The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jun. 15, 2021

Filed:

Nov. 15, 2018
Applicant:

International Business Machines Corporation, Armonk, NY (US);

Inventors:

Ngoc Minh Tran, Dublin, IE;

Mathieu Sinn, Dublin, IE;

Ambrish Rawat, Dublin, IE;

Maria-Irina Nicolae, Dublin, IE;

Martin Wistuba, Dublin, IE;

Attorneys:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/55 (2013.01); G06F 21/56 (2013.01); H04L 29/06 (2006.01); G06N 3/08 (2006.01); G06F 30/27 (2020.01);
U.S. Cl.
CPC ...
G06F 21/566 (2013.01); G06F 21/554 (2013.01); G06N 3/088 (2013.01); G06F 21/556 (2013.01); G06F 30/27 (2020.01); G06F 2221/033 (2013.01); H04L 29/06911 (2013.01);
Abstract

A method for protecting a machine learning model includes: generating a first adversarial example by modifying an original input using an attack tactic, wherein the model accurately classifies the original input but does not accurately classify at least the first adversarial example; training a defender to protect the model from the first adversarial example by updating a strategy of the defender based on predictive results from classifying the first adversarial example; updating the attack tactic based on the predictive results from classifying the first adversarial example; generating a second adversarial example by modifying the original input using the updated attack tactic, wherein the trained defender does not protect the model from the second adversarial example; and training the defender to protect the model from the second adversarial example by updating the at least one strategy of the defender based on results obtained from classifying the second adversarial example.


Find Patent Forward Citations

Loading…