IP Library › Granted Patent US 11,875,586
Granted Patent B2
US 11,875,586 · App. 17/168,547 · Granted Jan 16, 2024

Detection and mitigation of cyber attacks on binary image recognition systems

Inventors: Eric Balkanski (New York, NY); Harrison Chase (San Francisco, CA); Kojin Oshiba (San Francisco, CA); Alexander Rilee (Cambridge, MA); Yaron Singer (Menlo Park, CA); Richard Wang (West Hills, CA)
Assignee: ROBUST INTELLIGENCE, INC.
G06V30/40G06F18/2433G06F21/577G06N20/00G06V10/761G06V30/20G06F2221/034G06V30/10
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,875,586
App. No.
17/168,547
Filed
Feb 5, 2021
Granted
Jan 16, 2024
Kind
B2
Examiner
LIU, ZHE
Art Unit
2493
USPC
726/25
Abstract

A computer-implemented method, comprising receiving, by a computer system, binary image data, the computer system configured to detect a pixel value in the binary image data to represent a non-machine language value related to the binary image data; determining, by the computer system, that the binary image data further comprises at least a pixel value that is altered in a manner to change the non-machine language value related to the binary image data when read by an image recognition system; and alerting, by the computer system, to the image recognition system to review the binary image data.

Claims (44)

1. A computer-implemented method for detecting vulnerabilities of a model for binary image classification, comprising:

receiving, by a computer system, a binary image data, the computer system configured to detect a pixel value in the binary image data to represent a non-machine language value related to the binary image data;

determining, by the computer system, that the binary image data further comprises at least a pixel value that is altered in a manner to change the non-machine language value related to the binary image data when read by an image recognition system; and

alerting, by the computer system, to the image recognition system to review the binary image data,

wherein the image recognition system includes:

a first artificial intelligence model that classifies a first portion of the binary image data that represents a numerical amount written in numbers; and

a second artificial intelligence model that classifies a second portion of the binary image data that represents the numerical amount written in letters;

wherein said determining includes determining that the first and second artificial intelligence models are attacked simultaneously such that the changed non-machine language value associated with the first portion matches the changed non-machine language value associated with the second portion when read by the image recognition system, and

wherein said determining that the first and second artificial intelligence models are attacked simultaneously comprises determining that an untargeted attack using a shaded combinatorial attack on recognition systems is used on at least one of the first and second artificial intelligence models, wherein the shaded combinatorial attack includes one or more iterations, at least one of the iterations including evaluating gains of one or more pixels of the binary image data based upon spatial and temporal correlations among the gains of the pixels across the iterations.

2. The computer-implemented method of claim 1 , wherein the at least one of the iterations further includes:

determining whether a selected pixel of the pixels has a gain greater than a threshold; and

at least one of flipping the selected pixel or flipping a pixel on a boundary of black and white regions of the binary image data that is associated with the largest gain among all pixels on the boundary, based upon said determining whether the selected pixel has the gain greater than the threshold.

3. The computer-implemented method of claim 2 , further comprising determining whether a target version of the shaded combinatorial attack on recognition systems was implemented twice to attack both of the first and second artificial intelligence models.

4. One or more non-transitory computer readable media comprising instructions that, when executed with a computer system configured to review binary, cause the computer system to at least:

receive, by the computer system, a binary image data, the computer system configured to detect a pixel value in the binary image data to represent a non-machine language value related to the binary image data;

determine, by the computer system, that the binary image data further comprises at least a pixel value that is altered in a manner to change the non-machine language value related to the binary image data when read by an image recognition system; and

alert, by the computer system, to the image recognition system to review the binary image data,

wherein the image recognition system includes:

a first artificial intelligence model that classifies a first portion of the binary image data that represents a numerical amount written in numbers; and

a second artificial intelligence model that classifies a second portion of the binary image data that represents the numerical amount written in letters;

wherein said determining includes determining that the first and second artificial intelligence models are attacked simultaneously such that the changed non-machine language value associated with the first portion matches the changed non-machine language value associated with the second portion when read by the image recognition system, and

wherein said determining that the first and second artificial intelligence models are attacked simultaneously comprises determining that an untargeted attack using a shaded combinatorial attack on recognition systems is used on at least one of the first and second artificial intelligence models, wherein the shaded combinatorial attack includes one or more iterations, at least one of the iterations including evaluating gains of one or more pixels of the binary image data based upon spatial and temporal correlations among the gains of the pixels across the iterations.

