IP Library › Granted Patent US 11,681,796
Granted Patent B2
US 11,681,796 · App. 16/566,862 · Granted Jun 20, 2023

Learning input preprocessing to harden machine learning models

Inventors: Ngoc Minh Tran (Dublin, IE); Mathieu Sinn (Dublin, IE); Maria-Irina Nicolae (Dublin, IE); Martin Wistuba (Dublin, IE); Ambrish Rawat (Dublin, IE); Beat Buesser (Dublin, IE)
Assignee: INTERNATIONAL BUSINESS MACHINES CORPORATION
G06F21/552G06N3/082G06N20/00G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,681,796
App. No.
16/566,862
Granted
Jun 20, 2023
Kind
B2
Abstract

Various embodiments are provided for securing machine learning models by one or more processors in a computing system. One or more hardened machine learning models that are secured against adversarial attacks are provided by applying one or more of a plurality of combinations of selected preprocessing operations from one or more machine learning models, a data set used for hardening the one or more machine learning models, a list of preprocessors, and a selected number of learners.

Claims (38)

1. A method for securing machine learning models in a computing environment by one or more processors comprising:

receiving, as input, one or more machine learning models, a data set used for hardening the one or more machine learning models, a list of preprocessors, and a selected number of learners trained in sequence;

providing one or more hardened machine learning models secured against adversarial attacks by applying one or more of a plurality of combinations of selected preprocessing operations from the one or more machine learning models using the input, wherein one of the selected preprocessing operations includes receiving an image of the data set, preprocessing the image by each preprocessor on the list of preprocessors without changing a shape of the image, and outputting a new, cleansed image to subsequently be classified by a classifier of the one or more hardened machine learning models, and wherein a logit for predicting a classification by the one or more hardened machine learning models is obtained from any of the selected number of learners.

2. The method of claim 1 , further including learning a degree of adversarial robustness of each of the plurality of combinations of selected preprocessing operations.

3. The method of claim 1 , further including:

receiving one or more data instances from the data set; and

transforming the one or more data instances by applying one or more transformation operations by one or more of the plurality of combinations of selected preprocessing operations.

4. The method of claim 1 , further including preprocessing incoming data using one or more of the plurality of combinations of selected preprocessing operations prior to being consumed by the one or more machine learning models.

5. The method of claim 1 , further including determining a security score for the one or more hardened machine learning models indicating a level of security from the adversarial attacks.

6. The method of claim 1 , further including:

learning one or more parameters for each of the selected number of learners; and

learning each of the plurality of combinations of selected preprocessing operations that harden the one or more machine learning models.

7. A system for securing machine learning models in a computing environment, comprising:

one or more computers with executable instructions that when executed cause the system to:

receive, as input, one or more machine learning models, a data set used for hardening the one or more machine learning models, a list of preprocessors, and a selected number of learners trained in sequence;

provide one or more hardened machine learning models secured against adversarial attacks by applying one or more of a plurality of combinations of selected preprocessing operations from the one or more machine learning models using the input, wherein one of the selected preprocessing operations includes receiving an image of the data set, preprocessing the image by each preprocessor on the list of preprocessors without changing a shape of the image, and outputting a new, cleansed image to subsequently be classified by a classifier of the one or more hardened machine learning models, and wherein a logit for predicting a classification by the one or more hardened machine learning models is obtained from any of the selected number of learners.

8. The system of claim 7 , wherein the executable instructions further learn a degree of adversarial robustness of each of the plurality of combinations of selected preprocessing operations.

9. The system of claim 7 , wherein the executable instructions further:

receive one or more data instances from the data set; and

transform the one or more data instances by applying one or more transformation operations by one or more of the plurality of combinations of selected preprocessing operations.

10. The system of claim 7 , wherein the executable instructions further preprocess incoming data using one or more of the plurality of combinations of selected preprocessing operations prior to being consumed by the one or more machine learning models.

11. The system of claim 7 , wherein the executable instructions further determine a security score for the one or more hardened machine learning models indicating a level of security from the adversarial attacks.

12. The system of claim 7 , wherein the executable instructions further:

learn one or more parameters for each of the selected number of learners; and

learn each of the plurality of combinations of selected preprocessing operations that harden the one or more machine learning models.

13. A computer program product for, by a processor, securing machine learning models in a computing environment, the computer program product comprising a non-transitory computer-readable storage medium having computer-readable program code portions stored therein, the computer-readable program code portions comprising:

an executable portion that receives, as input, one or more machine learning models, a data set used for hardening the one or more machine learning models, a list of preprocessors, and a selected number of learners trained in sequence;

an executable portion that provides one or more hardened machine learning models secured against adversarial attacks by applying one or more of a plurality of combinations of selected preprocessing operations from the one or more machine learning models using the input, wherein one of the selected preprocessing operations includes receiving an image of the data set, preprocessing the image by each preprocessor on the list of preprocessors without changing a shape of the image, and outputting a new, cleansed image to subsequently be classified by a classifier of the one or more hardened machine learning models, and wherein a logit for predicting a classification by the one or more hardened machine learning models is obtained from any of the selected number of learners.

14. The computer program product of claim 13 , further including an executable portion that:

learns a degree of adversarial robustness of each of the plurality of combinations of selected preprocessing operations; and

determines a security score for the one or more hardened machine learning models indicating a level of security from the adversarial attacks.

15. The computer program product of claim 13 , further including an executable portion that:

receives one or more data instances from the data set; and

transforms the one or more data instances by applying one or more transformation operations by one or more of the plurality of combinations of selected preprocessing operations.

16. The computer program product of claim 13 , further including an executable portion that preprocesses incoming data using one or more of the plurality of combinations of selected preprocessing operations prior to being consumed by the one or more machine learning models.

17. The computer program product of claim 13 , further including an executable portion that:

learns one or more parameters for each of the selected number of learners; and

learn each of the plurality of combinations of selected preprocessing operations that harden the one or more machine learning models.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 10, 2019
From: TRAN, NGOC MINH; SINN, MATHIEU; NICOLAE, MARIA-IRINA; WISTUBA, MARTIN; RAWAT, AMBRISH; BUESSER, BEAT
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 050333/0849 →
Continuity (1)
Related Publication 20210073376A1 · Mar 11, 2021
Cited By (1)
US 12,537,826