{"id":36032,"date":"2022-03-01T10:49:26","date_gmt":"2022-03-01T15:49:26","guid":{"rendered":"https:\/\/www.bu.edu\/cise\/?p=36032"},"modified":"2022-03-14T14:55:22","modified_gmt":"2022-03-14T18:55:22","slug":"building-safe-and-trustworthy-ai-systems","status":"publish","type":"post","link":"https:\/\/www.bu.edu\/cise\/building-safe-and-trustworthy-ai-systems\/","title":{"rendered":"Wenchao Li: Building Safe and Trustworthy AI Systems"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">Artificial intelligence (AI) is everywhere, powering applications such as Spotify music suggestions, facial recognition from your smartphone or the ETA of your Uber. Neural networks are also being explored as controllers in a breadth of safety-critical systems, from piloting drones to detecting anomalies in nuclear power plants to maintaining first responder communication systems. At the same time, AI is vulnerable to cyber-attacks that can go undetected. AI is also increasingly complex, making it difficult to understand how the model decides. How can we trust the machine if we don\u2019t fully understand it?\u00a0\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><img loading=\"lazy\" src=\"\/cise\/files\/2017\/02\/Wenchao-Li-pic-for-web.jpg\" alt=\"\" class=\" wp-image-34619 alignleft\" width=\"297\" height=\"297\" srcset=\"https:\/\/www.bu.edu\/cise\/files\/2017\/02\/Wenchao-Li-pic-for-web.jpg 426w, https:\/\/www.bu.edu\/cise\/files\/2017\/02\/Wenchao-Li-pic-for-web-150x150.jpg 150w, https:\/\/www.bu.edu\/cise\/files\/2017\/02\/Wenchao-Li-pic-for-web-300x300.jpg 300w, https:\/\/www.bu.edu\/cise\/files\/2017\/02\/Wenchao-Li-pic-for-web-100x100.jpg 100w\" sizes=\"(max-width: 297px) 100vw, 297px\" \/>Professor Wenchao Li (ECE) leads the <\/span><a href=\"https:\/\/sites.bu.edu\/depend\/\" target=\"_blank\" rel=\"noopener noreferrer\"><span style=\"font-weight: 400;\">Dependable Computing Laboratory<\/span><\/a><span style=\"font-weight: 400;\"> at Boston University where he and his team are addressing these challenges. The researchers have developed a combination of computational proof methods (a.k.a. formal methods) and machine learning techniques to make AI systems more trustworthy.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201cSafety and security concerns are significant hurdles hindering the widespread adoption of AI and AI-enabled systems,\u201d says Wenchao Li, Assistant Professor of Electrical and Computer Engineering (ECE) and Systems Engineering (SE) at Boston University. \u201cLarge-scale deployments of deep learning systems rely critically on their trustworthiness which, in turn, depends on the ability to assess and demonstrate the safety of such systems. There\u2019s still a lack of guarantees on the reliability of these systems.\u201d<\/span><\/p>\n<p><span style=\"font-weight: 400;\">An artificial neural network is a computational model, inspired by the brain, that is trained to learn, recognize patterns, and make decisions. Neural networks are vulnerable to adversarial attacks designed to trick the system, at the input, into making incorrect decisions, at the output. The classic example of this is a stop sign altered by a tiny perturbation designed to fool driverless cars to interpret it as a speed limit sign.\u00a0\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201cThe vulnerability of deep neural networks to adversarial examples has spurred the development of training methods for learning more robust models,\u201d says Li .\u00a0 \u201cThere is also growing recognition in the field that models need to be certified as robust to adversarial examples.\u201d\u00a0\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In their paper entitled<\/span><a href=\"https:\/\/arxiv.org\/pdf\/2008.06081.pdf\" target=\"_blank\" rel=\"noopener noreferrer\"><span style=\"font-weight: 400;\"> Adversarial Training and Provable Robustness<\/span><\/a><span style=\"font-weight: 400;\">, Li and his students present a principled framework called AdvIBP that combines adversarial training and provable robustness verification for training certifiably robust neural networks.\u00a0 In this work, they also present a novel gradient descent method for two-objective optimization that uses moment estimates to address the issue of bias in stochastic multi-gradients. The researchers validated their method on a set of commonly used benchmarks and demonstrated that AdvIBP can learn provably robust neural networks that match or out-perform state-of-art techniques.