Logo do repositório
 

ISEP - DM – Engenharia de Inteligência Artificial

URI permanente para esta coleção:

Navegar

Entradas recentes

A mostrar 1 - 10 de 112
  • Securing retrieval-augmented generation
    Publication . PEREIRA, PEDRO EMANUEL SOUSA; Pereira, Isabel Cecília Correia da Silva Praça Gomes; Maia, Eva Catarina Gomes
    Retrieval-Augmented Generation (RAG) systems improve the factual grounding of language models by retrieving external documents before generating an answer. However, this dependence on external knowledge also creates a security risk, if the retrieval corpus is poisoned, the generated response may become incorrect while still appearing evidence-based. This thesis investigates the robustness of RAG pipelines against knowledge-base poisoning attacks. It rst analyzes how retrieval architecture, retrieval depth, database composition, chunking, dataset characteristics, and generator choice in uence poisoning vulnerability. The results show that robustness is a pipeline-level property, dense and graph-based retrieval are generally more resistant than lexical retrieval, but larger top-K values and poisoned multi-database settings increase exposure to adversarial content. The thesis then introduces Micro Collaborative Poisoning, a distributed attack in which several small, plausible poisoned documents collectively support the same false claim. Experiments show that this attack is less obvious at the document level than stronger concentrated poisoning, yet it can still achieve comparable downstream attack success. Overall, the ndings demonstrate that trustworthy RAG systems require defenses that combine robust retrieval, source integrity, cross-document analysis, and cautious generation.
  • Topology-dependent privacy risks in decentralized federated learning
    Publication . GOUVEIA, JOSÉ INÁCIO ANTUNES DE; Pereira, Isabel Cecília Correia da Silva Praça Gomes; Amorim, Ivone de Fátima da Cruz
    Federated Learning (FL) has established itself as a leading paradigm for collaborative machine learning, allowing participants to train models collectively without sharing their private data. Despite its privacy-preserving design, the periodic exchange of model updates leaves these systems vulnerable to information leakage. Notable threats include Membership Inference Attacks (MIA), which exploit model overfitting to determine if specific data samples were used during training, and Gradient Inversion Attacks (GIA), which attempt to reconstruct the exact training images from shared gradients. While existing literature has proposed various active defenses and investigated privacy risks within star and mesh network topologies, a systematic evaluation of how attack effectiveness evolves across training rounds over a diverse spectrum of network topologies remains a critical research gap. This dissertation presents a comprehensive empirical analysis of how different network topologies influence data privacy in centralized and decentralized FL systems over time. By isolating the network topology as the primary variable, we evaluate the vulnerability of six distinct topologies, star, tree, line, ring, full mesh, and partial mesh, against three MIA variants and a GIA. The experiments were conducted using the MNIST and CIFAR10 datasets under both Independent and Identically Distributed and Non-Independent and Identically Distributed (Non-IID) data distributions to capture the temporal evolution of these attacks across the training rounds. Our findings show that network topologies fundamentally dictate the severity and localization of privacy leakage. For instance, intermediate aggregation in the tree topology acts as a native privacy shield, effectively hiding memorized features from a central root node, though it inadvertently shifts the primary risk to intermediate edge nodes. Furthermore, the analysis reveals that extreme data heterogeneity (Non-IID) significantly aggravates vulnerabilities across all topologies, heavily increasing MIA and GIA success rates on complex visual tasks. Moreover, the results establish that restricting an adversary’s awareness of the broader network topology severely impedes their ability to accurately execute GIA, as successful data reconstruction depends heavily on precise knowledge of the aggregation phase in federated systems. Ultimately, this research highlights that network topology can be strategically leveraged as passive defense mechanisms.
