AdverQuil: an efficient adversarial detection and alleviation technique for black-box neuromorphic computing systems

AdverQuil: an efficient adversarial detection and alleviation technique for black-box neuromorphic computing systems
复制标题

DOI:
10.1145/3287624.3288753
复制
发表时间:
2019-01
期刊:
Proceedings of the 24th Asia and South Pacific Design Automation Conference
影响因子:
--
通讯作者:
Hsin-Pai Cheng;Juncheng Shen;Huanrui Yang;Qing Wu;Hai Helen Li;Yiran Chen
Hsin-Pai Cheng;Juncheng Shen;Huanrui Yang;Qing Wu;Hai Helen Li;Yiran Chen
中科院分区:
其他
文献类型:
--
作者:
Hsin-Pai Cheng;Juncheng Shen;Huanrui Yang;Qing Wu;Hai Helen Li;Yiran Chen

文献摘要

相似文献

近年来,神经形态计算系统(NCS)因其高能量效率而在加速神经网络计算方面获得了广泛的应用。然而,神经网络对敌意攻击的脆弱性引起了网络控制系统的严重安全担忧。此外,在某些应用场景中,用户对NCS的访问权限是有限的。在这种情况下,需要改变NCS训练方法的防御技术变得不可行,例如对抗性训练。在这项工作中,我们提出了AdverQuil-一种有效的黑盒网络控制系统的对抗性检测和缓解技术。AdverQuil可以在不改变原始神经网络的结构/参数或其训练方法的情况下,识别输入样本的对抗性强度,并为NCS选择最优策略来应对攻击。实验结果表明,在MNIST和CIFAR-10数据集上,AdverQuil达到了79.5-167K图像/秒/瓦的高效率。AdverQuil引入的硬件开销不到25%,并可与各种对抗性缓解技术相结合,在硬件成本、能源效率和分类准确性之间提供灵活的权衡。
In recent years, neuromorphic computing systems (NCS) have gained popularity in accelerating neural network computation because of their high energy efficiency. The known vulnerability of neural networks to adversarial attack, however, raises a severe security concern of NCS. In addition, there are certain application scenarios in which users have limited access to the NCS. In such scenarios, defense technologies that require changing the training methods of the NCS, e.g., adversarial training become impracticable. In this work, we propose AdverQuil - an efficient adversarial detection and alleviation technique for black-box NCS. AdverQuil can identify the adversarial strength of input examples and select the best strategy for NCS to respond to the attack, without changing structure/parameter of the original neural network or its training method. Experimental results show that on MNIST and CIFAR-10 datasets, AdverQuil achieves a high efficiency of 79.5 - 167K image/sec/watt. AdverQuil introduces less than 25% of hardware overhead, and can be combined with various adversarial alleviation techniques to provide a flexible trade-off between hardware cost, energy efficiency and classification accuracy.