IP Library Granted Patent US 12,450,896
Granted Patent B2
US 12,450,896 · App. 18/478,335 · Granted Oct 21, 2025

Apparatus, method, and computer-readable medium for robust response to adversarial perturbations using hyperdimensional vectors

Inventor: Narayan Srinivasa (San Jose, CA)
Assignee: Intel Corporation
G06V20/00G06F18/214G06F30/34G06N3/08G06V10/454G06V10/764G06V10/774G09G3/2003G09G3/3607
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,450,896
App. No.
18/478,335
Granted
Oct 21, 2025
Kind
B2
Abstract

Apparatuses, methods, and articles of manufacture are disclosed. An example apparatus includes processor circuitry to assign a location value hyperdimensional vector (HDV) to a location in an image of a first patch of one or more pixels, assign at least a first channel HDV to the first patch, determine at least one pixel intensity value HDV for each of the one or more pixels in the first patch, bind together each of the pixel intensity value HDVs into at least one patch intensity value HDV, bind together the at least first channel HDV and the at least one patch intensity value HDV to produce a patch consensus intensity HDV, and generate a first hyperdimensional representation patch value HDV of the first patch by binding together at least a combination of the patch consensus intensity HDV and the location value HDV.

Claims (46)

1. An apparatus comprising:

interface circuitry to access a training image;

machine readable instructions; and

at least one programmable circuit to be programmed based on the machine readable instructions to:

determine first hyperdimensional vectors corresponding respectively to patches of the training image;

combine the first hyperdimensional vectors based on second hyperdimensional vectors representative of respective locations of the patches to encode the training image into a third hyperdimensional vector; and

train a neural network based on the third hyperdimensional vector.

2. The apparatus of claim 1 , wherein the interface circuitry is to access an adversarial image with at least one adversarial perturbation, and one or more of the at least one programmable circuit is to operate the trained neural network to classify the adversarial image as adversarial relative to the training image.

3. The apparatus of claim 2 , wherein the training image is a first image, the interface circuitry is to access a second image to be classified by the trained neural network, and one or more of the at least one programmable circuit is to:

segment the second image into patches of the second image; and

encode respective ones of the patches of the second image into corresponding fourth hyperdimensional vectors.

4. The apparatus of claim 3 , wherein one or more of the at least one programmable circuit is to;

combine the fourth hyperdimensional vectors based on fifth hyperdimensional vectors representative of respective locations of the patches of the second image to encode the second image into a sixth hyperdimensional vector; and

provide the sixth hyperdimensional vector to the trained neural network to classify the second image.

5. The apparatus of claim 4 , wherein one or more of the at least one programmable circuit is to use a consensus sum to encode the sixth hyperdimensional vector.

6. The apparatus of claim 4 , wherein one or more of the at least one programmable circuit is to combine respective ones of the fourth hyperdimensional vectors with corresponding ones of the fifth hyperdimensional vectors based on a binding operation.

7. The apparatus of claim 6 , wherein one or more of the at least one programmable circuit is to determine the fourth hyperdimensional vectors based on a permutation operation.

8. A non-transitory computer readable medium comprising instructions to cause at least one programmable circuit to:

determine first hyperdimensional vectors corresponding respectively to patches of a training image;

combine the first hyperdimensional vectors based on second hyperdimensional vectors representative of respective locations of the patches to encode the training image into a third hyperdimensional vector; and

train a neural network based on the third hyperdimensional vector.

9. The non-transitory computer readable medium of claim 8 , wherein the instructions are to cause one or more of the at least one programmable circuit to operate the neural network to classify an adversarial image as having at least one adversarial perturbation.

10. The non-transitory computer readable medium of claim 9 , wherein the training image is a first image, and the instructions are to cause one or more of the at least one programmable circuit to:

access a second image to be classified by the trained neural network;

segment the second image into patches of the second image; and

encode respective ones of the patches of the second image into corresponding fourth hyperdimensional vectors.

11. The non-transitory computer readable medium of claim 10 , wherein the instructions are to cause one or more of the at least one programmable circuit to;

combine the fourth hyperdimensional vectors based on fifth hyperdimensional vectors representative of respective locations of the patches of the second image to encode the second image into a sixth hyperdimensional vector; and

provide the sixth hyperdimensional vector to the trained neural network to classify the second image.

12. The non-transitory computer readable medium of claim 11 , wherein the instructions are to cause one or more of the at least one programmable circuit to use a consensus sum to encode the sixth hyperdimensional vector.

13. The non-transitory computer readable medium of claim 11 , wherein the instructions are to cause one or more of the at least one programmable circuit to combine respective ones of the fourth hyperdimensional vectors with corresponding ones of the fifth hyperdimensional vectors based on a binding operation.

