Spectral Perturbation Tensors for Covert Classifier Misclassification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Classification strategies based on training data in spectroscopy exhibit low robustness to subtle systematic deviations, leading to potential misclassification in applications like drug testing and DNA matching, where decisions are sensitive to minor impurities or noise.

Innovation Solution

The implementation of generative adversarial networks (GANs) to modify spectra for intentional misclassification, creating a spectral perturbation tensor that shifts the initial spectrum towards a target position, allowing for the design of classifiers less susceptible to adversarial attempts and improving reliability with limited data sets.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If classification strategies are based on training data with dimension reduction methods, then classification decisions can be made efficiently, but the robustness to subtle systematic deviations deteriorates

Engineering Contradiction:
Improveclassification efficiencyVSAvoidrobustness to subtle deviations
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by generating adversarial examples during the training phase that incorporate subtle systematic deviations and impurities. These adversarial training samples are created in advance to teach the classifier to recognize and tolerate variations that would otherwise cause misclassification, thereby improving robustness before actual classification decisions are made

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements preliminary anti-action by intentionally introducing adversarial perturbations and impurities into training data to counteract the vulnerability to subtle deviations. By pre-exposing the classifier to these harmful patterns in a controlled manner, the system develops resistance against similar deviations in real-world applications, transforming the harmful factor into a training opportunity

Inventive Principle:
Principle #9Preliminary anti-action

2Reliability

If generative adversarial networks are used to modify spectra for intentional misclassification, then the vulnerability to adversarial attacks is demonstrated, but this creates a means for intentional malfeasance

Engineering Contradiction:
Improveclassification integrityVSAvoidintentional misclassification
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent converts the harmful capability of adversarial attacks into a beneficial training mechanism. By using generative adversarial networks to create adversarial examples, the system transforms potential malicious perturbations into valuable training data that strengthens the classifier's robustness. The same mechanism that could be used for misclassification is repurposed to improve classification integrity through adversarial training

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

3Reliability

If subtle perturbations are applied to spectra, then misclassification can be induced covertly, but detecting and measuring these perturbations becomes difficult

Engineering Contradiction:
Improveclassification accuracyVSAvoidperturbation detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements feedback by creating adversarial examples with known perturbation patterns and using these to train the classifier to recognize such perturbations. The system learns from the feedback loop between adversarial generation and classification outcomes, developing the ability to detect and measure subtle perturbations that would otherwise be difficult to identify, thereby maintaining classification accuracy even when perturbations are present

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12039461B2Methods for inducing a covert misclassification
Publication Date: 2024.07.16 PURDUE RES FOUND
  • US12039461B2 patent drawing
  • US12039461B2 patent drawing
  • US12039461B2 patent drawing

AI summary

A method for inducing a covert misclassification performed on a non-transitory computer readable medium, the method includes identifying a target position. The method further includes creating a spectral perturbation tensor. The spectral perturbation tensor is configured to shift a projection of an initial spectrum towards the target position. Additionally, the method includes combining the spectral perturbation tensor to the initial spectrum. Further, the method includes classifying the combination of the spectral perturbation tensor and the initial spectrum with an established classifier, thereby designing the spectral perturbation tensor such that the combination is misclassified.