Back to search
MSCA Doctoral Network SPRING Linkedin · Posted 11d ago

DC1 – Physics-informed adversarial robustness of network models

Bielefeld

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

Organisation/Institute: Universität Bielefeld (UNIBI) Germany (www.uni-bielefeld.de)

Supervisor: Prof. Barbara Hammer

Contacts: [email protected];

Project Description

Objectives

The increasing availability of smart components in critical infrastructure offers great promises yet add vulnerability to adversarial attacks. Defense mechanisms rely on adversarial training or numeric methods which increase the stability of models to adversarial perturbations. In the absence of domain knowledge, perturbations are modelled as small but otherwise arbitrary changes. This does not coincide with human perception, nor does it capture vulnerabilities which occur in practice as initially small changes can accumulate via catastrophic resonance. Realistic attacks which model the knowledge of an attacker constitute one promising approach to challenge network intrusion detection. Yet this method does not target interactions caused by physical constraints such as formalized by system invariances. There is a need to better understand adversarial settings given physical constraints, how these can impact smart components in critical infrastructure, and how such vulnerabilities can be avoided.

This DC will transfer concepts of physics-informed learning, to achieve realistic adversarial examples to challenge and improve AI models as regards their robustness to adversarial scenarios. Major challenges are how to model realistic attacks given physical constraints and behavioral observations and how to solve the resulting optimization problems efficiently. We will harvest on recent work which uses generative models to provide additional training data in spatial or temporal learning scenarios and condition training on given physical constraints. Moreover, we will make use of approximations and mixed optimization technologies to target the resulting optimization problems. This way, this individual research project will develop novel efficient technologies for physics-informed generation of adversarial patterns and robust training in spatio-temporal scenarios.

Expected Results

  • A comprehensive theoretical framework how to model physics-informed adversarial attacks.
  • Design of generative models which can be conditioned on physical constraints and which allow adversarial sampling.
  • Realization of the algorithms as open-source toolkit.
  • Transfer of the technologies to the domains of water distribution systems and transportation.

Related bibliography

J. Sande-Rios, J. Canal-Sanchez, C. Manzano-Hernandez and S. Pastrana, "Threat Analysis and Adversarial Model for Smart Grids," in 2024 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW), Vienna, Austria, 2024 pp. 130-145.

Anirban Chakraborty, Manaar Alam, Vishal Dey, Anupam Chattopadhyay, and Debdeep Mukhopadhyay. 2021. A survey on adversarial attacks and defences. CAAI Transactions on Intelligence Technology 6, 1 (March 2021), 25–45. https://doi.org/10.1049/cit2.12028

Jan Philip Göpfert, André Artelt, Heiko Wersing, Barbara Hammer: Adversarial Attacks Hidden in Plain Sight. IDA 2020: 235-247

Roman Schotten, et al., Data for critical infrastructure network modelling of natural hazard impacts: Needs and influence on model characteristics, Resilient Cities and Structures, Volume 3, Issue 1, 2024, Pages 55-65, ISSN 2772-7416, https://doi.org/10.1016/j.rcns.2024.01.002.

Giovanni Apruzzese, Mauro Andreolini, Luca Ferretti, Mirco Marchetti, and Michele Colajanni. 2022. Modeling Realistic Adversarial Attacks against Network Intrusion Detection Systems. Digital Threats 3, 3, Article 31 (September 2022), 19 pages. https://doi.org/10.1145/3469659

I.Ashraf, J. Strotherm, L. Hermes, B. Hammer: Physics-Informed Graph Neural Networks for Water Distribution Systems. AAAI 2024: 21905-21913

Thorben Markmann, Michiel Straat, Barbara Hammer: Koopman-Based Surrogate Modelling of Turbulent Rayleigh-Bénard Convection. IJCNN 2024: 1-8

Philip Kenneweg, Dominik Stallmann, Barbara Hammer: Novel transfer learning schemes based on Siamese networks and synthetic data. Neural Comput. Appl. 35(11): 8423-8436 (2023)

Paul Stahlhofen, A. Artelt, L. Hermes, B. Hammer: Adversarial Attacks on Leakage Detectors in Water Distribution Networks. IWANN (2) 2023: 451-463

Planned Secondments

TUG (AT), Dr. B. Könighofer, M12-M15, 4M, investigate coverage of physically plausible adversarial scenarios by formal bounds;

UCY (CY), Dr. D. Eliade, M27-M30, 4M, transfer of technologies to pump control in water distribution systems;

HRI (DE), Dr. M. Olhofer, M32-35, 4M, transfer of technologies to human interaction in transportation

Specific Requirements for the Project

  • Excellent programming skills, including Python
  • Knowledge of machine learning
  • Experience in deep learning
  • Advanced skills in mathematical modeling

This fellowship requires admission to the Doctoral studies of Intelligent Systems at the CITEC graduate school at the University of Bielefeld.

Salary

Remuneration is based on pay scale 13 of the collective agreement for the public sector in the federal states (TV-L), which currently amounts to a gross monthly salary (Bruttogehalt) of at least EUR 4629.74 (includes social security contributions and mobility allowance). Additional family allowance is provided if applicable.

Download consent form Apply online for these positions

Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search