서브메뉴
검색
New Perspectives on Adversarially Robust Machine Learning Systems
New Perspectives on Adversarially Robust Machine Learning Systems
상세정보
- 자료유형
- 학위논문 서양
- 최종처리일시
- 20250211151009
- ISBN
- 9798384447146
- DDC
- 004
- 서명/저자
- New Perspectives on Adversarially Robust Machine Learning Systems
- 발행사항
- [Sl] : University of California, Berkeley, 2024
- 발행사항
- Ann Arbor : ProQuest Dissertations & Theses, 2024
- 형태사항
- 170 p
- 주기사항
- Source: Dissertations Abstracts International, Volume: 86-03, Section: B.
- 주기사항
- Advisor: Wagner, David.
- 학위논문주기
- Thesis (Ph.D.)--University of California, Berkeley, 2024.
- 초록/해제
- 요약Security has always been at the core of computer systems, from hardware to software, and network. Through their recent advancement, machine learning and artificial intelligence have found themselves an essential space in this software stack. This shiny new addition pushes the boundary of computer programs beyond what humans have imagined, from multi-media editing to intelligent personal assistants. Unfortunately, it is also becoming the weakest security link in this stack. One of the most alarming concerns of these ML and in particular, deep learning systems is the lack of robustness, a phenomenon termed adversarial examples.This Ph.D. dissertation presents an in-depth investigation into the adversarial robustness of deep learning systems with the goal of building a practical defense against these attacks. It consists of three main parts. The first focuses on improving the state-of-the-art defense, adversarial training, by means of high-quality data and supervision. We show that fine-grained supervision during training can increase the robustness of neural networks on an object classification task. In the second part, we take on a broader and more practical perspective on the defenses. We argue that the model-level defense, i.e., building more adversarially robust models, alone is necessary but not sufficient to achieve a secure system in practice. Instead, we propose a new model-level defense that when combined with the existing system-level defense, can provide a practical solution to an important and realistic type of attack. While our method does not completely stop all adversarial attacks, it shows that building a "reasonably" secure ML system may be within closer reach than the community largely believes. In the final part of this dissertation, we demonstrate a novel practical attack algorithm against a real-world large language model API with little cost and no human intervention. Identifying vulnerabilities is the first step to solving them. We hope that the insights developed in this dissertation will provide new perspectives to the research community and play an instrumental role in building a secure system against adversarial examples.
- 일반주제명
- Computer science
- 일반주제명
- Information technology
- 키워드
- Deep learning
- 키워드
- Machine learning
- 기타저자
- University of California, Berkeley Computer Science
- 기본자료저록
- Dissertations Abstracts International. 86-03B.
- 전자적 위치 및 접속
- 로그인 후 원문을 볼 수 있습니다.
MARC
008250123s2024 us c eng d■001000017160387
■00520250211151009
■006m o d
■007cr#unu||||||||
■020 ▼a9798384447146
■035 ▼a(MiAaPQ)AAI30995220
■040 ▼aMiAaPQ▼cMiAaPQ
■0820 ▼a004
■1001 ▼aSitawarin, Chawin.
■24510▼aNew Perspectives on Adversarially Robust Machine Learning Systems
■260 ▼a[Sl]▼bUniversity of California, Berkeley▼c2024
■260 1▼aAnn Arbor▼bProQuest Dissertations & Theses▼c2024
■300 ▼a170 p
■500 ▼aSource: Dissertations Abstracts International, Volume: 86-03, Section: B.
■500 ▼aAdvisor: Wagner, David.
■5021 ▼aThesis (Ph.D.)--University of California, Berkeley, 2024.
■520 ▼aSecurity has always been at the core of computer systems, from hardware to software, and network. Through their recent advancement, machine learning and artificial intelligence have found themselves an essential space in this software stack. This shiny new addition pushes the boundary of computer programs beyond what humans have imagined, from multi-media editing to intelligent personal assistants. Unfortunately, it is also becoming the weakest security link in this stack. One of the most alarming concerns of these ML and in particular, deep learning systems is the lack of robustness, a phenomenon termed adversarial examples.This Ph.D. dissertation presents an in-depth investigation into the adversarial robustness of deep learning systems with the goal of building a practical defense against these attacks. It consists of three main parts. The first focuses on improving the state-of-the-art defense, adversarial training, by means of high-quality data and supervision. We show that fine-grained supervision during training can increase the robustness of neural networks on an object classification task. In the second part, we take on a broader and more practical perspective on the defenses. We argue that the model-level defense, i.e., building more adversarially robust models, alone is necessary but not sufficient to achieve a secure system in practice. Instead, we propose a new model-level defense that when combined with the existing system-level defense, can provide a practical solution to an important and realistic type of attack. While our method does not completely stop all adversarial attacks, it shows that building a "reasonably" secure ML system may be within closer reach than the community largely believes. In the final part of this dissertation, we demonstrate a novel practical attack algorithm against a real-world large language model API with little cost and no human intervention. Identifying vulnerabilities is the first step to solving them. We hope that the insights developed in this dissertation will provide new perspectives to the research community and play an instrumental role in building a secure system against adversarial examples.
■590 ▼aSchool code: 0028.
■650 4▼aComputer science
■650 4▼aInformation technology
■653 ▼aAdversarial examples
■653 ▼aAdversarial robustness
■653 ▼aDeep learning
■653 ▼aMachine learning
■653 ▼aSystem-level defense
■690 ▼a0984
■690 ▼a0489
■690 ▼a0800
■71020▼aUniversity of California, Berkeley▼bComputer Science.
■7730 ▼tDissertations Abstracts International▼g86-03B.
■790 ▼a0028
■791 ▼aPh.D.
■792 ▼a2024
■793 ▼aEnglish
■85640▼uhttp://www.riss.kr/pdu/ddodLink.do?id=T17160387▼nKERIS▼z이 자료의 원문은 한국교육학술정보원에서 제공합니다.


