Searcharxiv⌕ Search

arXiv subjects

Guanxiong Liu

Publications and source records attributed to Guanxiong Liu.

At least 19 recordsLinked to original sources

A Client-level Assessment of Collaborative Backdoor Poisoning in Non-IID Federated Learning

Federated learning (FL) enables collaborative model training using decentralized private data from multiple clients. While FL has shown robustness against poisoning attacks with basic defenses, our research reveals new vulnerabilities stemming from non-independent and identically distributed (non-IID) data among clients. These vulnerabilities pose a substantial risk of model poisoning in real-world FL scenarios. To demonstrate such vulnerabilities, we develop a novel collaborative backdoor poisoning attack called CollaPois. In this attack, we distribute a single pre-trained model infected with a Trojan to a group of compromised clients. These clients then work together to produce malicious gradients, causing the FL model to consistently converge towards a low-loss region centered around the Trojan-infected model. Consequently, the impact of the Trojan is amplified, especially when the benign clients have diverse local data distributions and scattered local gradients. CollaPois stands out by achieving its goals while involving only a limited number of compromised clients, setting it apart from existing attacks. Also, CollaPois effectively avoids noticeable shifts or degradation in the FL model's performance on legitimate data samples, allowing it to operate stealthily and evade detection by advanced robust FL algorithms. Thorough theoretical analysis and experiments conducted on various benchmark datasets demonstrate the superiority of CollaPois compared to state-of-the-art backdoor attacks. Notably, CollaPois bypasses existing backdoor defenses, especially in scenarios where clients possess diverse data distributions. Moreover, the results show that CollaPois remains effective even when involving a small number of compromised clients. Notably, clients whose local data is closely aligned with compromised clients experience higher risks of backdoor infections.

cs.LG↗

An Adaptive Black-box Defense against Trojan Attacks (TrojDef)

Trojan backdoor is a poisoning attack against Neural Network (NN) classifiers in which adversaries try to exploit the (highly desirable) model reuse property to implant Trojans into model parameters for backdoor breaches through a poisoned training process. Most of the proposed defenses against Trojan attacks assume a white-box setup, in which the defender either has access to the inner state of NN or is able to run back-propagation through it. In this work, we propose a more practical black-box defense, dubbed TrojDef, which can only run forward-pass of the NN. TrojDef tries to identify and filter out Trojan inputs (i.e., inputs augmented with the Trojan trigger) by monitoring the changes in the prediction confidence when the input is repeatedly perturbed by random noise. We derive a function based on the prediction outputs which is called the prediction confidence bound to decide whether the input example is Trojan or not. The intuition is that Trojan inputs are more stable as the misclassification only depends on the trigger, while benign inputs will suffer when augmented with noise due to the perturbation of the classification features. Through mathematical analysis, we show that if the attacker is perfect in injecting the backdoor, the Trojan infected model will be trained to learn the appropriate prediction confidence bound, which is used to distinguish Trojan and benign inputs under arbitrary perturbations. However, because the attacker might not be perfect in injecting the backdoor, we introduce a nonlinear transform to the prediction confidence bound to improve the detection accuracy in practical settings. Extensive empirical evaluations show that TrojDef significantly outperforms the-state-of-the-art defenses and is highly stable under different settings, even when the classifier architecture, the training process, or the hyper-parameters change.

cs.CR↗

Smart Traffic Monitoring System using Computer Vision and Edge Computing

Traffic management systems capture tremendous video data and leverage advances in video processing to detect and monitor traffic incidents. The collected data are traditionally forwarded to the traffic management center (TMC) for in-depth analysis and may thus exacerbate the network paths to the TMC. To alleviate such bottlenecks, we propose to utilize edge computing by equipping edge nodes that are close to cameras with computing resources (e.g. cloudlets). A cloudlet, with limited computing resources as compared to TMC, provides limited video processing capabilities. In this paper, we focus on two common traffic monitoring tasks, congestion detection, and speed detection, and propose a two-tier edge computing based model that takes into account of both the limited computing capability in cloudlets and the unstable network condition to the TMC. Our solution utilizes two algorithms for each task, one implemented at the edge and the other one at the TMC, which are designed with the consideration of different computing resources. While the TMC provides strong computation power, the video quality it receives depends on the underlying network conditions. On the other hand, the edge processes very high-quality video but with limited computing resources. Our model captures this trade-off. We evaluate the performance of the proposed two-tier model as well as the traffic monitoring algorithms via test-bed experiments under different weather as well as network conditions and show that our proposed hybrid edge-cloud solution outperforms both the cloud-only and edge-only solutions.

