Neural Network Mitigation Layer for Adversarial Input Recognition

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Convolutional neural networks are prone to false recognition of objects from altered inputs, such as manipulated images or speech patterns, which can lead to incorrect identifications and lack robustness against adversarial attacks.

Innovation Solution

A method is introduced to mitigate false recognition by identifying and suppressing specific nodes and layers in the neural network that are activated by altered inputs, without altering the weights of pre-trained nodes, thereby reducing false recognitions and enhancing the network's accuracy and robustness.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the neural network processes altered inputs, then it can identify objects from modified data, but it produces false recognitions and incorrect identifications

Engineering Contradiction:
Improveability to process altered inputsVSAvoidaccuracy of object recognition
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the neural network into multiple layers and identifies specific mitigation layers and nodes that are responsible for false recognitions. By dividing the network into processable segments, the system can selectively suppress problematic nodes while preserving functional ones, thus maintaining the ability to process altered inputs without sacrificing recognition accuracy.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts and identifies specific nodes within the neural network that are responsible for false recognitions when processing altered inputs. By taking out these harmful nodes for suppression, the system removes the source of false recognitions while preserving the rest of the network's functionality for legitimate object recognition tasks.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If the neural network suppresses output from mitigation nodes, then false recognitions are reduced, but the network complexity increases due to additional mitigation layers

Engineering Contradiction:
Improvereduction of false recognitionsVSAvoidstructural complexity of neural network
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent performs preliminary identification of mitigation layers and nodes during the training phase, before the network is deployed for actual object recognition. By pre-identifying which nodes are likely to cause false recognitions, the system prepares the mitigation structure in advance, avoiding the need for complex real-time analysis and reducing overall system complexity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies suppression selectively to specific local nodes and layers within the neural network rather than uniformly across the entire network. This localized approach targets only the problematic mitigation nodes while leaving the rest of the network architecture intact, thus reducing false recognitions without unnecessarily increasing overall network complexity.

Inventive Principle:
Principle #3Local quality

3Reliability

If the neural network is trained to recognize objects from altered inputs, then it becomes more robust against adversarial attacks, but it requires additional training data and computational resources

Engineering Contradiction:
Improverobustness against adversarial attacksVSAvoidtraining efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent enables the neural network to self-identify its own vulnerability points by analyzing which nodes produce false recognitions when processing altered inputs. The network performs self-diagnosis to determine which nodes need suppression, eliminating the need for external manual analysis or complex external training procedures, thus improving training efficiency while maintaining robustness.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes the operational parameters of specific nodes by suppressing their outputs during the mitigation phase. By adjusting the activation state of mitigation nodes from active to suppressed, the network adapts its behavior to reject false recognitions while maintaining normal operation for legitimate inputs, achieving robustness through parameter adjustment rather than extensive retraining.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11763159B2Mitigating false recognition of altered inputs in convolutional neural networks
Publication Date: 2023.09.19 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11763159B2 patent drawing
  • US11763159B2 patent drawing
  • US11763159B2 patent drawing

AI summary

A neural network is configured to suppress an output of a mitigation node in a mitigation layer of the neural network. The neural network is pre-configured to recognize objects from inputs when operating using a processor and a memory. An actual input is sent to the neural network for object recognition, the actual input is an altered input. By suppressing the output of the mitigation node, the neural network is caused to avoid falsely recognizing an object from the actual input, where the altered input is configured to cause the neural network to falsely recognize the object from the actual input.