Adversarial Text Program for AI Analysis Resistance

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Digital text documents transmitted through non-secure channels are vulnerable to automated analysis by unauthorized AI systems, lacking effective mechanisms to preserve semantic meaning while thwarting AI-based text analytics.

Innovation Solution

An adversarial text program identifies critical text portions impacting AI model predictions, generates semantically equivalent text to reduce confidence scores, and suggests modifications to enhance text robustness against AI analysis while maintaining original meaning.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If digital text documents are transmitted through non-secure channels, then communication efficiency and accessibility are improved, but the text contents become vulnerable to automated analysis by unauthorized third-party AI systems

Engineering Contradiction:
Improvecommunication efficiencyVSAvoidvulnerability to automated analysis
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system applies preliminary anti-action by proactively modifying the text document before transmission to include adversarial perturbations. These perturbations are designed to preemptively counteract AI-based analysis by reducing the confidence scores of unauthorized AI systems, while maintaining the original semantic meaning and human readability of the document.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The system employs parameter changes by subtly altering text parameters such as word choices, sentence structures, or character-level features in ways that are imperceptible to human readers but significantly impact AI model predictions. These parameter modifications reduce the effectiveness of automated text analysis while preserving the document's intended meaning.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If text modifications are made to obstruct AI analysis, then protection against automated analysis is improved, but the semantic meaning of the original text may be altered

Engineering Contradiction:
Improveprotection effectivenessVSAvoidsemantic meaning preservation
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system applies local quality by making targeted, localized modifications to specific portions of the text that are most susceptible to AI analysis. These modifications are carefully selected to maintain the overall semantic integrity of the document while providing effective protection against automated analysis in critical areas.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system uses copying by generating semantically equivalent alternative text that preserves the original meaning while having different linguistic characteristics that reduce AI analysis effectiveness. Multiple semantically equivalent versions can be created to maintain meaning while obstructing automated analysis.

Inventive Principle:
Principle #26Copying

3Reliability

If adversarial text modifications are applied, then confidence scores of AI predictions are reduced, but the complexity of the text processing system increases

Engineering Contradiction:
ImproveAI analysis resistanceVSAvoidtext processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system applies segmentation by dividing the text processing into distinct modular components: analysis component, modification component, and verification component. This segmentation allows each module to perform its specific function independently, managing complexity while achieving effective adversarial text protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system employs feedback mechanisms to iteratively evaluate the effectiveness of text modifications and adjust them accordingly. The feedback loop monitors AI confidence scores and refines the adversarial modifications to maximize protection while minimizing unnecessary complexity in the processing system.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11562139B2Text data protection against automated analysis
Publication Date: 2023.01.24 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11562139B2 patent drawing
  • US11562139B2 patent drawing
  • US11562139B2 patent drawing

AI summary

A method, computer system, and a computer program product for text data protection is provided. The present invention may include receiving a text data. The present invention may also include identifying a portion of the received text data having a highest impact on a first confidence score associated with a target model prediction. The present invention may further include generating at least one semantically equivalent text relative to the identified portion of the received text data. The present invention may also include determining that the generated at least one semantically equivalent text produces a second confidence score associated with the target model prediction that is less than the first confidence score associated with the target model prediction. The present invention may further include generating a prompt to suggest modifying the identified portion of the received text data using the generated at least one semantically equivalent text.