Publications (21)
Detection of Adversarial Physical Attacks in Time-Series Image Data
Ramneet Kaur, Yiannis Kantaros, Wenwen Si +2
Deep neural networks (DNN) have become a common sensing modality in autonomous systems as they allow for semantically perceiving the ambient environment given input images. Neverth…
Real-Time Detectors for Digital and Physical Adversarial Inputs to Perception Systems
Yiannis Kantaros, Taylor Carpenter, Kaustubh Sridhar +3
Deep neural network (DNN) models have proven to be vulnerable to adversarial digital and physical attacks. In this paper, we propose a novel attack- and dataset-agnostic and real-t…
Calibrated Prediction with Covariate Shift via Unsupervised Domain Adaptation
Sangdon Park, Osbert Bastani, James Weimer +1
Reliable uncertainty estimates are an important tool for helping autonomous agents or human decision makers understand and leverage predictive models. However, existing approaches…
Curating Naturally Adversarial Datasets for Learning-Enabled Medical Cyber-Physical Systems
Sydney Pugh, Ivan Ruchkin, Insup Lee +1
Deep learning models have shown promising predictive accuracy for time-series healthcare applications. However, ensuring the robustness of these models is vital for building trustw…
CHEF: A Cheap and Fast Pipeline for Iteratively Cleaning Label Uncertainties (Technical Report)
Yinjun Wu, James Weimer, Susan B. Davidson
High-quality labels are expensive to obtain for many machine learning tasks, such as medical image classification tasks. Therefore, probabilistic (weak) labels produced by weak sup…
Towards Alternative Techniques for Improving Adversarial Robustness: Analysis of Adversarial Training at a Spectrum of Perturbations
Kaustubh Sridhar, Souradeep Dutta, Ramneet Kaur +3
Adversarial training (AT) and its variants have spearheaded progress in improving neural network robustness to adversarial perturbations and common corruptions in the last few year…
Improving Classifier Confidence using Lossy Label-Invariant Transformations
Sooyong Jang, Insup Lee, James Weimer
Providing reliable model uncertainty estimates is imperative to enabling robust decision making by autonomous agents and humans alike. While recently there have been significant ad…
Let's Talk Through Physics! Covert Cyber-Physical Data Exfiltration on Air-Gapped Edge Devices
Matthew Chan, Nathaniel Snyder, Marcus Lucas +7
Although organizations are continuously making concerted efforts to harden their systems against network attacks by air-gapping critical systems, attackers continuously adapt and u…
ModelGuard: Runtime Validation of Lipschitz-continuous Models
Taylor J. Carpenter, Radoslav Ivanov, Insup Lee +1
This paper presents ModelGuard, a sampling-based approach to runtime model validation for Lipschitz-continuous models. Although techniques exist for the validation of many classes…
Case Study: Verifying the Safety of an Autonomous Racing Car with a Neural Network Controller
Radoslav Ivanov, Taylor J. Carpenter, James Weimer +3
This paper describes a verification case study on an autonomous racing car with a neural network (NN) controller. Although several verification approaches have been proposed over t…
Resilient Linear Classification: An Approach to Deal with Attacks on Training Data
Sangdon Park, James Weimer, Insup Lee
Data-driven techniques are used in cyber-physical systems (CPS) for controlling autonomous vehicles, handling demand responses for energy management, and modeling human physiology…
Self-Driving Vehicle Verification Towards a Benchmark
Nima Roohi, Ramneet Kaur, James Weimer +2
Industrial cyber-physical systems are hybrid systems with strict safety requirements. Despite not having a formal semantics, most of these systems are modeled using Stateflow/Simul…
A Framework for Checkpointing and Recovery of Hierarchical Cyber-Physical Systems
Kaustubh Sridhar, Radoslav Ivanov, Vuk Lesi +6
This paper tackles the problem of making complex resource-constrained cyber-physical systems (CPS) resilient to sensor anomalies. In particular, we present a framework for checkpoi…
Guaranteed Conformance of Neurosymbolic Models to Natural Constraints
Kaustubh Sridhar, Souradeep Dutta, James Weimer +1
Deep neural networks have emerged as the workhorse for a large section of robotics and control applications, especially as models for dynamical systems. Such data-driven models are…
Confidence Calibration with Bounded Error Using Transformations
Sooyong Jang, Radoslav Ivanov, Insup Lee +1
As machine learning techniques become widely adopted in new domains, especially in safety-critical systems such as autonomous vehicles, it is crucial to provide accurate output unc…
REAFFIRM: Model-Based Repair of Hybrid Systems for Improving Resiliency
Luan Viet Nguyen, Gautam Mohan, James Weimer +3
Model-based design offers a promising approach for assisting developers to build reliable and secure cyber-physical systems (CPSs) in a systematic manner. In this methodology, a de…
Improving Neural Network Robustness via Persistency of Excitation
Kaustubh Sridhar, Oleg Sokolsky, Insup Lee +1
Improving adversarial robustness of neural networks remains a major challenge. Fundamentally, training a neural network via gradient descent is a parameter estimation problem. In a…
Memory-Consistent Neural Networks for Imitation Learning
Kaustubh Sridhar, Souradeep Dutta, Dinesh Jayaraman +2
Imitation learning considerably simplifies policy synthesis compared to alternative approaches by exploiting access to expert demonstrations. For such imitation policies, errors aw…
Exploring with Sticky Mittens: Reinforcement Learning with Expert Interventions via Option Templates
Souradeep Dutta, Kaustubh Sridhar, Osbert Bastani +4
Long horizon robot learning tasks with sparse rewards pose a significant challenge for current reinforcement learning algorithms. A key feature enabling humans to learn challenging…
Resilient Cyberphysical Systems and their Application Drivers: A Technology Roadmap
Somali Chaterji, Parinaz Naghizadeh, Muhammad Ashraful Alam +14
Cyberphysical systems (CPS) are ubiquitous in our personal and professional lives, and they promise to dramatically improve micro-communities (e.g., urban farms, hospitals), macro-…
Verisig: verifying safety properties of hybrid systems with neural network controllers
Radoslav Ivanov, James Weimer, Rajeev Alur +2
This paper presents Verisig, a hybrid system approach to verifying safety properties of closed-loop systems using neural networks as controllers. Although techniques exist for veri…