SearcharxivSearch

arXiv subjects

Antonio Cardone

Publications and source records attributed to Antonio Cardone.

4 recordsLinked to original sources

Trojans in Artificial Intelligence (TrojAI) Final Report

The Intelligence Advanced Research Projects Activity (IARPA) launched the TrojAI program to confront an emerging vulnerability in modern artificial intelligence: the threat of AI Trojans. These AI trojans are malicious, hidden backdoors intentionally embedded within an AI model that can cause a system to fail in unexpected ways, or allow a malicious actor to hijack the AI model at will. This multi-year initiative helped to map out the complex nature of the threat, pioneered foundational detection methods, and identified unsolved challenges that require ongoing attention by the burgeoning AI security field. This report synthesizes the program's key findings, including methodologies for detection through weight analysis and trigger inversion, as well as approaches for mitigating Trojan risks in deployed models. Comprehensive test and evaluation results highlight detector performance, sensitivity, and the prevalence of "natural" Trojans. The report concludes with lessons learned and recommendations for advancing AI security research.

cs.CR

AI Model Utilization Measurements For Finding Class Encoding Patterns

This work addresses the problems of (a) designing utilization measurements of trained artificial intelligence (AI) models and (b) explaining how training data are encoded in AI models based on those measurements. The problems are motivated by the lack of explainability of AI models in security and safety critical applications, such as the use of AI models for classification of traffic signs in self-driving cars. We approach the problems by introducing theoretical underpinnings of AI model utilization measurement and understanding patterns in utilization-based class encodings of traffic signs at the level of computation graphs (AI models), subgraphs, and graph nodes. Conceptually, utilization is defined at each graph node (computation unit) of an AI model based on the number and distribution of unique outputs in the space of all possible outputs (tensor-states). In this work, utilization measurements are extracted from AI models, which include poisoned and clean AI models. In contrast to clean AI models, the poisoned AI models were trained with traffic sign images containing systematic, physically realizable, traffic sign modifications (i.e., triggers) to change a correct class label to another label in a presence of such a trigger. We analyze class encodings of such clean and poisoned AI models, and conclude with implications for trojan injection and detection.

cs.LG

Rapid, Quantitative Therapeutic Screening for Alzheimer's Enzymes Enabled by Optimal Signal Transduction with Transistors

We show that simple, commercially sourced n-channel silicon field-effect transistors (nFETs) operating under closed loop control exhibit an ~3-fold improvement in pH readout resolution to (7.2+/-0.3)x10^-3 at a bandwidth of 10 Hz when compared with the open loop operation commonly employed by integrated ion-sensitive field-effect transistors (ISFETs). We leveraged the improved nFET performance to measure the change in solution pH arising from the activity of a pathological form of the kinase Cdk5, an enzyme implicated in Alzheimer's disease, and showed quantitative agreement with previous measurements. The improved pH resolution was realized while the devices were operated in a remote sensing configuration with the pH sensing element off-chip and connected electrically to the FET gate terminal. We compared these results with those measured by using a custom-built dual-gate 2D field-effect transistor (dg2DFET) fabricated with 2D semi-conducting MoS2 channels and a moderate device gain, alpha=8. Under identical solution conditions the pH resolution of the nFETs was only 2-fold worse than the dg2DFETs pH resolution of (3.9+/-0.7)x10^-3. Finally, using the nFETs, we demonstrated the effectiveness of a custom polypeptide, p5, as a therapeutic agent in restoring the function of Cdk5. We expect that the straight-forward modifications to commercially sourced nFETs demonstrated here will lower the barrier to widespread adoption of these remote-gate devices and enable sensitive bioanalytical measurements for high throughput screening in drug discovery and precision medicine applications.

physics.app-ph

Quantum Capacitance-Limited MoS2 Biosensors Enable Remote Label-Free Enzyme Measurements

We have demonstrated atomically thin, quantum capacitance-limited, field-effect transistors (FETs) that enable the detection of pH changes with ~75-fold higher sensitivity (4.4 V/pH) over the Nernst value of 59 mV/pH at room temperature when used as a biosensor. The transistors, which are fabricated from a monolayer of MoS2 with a room temperature ionic liquid (RTIL) in place of a conventional oxide gate dielectric, exhibit very low intrinsic noise resulting in a pH limit of detection (LOD) of 92x10^-6 at 10 Hz. This high device performance, which is a function of the structure of our device, is achieved by remotely connecting the gate to a pH sensing element allowing the FETs to be reused. Because pH measurements are fundamentally important in biotechnology, the low limit of detection demonstrated here will benefit numerous applications ranging from pharmaceutical manufacturing to clinical diagnostics. As an example, we experimentally quantified the function of the kinase Cdk5, an enzyme implicated in Alzheimer's disease, at concentrations that are 5-fold lower than physiological values, and with sufficient time-resolution to allow the estimation of both steady-state and kinetic parameters in a single experiment. The high sensitivity, low LOD and fast turnaround time of the measurements will allow the development of early diagnostic tools and novel therapeutics to detect and treat neurological conditions years before currently possible.

q-bio.QM