cs.CV↗

A Synergetic Attack against Neural Network Classifiers combining Backdoor and Adversarial Examples

In this work, we show how to jointly exploit adversarial perturbation and model poisoning vulnerabilities to practically launch a new stealthy attack, dubbed AdvTrojan. AdvTrojan is stealthy because it can be activated only when: 1) a carefully crafted adversarial perturbation is injected into the input examples during inference, and 2) a Trojan backdoor is implanted during the training process of the model. We leverage adversarial noise in the input space to move Trojan-infected examples across the model decision boundary, making it difficult to detect. The stealthiness behavior of AdvTrojan fools the users into accidentally trust the infected model as a robust classifier against adversarial examples. AdvTrojan can be implemented by only poisoning the training data similar to conventional Trojan backdoor attacks. Our thorough analysis and extensive experiments on several benchmark datasets show that AdvTrojan can bypass existing defenses with a success rate close to 100% in most of our experimental scenarios and can be extended to attack federated learning tasks as well.

cs.CR↗

CheXclusion: Fairness gaps in deep chest X-ray classifiers

Machine learning systems have received much attention recently for their ability to achieve expert-level performance on clinical tasks, particularly in medical imaging. Here, we examine the extent to which state-of-the-art deep learning classifiers trained to yield diagnostic labels from X-ray images are biased with respect to protected attributes. We train convolution neural networks to predict 14 diagnostic labels in 3 prominent public chest X-ray datasets: MIMIC-CXR, Chest-Xray8, CheXpert, as well as a multi-site aggregation of all those datasets. We evaluate the TPR disparity -- the difference in true positive rates (TPR) -- among different protected attributes such as patient sex, age, race, and insurance type as a proxy for socioeconomic status. We demonstrate that TPR disparities exist in the state-of-the-art classifiers in all datasets, for all clinical tasks, and all subgroups. A multi-source dataset corresponds to the smallest disparities, suggesting one way to reduce bias. We find that TPR disparities are not significantly correlated with a subgroup's proportional disease burden. As clinical models move from papers to products, we encourage clinical decision makers to carefully audit for algorithmic disparities prior to deployment. Our code can be found at, https://github.com/LalehSeyyed/CheXclusion

cs.CV↗

ManiGen: A Manifold Aided Black-box Generator of Adversarial Examples

Machine learning models, especially neural network (NN) classifiers, have acceptable performance and accuracy that leads to their wide adoption in different aspects of our daily lives. The underlying assumption is that these models are generated and used in attack free scenarios. However, it has been shown that neural network based classifiers are vulnerable to adversarial examples. Adversarial examples are inputs with special perturbations that are ignored by human eyes while can mislead NN classifiers. Most of the existing methods for generating such perturbations require a certain level of knowledge about the target classifier, which makes them not very practical. For example, some generators require knowledge of pre-softmax logits while others utilize prediction scores. In this paper, we design a practical black-box adversarial example generator, dubbed ManiGen. ManiGen does not require any knowledge of the inner state of the target classifier. It generates adversarial examples by searching along the manifold, which is a concise representation of input data. Through extensive set of experiments on different datasets, we show that (1) adversarial examples generated by ManiGen can mislead standalone classifiers by being as successful as the state-of-the-art white-box generator, Carlini, and (2) adversarial examples generated by ManiGen can more effectively attack classifiers with state-of-the-art defenses.

cs.CR↗

Using Single-Step Adversarial Training to Defend Iterative Adversarial Examples

Adversarial examples have become one of the largest challenges that machine learning models, especially neural network classifiers, face. These adversarial examples break the assumption of attack-free scenario and fool state-of-the-art (SOTA) classifiers with insignificant perturbations to human. So far, researchers achieved great progress in utilizing adversarial training as a defense. However, the overwhelming computational cost degrades its applicability and little has been done to overcome this issue. Single-Step adversarial training methods have been proposed as computationally viable solutions, however they still fail to defend against iterative adversarial examples. In this work, we first experimentally analyze several different SOTA defense methods against adversarial examples. Then, based on observations from experiments, we propose a novel single-step adversarial training method which can defend against both single-step and iterative adversarial examples. Lastly, through extensive evaluations, we demonstrate that our proposed method outperforms the SOTA single-step and iterative adversarial training defense. Compared with ATDA (single-step method) on CIFAR10 dataset, our proposed method achieves 35.67% enhancement in test accuracy and 19.14% reduction in training time. When compared with methods that use BIM or Madry examples (iterative methods) on CIFAR10 dataset, it saves up to 76.03% in training time with less than 3.78% degeneration in test accuracy.

