Leveraging Noise and Aggressive Quantization of In-Memory Computing for Robust DNN Hardware Against Adversarial Input and Weight Attacks
Sai Kiran Cherupally, Adnan Siraj Rakin, Shihui Yin, Mingoo Seok, Deliang Fan, Jae-sun Seo
摘要
In-memory computing (IMC) substantially improves the energy efficiency of deep neural network (DNNs) hardware by activating many rows together and performing analog computing. The noisy analog IMC induces some amount of accuracy drop in hardware acceleration, which is generally considered as a negative effect. However, in this work, we discover that such hardware intrinsic noise can, on the contrary, play a positive role in enhancing adversarial robustness. To achieve that, we propose a new DNN training scheme that integrates measured IMC hardware noise and aggressive partial sum quantization at the IMC crossbar. We show that this effectively improves the robustness of IMC DNN hardware against both adversarial input and weight attacks. Against black-box adversarial input attacks and bit-flip weight attacks, DNN robustness has improved by up to 10.5% (CFAR-10 accuracy) and 33.6% (number of bit-flips), respectively, compared to conventional DNNs.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- On the Intrinsic Robustness of NVM Crossbars Against Adversarial AttacksDeboleena Roy, Indranil Chakraborty, Timur Ibrayev, Kaushik RoyDAC 2021 · 被引用 16 次
- Diversity-aware Weight Perturbation Promotes Robust AdaptationZibo Chen, Ruxin Li, Zilu WangICML 2026
- Reshape and Adapt for Output Quantization (RAOQ): Quantization-aware Training for In-memory Computing SystemsBonan Zhang, Chia-Yu Chen, Naveen VermaICML 2024 · 被引用 9 次
- TFix: Exploiting the Natural Redundancy of Ternary Neural Networks for Fault Tolerant In-Memory Vector Matrix MultiplicationAkul Malhotra, Chunguang Wang, Sumeet Kumar GuptaDAC 2023 · 被引用 4 次
- Defensive approximation: securing CNNs using approximate computingAmira Guesmi, Ihsen Alouani, Khaled N. Khasawneh, Mouna Baklouti 等ASPLOS 2021 · 被引用 46 次
