Sanitizing Deep Generative Models Against Adversarial Attacks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Deep generative models are vulnerable to adversarial attacks, particularly from untrusted third-party sources, which can lead to material and reputational damage in mission-critical applications, as they require complex training and significant computational resources, making them susceptible to poisoning attacks and other forms of manipulation.

Innovation Solution

Implementing a method that applies adversarial attack detection operations on deep generative models using a processor, which includes sanitizing the models by applying static, dynamic, sample-based, and gradient analyses to identify and mitigate harmful modes and backdoor attacks, thereby protecting them against adversarial threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If deep generative models are trained with complex algorithms and significant computational resources, then the model performance and capability are improved, but the susceptibility to adversarial attacks and poisoning increases

Engineering Contradiction:
Improvemodel performanceVSAvoidsusceptibility to adversarial attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies multiple detection operations (static analysis, dynamic analysis, sample-based analysis, gradient analysis) before deploying the deep generative model to detect and mitigate adversarial attacks in advance. This preliminary action identifies suspicious patterns and poisonings in training data and model architecture, allowing the model to be sanitized before it becomes vulnerable to attacks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary detection and sanitization system that acts as a mediator between the training data/source and the deep generative model. This intermediary layer analyzes inputs, identifies adversarial content, and cleans the data before it reaches the model, thereby protecting the model from poisoning attacks while maintaining its performance.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If deep generative models are obtained from untrusted third-party sources, then the complexity and resource requirements are reduced, but the risk of backdoor attacks and manipulation increases

Engineering Contradiction:
Improvetraining complexityVSAvoidmodel integrity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent performs preliminary detection operations on externally sourced deep generative models before integration. Static analysis examines the model architecture for backdoor mechanisms, while dynamic analysis tests the model's behavior under various inputs. This preliminary verification ensures that models from untrusted sources do not contain malicious code or backdoors.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements a feedback mechanism where detection operations continuously monitor the deep generative model for signs of manipulation or backdoor activation. When suspicious behavior is detected, the system provides feedback to sanitize or reject the model, creating a closed-loop verification process that maintains model integrity despite external sourcing.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If multiple adversarial attack detection operations are applied on deep generative models, then the detection accuracy is improved, but the computational time and processing overhead increase

Engineering Contradiction:
Improveattack detection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies multiple detection operations (static, dynamic, sample-based, gradient analysis) to thoroughly detect adversarial attacks. By performing comprehensive multi-layered analysis, the system achieves high detection accuracy. The patent accepts the time cost of this excessive action as necessary to ensure model security against sophisticated attacks.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12182263B2Defending deep generative models against adversarial attacks
Publication Date: 2024.12.31 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US12182263B2 patent drawing
  • US12182263B2 patent drawing
  • US12182263B2 patent drawing

AI summary

Adversarial attack detection operations may be applied on one or more deep generative models for defending deep generative models from adversarial attacks. The adversarial attack may be detected on the one or more deep generative models based on the one or more of a plurality of adversarial attack detection operations. The one or more deep generative models may be sanitized based on the adversarial attack.