Selective Hardening for Neural Networks in FPGAs

Selective Hardening for Neural Networks in FPGAs
复制标题

DOI:
10.1109/tns.2018.2884460
复制
发表时间:
2019-01
影响因子:
1.8
通讯作者:
F. Libano;B. Wilson;Jordan L. Anderson;M. Wirthlin;Carlo Cazzaniga;Christopher D. Frost;P. Rech
F. Libano;B. Wilson;Jordan L. Anderson;M. Wirthlin;Carlo Cazzaniga;Christopher D. Frost;P. Rech
中科院分区:
工程技术3区
文献类型:
--
作者:
F. Libano;B. Wilson;Jordan L. Anderson;M. Wirthlin;Carlo Cazzaniga;Christopher D. Frost;P. Rech

文献摘要

被引文献

相似文献

神经网络正在成为汽车、军事和航空航天市场中自动化车辆的一个有吸引力的解决方案。由于其低成本、低功耗和灵活性,现场可编程门阵列(fpga)是实现神经网络的有前途的设备之一。不幸的是,fpga也被认为容易受到辐射引起的误差。在本文中,我们评估了在基于静态随机存取存储器的fpga中实现的两种神经网络[鸢尾花人工神经网络(ANN)和改进的美国国家标准与技术研究所(MNIST)卷积神经网络(CNN)]的输出正确性中辐射诱导误差的影响。特别是,我们注意到辐射会引起误差,这些误差会在影响或不影响神经网络功能的情况下改变网络的输出。我们称前者为临界错误,后者为可容忍错误。通过详尽的故障注入,我们确定了Iris Flower ANN和MNIST CNN在fpga上实现的部分,一旦损坏,更有可能产生严重或可容忍的错误。基于此分析,我们提出了一种选择性强化策略,该策略仅将神经网络中最脆弱的层复制三倍。通过中子辐射测试,我们的选择性硬化解决方案能够在我们测试的神经网络中以8%的边际开销掩盖40%的故障。
Neural networks are becoming an attractive solution for automatizing vehicles in the automotive, military, and aerospace markets. Thanks to their low-cost, low-power consumption, and flexibility, field-programmable gate arrays (FPGAs) are among the promising devices to implement neural networks. Unfortunately, FPGAs are also known to be susceptible to radiation-induced errors. In this paper, we evaluate the effects of radiation-induced errors in the output correctness of two neural networks [Iris Flower artificial neural network (ANN) and Modified National Institute of Standards and Technology (MNIST) convolutional neural network (CNN)] implemented in static random-access memory-based FPGAs. In particular, we notice that radiation can induce errors that modify the output of the network with or without affecting the neural network’s functionality. We call the former critical errors and the latter tolerable errors. Through exhaustive fault injection, we identify the portions of Iris Flower ANN and MNIST CNN implementation on FPGAs that are more likely, once corrupted, to generate a critical or a tolerable error. Based on this analysis, we propose a selective hardening strategy that triplicates only the most vulnerable layers of the neural network. With neutron radiation testing, our selective hardening solution was able to mask 40% of faults with a marginal 8% overhead in one of our tested neural networks.