  • Previsão inteligente de falhas microbiológicas em endoscópios descontaminados com quantificação de incerteza
    Publication . PEREIRA, FILIPE DANIEL NOGUEIRA BARBOSA; Sousa, Laura Luciana Cavalcante de; Martinho, Diogo Manuel Pereira
    Os endoscópios flexíveis são dispositivos médicos reutilizáveis sujeitos a ciclos repetidos de utilização clínica e descontaminação por High-Level Disinfection (HLD). Apesar dos protocolos estabelecidos, a vigilância microbiológica revela taxas de contaminação residual com impacto direto na segurança do doente. Os métodos convencionais, baseados em culturas microbiológicas realizadas após o reprocessamento, só identificam falhas depois de o equipamento ter reentrado em circulação. Torna-se, por isso, relevante desenvolver abordagens preditivas que estimem o risco de falha antes de cada ciclo de utilização, a partir de variáveis operacionais, de instrumentação e de manutenção. A dissertação propõe e avalia uma pipeline preditiva integrada para a estimação do risco microbiológico em endoscópios descontaminados, enquadrada como prova de conceito com dados sintéticos. Na ausência de datasets clínicos públicos anotados com desfechos microbiológicos, foi construído um dataset sintético causalmente estruturado, com 30 000 registos e 20 dispositivos simulados, cuja cadeia causal modela a progressão desde a instrumentação e o resíduo orgânico até à qualidade de reprocessamento e ao risco microbiológico acumulado. A variável-alvo microbial_failure foi calibrada para uma prevalência de aproximadamente 15%, num cenário com classe positiva minoritária. Foram comparados três modelos de aprendizagem automática: Regressão Logística como referência linear, Random Forest como referência de ensemble e Extreme Gradient Boosting (XGBoost) como modelo principal, pela compatibilidade com TreeSHAP e pelo desempenho em dados tabulares desbalanceados. O XGBoost calibrado por Platt scaling obteve Area Under the Precision-Recall Curve (AUPRC) de 0,400, Area Under the Receiver Operating Characteristic (AUROC) de 0,753, Brier score de 0,110 e Expected Calibration Error (ECE) de 0,009. A análise de limiares identificou 0,12 como o limiar mínimo com recall ≥ 0,70, captando 70,5% das falhas com valor preditivo negativo de 92,9%, em linha com a assimetria de custos entre falsos negativos e falsos positivos. A explicabilidade foi obtida por TreeSHAP e os fatores dominantes foram a intensidade de instrumentação e o protocolo de reprocessamento. A incerteza das previsões foi quantificada por reamostragem bootstrap, evidenciando previsões geralmente estáveis, com variabilidade acrescida em subconjuntos específicos e uma relação exploratória com a posição face ao limiar operacional. Seis estudos de robustez adicionais confirmaram a coerência interna dos resultados. Foi ainda desenvolvido um protótipo funcional de demonstração académica, integrando predição, incerteza e explicabilidade numa interface de apoio à interpretação. A limitação central é a ausência de validação com dados clínicos reais. Os resultados obtidos são evidência exploratória da viabilidade da abordagem em contexto sintético e não podem ser generalizados sem validação prospetiva independente. O trabalho foi desenvolvido como base metodológica para investigação futura com dados hospitalares reais.
