Improving the accuracy and robustness of RRAM-based in-memory computing against RRAM hardware noise and adversarial attacks

Improving the accuracy and robustness of RRAM-based in-memory computing against RRAM hardware noise and adversarial attacks
复制标题

DOI:
10.1088/1361-6641/ac461f
复制
发表时间:
2022-03-01
影响因子:
1.9
通讯作者:
Seo, Jae-Sun
Seo, Jae-Sun
中科院分区:
工程技术4区
文献类型:
--
作者:
Cherupally, Sai Kiran;Meng, Jian;Seo, Jae-Sun

文献摘要

被引文献

相似文献

我们提出了一种新颖的深度神经网络(DNN)训练方案以及电阻式随机存取存储器(RRAM)内存计算(IMC)硬件评估方法,以实现针对RRAM器件/阵列变化的高精度以及针对对抗性输入攻击的更强健性。我们展示了在包括ResNet - 18、AlexNet和VGG在内的先进DNN上评估得到的改进的IMC推理精度结果,这些DNN针对CIFAR - 10数据集采用了二进制、2位和4位激活/权重精度。这些DNN是通过从三个不同的基于RRAM的IMC原型芯片获得的实测噪声数据进行评估的。在这些不同的DNN和IMC芯片测量中,我们表明我们提出的硬件噪声感知DNN训练持续提高了实际IMC硬件的DNN推理精度,对于CIFAR - 10数据集,精度提高了高达8%。我们还分析了我们提出的噪声注入方案对具有1位、2位和4位激活/权重精度的ResNet - 18 DNN的对抗稳健性的影响。我们的结果表明,在对黑盒对抗性输入攻击的稳健性方面提高了高达6%。
We present a novel deep neural network (DNN) training scheme and resistive RAM (RRAM) in-memory computing (IMC) hardware evaluation towards achieving high accuracy against RRAM device/array variations and enhanced robustness against adversarial input attacks. We present improved IMC inference accuracy results evaluated on state-of-the-art DNNs including ResNet-18, AlexNet, and VGG with binary, 2-bit, and 4-bit activation/weight precision for the CIFAR-10 dataset. These DNNs are evaluated with measured noise data obtained from three different RRAM-based IMC prototype chips. Across these various DNNs and IMC chip measurements, we show that our proposed hardware noise-aware DNN training consistently improves DNN inference accuracy for actual IMC hardware, up to 8% accuracy improvement for the CIFAR-10 dataset. We also analyze the impact of our proposed noise injection scheme on the adversarial robustness of ResNet-18 DNNs with 1-bit, 2-bit, and 4-bit activation/weight precision. Our results show up to 6% improvement in the robustness to black-box adversarial input attacks.