Dynamic Ensemble Defense Against Adversarial AI Attacks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing AI defense methods are static and unable to adapt to changing adversarial attacks, lacking dynamic synthesis and diversity in ensemble-based defenses, which limits their effectiveness in real-world scenarios.

Innovation Solution

The development of dynamic ensemble-based defenses that select and adapt a subset of weak defenses dynamically, using a library of transformations and monitoring performance to continuously improve and re-synthesize ensembles, ensuring adaptability to real-time attacks and changing attacker behavior.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If static defense methods are used, then implementation is simple, but adaptability to changing adversarial attacks deteriorates

Engineering Contradiction:
Improveadaptability to changing adversarial attacksVSAvoidensemble selection and dynamic synthesis complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic ensemble selection where the defense configuration changes over time based on observed attack patterns. The system transitions from static pre-defined ensembles to dynamic selection of weak defenses, allowing the defense mechanism to adapt its structure and behavior in response to evolving adversarial threats.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback loops that monitor adversarial attack patterns and use this information to dynamically adjust the ensemble composition. The performance metric and diversity measurement provide feedback signals that guide the selection and synthesis of weak defenses, creating a closed-loop adaptive defense system.

Inventive Principle:
Principle #23Feedback

2Reliability

If large ensembles of weak defenses are used, then defense effectiveness improves, but resource consumption increases

Engineering Contradiction:
Improvedefense effectivenessVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts and selects only the necessary subset of weak defenses from a larger library, rather than deploying all available defenses. The ensemble selection process identifies and extracts the most effective combination of weak defenses based on diversity metrics and performance requirements, reducing unnecessary resource consumption while maintaining defense effectiveness.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system applies partial action by using a limited number of carefully selected weak defenses rather than all possible defenses. The ensemble size is optimized to provide sufficient defense effectiveness while avoiding excessive resource consumption, achieving the right balance between protection and efficiency.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If diverse ensemble compositions are maintained, then robustness against various attacks improves, but ensemble selection complexity increases

Engineering Contradiction:
Improverobustness against various attacksVSAvoidensemble selection complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses diversity as a key parameter to measure and optimize ensemble composition. By defining and measuring ensemble diversity through specific metrics, the system can systematically select weak defenses that maximize diversity, thereby improving robustness against various attack types while managing selection complexity through parameterized optimization.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20220171848A1System and Method for Synthesizing Dynamic Ensemble-Based Defenses to Counter Adversarial Attacks
Publication Date: 2022.06.02 UNIVERSITY OF SOUTH CAROLINA
  • US20220171848A1 patent drawing
  • US20220171848A1 patent drawing
  • US20220171848A1 patent drawing

AI summary

A method and device for synthesizing adaptive defenses of artificial intelligence (AI) systems against adversarial attacks. The method comprises, during a design phase, creating a library of weak defenses (WDs); preprocessing the WDs in the library; selecting a subset W of WDs from the WDs in the library; and, during a deployment phase, synthesizing an ensemble strategy based on an input of the selected subset W of WDs, the ensemble strategy used as a defense against adversarial attacks.