50 Lower College Rd, University of Rhode Island, Kingston, RI 02881, USA

https://web.uri.edu/iacr/seminars/ #AI Lab
View map

Please see below for the next talk in the fall seminar series organized by the Institute for AI & Computational Research on AI/ML techniques and applications across various scientific domains. You can find a table of upcoming talks here: https://web.uri.edu/iacr/seminars/.

 

Speaker: Kaleel Mahmood  (URI)

Date/Time/Location: Dec 4, 3pm, Memorial Union room 308.

Title: Busting the Paper Ballot: Voting Meets Adversarial Machine Learning


Abstract: Can adversarial machine learning change the outcome of US election? We present the security risk associated with using machine learning classifiers in United States election tabulators. The central classification task in election tabulation is deciding whether a mark does or does not appear on a bubble associated to an alternative in a contest on the ballot. Barretto et al. (E-Vote-ID 2021) reported that convolutional neural networks are a viable option in this field, as they outperform simple feature-based classifiers. Our contributions to election security can be divided into four parts. To demonstrate and analyze the hypothetical vulnerability of machine learning models on election tabulators, we first introduce four new ballot datasets. Second, we train and test a variety of different models on our new datasets. These models include support vector machines, convolutional neural networks (a basic CNN, VGG and ResNet), and vision transformers (Twins and CaiT). Third, using our new datasets and trained models, we demonstrate that traditional white box attacks are ineffective in the voting domain due to gradient masking. Our analyses further reveal that gradient masking is a product of numerical instability. We use a modified difference of logits ratio loss to overcome this issue (Croce and Hein, ICML 2020). Fourth, in the physical world, we conduct attacks with the adversarial examples generated using our new methods. In traditional adversarial machine learning, a high (50% or greater) attack success rate is ideal. However, for certain elections, even a 5% attack success rate can flip the outcome of a race. We show such an impact is possible in the physical domain.

Event Details

See Who Is Interested

0 people are interested in this event

User Activity

No recent activity