Enhancing the Security of Collaborative Deep Neural Networks: An Examination of the Effect of Low Pass Filters

Enhancing the Security of Collaborative Deep Neural Networks: An Examination of the Effect of Low Pass Filters
复制标题

DOI:
10.1145/3583781.3590299
复制
发表时间:
2023-06
期刊:
Proceedings of the Great Lakes Symposium on VLSI 2023
影响因子:
--
通讯作者:
Adewale A. Adeyemo;S. R. Hasan
Adewale A. Adeyemo;S. R. Hasan
中科院分区:
其他
文献类型:
--
作者:
Adewale A. Adeyemo;S. R. Hasan

文献摘要

相似文献

为了确保在边缘设备上部署深度神经网络 (DNN) 时不影响准确性和延迟,经过训练的 DNN 模型可以跨多个协作边缘设备进行分区以进行推理。然而,这种协作推理范例带来了新的安全风险,因为其中一个协作边缘设备可能是恶意的或受到损害,从而导致推理结果的准确性和可靠性受到损害。为了应对这一挑战,本文探讨了使用低通滤波器来增强协作 DNN 的鲁棒性。该研究部署了一个在德国交通标志识别基准 (GTSRB) 数据集上训练的 VGG16 网络,以及在 ImageNet 数据集上训练的 MobileNet 网络,使用两种流行的协作推理方法。易受攻击的边缘设备的输出特征图 (FM) 使用四种高级对抗噪声进行扰动,即散斑噪声、椒盐噪声、高斯噪声和快速梯度签名方法 (FGSM)。实验结果表明,实施低通滤波可以显着增强协作 DNN 的鲁棒性。平均而言,top-1 分类精度提高了 2.1 倍,使得 DNN 对对抗性攻击更加鲁棒。
To ensure that accuracy and latency are not compromised while deploying Deep Neural Networks (DNNs) on edge devices, trained DNN models can be partitioned across many collaborating edge devices for inference. However, this collaborative inference paradigm raises new security risks because one of the collaborating edge devices could be malicious or compromised, leading to compromised accuracy and reliability of inference results. To address this challenge, this paper explores the use of low-pass filters to enhance the robustness of Collaborative DNNs. The study deploys a VGG16 network, trained on the German Traffic Sign Recognition Benchmarks (GTSRB) dataset, and a MobileNet network trained on the ImageNet dataset, using two prevalent collaborative inference methodologies. The output feature maps (FMs) of a vulnerable edge device are perturbed using four advanced adversarial noises, namely Speckle, Salt-and-Pepper, Gaussian noise, and the Fast Gradient Signed Method (FGSM). Experimental results demonstrate that implementing low-pass filtering can significantly enhance the robustness of Collaborative DNNs. On average, the top-1 classification accuracy is improved by 2.1x times, making the DNNs more robust to adversarial attacks.