2-in-1 Accelerator: Enabling Random Precision Switch for Winning Both Adversarial Robustness and Efficiency

2-in-1 Accelerator: Enabling Random Precision Switch for Winning Both Adversarial Robustness and Efficiency
复制标题

DOI:
10.1145/3466752.3480082
复制
发表时间:
2021-09
期刊:
MICRO-54: 54th Annual IEEE/ACM International Symposium on Microarchitecture
影响因子:
--
通讯作者:
Yonggan Fu;Yang Zhao;Qixuan Yu;Chaojian Li;Yingyan Lin
Yonggan Fu;Yang Zhao;Qixuan Yu;Chaojian Li;Yingyan Lin
中科院分区:
其他
文献类型:
--
作者:
Yonggan Fu;Yang Zhao;Qixuan Yu;Chaojian Li;Yingyan Lin

文献摘要

被引文献

相似文献

深度神经网络(DNN)最近的突破和数十亿物联网(IoT)设备的出现激发了对配备特定领域DNN加速器的智能IoT设备的爆炸性需求。然而,将DNN加速器支持的智能功能部署到现实世界的物联网设备中仍然特别具有挑战性。首先,强大的DNN通常具有令人望而却步的复杂性,而物联网设备通常受到严格的资源限制。其次,虽然DNN容易受到对抗性攻击,特别是在暴露于复杂现实环境的物联网设备上,但许多物联网应用程序需要严格的安全性。现有的DNN加速器大多只解决上述两个挑战之一(即,效率或对抗鲁棒性),同时忽略或甚至牺牲另一个。为此,我们提出了一个2合1加速器,这是一个集成的算法加速器协同设计框架,旨在赢得DNN加速器的对抗鲁棒性和效率。具体来说,我们首先提出了一种随机精度切换(RPS)算法,该算法可以通过在训练和推理期间将随机DNN量化作为原位模型切换来有效地保护DNN免受对抗性攻击。此外,我们提出了一种新的精度可扩展的加速器,其特征在于(1)一种新的精度可扩展的MAC单元架构,该架构在空间上对时间MAC单元进行平铺,以提高可实现的效率和灵活性,以及(2)由我们的通用加速器优化器搜索的系统优化的并行流。广泛的实验和消融研究验证了我们的2合1加速器不仅可以在各种攻击下积极提高DNN加速器的对抗鲁棒性和效率,而且还可以自然地支持即时鲁棒性-效率权衡,以适应不同的资源,而无需DNN重新训练。我们相信,我们的二合一加速器为强大而高效的加速器设计开辟了一个令人兴奋的前景。
The recent breakthroughs of deep neural networks (DNNs) and the advent of billions of Internet of Things (IoT) devices have excited an explosive demand for intelligent IoT devices equipped with domain-specific DNN accelerators. However, the deployment of DNN accelerator enabled intelligent functionality into real-world IoT devices still remains particularly challenging. First, powerful DNNs often come at prohibitive complexities, whereas IoT devices often suffer from stringent resource constraints. Second, while DNNs are vulnerable to adversarial attacks especially on IoT devices exposed to complex real-world environments, many IoT applications require strict security. Existing DNN accelerators mostly tackle only one of the two aforementioned challenges (i.e., efficiency or adversarial robustness) while neglecting or even sacrificing the other. To this end, we propose a 2-in-1 Accelerator, an integrated algorithm-accelerator co-design framework aiming at winning both the adversarial robustness and efficiency of DNN accelerators. Specifically, we first propose a Random Precision Switch (RPS) algorithm that can effectively defend DNNs against adversarial attacks by enabling random DNN quantization as an in-situ model switch during training and inference. Furthermore, we propose a new precision-scalable accelerator featuring (1) a new precision-scalable MAC unit architecture which spatially tiles the temporal MAC units to boost both the achievable efficiency and flexibility and (2) a systematically optimized dataflow that is searched by our generic accelerator optimizer. Extensive experiments and ablation studies validate that our 2-in-1 Accelerator can not only aggressively boost both the adversarial robustness and efficiency of DNN accelerators under various attacks, but also naturally support instantaneous robustness-efficiency trade-offs adapting to varied resources without the necessity of DNN retraining. We believe our 2-in-1 Accelerator has opened up an exciting perspective for robust and efficient accelerator design.