Search NASA⌕ Search

SEARCH · Search NASA

Results for “reconstruction attack”

Search indexed NASA NTRS and DOE OSTI research on propulsion, heat transfer, battery materials and energy systems. Follow report and document links to the original sources.

Quote a phrase for an exact phrase match. Source license links do not imply unrestricted reuse.

OASIS: Offsetting Active Reconstruction Attacks in Federated Learning

Federated Learning (FL) has garnered significant attention for its potential to protect user privacy while enhancing model training efficiency. For that reason, FL has found its use in various domains, from health care to industrial engineering, especially where data cannot be easily exchanged due to sensitive information or privacy laws. However, recent research has demonstrated that FL protocols can be easily compromised by active reconstruction attacks executed by dishonest servers. These attacks involve the malicious modification of global model parameters, allowing the server to obtain a verbatim copy of users' private data by inverting their gradient updates. Tackling this class of attack remains a crucial challenge due to the strong threat model. In this paper, we propose a defense mechanism, namely OASIS, based on image augmentation that effectively counteracts active reconstruction attacks while preserving model performance. We first uncover the core principle of gradient inversion that enables these attacks and theoretically identify the main conditions by which the defense can be robust regardless of the attack strategies. We then construct our defense with image augmentation showing that it can undermine the attack principle. Comprehensive evaluations demonstrate the efficacy of the defense mechanism highlighting its feasibility as a solution.

deep neural networks↗

Securing Federated Learning Against Active Reconstruction Attacks

Federated Learning (FL) has amassed notable attention for its ability to preserve user privacy while emphasizing the retainment of model training efficiency. Due to this potential, FL has been integrated in many domains, such as healthcare, finance, law, and industrial engineering, where data cannot be easily exchanged due to sensitive information and strict privacy laws. However, current research has indicated that FL protocols are easily compromised by active data reconstruction attacks employed by actively dishonest servers. The malicious modification of global model parameters allows an actively dishonest server to obtain a direct copy of users’ private data via gradient inversion. Here, this class of attacks is highly underexplored and continues to be a major challenge due to the intense threat model. In this paper, we propose OASIS as a scalable and modality-agnostic defense based on data augmentation that counteracts active data reconstruction attacks while preserving model performance. To generalize our defense, we uncover the intuition behind gradient inversion that enables these attacks and theoretically establish the conditions by which the defense can be considered robust regardless of attack design. From this, we formulate our defense with data augmentation that illustrates its ability to undermine the attack principle. We evaluate OASIS on five real-world datasets–two image-based (ImageNet and CIFAR100) and three text-based (Wikitext, Stack Overflow, and Shakespeare)–which span diverse uses cases such as vision tasks and language modeling. Comprehensive evaluations on these datasets exhibit the efficacy of OASIS and highlight its feasibility as a solution.

97 MATHEMATICS AND COMPUTING↗

Position-Enhanced Gradient Attack (PEGA) on Medical Language Models

Federated Learning (FL) enables collaborative training of language models on sensitive clinical notes without sharing the data. However, this paradigm is vulnerable to gradient inversion attacks that can reconstruct private data from shared gradients. We find that state-of-the-art attacks are less effective in the medical domain, failing to overcome the unique challenges posed by its specialized vocabulary and unstructured format. To address this, we introduce the Position-Enhanced Gradient Attack (PEGA), a novel attack that makes gradients position-aware by optimizing token and position embeddings simultaneously. PEGA employs two key innovations: a periodic sorting of positional embeddings to resolve token order ambiguity and a late-stage embedding replacement strategy to correct hard-to-recover critical tokens. To evaluate the leakage of sensitive data more directly, we also propose the Unified PHI-Recall (UPHI), a new metric measuring the recovery of Protected Health Information. Experiments on the MIMIC-III dataset show that PEGA significantly outperforms leading attacks like TAG and LAMP, particularly in its ability to reconstruct identifiable patient information, exposing a more severe and nuanced privacy risk in federated medical NLP.

