Achieving Certified Robustness for Brain-Inspired Low-Dimensional Computing Classifiers

Achieving Certified Robustness for Brain-Inspired Low-Dimensional Computing Classifiers
复制标题

DOI:
10.1109/infocomwkshps57453.2023.10225774
复制
发表时间:
2023-05
期刊:
IEEE INFOCOM 2023 - IEEE Conference on Computer Communications Workshops (INFOCOM WKSHPS)
影响因子:
--
通讯作者:
Fangfang Yang;Shijin Duan;Xiaolin Xu;Shaolei Ren
Fangfang Yang;Shijin Duan;Xiaolin Xu;Shaolei Ren
中科院分区:
其他
文献类型:
--
作者:
Fangfang Yang;Shijin Duan;Xiaolin Xu;Shaolei Ren

文献摘要

相似文献

机器学习应用中的大脑启发超维计算(HDC)在能源效率和低延迟方面取得了巨大成功。低维计算(LDC)分类模型的提出,不仅提高了现有基于低维计算的分类模型的推理精度,而且消除了其中的超高维数。然而,LDC模型对抗性扰动的安全性部分尚未被触及。在本文中,我们采用的边界技术,区间边界传播(IBP),训练的LDC分类模型,可证明对$L_{\infty}$ norm-bounded对抗性攻击的鲁棒性。具体来说,我们传播$L_{\infty}$ norm-bounded包围盒周围的原始输入通过层的LDC模型使用区间算法。在传播之后,可以基于输出边界框的上界和下界来计算最坏情况的预测对数。通过最小化最坏情况预测和真实标签之间的损失,预测标签可以在$L_{\infty}$范数有界球内的所有可能的对抗扰动下保持不变。我们评估算法的MNIST和时尚MNIST数据集。实验结果证实,我们训练的模型与IBP表现出强大的投影梯度下降(PGD)攻击和内存错误的鲁棒性。
Brain-inspired hyperdimensional computing (HDC) in machine learning applications has been achieving great success in terms of energy efficiency and low latency. The proposal of low-dimensional computing (LDC) classification model not only improves the inference accuracy of existing HDC-based models but also gets rid of the ultra-high dimension in them. However, the security part of LDC model to adversarial perturbations has not been touched. In this paper, we adopt the bounding technique, interval bound propagation (IBP), to train a LDC classification model that is provably robust against $L_{\infty}$ norm-bounded adversarial attacks. Specifically, we propagate the $L_{\infty}$ norm-bounded bounding box around the original input through layers of LDC model using interval arithmetic. After propagation, the worst case prediction logits can be computed based on the upper bound and the lower bound of the output bounding box. By minimizing the loss between the worst case prediction and the true label, the predicted label could be kept invariant over all possible adversarial perturbations within $L_{\infty}$ norm-bounded ball. We evaluate the algorithm on both MNIST and fashion MNIST datasets. The experiment results corroborate that our trained models with IBP exhibit robustness against strong projected gradient descent (PGD) attacks and memory errors.