Collaborative Research: SHF: Medium: Approximate Computing for Machine Learning Security: Foundations and Accelerator Design
Collaborative Research: SHF: Medium: Approximate Computing for Machine Learning Security: Foundations and Accelerator Design
批准号:
2212427
负责人:
Khaled Khasawneh
金额:
$40.0万
依托单位:
依托单位国家:
美国
项目类别:
Continuing Grant
财政年份:
2022
资助国家:
美国
项目状态:
未结题
起止时间:
2022-08-01 至 2026-07-31
中文摘要
深度神经网络(dnn)在越来越多的应用领域取得了最先进的性能。然而,它们大规模部署的威胁之一是容易受到对抗性机器学习攻击,攻击者向输入数据注入微小的扰动,导致DNN错误分类,从而产生潜在的危险结果(例如,将停车标志误认为限速标志)。在这个项目中,研究人员将探索如何用近似计算元素构建dnn来提高它们对这些对抗性攻击的鲁棒性。近似计算是一种构建更简单(因此性能更高、更可持续)但不计算操作的确切结果的计算元素的技术。研究人员将探索如何选择近似计算元素,并将其用于构建可持续的深度神经网络加速器,以平衡性能、准确性和安全性。该提案的预期贡献包括对dnn的近似和鲁棒性之间关系的新见解。该项目将探索哪种近似技术可以产生有效的dnn,以平衡准确性、性能、可持续性和对抗攻击的保护,并开发可以在这些维度上找到最佳工作点的优化框架。它还将探讨如何构建专门针对此应用程序的新的近似计算元素。该项目将利用这些发现来构建可持续、高性能和精确的深度神经网络加速器。该项目还将探索其他基于近似计算的技术,以防止威胁dnn安全和隐私的其他类型的攻击,以及不同的深度神经网络学习结构。该项目预计将对机器学习模型的安全性、可持续性和准确性产生重大影响。研究小组将与研究界分享研究的所有副产品。该项目将培养研究生和本科生。研究人员将开发用于机器学习、计算机体系结构和计算机安全课程的新教材。该奖项反映了美国国家科学基金会的法定使命,并通过使用基金会的知识价值和更广泛的影响审查标准进行评估,被认为值得支持。
英文摘要
Deep Neural Networks (DNNs) are achieving state-of-the-art performance on a large and expanding number of application domains. However, one of the threats to their wide-scale deployment is vulnerability to adversarial machine learning attacks, where an adversary injects small perturbations to the input data that cause the DNN to misclassify, with potentially dangerous outcomes (for example, mistaking a stop sign for a speed limit sign). In this project, the researchers will explore how building DNNs with approximate computing elements improves their robustness to these adversarial attacks. Approximate computing is a technique to build computing elements that are simpler (and therefore higher performing and more sustainable) but do not compute the exact result of an operation. The investigators will explore how to select approximate computing elements and use them in building sustainable DNN accelerators that balance performance, accuracy, and security.The proposal's expected contributions include developing new insights into the relationship between approximation and robustness of DNNs. The project will explore what types of approximation techniques result in effective DNNs that balance accuracy, performance, sustainability, and protection against adversarial attacks and develop optimization frameworks that can find optimal operating points along these dimensions. It will also explore how to build new approximate computing elements specifically targeted toward this application. The project will use these findings to build sustainable, performant, and accurate DNN accelerators. The project will also explore other approximate computing-based techniques to protect against other types of attacks threatening the security and privacy of DNNs, as well as for different deep neural network learning structures. The project is expected to have significant impacts on security, sustainability, and accuracy of machine learning models. The research team will share all of the byproducts of the research with the research community. The project will train graduate and undergraduate students. The investigators will develop new educational material for use in machine learning, computer architecture, and computer security classes.This award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
期刊论文(4)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
A Brain-inspired Approach for Malware Detection using Sub-semantic Hardware Features
使用子语义硬件功能检测恶意软件的受大脑启发的方法
DOI:
10.1145/3583781.3590293
发表时间:
2023
期刊:
Proceedings Great Lakes Symposium on VLSI
影响因子:
--
作者:
[Parsa, Maryam, Khasawneh, Khaled N., Alouani, Ihsen]
通讯作者:
Alouani, Ihsen
DOI:
10.1109/tcad.2023.3296379
发表时间:
2023-12
期刊:
IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems
影响因子:
2.9
作者:
[Md. Shohidul Islam;Ihsen Alouani;Khaled N. Khasawneh]
通讯作者:
Md. Shohidul Islam;Ihsen Alouani;Khaled N. Khasawneh
VPP: Privacy Preserving Machine Learning via Undervolting
VPP:通过欠压保护隐私的机器学习
DOI:
10.1109/host55118.2023.10133266
发表时间:
2023
期刊:
IEEE International Symposium on Hardware Oriented Security and Trust (HOST
影响因子:
--
作者:
[Islam, Md Shohidul, Omidi, Behnam, Alouani, Ihsen, Khasawneh, Khaled N.]
通讯作者:
Khasawneh, Khaled N.
Stochastic-HMDs: Adversarial-Resilient Hardware Malware Detectors via Undervolting
随机 HMD:通过欠压实现对抗性弹性硬件恶意软件检测器
DOI:
--
发表时间:
2023
期刊:
Proceedings ACM IEEE Design Automation Conference
影响因子:
--
作者:
[Islam, Md Shohidul, Alouani, Ihsen, Khasawneh, Khaled N.]
通讯作者:
Khasawneh, Khaled N.
Collaborative Research: SaTC: CORE: Medium: Targeted Microarchitectural Attacks and Defenses in Cloud Infrastructure
-
批准号:2155002
-
项目类别:Standard Grant
-
资助金额:$60.0万
-
财政年份:2022
-
负责人:Khaled Khasawneh
-
依托单位:
国内基金
海外基金
登录
查看更多内容
Research on Quantum Field Theory without a Lagrangian Description
-
批准号:24ZR1403900
-
项目类别:省市级项目
-
资助金额:--
-
批准年份:2024
-
负责人:SATOSHI NAWATA
-
依托单位:
Cell Research
-
批准号:31224802
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2012
-
负责人:程磊
-
依托单位:
Cell Research
-
批准号:31024804
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2010
-
负责人:程磊
-
依托单位:
Cell Research (细胞研究)
-
批准号:30824808
-
项目类别:专项基金项目
-
资助金额:24.0万元
-
批准年份:2008
-
负责人:张爱兰
-
依托单位:
Research on the Rapid Growth Mechanism of KDP Crystal
-
批准号:10774081
-
项目类别:面上项目
-
资助金额:45.0万元
-
批准年份:2007
-
负责人:滕冰
-
依托单位: