Stochastic-Shield: A Probabilistic Approach Towards Training-Free Adversarial Defense in Quantized CNNs

Stochastic-Shield: A Probabilistic Approach Towards Training-Free Adversarial Defense in Quantized CNNs
复制标题

Stochastic-Shield:一种在量化 CNN 中实现免训练对抗防御的概率方法

DOI:
10.1145/3469261.3469404
复制
发表时间:
2021
期刊:
Proceedings of the 1st Workshop on Security and Privacy for Mobile AI
影响因子:
--
通讯作者:
Partha P. Maji
Partha P. Maji
中科院分区:
--
文献类型:
--
作者:
Lorena Qendro;Sangwon Ha;R. D. Jong;Partha P. Maji

文献摘要

参考文献

被引文献

相似文献

量化神经网络(NN)是在小型硬件平台上高效部署深度学习模型的通用标准。然而,我们注意到量化的神经网络和全精度模型一样容易受到敌意攻击。随着我们随身携带或周围的小型设备上神经网络的激增,需要高效的模型,而不会在存在恶意扰动的情况下牺牲对预测的信任。目前的缓解方法通常需要对抗性培训,或者在增加对抗性例子的强度时被绕过。在这项工作中,我们调查了概率框架如何帮助克服上述量化深度学习模型的限制。我们探索了随机屏蔽:一种灵活的防御机制,它利用了输入过滤层和通过蒙特卡罗退学实现的概率深度学习方法。我们表明,通过准确地启用每个模块,而不需要重新培训或特殊微调,可以共同实现效率和稳健性。
Quantized neural networks (NN) are the common standard to efficiently deploy deep learning models on tiny hardware platforms. However, we notice that quantized NNs are as vulnerable to adversarial attacks as the full-precision models. With the proliferation of neural networks on small devices that we carry or surround us, there is a need for efficient models without sacrificing trust in the prediction in presence of malign perturbations. Current mitigation approaches often need adversarial training or are bypassed when the strength of adversarial examples is increased. In this work, we investigate how a probabilistic framework would assist in overcoming the aforementioned limitations for quantized deep learning models. We explore Stochastic-Shield: a flexible defense mechanism that leverages an input filtering layer and a probabilistic deep learning approach materialized via Monte Carlo dropout. We show that it is possible to jointly achieve efficiency and robustness by accurately enabling each module without the burden of re-retraining or ad hoc fine-tuning.
DOI: --
发表时间: 2017-07
期刊: arXiv: Machine Learning
影响因子: --
作者:
John Bradshaw;A. G. Matthews;Zoubin Ghahramani
通讯作者: John Bradshaw;A. G. Matthews;Zoubin Ghahramani
DOI: --
发表时间: 2018-05
期刊: arXiv: Machine Learning
影响因子: --
作者:
Dimitris Tsipras;Shibani Santurkar;Logan Engstrom;Alexander Turner;A. Madry
通讯作者: Dimitris Tsipras;Shibani Santurkar;Logan Engstrom;Alexander Turner;A. Madry