Censoring chemical data to mitigate dual use risk

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Campbell, Quintina L., Herington, Jonathan, White, Andrew D.
Natura: Preprint
Pubblicazione: 2023
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866918170175995904
author Campbell, Quintina L.
Herington, Jonathan
White, Andrew D.
author_facet Campbell, Quintina L.
Herington, Jonathan
White, Andrew D.
contents Machine learning models have dual-use potential, potentially serving both beneficial and malicious purposes. The development of open-source models in chemistry has specifically surfaced dual-use concerns around toxicological data and chemical warfare agents. We discuss a chain risk framework identifying three misuse pathways and corresponding mitigation strategies: inference-level, model-level, and data-level. At the data level, we introduce a model-agnostic noising method to increase prediction error in specific desired regions (sensitive regions). Our results show that selective noise induces variance and attenuation bias, whereas simply omitting sensitive data fails to prevent extrapolation. These findings hold for both molecular feature multilayer perceptrons and graph neural networks. Thus, noising molecular structures can enable open sharing of potential dual-use molecular data.
format Preprint
id arxiv_https___arxiv_org_abs_2304_10510
institution arXiv
publishDate 2023
record_format arxiv
spellingShingle Censoring chemical data to mitigate dual use risk
Campbell, Quintina L.
Herington, Jonathan
White, Andrew D.
Machine Learning
Cryptography and Security
Computers and Society
Chemical Physics
Machine learning models have dual-use potential, potentially serving both beneficial and malicious purposes. The development of open-source models in chemistry has specifically surfaced dual-use concerns around toxicological data and chemical warfare agents. We discuss a chain risk framework identifying three misuse pathways and corresponding mitigation strategies: inference-level, model-level, and data-level. At the data level, we introduce a model-agnostic noising method to increase prediction error in specific desired regions (sensitive regions). Our results show that selective noise induces variance and attenuation bias, whereas simply omitting sensitive data fails to prevent extrapolation. These findings hold for both molecular feature multilayer perceptrons and graph neural networks. Thus, noising molecular structures can enable open sharing of potential dual-use molecular data.
title Censoring chemical data to mitigate dual use risk
topic Machine Learning
Cryptography and Security
Computers and Society
Chemical Physics
url https://arxiv.org/abs/2304.10510