14. A method comprising:

determining first hyperdimensional vectors corresponding respectively to patches of a first image;

combining the first hyperdimensional vectors based on second hyperdimensional vectors representative of respective locations of the patches to encode the first image into a third hyperdimensional vector;

training a neural network based on the third hyperdimensional vector; and

executing the trained neural network on a second image to generate an output classifying the second image.

15. The method of claim 14 , including:

segmenting the second image into patches of the second image; and

encoding respective ones of the patches of the second image into corresponding fourth hyperdimensional vectors.

16. The method of claim 15 , including:

combining the fourth hyperdimensional vectors based on fifth hyperdimensional vectors representative of respective locations of the patches of the second image to encode the second image into a sixth hyperdimensional vector; and

providing the sixth hyperdimensional vector to the trained neural network to classify the second image.

17. The method of claim 16 , wherein the combining includes using a consensus sum to encode the sixth hyperdimensional vector.

18. The non-transitory computer readable medium of claim 11 , wherein the instructions are to cause one or more of the at least one programmable circuit to determine the fourth hyperdimensional vectors based on a permutation operation.

19. The method of claim 16 , wherein the combining of respective ones of the fourth hyperdimensional vectors with corresponding ones of the fifth hyperdimensional vectors is based on a binding operation.

20. The method of claim 16 , including determining the fourth hyperdimensional vectors based on a permutation operation.

Continuity (2)
Continuation 17359520 · Jun 26, 2021
Related Publication 20240112460A1 · Apr 4, 2024
References Cited (54)
US 11574209B2 · Karunaratne · 2023 [cited by examiner]
US 11610115B2 · Kar et al. · 2023 [cited by applicant]
US 11631193B1 · Akbas et al. · 2023 [cited by applicant]
US 11669724B2 · Sallee et al. · 2023 [cited by applicant]
US 11686848B2 · Tu et al. · 2023 [cited by applicant]
US 11854253B2 · Srinivasa · 2023 [cited by applicant]
US 20170262995A1 · Li · 2017 [cited by examiner]
US 20180144208A1 · Lu · 2018 [cited by examiner]
US 20190370598A1 · Martin · 2019 [cited by examiner]
US 20210004648A1 · Ghosh · 2021 [cited by examiner]
US 20210064938A1 · Ahuja et al. · 2021 [cited by applicant]
US 20210117791A1 · Song et al. · 2021 [cited by applicant]
US 20210326756A1 · Khaleghi · 2021 [cited by examiner]
US 20210334703A1 · Salamat · 2021 [cited by examiner]
US 20210342701A1 · Ayush · 2021 [cited by examiner]
US 20220019441A1 · Rosing · 2022 [cited by examiner]
US 20220108135A1 · Brady et al. · 2022 [cited by applicant]
US 20220130019A1 · Jeong et al. · 2022 [cited by applicant]
US 20220147758A1 · Hiromoto · 2022 [cited by examiner]
US 20220277194A1 · Hiromoto et al. · 2022 [cited by applicant]
Kanerva, “Hyperdimensional Computing: An Introduction to Computing in Distributed Representation with High-Dimensional Random Vectors,” Cognitive Computation, vol. 1,, Jan. 28, 2009, 21 pages. [cited by applicant]
Krizhevsky et al., “ImageNet Classification with Deep Convolutional Neural Networks,” Advances in Neural Information Processing Systems 2012, Jan. 2012, 9 pages. [cited by applicant]
Szegedy et al., “Intriguing Properties of Neural Networks,” Proceedings of the International Conference on Learning Representations (ICLR), Feb. 19, 2014, 10 pages. [cited by applicant]
Goodfellow et al., “Explaining and Harnessing Adversarial Examples,” International Conference on Learning Representations (ICLR), Mar. 20, 2015, 11 pages. [cited by applicant]
Nguyen et al., “Deep Neural Networks are Easily Fooled: High Confidence Predictions for Unrecognizable mages,” IEEE Conference on Computer Vision and Pattern Recognition, Jun. 2015, 20 pages. [cited by applicant]
Papernot et al., “The Limitations of Deep Learning in Adversarial Settings,” IEEE European Symposium on Security and Privacy, Nov. 24, 2015, 16 pages. [cited by applicant]
Moosavi-Dezfooli et al., “DeepFool: A Simple and Accurate Method to Fool Deep Neural Networks,” IEEE Conference on Computer Vision and Pattern Recognition, Jun. 2016, 9 pages. [cited by applicant]
Rahimi et al., “Hyperdimensional Computing for Noninvasive Brain-Computer Interfaces: Blind and One-Shot Classification of EEG Error-Related Potentials,” 10th EAI International Conference on Bio-Inspired Information and… [cited by applicant]
