Umeå University's logo

umu.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
A training rate and survival heuristic for inference and robustness evaluation (Trashfire)
Umeå University, Faculty of Science and Technology, Department of Computing Science.
Umeå University, Faculty of Science and Technology, Department of Computing Science. Elastisys AB.ORCID iD: 0000-0002-0751-9695
Umeå University, Faculty of Science and Technology, Department of Computing Science.ORCID iD: 0000-0001-7119-7646
Umeå University, Faculty of Science and Technology, Department of Computing Science. Elastisys AB.ORCID iD: 0000-0002-2633-6798
2025 (English)In: Proceedings of 2024 International Conference on Machine Learning and Cybernetics, IEEE, 2025, p. 613-623Conference paper, Published paper (Refereed)
Abstract [en]

Machine learning models—deep neural networks in particular—have performed remarkably well on benchmark datasets across a wide variety of domains. However, the ease of finding adversarial counter-examples remains a persistent problem when training times are measured in hours or days and the time needed to find a successful adversarial counter-example is measured in seconds. Much work has gone into generating and defending against these adversarial counter-examples, however the relative costs of attacks and defences are rarely discussed. Additionally, machine learning research is almost entirely guided by test/train metrics, but these would require billions of samples to meet industry standards. The present work addresses the problem of understanding and predicting how particular model hyper-parameters influence the performance of a model in the presence of an adversary. The proposed approach uses survival models, worst-case examples, and a cost-aware analysis to precisely and accurately reject a particular model change during routine model training procedures rather than relying on real-world deployment, expensive formal verification methods, or accurate simulations of very complicated systems (e.g., digitally recreating every part of a car or a plane). Through an evaluation of many pre-processing techniques, adversarial counter-examples, and neural network configurations, the conclusion is that deeper models do offer marginal gains in survival times compared to more shallow counterparts. However, we show that those gains are driven more by the model inference time than inherent robustness properties. Using the proposed methodology, we show that ResNet is hopelessly insecure against even the simplest of white box attacks.

Place, publisher, year, edition, pages
IEEE, 2025. p. 613-623
Series
Proceedings (International Conference on Machine Learning and Cybernetics), ISSN 2160-133X, E-ISSN 2160-1348
Keywords [en]
Machine Learning, Computer Vision, Neural Networks, Adversarial AI, Trustworthy AI
National Category
Artificial Intelligence Security, Privacy and Cryptography Computer Sciences
Identifiers
URN: urn:nbn:se:umu:diva-237109DOI: 10.1109/ICMLC63072.2024.10935101ISBN: 979-8-3315-2804-1 (electronic)ISBN: 979-8-3315-2805-8 (print)OAI: oai:DiVA.org:umu-237109DiVA, id: diva2:1949253
Conference
2024 International Conference on Machine Learning and Cybernetics (ICMLC),Miyazaki, Japan, September 20-23,
Funder
Knut and Alice Wallenberg Foundation, 2019.0352eSSENCE - An eScience CollaborationAvailable from: 2025-04-02 Created: 2025-04-02 Last updated: 2025-04-02Bibliographically approved

Open Access in DiVA

No full text in DiVA

Other links

Publisher's full text

Authority records

Meyers, CharlesSaleh Sedghpour, Mohammad RezaLöfstedt, TommyElmroth, Erik

Search in DiVA

By author/editor
Meyers, CharlesSaleh Sedghpour, Mohammad RezaLöfstedt, TommyElmroth, Erik
By organisation
Department of Computing Science
Artificial IntelligenceSecurity, Privacy and CryptographyComputer Sciences

Search outside of DiVA

GoogleGoogle Scholar

doi
isbn
urn-nbn

Altmetric score

doi
isbn
urn-nbn
Total: 30 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf