Boosting Robustness of Deep Neural Networks against Sparsity-aware Adversarial Attacks
Boosting Robustness of Deep Neural Networks against Sparsity-aware Adversarial Attacks
批准号:
580570-2022
负责人:
Atoofian, EhsanE
金额:
$2.19万
依托单位:
依托单位国家:
加拿大
项目类别:
Alliance Grants
财政年份:
2022
资助国家:
加拿大
项目状态:
已结题
起止时间:
2022-01-01 至 2023-12-31
中文摘要
点击翻译按钮获取中文摘要
英文摘要
Deep neural networks (DNNs) are one of the most prominent technologies of our time, as they achieve state-of-the-art performance in a wide range of real-world applications. Despite the success of DNNs, they are vulnerable to adversarial attacks. It has been shown that carefully crafted input perturbations can fool well-trained DNNs. This causes serious concerns in security-sensitive applications such as online banking or autonomous driving. Failure of DNNs to function correctly in the presence of malicious attacks can result in severe consequences such as identity theft, financial losses, and even endangering human lives. In this research project, we focus on a new type of adversarial attack that targets energy and latency of DNNs rather than their accuracy. Over the last few years, DNNs were deployed into mobile devices. Mobile devices have limited power budget as they mostly operate on battery. As a result, defending DNNs against energy-aware adversarial attacks is crucial for success of mobile computing. Exploiting sparse values in DNNs has emerged as an effective technique to improve energy-efficiency of machine learning algorithms in resource-constrained applications. Reducing sparsity increases energy and execution time of DNNs. Despite of significant advancement in defence of DNNs against adversarial attacks over the last few years, there is no solution to defend DNNs against those attacks that target energy based on sparsity. To protect DNNs against these types of attacks, we propose to use the correlation between firing neurons and predictions made by a DNN. Each set of neurons in a DNN are responsible for detecting a specific feature in an input. By monitoring the firing neurons during the inference phase, we can detect those neurons that are activated maliciously for a given class. The outcome of this project will help Canadian high-tech industry to detect and disable malicious attacks that impact energy consumption of computing systems. In addition, highly-qualified personnel that will be trained through this program will gain valuable experience in the area of robust DNNs which in turn will help Canadian high-tech companies and will give them edge in the area of robust computing.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Approximate Quantum Arithmetic Units
-
批准号:580808-2022
-
项目类别:Alliance Grants
-
资助金额:$1.82万
-
财政年份:2022
-
负责人:Atoofian, EhsanE
-
依托单位:
海外基金