Robustness Setting Device for Adversarial Sample Neutralization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing machine learning models, particularly neural networks, are vulnerable to adversarial samples and require a significant number of adversarial samples for retraining to achieve robustness, making it challenging to simply provide robustness against such samples.

Innovation Solution

A robustness setting device and method that specify a required robustness level for a computation device by determining a noise removal level for input signals with added perturbations, using quantization to neutralize adversarial samples, and evaluating the robustness based on output accuracy across multiple perturbation levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If retraining is performed using adversarial examples, then robustness against adversarial samples is improved, but the complexity and resource requirements increase significantly

Engineering Contradiction:
Improverobustness against adversarial samplesVSAvoidcomplexity of providing robustness
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The invention extracts and removes the perturbation component from adversarial samples through spectral analysis. By identifying and eliminating the adversarial perturbation in the frequency domain, the system achieves robustness without requiring model retraining, thus reducing complexity while maintaining reliability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The invention introduces spectral analysis as an intermediary process between the adversarial sample input and the model processing. This intermediate step transforms the problem from model retraining to perturbation removal, simplifying the approach to achieving robustness

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a sufficient number of adversarial samples are prepared for retraining, then robustness is improved, but the time and computational resources required increase

Engineering Contradiction:
Improverobustness against adversarial samplesVSAvoidtime for preparing and retraining
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The invention performs preliminary spectral analysis on the adversarial samples to identify and remove perturbations before model processing. This preliminary action eliminates the need for time-consuming retraining processes while maintaining robustness

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention replaces the mechanical retraining process with a spectral analysis-based perturbation removal approach. This substitution eliminates the need for iterative model training and significantly reduces the time and computational resources required

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If noise removal is applied to input signals, then robustness against adversarial samples is improved, but the accuracy on normal inputs may deteriorate

Engineering Contradiction:
Improverobustness against adversarial samplesVSAvoidoutput accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The invention applies noise removal selectively only to the perturbation components identified through spectral analysis, rather than uniformly to all input signals. This localized approach preserves the quality of normal inputs while removing adversarial perturbations, maintaining both robustness and accuracy

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20220207304A1Robustness setting device, robustness setting method, storage medium storing robustness setting program, robustness evaluation device, robustness evaluation method, storage medium storing robustness evaluation program, computation device, and storage medium storing program
Publication Date: 2022.06.30 NEC CORP
  • US20220207304A1 patent drawing
  • US20220207304A1 patent drawing
  • US20220207304A1 patent drawing

AI summary

A robustness setting device provided with robustness specifying means for specifying a robustness level required in a computation device using a trained model against an adversarial sample that is an input signal to which a perturbation has been added in order to induce an erroneous determination by the trained model; and level determination means for determining a noise removal level for the input signal based on the robustness level.