Neural Network Mitigation Layer for Adversarial Input Recognition
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Convolutional neural networks are prone to false recognition of objects from altered inputs, such as manipulated images or speech patterns, which can lead to incorrect identifications and lack robustness against adversarial attacks.
Innovation Solution
A method is introduced to mitigate false recognition by identifying and suppressing specific nodes and layers in the neural network that are activated by altered inputs, without altering the weights of pre-trained nodes, thereby reducing false recognitions and enhancing the network's accuracy and robustness.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the neural network processes altered inputs, then it can identify objects from modified data, but it produces false recognitions and incorrect identifications
Solution Approach 1:
The patent segments the neural network into multiple layers and identifies specific mitigation layers and nodes that are responsible for false recognitions. By dividing the network into processable segments, the system can selectively suppress problematic nodes while preserving functional ones, thus maintaining the ability to process altered inputs without sacrificing recognition accuracy.
Solution Approach 2:
The patent extracts and identifies specific nodes within the neural network that are responsible for false recognitions when processing altered inputs. By taking out these harmful nodes for suppression, the system removes the source of false recognitions while preserving the rest of the network's functionality for legitimate object recognition tasks.
2Reliability
If the neural network suppresses output from mitigation nodes, then false recognitions are reduced, but the network complexity increases due to additional mitigation layers
Solution Approach 1:
The patent performs preliminary identification of mitigation layers and nodes during the training phase, before the network is deployed for actual object recognition. By pre-identifying which nodes are likely to cause false recognitions, the system prepares the mitigation structure in advance, avoiding the need for complex real-time analysis and reducing overall system complexity.
Solution Approach 2:
The patent applies suppression selectively to specific local nodes and layers within the neural network rather than uniformly across the entire network. This localized approach targets only the problematic mitigation nodes while leaving the rest of the network architecture intact, thus reducing false recognitions without unnecessarily increasing overall network complexity.
3Reliability
If the neural network is trained to recognize objects from altered inputs, then it becomes more robust against adversarial attacks, but it requires additional training data and computational resources
Solution Approach 1:
The patent enables the neural network to self-identify its own vulnerability points by analyzing which nodes produce false recognitions when processing altered inputs. The network performs self-diagnosis to determine which nodes need suppression, eliminating the need for external manual analysis or complex external training procedures, thus improving training efficiency while maintaining robustness.
Solution Approach 2:
The patent changes the operational parameters of specific nodes by suppressing their outputs during the mitigation phase. By adjusting the activation state of mitigation nodes from active to suppressed, the network adapts its behavior to reject false recognitions while maintaining normal operation for legitimate inputs, achieving robustness through parameter adjustment rather than extensive retraining.
Data Source
AI summary
A neural network is configured to suppress an output of a mitigation node in a mitigation layer of the neural network. The neural network is pre-configured to recognize objects from inputs when operating using a processor and a memory. An actual input is sent to the neural network for object recognition, the actual input is an altered input. By suppressing the output of the mitigation node, the neural network is caused to avoid falsely recognizing an object from the actual input, where the altered input is configured to cause the neural network to falsely recognize the object from the actual input.