5. The non-transitory computer readable media of claim 4 , wherein the at least one of the iterations further includes:

determining whether a selected pixel of the pixels has a gain greater than a threshold; and

at least one of flipping the selected pixel or flipping a pixel on a boundary of black and white regions of the binary image data that is associated with the largest gain among all pixels on the boundary, based upon said determining whether the selected pixel has the gain greater than the threshold.

6. The non-transitory computer readable media of claim 5 , further comprising determining whether a target version of the shaded combinatorial attack on recognition systems was implemented twice to attack both of the first and second artificial intelligence models.

7. The non-transitory computer readable media of claim 4 , wherein the binary image data is at least one of an alphanumerical sequence or a check.

8. The non-transitory computer readable media of claim 4 , wherein the image recognition system is an optical character recognition system.

9. A computer-implemented method for determining vulnerabilities of a model for binary image classification, comprising:

receiving, by a computer system, a binary image data, the computer system configured to test a set of pixel values in the binary image data to represent a non-machine language value related to the binary image data in an image recognition system;

determining, by the computer system, that the binary image data further comprises at least a pixel value is altered in a manner to change the non-machine language value related to the binary image data when read by the image recognition system; and

alerting, by the computer system, that the image recognition system is vulnerable to a spoofing attack,

wherein the image recognition system includes:

a first artificial intelligence model that classifies a first portion of the binary image data that represents a numerical amount written in numbers; and

a second artificial intelligence model that classifies a second portion of the binary image data that represents the numerical amount written in letters;

wherein said determining includes determining that the first and second artificial intelligence models are attacked simultaneously such that the changed non-machine language value associated with the first portion matches the changed non-machine language value associated with the second portion when read by the image recognition system, and

wherein said determining that the first and second artificial intelligence models are attacked simultaneously comprises determining that an untargeted attack using a shaded combinatorial attack on recognition systems is used on at least one of the first and second artificial intelligence models, wherein the shaded combinatorial attack includes one or more iterations, at least one of the iterations including evaluating gains of one or more pixels of the binary image data based upon spatial and temporal correlations among the gains of the pixels across the iterations.

10. The computer-implemented method of claim 9 , wherein the at least one of the iterations further includes:

determining whether a selected pixel of the pixels has a gain greater than a threshold; and

at least one of flipping the selected pixel or flipping a pixel on a boundary of black and white regions of the binary image data that is associated with the largest gain among all pixels on the boundary, based upon said determining whether the selected pixel has the gain greater than the threshold.

11. The computer-implemented method of claim 10 , further comprising determining whether a target version of the shaded combinatorial attack on recognition systems was implemented twice to attack both of the first and second artificial intelligence models.

12. The computer-implemented method of claim 9 , wherein the binary image data is an alphanumerical sequence.

13. The computer-implemented method of claim 9 , wherein the image recognition system is an optical character recognition system.

14. The computer-implemented method of claim 9 , wherein the binary image data is a check.

Assignments (3)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 25, 2026
From: ROBUST INTELLIGENCE LLC
To: CISCO TECHNOLOGY, INC.
Reel/Frame 075771/0957 →
CHANGE OF NAME Recorded Apr 17, 2025
From: ROBUST INTELLIGENCE, INC.
To: ROBUST INTELLIGENCE LLC
Reel/Frame 070887/0767 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 1, 2023
From: BALKANSKI, ERIC; CHASE, HARRISON; OSHIBA, KOJIN; RILEE, ALEXANDER; SINGER, YARON; WANG, RICHARD
To: ROBUST INTELLIGENCE, INC.
Reel/Frame 065739/0116 →
Continuity (2)
Provisional Application 62971021 · Feb 6, 2020
Related Publication 20210248241A1 · Aug 12, 2021