The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jun. 27, 2023

Filed:

Jul. 10, 2018
Applicant:

International Business Machines Corporation, Armonk, NY (US);

Inventors:

Nathalie Baracaldo-Angel, San Jose, CA (US);

Bryant Chen, San Jose, CA (US);

Evelyn Duesterwald, Millwood, NY (US);

Heiko H. Ludwig, San Francisco, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 9/40 (2022.01); G06N 20/00 (2019.01); G06F 18/21 (2023.01); G06F 18/2113 (2023.01);
U.S. Cl.
CPC ...
H04L 63/1466 (2013.01); G06F 18/217 (2023.01); G06F 18/2113 (2023.01); G06N 20/00 (2019.01); H04L 63/1441 (2013.01);
Abstract

Computer-implemented methods, program products, and systems for provenance-based defense against poison attacks are disclosed. In one approach, a method includes: receiving observations and corresponding provenance data from data sources; determining whether the observations are poisoned based on the corresponding provenance data; and removing the poisoned observation(s) from a final training dataset used to train a final prediction model. Another implementation involves provenance-based defense against poison attacks in a fully untrusted data environment. Untrusted data points are grouped according to provenance signature, and the groups are used to train learning algorithms and generate complete and filtered prediction models. The results of applying the prediction models to an evaluation dataset are compared, and poisoned data points identified where the performance of the filtered prediction model exceeds the performance of the complete prediction model. Poisoned data points are removed from the set to generate a final prediction model.


Find Patent Forward Citations

Loading…