Risk evaluation apparatus, risk evaluation method, and non-transitory computer-readable recording medium

US12292976B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-12292976-B2
Application numberUS-202017782195-A
CountryUS
Kind codeB2
Filing dateJan 14, 2020
Priority dateJan 14, 2020
Publication dateMay 6, 2025
Grant dateMay 6, 2025

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

The risk evaluation apparatus evaluates the risk of a machine learning model. The risk evaluation apparatus includes a recording unit, a loss function regression model acquirer, an attack noise addition unit, an error acquisition unit, and an evaluation unit. The recording unit records a set of predetermined loss functions and a set of pairs of data and labels predetermined. The loss function regression model acquirer determines a regression model of the loss function in the vicinity of data by nonparametric regression. The attack noise addition unit creates attack data that is an Adversarial Example using the regression model. The error acquisition unit determines the error between the output of the machine learning model when the data is input and the output of the machine learning model when the attack data is input. The evaluation unit evaluates the risk based on a set of errors.

First claim

Opening claim text (preview).

The invention claimed is: 1. A risk evaluation apparatus for evaluating a risk of a machine learning model, the risk evaluation apparatus comprising: a recording medium configured to record a set of loss functions that are predetermined and a set of a plurality of pairs of data and labels that are predetermined; and processing circuitry configured to: execute a loss function regression model acquirer process which determines, for each of the loss functions and for each of the plurality of pairs of data and labels, a regression model of the loss function in a vicinity of the data by nonparametric regression; execute an attack noise addition process which creates attack data using the regression model for each of the loss functions and for each of the plurality of pairs of data and labels; execute an error acquisition process which obtains a set of errors, each of which is an error between an output of the machine learning model in a case where the data recorded in the recording medium is input and an output of the machine learning model in a case where the attack data is input for each of the loss functions and for each of the plurality of pairs of data and labels; and execute an evaluation process which evaluates a risk based on the set of errors. 2. The risk evaluation apparatus according to claim 1 , wherein the loss function regression model acquirer process: randomly changes the data in a vicinity of the data in accordance with a predetermined distribution within a space that can be input into the machine learning model, to determine random change data; determines regression training data, the regression training data being a pair of the random change data and a loss value obtained from the loss function in a case where an output of the machine learning model when the random change data is input and the label are input; and determines the regression model using a set of the regression training data. 3. The risk evaluation apparatus according to claim 2 , wherein the random change data is obtained by: adding, to the data, a random number generated in accordance with the predetermined distribution and performing adjustment for obtaining an addition result being within a space that can be input into the machine learning model. 4. The risk evaluation apparatus according to claim 2 , wherein the predetermined distribution is a normal distribution. 5. The risk evaluation apparatus according to claim 1 , wherein the nonparametric regression is a Gaussian process regression. 6. A risk evaluation method for evaluating a risk of a machine learning model, the risk evaluation method comprising: preparing a set of loss functions that are predetermined and a set of a plurality of pairs of data and labels that are predetermined; determining, for each of the loss functions and for each of the plurality of pairs of data and labels, a regression model of the loss function in a vicinity of the data by nonparametric regression; creating, for each of the loss functions and for each of the plurality of pairs of data and labels, attack data being an Adversarial Example using the regression model; obtaining a set of errors, each of which is an error between an output of the machine learning model in a case where the data prepared is input for each of the loss functions and for each of the plurality of pairs of data and labels; and evaluating a risk based on the set of errors. 7. The risk evaluation apparatus according to claim 3 , wherein the predetermined distribution is a normal distribution. 8. The risk evaluation apparatus according to claim 2 , wherein the nonparametric regression is a Gaussian process regression. 9. The risk evaluation apparatus according to claim 3 , wherein the nonparametric regression is a Gaussian process regression. 10. The risk evaluation apparatus according to claim 4 , wherein the nonparametric regression is a Gaussian process regression. 11. A non-transitory computer-readable recording medium storing executable instructions thereon which, when executed by circuitry, cause the executable instructions to perform a method for evaluating a risk of a machine learning model, the method comprising: recording a set of loss functions that are predetermined and a set of a plurality of pairs of data and labels that are predetermined; executing a loss function regression model acquirer process which determines, for each of the loss functions and for each of the plurality of pairs of data and labels, a regression model of the loss function in a vicinity of the data by nonparametric regression; executing an attack noise addition process which creates attack data using the regression model for each of the loss functions and for each of the plurality of pairs of data and labels; executing an error acquisition process which obtains a set of errors, each of which is an error between an output of the machine learning model in a case where the data recorded in the recording medium is input and an output of the machine learning model in a case where the attack data is input for each of the loss functions and for each of the plurality of pairs of data and labels; and executing an evaluation process which evaluates a risk based on the set of errors.

Assignees

Inventors

Classifications

  • Machine learning · CPC title

  • using kernel methods, e.g. support vector machines [SVM] · CPC title

  • G06F21/57Primary

    Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities · CPC title

  • G06F21/577Primary

    Assessing vulnerabilities and evaluating computer system security · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US12292976B2 cover?
The risk evaluation apparatus evaluates the risk of a machine learning model. The risk evaluation apparatus includes a recording unit, a loss function regression model acquirer, an attack noise addition unit, an error acquisition unit, and an evaluation unit. The recording unit records a set of predetermined loss functions and a set of pairs of data and labels predetermined. The loss function r…
Who is the assignee on this patent?
Nippon Telegraph & Telephone
What technology area does this patent fall under?
Primary CPC classification G06F21/57. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue May 06 2025 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 4 related publications on this page (citations in our corpus or others sharing the same primary CPC).