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201cThis research has the potential to enable the efficient training of robust deep learning systems,\u201d says Li. \u201cIt can help unlock deep learning applications that are currently not deployable due to safety, robustness or security concerns.\u201d<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Li\u2019s research in AI and <\/span><span style=\"font-weight: 400;\">AI-enabled systems<\/span><span style=\"font-weight: 400;\"> address the many multi-dimensional challenges to improving their safety and security, including novel methods and techniques in areas such as reachability analysis for neural-network controlled systems, neural trojan attacks and defenses, neural-network repair and reinforcement learning. With a <\/span>f<span style=\"font-weight: 400;\">ocus on obtaining provable guarantees on systems, their work spans a breadth of applications, from electronic design automation, through multi-robot systems, to self-driving cars. <\/span><span style=\"font-weight: 400;\">\u00a0Learn more about Li\u2019s work <\/span><a href=\"https:\/\/sites.bu.edu\/depend\/research\/\" target=\"_blank\" rel=\"noopener noreferrer\"><span style=\"font-weight: 400;\">here<\/span><\/a><span style=\"font-weight: 400;\">.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u201cNeural networks are hugely important,\u201d says Li.\u00a0 \u201cNeural networks have transformed the way we approach problems in many different applications. Making an impact on these problems has the potential to change people\u2019s lives, not just from the technical aspect but on the actual adoption of these systems.\u201d\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Prior to joining BU, Li was a Computer Scientist in the Computer Science Laboratory at SRI International, Menlo Park. He received a B.S., M.S. and Ph.D. in Electrical Engineering and Computer Sciences and a B.A. in Economics from the University of California, Berkeley. His Ph.D. thesis on specification mining was awarded the ACM Outstanding Ph.D. Dissertation Award in Electronic Design Automation. He also received the Leon O. Chua Award at UC Berkeley for outstanding achievement in the area of nonlinear science.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">His publications can be found <\/span><a href=\"https:\/\/scholar.google.com\/citations?user=zwA5eokAAAAJ&amp;hl=en\" target=\"_blank\" rel=\"noopener noreferrer\"><span style=\"font-weight: 400;\">here<\/span><\/a><span style=\"font-weight: 400;\">.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Artificial intelligence (AI) is everywhere, powering applications such as Spotify music suggestions, facial recognition from your smartphone or the ETA of your Uber. Neural networks are also being explored as controllers in a breadth of safety-critical systems, from piloting drones to detecting anomalies in nuclear power plants to maintaining first responder communication systems. At the [&hellip;]<\/p>\n","protected":false},"author":18553,"featured_media":36038,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[204],"tags":[],"_links":{"self":[{"href":"https:\/\/www.bu.edu\/cise\/wp-json\/wp\/v2\/posts\/36032"}],"collection":[{"href":"https:\/\/www.bu.edu\/cise\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.bu.edu\/cise\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/cise\/wp-json\/wp\/v2\/users\/18553"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/cise\/wp-json\/wp\/v2\/comments?post=36032"}],"version-history":[{"count":10,"href":"https:\/\/www.bu.edu\/cise\/wp-json\/wp\/v2\/posts\/36032\/revisions"}],"predecessor-version":[{"id":36060,"href":"https:\/\/www.bu.edu\/cise\/wp-json\/wp\/v2\/posts\/36032\/revisions\/36060"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.bu.edu\/cise\/wp-json\/wp\/v2\/media\/36038"}],"wp:attachment":[{"href":"https:\/\/www.bu.edu\/cise\/wp-json\/wp\/v2\/media?parent=36032"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.bu.edu\/cise\/wp-json\/wp\/v2\/categories?post=36032"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.bu.edu\/cise\/wp-json\/wp\/v2\/tags?post=36032"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}