  • An explainable and privacy-preserving machine learning pipeline for early detection of endometriosis leveraging liquid biopsy and minimally-invasive C
    Publication . MANESSE, CIRO MIGUEL POÇAS FERREIRA; Martinho, Diogo Emanuel Pereira; Conceição, Luís Manuel Silva
    Endometriosis a!ects approximately one in ten women of reproductive age, yet it is diagnosed, on average, seven to eight years after the onset of symptoms, and in some studies up to twelve. This diagnostic delay is associated with prolonged symptoms, uncertainty, repeated healthcare contacts and delayed therapeutic intervention, largely because a definitive diagnosis still depends on an invasive surgical procedure, namely laparoscopy. Recent progress in Machine Learning, together with the growing availability of clinical and molecular data, o!ers a realistic opportunity to shorten this interval. This dissertation investigates whether a non-invasive, explainable and privacy-preserving Machine Learning pipeline can support an earlier clinical suspicion of Endometriosis from micro-RNA (miRNA) measured in a blood sample, that is, a liquid biopsy. Three requirements are addressed: the test must be non-invasive; its decisions must be explainable, so that a clinician can examine and verify them; and the training procedure must protect sensitive patient data. To the best of the author’s knowledge, no previous work brings these three properties together for Endometriosis detection. Working exclusively with real, public data, a leakage-safe pipeline was built for the serummiRNA cohort GSE279435 (127 samples; 67 Endometriosis, 60 benign controls). A central observation in understanding the data is that the measurements are left-censored at the assay’s limit of detection, so that a missing value is itself informative. Additionally, every preprocessing step was fitted strictly inside each cross-validation fold to avoid optimistic bias. Five classifiers were compared under nested, repeated, stratified cross-validation. The two strongest (Random Forest and LightGBM) reached an area under the ROC curve of 0.77– 0.78 with balanced sensitivity and specificity, a performance comparable to that of the previously published eleven-miRNA model evaluated on the same cohort. Explainability was provided with SHAP, which makes each prediction inspectable both globally and at the level of an individual patient, allowing the model to be examined rather than trusted blindly. Five of the ten most influential miRNAs coincide with the published diagnostic panel, which grounds the model’s reasoning in established biology; the remaining five are plausible additional candidates, consistent with the di!erential-expression analysis, that would warrant follow-up in larger studies. On privacy, this is, to the best of the author’s knowledge, the first work to apply both Di!erential Privacy and Federated Learning to non-invasive miRNA-based Endometriosis detection. In a simulated federated setting, created by partitioning the public cohort into four virtual sites, a Federated Learning implementation built with NVIDIA FLARE trained a shared model without moving any raw data and recovered approximately 95% of the accuracy of a model trained on the pooled data, well above what any single site achieved in isolation. Di!erential Privacy, in contrast, reduced accuracy to little above chance at the privacy levels that would meaningfully protect patients, illustrating how costly strong, sample-level privacy guarantees become when the cohort is this small (n = 127). A cross-platform exploratory test on an independent plasma cohort indicated that the general signal — that circulating miRNA carries an Endometriosis-related signal — holds across biofluids, even though the specific serum signature does not transfer directly to plasma. The contribution of this work is therefore not a higher headline accuracy but a pipeline that, using real public data, reaches the performance of the previously published model while adding two properties that model did not have: explanations a clinician can recognise, and training that never centralises patient data. The proposed pipeline is presented not as a medical device, but as a reproducible and ethically framed foundation for the larger, multiinstitutional validation studies needed to support earlier clinical suspicion of Endometriosis.
  • Sistema multi-agente resiliente para detecção de spam com proteção contra prompt injection
    Publication . SILVA, STÉFANE KATARINE RODRIGUES DA; Pereira, Isabel Cecília Correia da Silva Praça Gomes; Costa, Daniel Duarte
    A proliferação de spam e ataques de phishing representa ameaça crítica à segurança cibernética, com 45,6% do tráfego global de e-mail classificado como malicioso em 2023. Embora Large Language Models (LLMs) demonstrem eficácia superior na detecção contextual de ameaças, sua adoção introduz vulnerabilidades inéditas através de ataques de prompt injection, com taxa de sucesso documentada em 36 modelos comerciais. Esta dissertação propõe um sistema multi-agente resiliente que integra detecção de spam e mitigação de prompt injection através de arquitetura de defesa em profundidade. O sistema implementa seis agentes especializados coordenados pelo framework LangGraph: SanitizationAgent, PromptInjectionAgent, LLMClassifier, HashAnalyzer, MaliciousContentAgent e ResultAggregator. Experimentos em dataset de 1.000 amostras balanceadas demonstraram acurácia de 87%, recall de 92,8% e F1-Score de 86%, superando métodos tradicionais e posicionando-se competitivamente frente a abordagens de Deep Learning. A arquitetura modular permite incorporação de novos agentes sem reestruturação, enquanto mecanismos de tolerância a falhas garantem operação contínua mesmo diante de componentes comprometidos. Os resultados validam a viabilidade de sistemas multi-agente baseados em LLMs para aplicações críticas de segurança cibernética.
