250123s2024        us                              c    eng  d
■001000017162754
■00520250211152050
■006m          o    d                
■007cr#unu||||||||
■020    ▼a9798342108003
■035    ▼a(MiAaPQ)AAI31345378
■035    ▼a(MiAaPQ)Purdue25823644
■040    ▼aMiAaPQ▼cMiAaPQ
■0820  ▼a150
■1001  ▼aTao,  Guanhong.
■24510▼aTowards  Secure  and  Safe  AI-enabled  Systems  Through  Optimizations
■260    ▼a[Sl]▼bPurdue  University▼c2024
■260  1▼aAnn  Arbor▼bProQuest  Dissertations  &  Theses▼c2024
■300    ▼a213  p
■500    ▼aSource:  Dissertations  Abstracts  International,  Volume:  86-05,  Section:  B.
■500    ▼aAdvisor:  Zhang,  Xiangyu;Li,  Ninghui;Xue,  Yexiang;Tan,  Lin.
■5021  ▼aThesis  (Ph.D.)--Purdue  University,  2024.
■520    ▼aArtificial  intelligence  (AI)  is  increasingly  integrated  into  critical  systems  across  various  sectors,  including  public  surveillance,  autonomous  driving,  and  malware  detection.  Despite  their  impressive  performance  and  promise,  the  security  and  safety  of  AI-enabled  systems  remain  significant  concerns.  Like  conventional  systems  that  have  software  bugs  or  vulnerabilities,  applications  leveraging  AI  are  also  susceptible  to  such  issues.  Malicious  behaviors  can  be  intentionally  injected  into  AI  models  by  adversaries,  creating  a  backdoor.  These  models  operate  normally  with  benign  inputs  but  consistently  misclassify  samples  containing  an  attacker-inserted  trigger,  known  as  a  backdoor  attack.However,  backdoors  can  not  only  be  injected  by  an  attacker  but  may  also  naturally  exist  in  normally  trained  models.  One  can  find  backdoor  triggers  in  benign  models  that  cause  any  inputs  with  the  trigger  to  be  misclassified,  a  phenomenon  termed  natural  backdoors.  Regardless  of  whether  they  are  injected  or  natural,  backdoors  can  take  various  forms,  which  increases  the  difficulty  of  identifying  such  vulnerabilities.  This  challenge  is  exacerbated  when  access  to  AI  models  is  limited.This  dissertation  introduces  an  optimization-based  technique  that  reverse-engineers  trigger  patterns  exploited  by  backdoors,  whether  injected  or  natural.  It  formulates  how  backdoor  triggers  modify  inputs  down  to  the  pixel  level  to  approximate  their  potential  forms.  The  intended  changes  in  output  predictions  guide  the  reverse-engineering  process,  which  involves  computing  the  input  gradient  or  sampling  possible  perturbations  when  model  access  is  limited.  Although  various  types  of  backdoors  exist,  this  dissertation  demonstrates  that  they  can  be  effectively  clustered  into  two  categories  based  on  their  methods  of  input  manipulation.  The  development  of  practical  reverse-engineering  approaches  is  based  on  this  fundamental  classification,  leading  to  the  successful  identification  of  backdoor  vulnerabilities  in  AI  models.To  alleviate  such  security  threats,  this  dissertation  introduces  a  novel  hardening  technique  that  enhances  the  robustness  of  models  against  adversary  exploitation.  It  sheds  light  on  the  existence  of  backdoors,  which  can  often  be  attributed  to  the  small  distance  between  two  classes.  Based  on  this  analysis,  a  class  distance  hardening  method  is  proposed  to  proactively  enlarge  the  distance  between  every  pair  of  classes  in  a  model.  This  method  is  effective  in  eliminating  both  injected  and  natural  backdoors  in  a  variety  of  forms.This  dissertation  aims  to  highlight  both  existing  and  newly  identified  security  and  safety  challenges  in  AI  systems.  It  introduces  novel  formulations  of  backdoor  trigger  patterns  and  provides  a  fundamental  understanding  of  backdoor  vulnerabilities,  paving  the  way  for  the  development  of  safer  and  more  secure  AI  systems.
■590    ▼aSchool  code:  0183.
■650  4▼aSuccess
■650  4▼aSystems  science
■690    ▼a0800
■690    ▼a0790
■71020▼aPurdue  University.
■7730  ▼tDissertations  Abstracts  International▼g86-05B.
■790    ▼a0183
■791    ▼aPh.D.
■792    ▼a2024
■793    ▼aEnglish
■85640▼uhttp://www.riss.kr/pdu/ddodLink.do?id=T17162754▼nKERIS▼z이  자료의  원문은  한국교육학술정보원에서  제공합니다.

미리보기

내보내기

chatGPT토론

Ai 추천 관련 도서


    신착도서 더보기
    최근 3년간 통계입니다.

    소장정보

    • 예약
    • 소재불명신고
    • 나의폴더
    • 우선정리요청
    • 비도서대출신청
    • 야간 도서대출신청
    소장자료
    등록번호 청구기호 소장처 대출가능여부 대출정보
    TF11984 전자도서 대출가능 마이폴더 부재도서신고 비도서대출신청 야간 도서대출신청

    * 대출중인 자료에 한하여 예약이 가능합니다. 예약을 원하시면 예약버튼을 클릭하십시오.

    해당 도서를 다른 이용자가 함께 대출한 도서

    관련 인기도서

    로그인 후 이용 가능합니다.