AI Defense Module Generation for Adversarial Attack Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current machine learning methods are susceptible to adversarial attacks, leading to misclassifications and safety risks in applications like highly automated driving, as they fail to detect and counteract adversarial disturbances effectively.
Innovation Solution
A defense generator dynamically generates AI defense modules by determining a distribution function for model data, identifying statistical abnormalities in input data sets, and transforming data to filter out adversarial noise, thereby preventing attacks on AI units.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If existing defense methods are used, then protection against specific attacks is achieved, but the system cannot handle unlimited types of adversarial attacks
Solution Approach 1:
The defense system dynamically generates defense modules based on the input data characteristics. Instead of using fixed defense rules, the system adapts its defense strategy by creating customized defense modules that respond to the specific statistical properties of each input, enabling protection against unlimited attack types without proportionally increasing system complexity
Solution Approach 2:
The system performs self-analysis by determining statistical properties of its own input data and generating its own defense modules autonomously. The AI unit analyzes its input data's statistical characteristics and creates appropriate defense strategies without external intervention, allowing it to handle diverse attacks independently
2Reliability
If statistical analysis is performed on input data, then adversarial attacks can be detected, but processing time increases
Solution Approach 1:
The defense process is segmented into distinct stages: determining statistical properties of input data, comparing these properties against expected ranges, and generating defense modules based on the comparison results. This segmentation allows the system to perform comprehensive statistical analysis only when necessary, reducing overall processing time while maintaining detection accuracy
Data Source
Figure 1~3
Figure 4~5
Figure 6~7
AI summary
The present invention relates to an attack-deterrent generator (20) for dynamically generating at least one AI defense module (16). A core of the invention lies in the fact that a distribution function is determined for model data. The assumption of the invention is that the model data belong to a multiplicity of models or have a similar statistic behavior. It is thus possible to determine for an input data set whether the data of the input data set is to be associated with an adversarial attack. This is for example the case when statistic anomalies are determined in the input data set.