Memristor-Based Neuromorphic Hardware Improvement for Privacy-Preserving ANN

Memristor-Based Neuromorphic Hardware Improvement for Privacy-Preserving ANN
复制标题

DOI:
10.1109/tvlsi.2019.2923722
复制
发表时间:
2019-12-01
影响因子:
2.8
通讯作者:
Wang, Jinhui
Wang, Jinhui
中科院分区:
工程技术2区
文献类型:
--
作者:
Fu, Jingyan;Liao, Zhiheng;Wang, Jinhui

文献摘要

被引文献

相似文献

由于人工神经网络(ANN)收集了大量的个人数据,当它被用于与人有关的话题时,引起了人们对隐私保护的极大关注。一个健壮的解决方案是引入噪声注入机制作为差分隐私,它承诺强大的理论隐私保证。然而,带有噪声输入数据的隐私保护人工神经网络存在降低识别精度的重大风险。因此,迫切需要能够在严格保护敏感信息的同时,将用户数据应用于神经网络的技术。本文提出了一种线性优化(LO)方法,通过优化权值更新过程中忆阻器的性能来解决这一精度下降问题。LO方法不遵循传统的硬件和算法,而是通过使用不同的输入脉冲沿分段线计算更新参数。该方法可以减轻记忆电阻的非线性问题,而无需每次预读精确的电流电导,从而避免了复杂的外围电路。分别研究了两段、三段和四段模型下的LO方法的有效性。结果表明,在差分隐私理论要求的不同非线性和不同扰动噪声下,LO方法可将修改后的美国国家标准与技术研究院(MNIST)手写数字的识别准确率平均提高39.67%,为隐私保护技术提供了更大的空间和余地。
Because of collecting a large amount of personal data, when the artificial neural network (ANN) is used in human-related topics, it has raised great concerns on privacy preservation. A robust solution is to introduce a noise injection mechanism as differential privacy that promises strong theoretical privacy guarantees. However, privacy-preserving ANN with noisy input data has a substantial risk of reducing the recognition accuracy. Therefore, it is urgently needed to have technologies that can make users' data applied to neural networks while strictly protecting sensitive information. In this paper, a linear optimization (LO) method is proposed to address this accuracy degradation by optimizing the performance of memristor in weight updating processes. Instead of complying with the traditional hardware and algorithm, the LO method calculates update parameters along a piecewise line by using different input pulses. The proposed method can mitigate the nonlinear problem of memristor without prereading the precise current conductance each time, thereby avoiding complex peripheral circuits. The effectiveness of the proposed LO method with two-segment, three-segment, and four-segment models is investigated, respectively. The results show that under different nonlinearity and different perturbation noise required by differential privacy theory, the LO method can increase the recognition accuracy of Modified National Institute of Standards and Technology (MNIST) handwriting digits by 39.67% on average, which provides more space and margin for privacy-preserving technology.