Security of Deep Learning
Nicolas Papernot ~ ngp5056@cse.psu.edu PSU CSE - Dr. Patrick McDaniel’s lab 1Security of Deep Learning Nicolas Papernot ~ ngp5056@cse.psu.edu - - PowerPoint PPT Presentation
Security of Deep Learning Nicolas Papernot ~ ngp5056@cse.psu.edu - - PowerPoint PPT Presentation
All parts of this talk should not be further distributed without first contacting the author Security of Deep Learning Nicolas Papernot ~ ngp5056@cse.psu.edu PSU CSE - Dr. Patrick McDaniels lab 1 All parts of this talk should not be further
Neuron
- utput
input input input input
2 All parts of this talk should not be further distributed without first contacting the authorNeural Networks
3 All parts of this talk should not be further distributed without first contacting the authorDanger!
(Artificial) Neural Networks are far from modeling the brain’s behavior
>
4Deep Neural Networks
5 All parts of this talk should not be further distributed without first contacting the authorDeep Neural Networks
All parts of this talk should not be further distributed without first contacting the authorDeep Neural Networks
All parts of this talk should not be further distributed without first contacting the authorDeep Neural Networks
All parts of this talk should not be further distributed without first contacting the authorDeep Neural Networks
All parts of this talk should not be further distributed without first contacting the authorSpeech Recognition as Probabilistic Transduction
Audio Frame State
PhonemeWord
Sentence Meaning Feature Extraction Acoustic Model Decision Trees Lexicon Language Model NLP Source: Tara N. Sainath @ ICML DL Workshop 2015 14 All parts of this talk should not be further distributed without first contacting the authorAdversarial Samples
All parts of this talk should not be further distributed without first contacting the authorNeuron
- utput
input input input input
19 All parts of this talk should not be further distributed without first contacting the authorNeuron
y = ϕ @
m
X
j=0
wjxj 1 A
20 All parts of this talk should not be further distributed without first contacting the authorh2
- w31
w12
w21 w22 All parts of this talk should not be further distributed without first contacting the authorh2
- w31
w12
w21 w22 All parts of this talk should not be further distributed without first contacting the author1
All parts of this talk should not be further distributed without first contacting the authorrF(X)
All parts of this talk should not be further distributed without first contacting the authorh2
- w31
w12
w21 w22 All parts of this talk should not be further distributed without first contacting the authorX = (1, 0.37) X∗ = (1, 0.43)
All parts of this talk should not be further distributed without first contacting the authorF(X) = 0.11 F(X∗) = 0.95
All parts of this talk should not be further distributed without first contacting the authorWhat about Deep Neural Networks?
28 All parts of this talk should not be further distributed without first contacting the author30,000
All parts of this talk should not be further distributed without first contacting the author270,000
All parts of this talk should not be further distributed without first contacting the author97.10%
All parts of this talk should not be further distributed without first contacting the author4.02%
All parts of this talk should not be further distributed without first contacting the authorCurrent Research
All parts of this talk should not be further distributed without first contacting the author