---
title: "An AI “Vaccine” Can Block Adversarial Attacks"
description: "Scientists developed an AI \"vaccine\" that can make algorithms more resistant to hackers who launch adversarial attacks to try and confuse the systems."
date: "2019-06-20"
modified: "2019-06-20"
authors:
  - name: "Dan Robitzski"
    link: "https://futurism.com/authors/danrobitzski"
url: "https://futurism.com/the-byte/ai-vaccine-block-adversarial-attacks"
categories:
  - "Artificial Intelligence"
tags:
  - "adversarial attacks"
  - "artificial intelligence"
  - "the digest"
---

# An AI “Vaccine” Can Block Adversarial Attacks

![Scientists developed an AI "vaccine" that can make algorithms more resistant to hackers who launch adversarial attacks to try and confuse the systems.](<https://futurism.com/wp-content/uploads/2019/06/ai-vaccine-block-adversarial-attacks.jpg>)
*\<em\>Image: Victor Tangermann\</em\>*

## Virtual Vaccine

For as smart as artificial intelligence systems seem to get, they're still easily confused by hackers who launch so-called adversarial attacks — cyberattacks that trick algorithms into misinterpreting their training data, sometimes to disastrous ends.

In order to [bolster AI's defenses](<https://futurism.com/googles-ai-fight-club-will-train-systems-to-defend-against-future-cyberattacks>) from these dangerous hacks, scientists at the Australian research agency CSIRO [say in a press release](<https://www.csiro.au/en/News/News-releases/2019/Researchers-develop-vaccine-against-attacks-on-machine-learning>) they've created a sort of AI "vaccine" that trains algorithms on weak adversaries so they're better prepared for the real thing — not entirely unlike how vaccines expose our immune systems to inert viruses so they can fight off infections in the future.

## Get Your Shots

CSIRO found that AI systems like those that steer self-driving cars could [easily be tricked](<https://futurism.com/tesla-autopilot-shown-steering-towards-highway-barriers>) into thinking that a stop sign on the side of the road was actually a speed limit sign, a particularly dangerous example of how adversarial attacks could cause harm.

The scientists developed a way to distort the training data fed into an AI system so that it isn't as easily fooled later on, [according to research](<http://proceedings.mlr.press/v97/cranko19a/cranko19a.pdf>) presented at the [International Conference on Machine Learning](<https://icml.cc/>) last week.

"We implement a weak version of an adversary, such as small modifications or distortion to a collection of images, to create a more 'difficult' training data set," Richard Nock, head of machine learning at CSIRO, said in the press release. "When the algorithm is trained on data exposed to a small dose of distortion, the resulting model is more robust and immune to adversarial attacks."

READ MORE: [Researchers develop 'vaccine' against attacks on machine learning](<https://www.csiro.au/en/News/News-releases/2019/Researchers-develop-vaccine-against-attacks-on-machine-learning>) \[CSIRO newsroom\]

More on adversarial attacks: *[To Build Trust In Artificial Intelligence, IBM Wants Developers To Prove Their Algorithms Are Fair](<https://futurism.com/trust-artificial-intelligence-ibm>)*

## Author
Dan Robitzki is a senior reporter for Futurism, where he likes to cover AI, tech ethics, and medicine. He spends his extra time fencing and streaming games from Los Angeles, California.

### Author social links  
[Twitter](<https://x.com/danrobitzski>)