课题基金 / 基金详情

Boosting Robustness of Deep Neural Networks against Sparsity-aware Adversarial Attacks

Boosting Robustness of Deep Neural Networks against Sparsity-aware Adversarial Attacks
提高深度神经网络对抗稀疏感知对抗攻击的鲁棒性
批准号:
580570-2022
负责人:
Atoofian, EhsanE
金额:
$2.19万
依托单位:
依托单位国家:
加拿大
项目类别:
Alliance Grants
财政年份:
2022
资助国家:
加拿大
项目状态:
已结题
起止时间:
2022-01-01 至 2023-12-31

项目摘要

项目成果

Atoofian, EhsanE的其他基金

相似基金

相关文献

中文摘要
翻译
深度神经网络(DNN)是我们这个时代最突出的技术之一,因为它们在现实世界的广泛应用中实现了最先进的性能。尽管DNN取得了成功,但它们很容易受到对手的攻击。已经证明,精心设计的输入扰动可以愚弄训练有素的DNN。这在网上银行或自动驾驶等安全敏感应用中引发了严重担忧。在存在恶意攻击的情况下,DNN无法正常运行,可能会导致身份被盗、经济损失,甚至危及人类生命等严重后果。在这个研究项目中,我们专注于一种新型的对抗性攻击,它针对的是DNN的能量和延迟,而不是它们的准确性。在过去的几年里,DNN被部署到移动设备中。移动设备的电力预算有限,因为它们主要依靠电池运行。因此,保护DNN免受能量感知的对手攻击是移动计算成功的关键。利用DNN中的稀疏值来提高机器学习算法在资源受限应用中的能量效率已经成为一种有效的技术。降低稀疏性会增加DNN的能量和执行时间。尽管过去几年在防御DNN对抗攻击方面取得了显著进展,但没有解决方案来防御那些基于稀疏性以能量为目标的攻击。为了保护DNN免受这些类型的攻击,我们建议使用DNN发出的神经元和预测之间的相关性。DNN中的每组神经元负责检测输入中的特定特征。通过在推理阶段监测放电神经元,我们可以检测到针对给定类别被恶意激活的神经元。该项目的成果将有助于加拿大高科技行业检测和阻止影响计算系统能耗的恶意攻击。此外,将通过该计划培训的高素质人员将在稳健的DNN领域获得宝贵的经验,这反过来将帮助加拿大高科技公司,并使它们在稳健计算领域具有优势。
英文摘要
Deep neural networks (DNNs) are one of the most prominent technologies of our time, as they achieve state-of-the-art performance in a wide range of real-world applications. Despite the success of DNNs, they are vulnerable to adversarial attacks. It has been shown that carefully crafted input perturbations can fool well-trained DNNs. This causes serious concerns in security-sensitive applications such as online banking or autonomous driving. Failure of DNNs to function correctly in the presence of malicious attacks can result in severe consequences such as identity theft, financial losses, and even endangering human lives. In this research project, we focus on a new type of adversarial attack that targets energy and latency of DNNs rather than their accuracy. Over the last few years, DNNs were deployed into mobile devices. Mobile devices have limited power budget as they mostly operate on battery. As a result, defending DNNs against energy-aware adversarial attacks is crucial for success of mobile computing. Exploiting sparse values in DNNs has emerged as an effective technique to improve energy-efficiency of machine learning algorithms in resource-constrained applications. Reducing sparsity increases energy and execution time of DNNs. Despite of significant advancement in defence of DNNs against adversarial attacks over the last few years, there is no solution to defend DNNs against those attacks that target energy based on sparsity. To protect DNNs against these types of attacks, we propose to use the correlation between firing neurons and predictions made by a DNN. Each set of neurons in a DNN are responsible for detecting a specific feature in an input. By monitoring the firing neurons during the inference phase, we can detect those neurons that are activated maliciously for a given class. The outcome of this project will help Canadian high-tech industry to detect and disable malicious attacks that impact energy consumption of computing systems. In addition, highly-qualified personnel that will be trained through this program will gain valuable experience in the area of robust DNNs which in turn will help Canadian high-tech companies and will give them edge in the area of robust computing.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
Approximate Quantum Arithmetic Units
  • 批准号:
    580808-2022
  • 项目类别:
    Alliance Grants
  • 资助金额:
    $1.82万
  • 财政年份:
    2022
  • 负责人:
    Atoofian, EhsanE
  • 依托单位:
海外基金