cs.LG↗

Clinically Accurate Chest X-Ray Report Generation

The automatic generation of radiology reports given medical radiographs has significant potential to operationally and improve clinical patient care. A number of prior works have focused on this problem, employing advanced methods from computer vision and natural language generation to produce readable reports. However, these works often fail to account for the particular nuances of the radiology domain, and, in particular, the critical importance of clinical accuracy in the resulting generated reports. In this work, we present a domain-aware automatic chest X-ray radiology report generation system which first predicts what topics will be discussed in the report, then conditionally generates sentences corresponding to these topics. The resulting system is fine-tuned using reinforcement learning, considering both readability and clinical accuracy, as assessed by the proposed Clinically Coherent Reward. We verify this system on two datasets, Open-I and MIMIC-CXR, and demonstrate that our model offers marked improvements on both language generation metrics and CheXpert assessed accuracy over a variety of competitive baselines.

cs.CV↗

Using Intuition from Empirical Properties to Simplify Adversarial Training Defense

Due to the surprisingly good representation power of complex distributions, neural network (NN) classifiers are widely used in many tasks which include natural language processing, computer vision and cyber security. In recent works, people noticed the existence of adversarial examples. These adversarial examples break the NN classifiers' underlying assumption that the environment is attack free and can easily mislead fully trained NN classifier without noticeable changes. Among defensive methods, adversarial training is a popular choice. However, original adversarial training with single-step adversarial examples (Single-Adv) can not defend against iterative adversarial examples. Although adversarial training with iterative adversarial examples (Iter-Adv) can defend against iterative adversarial examples, it consumes too much computational power and hence is not scalable. In this paper, we analyze Iter-Adv techniques and identify two of their empirical properties. Based on these properties, we propose modifications which enhance Single-Adv to perform competitively as Iter-Adv. Through preliminary evaluation, we show that the proposed method enhances the test accuracy of state-of-the-art (SOTA) Single-Adv defensive method against iterative adversarial examples by up to 16.93% while reducing its training cost by 28.75%.

cs.LG↗

ZK-GanDef: A GAN based Zero Knowledge Adversarial Training Defense for Neural Networks

Neural Network classifiers have been used successfully in a wide range of applications. However, their underlying assumption of attack free environment has been defied by adversarial examples. Researchers tried to develop defenses; however, existing approaches are still far from providing effective solutions to this evolving problem. In this paper, we design a generative adversarial net (GAN) based zero knowledge adversarial training defense, dubbed ZK-GanDef, which does not consume adversarial examples during training. Therefore, ZK-GanDef is not only efficient in training but also adaptive to new adversarial examples. This advantage comes at the cost of small degradation in test accuracy compared to full knowledge approaches. Our experiments show that ZK-GanDef enhances test accuracy on adversarial examples by up-to 49.17% compared to zero knowledge approaches. More importantly, its test accuracy is close to that of the state-of-the-art full knowledge approaches (maximum degradation of 8.46%), while taking much less training time.

cs.LG↗

GanDef: A GAN based Adversarial Training Defense for Neural Network Classifier

Machine learning models, especially neural network (NN) classifiers, are widely used in many applications including natural language processing, computer vision and cybersecurity. They provide high accuracy under the assumption of attack-free scenarios. However, this assumption has been defied by the introduction of adversarial examples -- carefully perturbed samples of input that are usually misclassified. Many researchers have tried to develop a defense against adversarial examples; however, we are still far from achieving that goal. In this paper, we design a Generative Adversarial Net (GAN) based adversarial training defense, dubbed GanDef, which utilizes a competition game to regulate the feature selection during the training. We analytically show that GanDef can train a classifier so it can defend against adversarial examples. Through extensive evaluation on different white-box adversarial examples, the classifier trained by GanDef shows the same level of test accuracy as those trained by state-of-the-art adversarial training defenses. More importantly, GanDef-Comb, a variant of GanDef, could utilize the discriminator to achieve a dynamic trade-off between correctly classifying original and adversarial examples. As a result, it achieves the highest overall test accuracy when the ratio of adversarial examples exceeds 41.7%.

