IP Library › Granted Patent US 12,229,254
Granted Patent B2
US 12,229,254 · App. 17/560,943 · Granted Feb 18, 2025

Machine learning fraud resiliency using perceptual descriptors

Inventors: Raizy Kellermann (Jerusalem, IL); Omer Ben-Shalom (Rishon le-Tzion, IL); Alex Nayshtut (Gan Yavne, IL)
Assignee: INTEL CORPORATION
G06F21/554G06V10/7747G06V10/82G06V20/56
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,229,254
App. No.
17/560,943
Granted
Feb 18, 2025
Kind
B2
Abstract

Machine learning fraud resiliency using perceptual descriptors is described. An example of a computer-readable storage medium includes instructions for accessing multiple examples in a training dataset for a classifier system; calculating one or more perceptual hashes for each of the examples; generating clusters of perceptual hashes for the multiple examples based on the calculation of the one or more perceptual hashes for each of the plurality of examples; obtaining an inference sample for classification by the classifier system; generating a first classification result for the inference sample utilizing a neural network classifier and generating a second classification result utilizing the generated clusters of perceptual hashes; comparing the first classification result with the second classification result; and, upon a determination that the first classification result does not match the second classification result, determining a suspicion of an adversarial attack.

Claims (54)

1. One or more non-transitory computer-readable storage mediums having stored thereon executable computer program instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:

accessing a plurality of examples in a training dataset for a classifier system;

calculating a plurality of perceptual hashes for each of the plurality of examples, the plurality of perceptual hashes including a plurality of perceptual hash algorithms;

generating clusters of perceptual hashes for the plurality of examples based on the calculation of the plurality of perceptual hashes for each of the plurality of examples;

obtaining an inference sample for classification by the classifier system;

generating a first classification result for the inference sample utilizing a neural network classifier and generating a second classification result for the inference sample utilizing the generated clusters of perceptual hashes;

comparing the first classification result for the inference sample with the second classification result for the inference sample; and

upon a determination that the first classification result does not match the second classification result, determining a suspicion of an adversarial attack on the classifier system.

2. The storage mediums of claim 1 , wherein the instructions further include instructions for:

upon the determination that the first classification result does not match the second classification result, performing one or more actions in response to the determination of suspicion of an adversarial attack.

3. The storage mediums of claim 2 , wherein the one or more actions include one or more of:

generating an alert;

recording data regarding a possible adversarial input; and

halting or changing an operation of the classifier system.

4. The storage mediums of claim 1 , wherein the inference sample is an image.

5. The storage mediums of claim 1 , wherein the classifier system is a classifier for an autonomous driving vehicle or an assisted driving vehicle.

6. The storage mediums of claim 1 , wherein the suspicion of an adversarial attack includes a suspicion that one or more adversarial examples have been received for training of the classifier system.

7. A method comprising:

accessing a plurality of examples in a training dataset for a classifier system;

calculating a plurality of perceptual hashes for each of the plurality of examples, the plurality of perceptual hashes including a plurality of perceptual hash algorithms;

generating clusters of perceptual hashes for the plurality of examples based on the calculation of the plurality of perceptual hashes for each of the plurality of examples;

obtaining an inference sample for classification by the classifier system;

generating a first classification result for the inference sample utilizing a neural network classifier and generating a second classification result for the inference sample utilizing the generated clusters of perceptual hashes;

comparing the first classification result for the inference sample with the second classification result for the inference sample; and

upon a determination that the first classification result does not match the second classification result, determining a suspicion of an adversarial attack on the classifier system.

8. The method of claim 7 , further comprising:

upon the determination that the first classification result does not match the second classification result, performing one or more actions in response to the determination of suspicion of an adversarial attack.

9. The method of claim 8 , wherein the one or more actions include one or more of:

generating an alert;

recording data regarding a possible adversarial input; and

halting or changing an operation of the classifier system.

10. The method of claim 7 , wherein the inference sample is an image.

11. The method of claim 7 , wherein the classifier system is a classifier for an autonomous driving vehicle or an assisted driving vehicle.

12. The method of claim 7 , wherein the suspicion of an adversarial attack includes a suspicion that one or more adversarial examples have been received for training of the classifier system.

13. An apparatus comprising:

one or more processors to process data including data classification of inference samples; and

a storage for storing data including a training dataset of samples;

wherein the one or more processors are to:

access a plurality of examples in the training dataset;

calculate a plurality of perceptual hashes for each of the plurality of examples, the plurality of perceptual hashes including a plurality of perceptual hash algorithms;

generate clusters of perceptual hashes for the plurality of examples based on the calculation of the plurality of perceptual hashes for each of the plurality of examples;

obtain an inference sample for classification by the apparatus;

generate a first classification result for the inference sample utilizing a neural network classifier and generate a second classification result for the inference sample utilizing the generated clusters of perceptual hashes;

compare the first classification result for the inference sample with the second classification result for the inference sample; and

upon a determination that the first classification result does not match the second classification result, determine a suspicion of an adversarial attack on the apparatus.

14. The apparatus of claim 13 , wherein the one or more processors are further to:

upon the determination that the first classification result does not match the second classification result, perform one or more actions in response to the determination of suspicion of an adversarial attack.

15. The apparatus of claim 14 , wherein the one or more actions include one or more of:

generating an alert;

recording data regarding a possible adversarial input; and

halting or changing an operation of the apparatus.

16. The apparatus of claim 13 , wherein the inference sample is an image.

17. The apparatus of claim 13 , wherein the apparatus includes a classifier for an autonomous driving vehicle or an assisted driving vehicle.

18. The apparatus of claim 13 , wherein the suspicion of an adversarial attack includes a suspicion that one or more adversarial examples have been received for training of the apparatus.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2022
From: KELLERMANN, RAIZY; BEN-SHALOM, OMER; NAYSHTUT, ALEX
To: INTEL CORPORATION
Reel/Frame 058774/0567 →
Continuity (1)
Related Publication 20220114255A1 · Apr 14, 2022
References Cited (17)
US 11321856B1 · Caldwell · 2022 [cited by examiner]
US 11443531B1 · Saggu · 2022 [cited by examiner]
US 20190007476A1 · Rabbat · 2019 [cited by examiner]
US 20200111364A1 · Damsaz · 2020 [cited by examiner]
US 20210014270A1 · Thakur · 2021 [cited by examiner]
US 20210056404A1 · Goswami · 2021 [cited by examiner]
US 20210174132A1 · Mayes · 2021 [cited by examiner]
US 20210232931A1 · Speakman · 2021 [cited by examiner]
US 20210264268A1 · Goswami · 2021 [cited by examiner]
US 20210295154A1 · Groh · 2021 [cited by examiner]
US 20210309183A1 · Bielby · 2021 [cited by examiner]
US 20220092351A1 · Huang · 2022 [cited by examiner]
US 20220180173A1 · Jonnalagadda · 2022 [cited by examiner]
US 20220277173A1 · He · 2022 [cited by examiner]
US 20230054186A1 · Messous · 2023 [cited by examiner]
US 20230334332A1 · Wu · 2023 [cited by examiner]
WO WO2021105985A1 · 2021 [cited by examiner]