Xu, Nuo [University of Minnesota]↗

3D reconstruction and neural rendering for adversarial machine learning

While evasion attacks on computer vision systems have been widely studied, creating attacks that remain effective under significant changes in viewpoint continues to be challenging. Traditional approaches often rely on affine transformations of images, but these approaches degrade at larger perspective shifts and often produce unrealistic or ineffective perturbations. Recent methods use differentiable renderers to improve viewpoint robustness, but they typically depend on manually constructed 3D models. We introduce a semi-automated pipeline that generates physically printable and perspective-invariant adversarial patches using only a small set of 2D images. Our method integrates 3D reconstruction, neural rendering, adversarial patch optimization, and an object detection victim model into a unified workflow. We use 2D Gaussian Splatting for high fidelity mesh reconstruction and FlexPara for surface parameterization that produces texture maps suitable for patch editing. Together, these components form a fully differentiable pipeline in PyTorch3D that links texture modification to model outputs, enabling efficient optimization of patches that remain effective across many viewpoints. The complete process, from image capture to patch printing and physical evaluation, can be completed within a few hours. We demonstrate the effectiveness of the resulting patches through attacks on the YOLOv8 object detection model and discuss remaining challenges and opportunities for improving robustness and scalability.

Singhvi, Vivaan [ORNL] (ORCID:0009000586288221)↗

Deploying Adversarial Attacks in Super-Resolution Models

Reliable super-resolution methods are crucial for applications like remote sensing, grid resilience and disaster impact analysis, and standoff biometrics. These methods infuse additional high-frequency information into reconstructions, allowing for better contextualization and image intelligence. However, super-resolution models can also introduce hallucinations or other unseen vulnerabilities that could be exploited by an adversary. This is further compounded by the prominence of deep learning in these models, as models are often blindly applied on out-of-distribution images. In this work, we implement adversarial attacks in common open-source super-resolution models and examine their impact on reconstructions and downstream classification tasks. We find that an adversarially trained super-resolution model can produce high-quality reconstructions that degrade downstream classifications. Moreover, these attacks do not require access to low-resolution imagery or class labels at inference time. These results demonstrate the vulnerability of super-resolution methods to malicious actors and motivates the development of a detector for super-resolution adversarial attacks. Further exploration of adversarial attacks in this domain is required to ensure trustworthiness and robustness of super-resolution models for national security applications.

45 MILITARY TECHNOLOGY, WEAPONRY, AND NATIONAL DEF↗

The Double-edged Sword of Data-driven Super-Resolution: Adversarial Super-resolution Models

Data-driven super-resolution (SR) methods are often integrated into imaging pipelines as preprocessing steps to improve downstream tasks such as classification and detection. However, these SR models introduce a previously unexplored attack surface into imaging pipelines. In this paper, we present AdvSR, a framework demonstrating that adversarial behavior can be embedded directly into SR model weights during training, requiring no access to inputs at inference time. Unlike prior attacks that perturb inputs or rely on backdoor triggers, AdvSR operates entirely at the model level. By jointly optimizing for reconstruction quality and targeted adversarial outcomes, AdvSR produces models that appear benign under standard image quality metrics while inducing downstream misclassification. We evaluate AdvSR on three SR architectures (SRCNN, EDSR, SwinIR) paired with a YOLOv11 classifier and demonstrate that AdvSR models can achieve high attack success rates with minimal quality degradation. These findings highlight a new model-level threat for imaging pipelines, with implications for how practitioners source and validate models in safety-critical applications.

Sullivan, Haley [ORNL] (ORCID:0000000274069217)↗

In Situ Conversion of Artificial Proton‐Rich Shell to Inorganic Maskant Toward Stable Single‐Crystal Ni‐Rich Cathode

Single-crystal high-nickel oxide with an integral structure can prevent intergranular cracks and the associated detrimental reactions. Yet, its low surface-to-volume ratio makes surficial degradation a more critical factor in electrochemical performance. Herein, artificial proton-rich (ammonium bicarbonate) shell is successfully introduced on the nickel-rich LiNi 0.92 Co 0.06 Mn 0.02 O 2 single crystals for in situ electrochemically conversing into inorganic maskant to enhance stability of cathode. The process is that the surficial enriched proton, once released from the ammonium bicarbonate shell (proton reservoir) during 1st charge, is immediately captured by LiPF 6 , in situ electrochemically conversing to LiF and Li 3 PO 4 sub-nano particle dense maskant (sub-nano F-&P-maskant). The in situ formed compact nano F-&P-maskant significantly resists the cathode against electrolyte attack and improves the surface stability of particles during long-term cycling. Consequently, this surface modification enables 95% capacity retention after 100 cycles at a high voltage of 4.5 V in the half cell and 83% capacity retention after 800 cycles in the full cell. In conclusion, this work demonstrates a strategy for reconstructing the protective layer using the rational design of surficial enriched proton shells for advanced lithium batteries.