cs.LG↗

Low-Frequency Noise and Sliding of the Charge Density Waves in Two-Dimensional Materials

There has been a recent renewal of interest in charge-density-wave (CDW) phenomena, primarily driven by the emergence of two-dimensional (2D) layered CDW materials, such as 1T-TaS2, characterized by very high transition temperatures to CDW phases. In the extensively studied classical bulk CDW materials with quasi-1D crystal structure, the charge carrier transport exhibits intriguing sliding behavior, which reveals itself in the frequency domain as "narrowband" and "broadband" noise. Despite the increasing attention on physics of 2D CDWs, there have been few reports of CDW sliding, specifically in quasi-2D rare-earth tritellurides and none on the noise in any of 2D CDW systems. Here we report the results of low-frequency noise (LFN) measurements on 1T-TaS2 thin films - archetypal 2D CDW systems, as they are driven from the nearly commensurate (NC) to incommensurate (IC) CDW phases by voltage and temperature stimuli. We have found that noise in 1T-TaS2 devices has two pronounced maxima at the bias voltages, which correspond to the onset of CDW sliding and the NC-to-IC phase transition. We observed unusual Lorentzian noise features and exceptionally strong noise dependence on electric bias and temperature. We argue that LFN in 2D CDW systems has unique physical origin, different from known fundamental noise types. The specifics of LFN in 2D CDW materials can be explained by invoking the concept of interacting discrete fluctuators in the NC-CDW phase. Noise spectroscopy can serve as a useful tool for understanding electronic transport phenomena in 2D CDW materials characterized by coexistence of different phases and strong CDW pinning.

cond-mat.mes-hall↗

Two-Dimensional Oscillatory Neural Network Based on Charge-Density-Wave Devices Operating at Room Temperature

We propose an oscillatory neural network implemented with two-dimensional tantalum disulfide devices operating in the change density wave regime at room temperature. An elementary cell of the network consists of two 1T-TaS2 devices connected in series. Such a cell has constant output and oscillatory states. All cells have the same bias voltage. There is constant current flowing through the cell in the constant output mode. The oscillations occur at a certain bias voltage due to the electrical-field driven metal-to-insulator transition owing to the changes in the charge density wave phase in the 1T-TaS2 channel. Two 1T-TaS2 devices oscillate out-of-phase where one of the devices is in the insulator phase while the other one is in the metallic state. The nearest-neighbor cells are coupled via graphene transistors. The cells are resistively coupled if the graphene transistor is in the On state while they are capacitively coupled if the transistor is in the Off state. The operation of the oscillatory neural network is simulated numerically for the 30x30 node network. The results of our numerical modeling show the formation of artificial vortexes and cellular-automata type data processing. The two-dimensional 1T-TaS2 devices, utilized in the network, offer a unique combination of properties such as scalability, high operational frequency, fast synchronization speed, and radiation hardness, which makes them promising for both consumer electronic and defense applications.

cs.ET↗

Low-Frequency Electronic Noise in Exfoliated Quasi-1D TaSe3 van Der Waals Nanowires

We report results of investigation of the low-frequency electronic excess noise in quasi-1D nanowires of TaSe3 capped with quasi-2D h-BN layers. Semi-metallic TaSe3 is a quasi-1D van der Waals material with exceptionally high breakdown current density. It was found that TaSe3 nanowires have lower levels of the normalized noise spectral density, compared to carbon nanotubes and graphene. The temperature-dependent measurements revealed that the low-frequency electronic 1/f noise becomes the 1/f^2-type as temperature increases to about 400 K, suggesting the onset of electromigration (f is the frequency). Using the Dutta- Horn random fluctuation model of the electronic noise in metals we determined that the noise activation energy for quasi-1D TaSe3 nanowires is approximately E_P=1.0 eV. In the framework of the empirical noise model for metallic interconnects, the extracted activation energy, related to electromigration, is E_A=0.88 eV, consistent with that for Cu and Al interconnects. Our results shed light on the physical mechanism of low-frequency 1/f noise in quasi-1D van der Waals semi-metals and suggest that such material systems have potential for ultimately downscaled local interconnect applications.

