Systems and methods for protecting machine learning models against adversarial attacks

Inventors

Javidi, BahramSTERN, Adrian

Assignees

BG Negev Technologies and Applications LtdUniversity of Connecticut

Interested in licensing this patent?

MTEC can help explore whether this patent might be available for licensing for your application.

Publication Number

US-12287892-B2

Patent

Publication Date

2025-04-29

Expiration Date


Abstract

Embodiments pertain to systems configured to and methods for analyzing a scene comprising one or more objects. The system may be configured to perform the following: obtaining a set of optically encrypted image data describing a scene, including applying an optical manipulation to light incoming to an image acquisition device, whereby the image acquisition device outputs the set of optically encrypted image data, and wherein the optical manipulation is based on an encryption key; providing the set of optically encrypted image data to a machine learning model trained in accordance with the encryption key; and receiving from the machine learning model a prediction related to the scene.

Core Innovation

The disclosure provides optical encryption of scene light prior to digitization so that a machine learning model, including a deep neural network, makes correct predictions even when image input perturbations occur as adversarial attacks. The approach performs optical manipulation on scene light using an encryption key so that encrypted and correspondingly trained inputs are provided to the machine learning model for prediction. The disclosed scheme defends DNN-based image or scene analysis against adversarial perturbations.

The disclosure further describes an encryption plus transformation and optional decryption process to remove or deviate adversarial perturbations before machine learning inference. In this description, an encryption key characterizes the optical encryption, and a reconstruction or transformed image is used as an input to a model that is trained for the encrypted domain associated with that key. This enables predictions that are not degraded in the presence of adversarial perturbations.

An optically encrypting imaging device architecture is described that includes imaging optics and manipulation optics configured to apply encryption in the optical domain prior to digitization. The device uses controllable states or parameters controlled by a controller, together with an encryption key, and is further described with rotation of keys to increase security. The architecture is described in the context of image data that is optically encryptable, and machine learning training and inference are performed on inputs associated with the encryption key.

Claims Coverage

Not explicitly described in patent.

Not explicitly described in patent.

Stated Advantages

Robustness against adversarial attacks and adversarial input perturbations for DNN-based image or scene analysis.

Increased key space due to the use of an encryption key and key rotation as described.

Asymmetry requiring physical access for attack feasibility, rather than allowing purely digital counterattacks.

Prevention of adaptive counterattacks as described.

Reduced brute-force feasibility as described.

Documented Applications

Medical imaging and tissue analysis for driving decisions or interpretation using the disclosed DNN-based image or scene analysis that is protected against adversarial perturbations.

LiDAR or autonomous vehicles, where driving decisions are described as being supported by the disclosed defended DNN-based scene analysis.

JOIN OUR MAILING LIST

Stay Connected with MTEC

Keep up with active and upcoming solicitations, MTEC news and other valuable information.