  • Desenvolvimento de um Sistema de Reconhecimento Facial para o Instituto Federal do Maranhão (IFMA)
    Publication . SOUSA, RAFAEL NASCIMENTO DE; Ramos, Carlos Fernando da Silva
    Este documento apresenta o estudo e desenvolvimento de um sistema de reconhecimento facial para aplicação no Instituto Federal do Maranhão (IFMA). Este programa tem como objetivo otimizar processos do campus, especialmente a autenticação dos alunos selecionados para o auxílio alimentação. A pesquisa foi feita baseada em algoritmos de aprendizagem profunda (deep learning) e técnicas de otimização dos treinos. Além do desenvolvimento, foi feita também uma pesquisa aprofundada sobre o estado da arte da tecnologia de forma que orientasse os primeiros passos da implementação do software. O principal modelo utilizado na implementação é composto por uma rede siamesa regida por triplet loss. Os resultados indicam uma boa capacidade de reconhecimento e autenticação dos alunos, principalmente em uma base de dados menor, assim como é o objetivo. O projeto também discute os problemas encontrados, como otimização, aprendizado, ferramentas utilizadas e métodos. Também é abordado o tratamento de dados sensíveis como as fotografias de alunos do ensino médio brasileiro.
  • Ensemble AI Solutions for Personalized Sleep Monitoring Using Wrist-worn Wearables
    Publication . SILVA, VASCO ANTÓNIO PORTILHO CARVALHO DA; Conceição, Luis Manuel Silva
    Sleep disorders, including insomnia and sleep apnoea, affect a significant proportion of the global population and are closely linked to cardiovascular, metabolic, and mental health conditions. Accurate and long-term monitoring of sleep is therefore a public health priority, as early detection and personalised management can substantially improve quality of life and reduce healthcare costs. This dissertation explores how wrist-worn wearable devices, combined with advanced machine learning and explainable artificial intelligence (XAI) techniques, can enhance the monitoring and analysis of sleep. While polysomnography (PSG) remains the clinical gold standard for sleep assessment, its cost, intrusiveness, and limited scalability restrict its long-term and widespread applicability. To address these limitations, this work proposes an integrated framework that leverages multimodal data, including photoplethysmography (PPG) and accelerometry, for automatic sleep stage classification and the detection of sleep apnoea. The system incorporates ensemble machine learning models to generate high-quality, personalised insights into sleep quality. Furthermore, explainability is ensured through the application of XAI methods, namely SHAP and LIME, enabling healthcare professionals and end-users to understand and trust model predictions. Experimental validation was conducted using multiple publicly available datasets, demonstrating the system’s robustness and generalisability across heterogeneous populations. Ultimately, this research contributes to the development of transparent, non-invasive, and scalable sleep monitoring solutions. It lays the groundwork for real-world applications in personalised healthcare and the early detection of sleep disorders, promoting better clinical decision-making and long-term well-being.
  • Sistema Conversacional Especializado em Laudos de Honorários e Deontologia Médica com Recurso a Grafos de Conhecimento
    Publication . FARIA, RICARDO MIGUEL PEIXOTO; Faria, Luiz Felipe Rocha de
    Este documento apresenta o desenvolvimento e a avaliação de um sistema conversacional especializado no domínio de laudos de honorários e deontologia médica, com base na framework LightRAG, que combina recuperação de informação com grafos de conhecimento para mitigar alucinações. A partir de um domínio complexo, normativo e sensível, procurou-se garantir respostas factualmente sustentadas em documentos institucionais. A arquitetura implementada alinha a pergunta do utilizador com passagens recuperadas do corpus e com entidades e relações do grafo, o que incentiva uma geração ancorada em evidências. A avaliação do sistema conversacional recorreu a métricas semânticas, onde se observou boa cobertura temática, de 84%, e elevada recuperação do contexto e de entidades, de 93% e 92% correspondente, mas com uma precisão de recuperação e utilização parcial do contexto reduzida, de 24% e 58% respetivamente, coerentes com a utilização de modelos locais de pequena dimensão para embeddings e geração e de um grafo pouco denso, composto por cinquenta (50) nós e cinco (5) relações, o que corresponde a um grau médio de 0.2 e uma densidade de 0.00408. Conclui-se que esta combinação é promissora para domínios críticos, mas a sua eficiência depende da qualidade do grafo, da seletividade do recuperador e da capacidade geradora. Propõe-se, como trabalho futuro, evoluir para modelos de embeddings e LLM de maior dimensão e curadoria contínua do grafo, o que visa maior precisão, melhor uso do contexto e menor probabilidade de alucinação.