cond-mat.mes-hall↗

Breakdown Current Density in BN-Capped Quasi-1D TaSe3 Metallic Nanowires: Prospects of Interconnect Applications

We report results of investigation of the current-carrying capacity of nanowires made from the quasi-1D van der Waals metal tantalum triselenide capped with quasi-2D boron nitride. The chemical vapor transport method followed by chemical and mechanical exfoliation were used to fabricate mm-long TaSe3 wires with lateral dimensions in the 20 to 70 nm range. Electrical measurements establish that TaSe3/h-BN nanowire heterostructures have a breakdown current density exceeding 10 MA/cm2 - an order-of-magnitude higher than that in copper. Some devices exhibited an intriguing step-like breakdown, which can be explained by the atomic thread bundle structure of the nanowires. The quasi-1D single crystal nature of TaSe3 results in low surface roughness and the absence of grain boundaries; these features potentially can enable the downscaling of these wires to lateral dimensions in the few-nm range. These results suggest that quasi-1D van der Waals metals have potential for applications in the ultimately downscaled local interconnects.

cond-mat.mes-hall↗

An Integrated Tantalum Sulfide - Boron Nitride - Graphene Oscillator: A Charge-Density-Wave Device Operating at Room Temperature

The charge-density-wave (CDW) phase is a macroscopic quantum state consisting of a periodic modulation of the electronic charge density accompanied by a periodic distortion of the atomic lattice in quasi-1D or layered 2D metallic crystals. Several layered transition metal dichalcogenides, such as 1T-TaSe2, 1T-TaS2 and 1T-TiSe2, exhibit unusually high transition temperatures to different CDW symmetry-reducing phases. These transitions can be affected by environmental conditions, film thickness and applied electric bias. However, device applications of these intriguing systems at room temperature or their integration with other 2D materials have not been explored. Here we show that in 2D CDW 1T-TaS2, the abrupt change in the electrical conductivity and hysteresis at the transition point between nearly-commensurate and incommensurate charge-density-wave phases can be used for constructing an oscillator that operates at room temperature. The hexagonal boron nitride was capped on 1T-TaS2 thin film to provide protection from oxidation, and an integrated graphene transistor provides a voltage tunable, matched, low-resistance load enabling precise voltage control of the oscillator frequency. The integration of these three disparate two-dimensional materials, in a way that exploits the unique properties of each, yields a simple, miniaturized, voltage-controlled oscillator device. Theoretical considerations suggest that the upper limit of oscillation frequency to be in the THz regime.

cond-mat.mes-hall↗

Suppression of 1/f Noise in Near-Ballistic h-BN-Graphene-h-BN Heterostructure Field-Effect Transistors

We have investigated low-frequency 1/f noise in the boron nitride - grapheme - boron nitride heterostructure field - effect transistors on Si/SiO2 substrates (f is a frequency). The device channel was implemented with a single layer graphene encased between two layers of hexagonal boron nitride. The transistors had the charge carrier mobility in the range from 30000 to 36000 cm2/Vs at room temperature. It was established that the noise spectral density normalized to the channel area in such devices can be suppressed to 5 x 10^-9 μm2 Hz^-1, which is a factor of x5 - x10 lower than that in non-encapsulated graphene devices on Si/SiO2. The physical mechanism of noise suppression was attributed to screening of the charge carriers in the channel from traps in SiO2 gate dielectric and surface defects. The obtained results are important for the electronic and optoelectronic applications of graphene.

cond-mat.mes-hall↗

Graphene-Based Non-Boolean Logic Circuits

Graphene revealed a number of unique properties beneficial for electronics. However, graphene does not have an energy band-gap, which presents a serious hurdle for its applications in digital logic gates. The efforts to induce a band-gap in graphene via quantum confinement or surface functionalization have not resulted in a breakthrough. Here we show that the negative differential resistance experimentally observed in graphene field-effect transistors of "conventional" design allows for construction of viable non-Boolean computational architectures with the gap-less graphene. The negative differential resistance - observed under certain biasing schemes - is an intrinsic property of graphene resulting from its symmetric band structure. Our atomistic modeling shows that the negative differential resistance appears not only in the drift-diffusion regime but also in the ballistic regime at the nanometer-scale - although the physics changes. The obtained results present a conceptual change in graphene research and indicate an alternative route for graphene's applications in information processing.

cond-mat.mes-hall↗