AI Model Defense Configuration Against Adversarial Attacks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Artificial Intelligence (AI) systems are vulnerable to adversarial attacks, which can deceive machine learning classifiers and compromise their accuracy, particularly in security-sensitive applications, with existing protection measures often failing to adequately safeguard against advanced attacks.

Innovation Solution

A computing device and method that identifies and evaluates combinations of protection measures for AI applications using machine learning algorithms to adjust AI models with computationally efficient defenses, optimizing them based on target configurations, metrics, and real-time threat assessments to enhance robustness against various adversarial attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple protection measures are applied against different attacks, then the robustness of the AI application is improved, but the computational complexity and resource consumption increase

Engineering Contradiction:
ImproverobustnessVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the protection measures into distinct categories (e.g., input preprocessing, model hardening, output post-processing) and evaluates them independently before combining. This allows the system to select specific segmentation elements based on the identified attack vectors, reducing unnecessary computational complexity while maintaining comprehensive protection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Instead of applying all possible protection measures universally, the patent implements partial action by selecting only the necessary protection measures based on the vulnerability assessment. The system determines the minimum effective combination of protections required to address identified threats, avoiding excessive computational resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

2Reliability

If protection measures are applied to defend against adversarial attacks, then the accuracy under attack is improved, but the computational resources required increase

Engineering Contradiction:
Improveaccuracy under attackVSAvoidcomputational resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent performs preliminary vulnerability assessment and attack simulation before implementing full protection measures. By pre-identifying the most critical vulnerability vectors and testing protection effectiveness in advance, the system can optimize the combination of measures to achieve maximum accuracy protection with minimum computational resource consumption.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adjusts protection measure parameters based on the specific attack scenario and vulnerability profile. This includes modifying the strength and scope of protection measures according to the identified threat level, allowing the system to allocate computational resources efficiently while maintaining high accuracy under adversarial conditions.

Inventive Principle:
Principle #35Parameter changes

3Adaptability or versatility

If a comprehensive set of protection measures is implemented, then the coverage of attack vectors is improved, but the time required for assessment and optimization increases

Engineering Contradiction:
Improvecoverage of attack vectorsVSAvoidassessment time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The patent segments attack vectors into distinct categories (e.g., data poisoning, adversarial examples, model extraction) and evaluates protection measures against each segment independently. This segmentation enables comprehensive coverage of all attack types while reducing assessment time through parallel evaluation of discrete protection components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements feedback mechanisms where the vulnerability assessment results feed back into the protection measure selection and optimization process. This iterative feedback loop allows the system to refine the protection combination based on actual performance data, reducing the time required for comprehensive assessment by learning from previous evaluations.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11275841B2Combination of protection measures for artificial intelligence applications against artificial intelligence attacks
Publication Date: 2022.03.15 ADVERSA AI LTD
  • US11275841B2 patent drawing
  • US11275841B2 patent drawing
  • US11275841B2 patent drawing

AI summary

A method and system of protecting an artificial intelligence (AI) application are provided. Parameters of the AI application are identified. An assessment of a vulnerability of the AI application is performed, including: applying a combination of protection measures comprising two or more protection measures against at least two different attacks and at least one dataset, and determining whether the combination of protection measures is successful in defending the AI application. A target configuration of an AI model to protect the AI application is determined based on the assessed vulnerability of the AI application. An AI enhanced algorithm is determined to adjust the AI model to include a combination of most computationally efficient defenses based on the target configuration. The adjusted AI model is used to protect the AI application.