25 ENERGY STORAGE↗

On the Abuse and Detection of Polyglot Files

A polyglot is a file that is valid in two or more formats. Polyglot files pose a problem for file-upload and generative AI web interfaces that rely on format identification to determine how to securely handle incoming files. In this work we found that existing file-format and embedded-file detection tools, even those developed specifically for polyglot files, fail to reliably detect polyglot files used in the wild. To address this issue, we studied the use of polyglot files by malicious actors in the wild, finding 30 polyglot samples and 15 attack chains that leveraged polyglot files. Using knowledge from our survey of polyglot usage in the wild---the first of its kind---we created a novel data set based on adversary techniques. We then trained a machine learning detection solution, PolyConv, using this data set. PolyConv achieves a precision-recall area-under-curve score of 0.999 with an F1 score of 99.20% for polyglot detection and 99.47% for file-format identification, significantly outperforming all other tools tested. We developed a content disarmament and reconstruction tool, ImSan, that successfully sanitized 100% of the tested image-based polyglots, which were the most common type found via the survey. Our work provides concrete tools and suggestions to enable defenders to better defend themselves against polyglot files, as well as directions for future work to create more robust file specifications and methods of disarmament.

Oesch, T [ORNL] (ORCID:0000000269091022)↗

Unlocking the distinctive enzymatic functions of the early plant biomass deconstructive genes in a brown rot fungus by cell-free protein expression

ABSTRACT Saprotrophic fungi that cause brown rot of woody biomass evolved a distinctive mechanism that relies on reactive oxygen species (ROS) to kick-start lignocellulosic polymers’ deconstruction. These ROS agents are generated at incipient decay stages through a series of redox relays that shuttle electrons from fungus’s central metabolism to extracellular Fenton chemistry. A list of genes has been suggested encoding the enzyme catalysts of the redox processes involved in ROS’s function. However, navigating the functions of the encoded enzymes has been challenging due to the lack of a rapid method for protein synthesis. Here, we employed cell-free expression system to synthesize four redox or degradative enzymes, which were identified, by transcriptomic data, as conserved players of the ROS oxidation phase across brown rot fungal species. All four enzymes were successfully expressed and showed activities that enable confident assignment of function, namely, benzoquinone reductase (BQR), ferric reductase, α-L-arabinofuranosidase (ABF), and heme-thiolate peroxidase (HTP). Detailed analysis of their catalytic features within the context of brown rot environments allowed us to interpret their roles during ROS-driven wood decomposition. Specifically, we validated the functions of BQR as the driver redox enzyme of Fenton cycles and reconstructed its interactions with the co-occurring HTP or laccase and ABF. Taken together, this research demonstrated that the cell-free expression platform is adequate for synthesizing functional fungal enzymes and provided an alternative route for the rapid characterization of fungal proteins, escalating our understanding of the distinctive biocatalyst system for plant biomass conversion. IMPORTANCE Brown rot fungi are efficient wood decomposers in nature, and their unique degradative systems harbor untapped catalysts pursued by the biorefinery and bioremediation industries. While the use of “omics” platforms has recently uncovered the key “oxidative-hydrolytic” mechanisms that allow these fungi to attack lignocellulose, individual protein characterization is lagging behind due to the lack of a robust method for rapid synthesis of crucial fungal enzymes. This work delves into the studies of biochemical functions of brown rot enzymes using a rapid, cell-free expression platform, which allowed the successful depictions of enzymes’ catalytic features, their interactions with Fenton chemistry, and their roles played during the incipient stage of brown rot when fungus sets off the reactive oxygen species for oxidative degradation. We expect this research could illuminate cell-free protein expression system’s use to fulfill the increasing need for functional studies of fungal enzymes, advancing the discoveries of novel biomass-converting catalysts.

60 APPLIED LIFE SCIENCES↗