Kurakin et al., “Adversarial Machine Learning at Scale,” arXiv:1611.01236, Feb. 11, 2017, 17 pages. [cited by applicant]
Carlini et al., “Towards Evaluating the Robustness of Neural Networks,” 2017 IEEE Symposium on Security and Privacy (SP), IEEE Symposium, IEEE, Mar. 22, 2017, 19 pages. [cited by applicant]
Liu et al., “Towards Robust Neural Networks via Random Self-Ensemble,” ECCV, Dec. 2017, 17 pages. [cited by applicant]
Xie et al., “Mitigating Adversarial Effects Through Randomization,” International Conference on Learning Representations, Feb. 28, 2018, 16 pages. [cited by applicant]
Dhillon et al., “Stochastic Activation Pruning for Robust Adversarial Defense,” International Conference on Learning Representations ICLR, Mar. 5, 2018, 13 pages. [cited by applicant]
Eykholt et al., “Robust Physical-World Attacks on Deep Learning Visual Classification,” IEEE Conference on Computer Vision and Pattern Recognition, Apr. 10, 2018, 10 pages. [cited by applicant]
Song et al., “PixelDefend: Leveraging Generative Models to Understand and Defend Against Adversarial Examples,” International Conference on Learning Representations, May 21, 2018, 20 pages. [cited by applicant]
Athalye et al., “Synthesizing Robust Adversarial Examples,” 35th International Conference on Machine Learning, Jul. 2018, 19 pages. [cited by applicant]
Karmon et al., “Localized and Visible Adversarial Noise.” 35th International Conference on Machine Learning, Jul. 2018, 9 pages. [cited by applicant]
Biggio et al., “Wild Patterns: Ten Years After the Rise of Adversarial Machine Learning,” Pattern Recognition, vol. 84, Jul. 19, 2018, 17 pages. [cited by applicant]
Sharma et al., “Attacking the Madry Defense Model with L1-Based Adversarial Examples,” ICLR 2018 Workshops, Jul. 27, 2018, 9 pages. [cited by applicant]
Athalye et al., “Obfuscated Gradients Give a False Sense of Security: Circumventing Defenses to Adversarial Examples,” International Conference on Machine Learning, Jul. 31, 2018, 12 pages. [cited by applicant]
Schott et al., “Towards the First Adversarially Robust Neural Network Model on MNIST,” Computer Vision and Pattern Recognition, Sep. 20, 2018, 16 pages. [cited by applicant]
Rakin et al., “Parametric Noise Injection: Trainable Randomness to Improve Deep Neural Network Robustness against Adversarial Attack,” Computer Vision and Pattern Recognition, Nov. 2018, 15 pages. [cited by applicant]
Brendel et al., “Adversarial Vision Challenge,” preprint at https://arxiv.org/abs/1808.01976, Dec. 6, 2018, 10 pages. [cited by applicant]
Mitrokhin et al., “Learning Sensorimotor Control with Neuromorphic Sensors: Toward Hyperdimensional Active Perception,” Science Robotics, May 15, 2019, 11 pages. [cited by applicant]
Madry et al., “Towards Deep Learning Models Resistant to Adversarial Attacks,” International Conference on Learning Representations (ICLR), Sep. 4, 2019, 28 pages. [cited by applicant]
Tsipras et al., “Robustness May be at Odds with Accuracy,” International Conference on Learning Representations (ICLR), 2019, 24 pages. [cited by applicant]
Shafahi et al., “Adversarial training for free!” Advances in Neural Information Processing Systems 32, Nov. 20, 2019, 12 pages. [cited by applicant]
Rusak et al., “Increasing the Robustness of DNNs Against Image Corruptions by Playing the Game of Noise,” International Conference on Learning Representations (ICLR), Jan. 2020, 34 Pages. [cited by applicant]
Wong et al., “Fast is Better Than Free: Revisiting Adversarial Training,” International Conference on Learning Representations (ICLR), Jan. 2020, 17 pages. [cited by applicant]
Mitrokhin et al., “Symbolic Representation and Learning with Hyperdimensional Computing,” Front. Robot. AI, Sec. Computational Intelligence in Robotics, Jun. 9, 2020, 11 pages. [cited by applicant]
Shridhar et al., “ProbAct A Probabilistic Activation Function for Deep Neural Networks,” 12th Annual Workshop on Optimization for Machine Learning (OPT), Jun. 16, 2020, 14 pages. [cited by applicant]
United States Patent and Trademark Office, “Requirement for Restriction/Election,” issued in connection with U.S. Appl. No. 17/359,520, dated Mar. 6, 2023, 6 pages. [cited by applicant]
United States Patent and Trademark Office, “Notice of Allowance and Fee(s) Due,” issued in connection with U.S. Appl. No. 17/359,520, dated Aug. 3, 2023, 8 pages. [cited by applicant]
United States Patent and Trademark Office, “Corrected Notice of Allowabiliy,” issued in connection with U.S. Appl. No. 17/359,520, dated Oct. 10, 2023, 2 pages. [cited by applicant]