Relative Robustness of Quantized Neural Networks Against Adversarial Attacks

Relative Robustness of Quantized Neural Networks Against Adversarial Attacks
复制标题

DOI:
10.1109/ijcnn48605.2020.9207596
复制
发表时间:
2020-03
期刊:
2020 International Joint Conference on Neural Networks (IJCNN)
影响因子:
--
通讯作者:
Kirsty Duncan;Ekaterina Komendantskaya;Rob Stewart;M. Lones
Kirsty Duncan;Ekaterina Komendantskaya;Rob Stewart;M. Lones
中科院分区:
其他
文献类型:
--
作者:
Kirsty Duncan;Ekaterina Komendantskaya;Rob Stewart;M. Lones

文献摘要

被引文献

相似文献

神经网络越来越多地被转移到边缘计算设备和智能传感器,以减少延迟和节省带宽。为了将训练好的神经网络放入这些资源受限的设备中,量化等神经网络压缩是必要的。同时,它们在安全关键应用中的使用增加了验证神经网络特性的需要。对抗性扰动有可能被用作对神经网络的攻击机制,导致“明显错误的”错误分类。已经提出了SMT解算器来正式证明对这种对抗性扰动的健壮性保证。我们调查了当神经网络的精度被量化时,这些稳健性保证如何被很好地保持。我们还评估了敌意攻击如何有效地转移到量化神经网络。结果表明,量化神经网络相对于全精度神经网络(98.6%-99.7%)总体上是稳健的,当扰动的细微程度增加时,对抗性攻击的转移率降低到52.05%。这些结果表明,量化引入了对对抗性攻击的转移的弹性,而导致的健壮性损失可以忽略不计。
Neural networks are increasingly being moved to edge computing devices and smart sensors, to reduce latency and save bandwidth. Neural network compression such as quantization is necessary to fit trained neural networks into these resource constrained devices. At the same time, their use in safety-critical applications raises the need to verify properties of neural networks. Adversarial perturbations have potential to be used as an attack mechanism on neural networks, leading to "obviously wrong" misclassification. SMT solvers have been proposed to formally prove robustness guarantees against such adversarial perturbations. We investigate how well these robustness guarantees are preserved when the precision of a neural network is quantized. We also evaluate how effectively adversarial attacks transfer to quantized neural networks. Our results show that quantized neural networks are generally robust relative to their full precision counterpart (98.6%–99.7%), and the transfer of adversarial attacks decreases to as low as 52.05% when the subtlety of perturbation increases. These results show that quantization introduces resilience against transfer of adversarial attacks whilst causing negligible loss of robustness.