  • Um Estudo Comparativo entre CNNs e Vision Transformers para Reconhecimento Facial em Sistemas de Autenticação
    Publication . FERREIRA, GUSTAVO LEVI VIEIRA; Ramos, Carlos Fernando da Silva
    Facial recognition has established itself as one of the most promising solutions for authentication systems, combining practicality, speed, and no explicit interaction on the part of the user. However, its use in real environments raises critical challenges, especially in balancing productivity and security. Spoofing attacks and fraudulent login attempts pose significant threats that can compromise the reliability and security of these systems. Therefore, this thesis proposes a solution that aims to implement a facial recognition-based authentication mechanism capable of combining performance and resilience in the face of multiple attack attempts. To this end, Convolutional Neural Networks (CNNs) and Vision Transformers (ViTs) architectures were explored and compared, evaluating their behavior in terms of speed, performance, and accuracy. The results highlight the advantages and limitations of each approach, providing possible architecture and development for the topic in question in order to achieve a solution that is both useful and secure.
  • ARMS: Augmented Reasoning Multi-Agent System
    Publication . OLIVEIRA, FRANCISCO LUÍS PEREIRA; Gomes, Luís Filipe de Oliveira
    The developments brought by the transformer architecture have sparked a technological revolution that created a wide range of possible use cases where these models are employed as individuals responsible for handling a diverse array of tasks, from chatbots to more deterministic such as API call and control. However, due to the novelty of these models there has been a lack for standardization when developing proper, controlled real implementations. It is assumed that the present time is considered to be an alchemy-like stage of large-language model usage, and many di􀆯erent innovations are born almost every day and everywhere around the world. Great investments are also being made on the field, and there has never been better time to dedicate e􀆯orts into discovering and exploring the limits and capacities of this technology of the future. Multi-agent systems belong to a domain of artificial intelligence that has been in the development for many years resulting in refined and mature architectures, communication protocols, and implementation paradigms. However, implementation might sometimes be di􀆯icult due to the overhead required in orchestrating proper communication protocols, decision engines, and agent architecture. Furthermore, agent-to-human communication is not always seamless since most agents have programmatic-machine language which might not be easy for actors that are not contextualized or are technically inclined to interact with. This dissertation proposes a system that aims to fuse the capabilities of large-language models to communicate through natural language and rationalize inputs with the capabilities that distributed multi-agent systems o􀆯er to resolve tasks that might be present in industrial and smart-building scenarios. Moreover, through the implementation of specific pieces of hardware, referred below as tools, the proposed system tries to increase the degree of impact that decisions made by large-language models have in the environment around them. The system proposed, named “Augmented Reasoning Multi-Agent System” (ARMS), also allows users to communicate directly with agents through natural language conversations facilitating information and desire exchange. Agent-to-Agent communication is also deeply investigated and controlled using specific techniques to manage communication flow and objective-oriented exchanges. Besides a review of the state-of-the-art on topics related to the solution that culminates in a discussion about large-language model-powered agents vs traditional agents, this thesis includes five di􀆯erent that test the solution: basic task delegation, interconnected agents, user registration system, vacation system, and building control. Each of these case studies were built incrementally, meaning that the most basic and core principles were firstly tested on the first use cases, culminating on a final one that integrated multiple components previously tested at a large scale. The results from the case studies demonstrated positive results in achieving a multi-agent system that can manipulate the world around it and establish human communication as needed, leveraging large-language models’ capabilities for the decision-making processes, as well as inter-connection.