Trustworthy AI: Poisoning Attacks on AI | AI FOR GOOD DISCOVERY
Battista Biggio (University of Cagliari) presents his research on Poisoning Attacks on AI as part of the Trustworthy AI series.
WHAT IS TRUSTWORTHY AI SERIES?
Artificial Intelligence (AI) systems have steadily grown in complexity, gaining predictivity often at the expense of interpretability, robustness and trustworthiness. Deep neural networks are a prime example of this development. While reaching “superhuman” performances in various complex tasks, these models are susceptible to errors when confronted with tiny (adversarial) variations of the input – variations which are either not noticeable or can be handled reliably by humans. This expert talk series will discuss these challenges of current AI technology and will present new research aiming at overcoming these limitations and developing AI systems which can be certified to be trustworthy and robust.
⏱ Shownotes:
00:00 Opening remarks by ITU
00:58 Introduction by Wojciech Samek
01:37 Introduction by Battista Biggio - Poisoning Attacks on AI
02:50 Artificial Intelligence Today
04:11 is AI really smart?
04:59 Adversarial Examples - (Gradient-based Evasion Attacks)
06:31 Not only in the digital domain
07:51 Other applicable domain
11:04 Timeline of Learning Security
12:21 Attacks against Machine Learning
14:56 Poisoning attacks
21:00 Poisoning is a Bilevel Optimization problem
22:43 Bilevel Optimization
23:58 Gradient-based poisoning attacks
25:19 Experiment on MNIST digits
26:01 is bilevel optimization really needed?
26:48 Towards poisoning deep neural networks
28:33 Poisoning attacks on algorithm fairness
29:13 Why do adversarial attacks transfer?
30:26 Countering Poisoning attacks
32:20 Robust regression with TRIM statistics
34:10 Strength-detectability dilemma for poisoning attacks
34:35 Backdoor attacks
37:18 Backdoor poisoning: three main categories
39:50 Defending against backdoor poisoning attacks
40:50 Ongoing work: backdoor smoothing
42:23 Why is AI vulnerable?
44:41 What can we do, then?
45:30 Conclusion
46:04 Q&A Session
1:02:24 Closing Q&A Session
1:02:34 Closing from ITU
The Trustworthy AI series is moderated by Wojciech Samek, Head of AI Department at Fraunhofer HHI, one of the top 20 AI labs in the world:https://www.analyticsinsight.net/top-20-artificial-intelligence-research-labs-in-the-world-in-2021/.
Website:https://aiforgood.itu.int//
Twitter:https://twitter.com/ITU_AIForGood
LinkedIn Page:https://www.linkedin.com/company/26511907
LinkedIn Group:https://www.linkedin.com/groups/8567748
Instagram:https://www.instagram.com/aiforgood
Facebook:https://www.facebook.com/AIforGood