Patent №
US 11,675,896
Granted
2023-06-13
Filed 2020
Owner
INTERNATIONAL BUSINESS MACHINES CORPORATION
Lab
AI components
7
ml · nlp · vision · kr · planning · evo · hardware
Assignment
Recorded
Dataset
AIPD
2023_r1 edition
Application
16844867
A method, apparatus and computer program product to defend learning models that are vulnerable to adversarial example attack. It is assumed that data (a “dataset”) is available in multiple modalities (e.g., text and images, audio and images in video, etc.). The defense approach herein is premised on the recognition that the correlations between the different modalities for the same entity can be exploited to defend against such attacks, as it is not realistic for an adversary to attack multiple modalities. To this end, according to this technique, adversarial samples are identified and rejected if the features from one (the attacked) modality are determined to be sufficiently far away from those of another un-attacked modality for the same entity. In other words, the approach herein leverages the consistency between multiple modalities in the data to defend against adversarial attacks on one modality.
AI classification
Ownership
INTERNATIONAL BUSINESS MACHINES CORPORATION
assignment · 523600338
Assignors
MOLLOY, IAN MICHAEL, PARK, YOUNGJA, LEE, TAESUNG, WANG, WENJIE
On an employer assignment, the assignors are typically the inventors.