AIセキュリティポータル K Program
Improving Robustness Against Adversarial Attacks with Deeply Quantized Neural Networks
Share
Abstract
Reducing the memory footprint of Machine Learning (ML) models, particularly Deep Neural Networks (DNNs), is essential to enable their deployment into resource-constrained tiny devices. However, a disadvantage of DNN models is their vulnerability to adversarial attacks, as they can be fooled by adding slight perturbations to the inputs. Therefore, the challenge is how to create accurate, robust, and tiny DNN models deployable on resource-constrained embedded devices. This paper reports the results of devising a tiny DNN model, robust to adversarial black and white box attacks, trained with an automatic quantizationaware training framework, i.e. QKeras, with deep quantization loss accounted in the learning loop, thereby making the designed DNNs more accurate for deployment on tiny devices. We investigated how QKeras and an adversarial robustness technique, Jacobian Regularization (JR), can provide a co-optimization strategy by exploiting the DNN topology and the per layer JR approach to produce robust yet tiny deeply quantized DNN models. As a result, a new DNN model implementing this cooptimization strategy was conceived, developed and tested on three datasets containing both images and audio inputs, as well as compared its performance with existing benchmarks against various white-box and black-box attacks. Experimental results demonstrated that on average our proposed DNN model resulted in 8.3% and 79.5% higher accuracy than MLCommons/Tiny benchmarks in the presence of white-box and black-box attacks on the CIFAR-10 image dataset and a subset of the Google Speech Commands audio dataset respectively. It was also 6.5% more accurate for black-box attacks on the SVHN image dataset.
A Survey of Deep Neural Network Architectures and their Applications
W. Liu, Z. Wang, X. Liu
Published: 2017
Characterising Across-Stack Optimisations for Deep Convolutional Neural Networks
J. Turner, J. Cano, V. Radu
Published: 2018
Adversarial Machine Learning Attacks and Defense Methods in the Cyber Security Domain
Ihai Rosenberg, Asaf Shabtai, Yuval Elovici, Lior Rokach
Published: 7.6.2020
Adversarial Attacks in Modulation Recognition with Convolutional Neural Networks
Y. Lin, H. Zhao, X. Ma
Published: 2020
OTA-TinyML: Over the Air Deployment of TinyML Models and Execution on IoT Devices
B. Sudharsan, J. G. Breslin, M. Tahir
Published: 2022
TensorFlow Lite Micro: Embedded Machine Learning for TinyML Systems
R. David, J. Duke, A. Jain
Published: 2021
Larq: An Open-Source Library for Training Binarized Neural Networks
L. Geiger, P. Team
Published: 2020
Xilinx/brevitas
A. Pappalardo
Published: 2021
A QKeras Neural Network Zoo for Deeply Quantized Imaging
F. Loro, D. Pau, V. Tomaselli
Published: 2021
Automatic Heterogeneous Quantization of Deep Neural Networks for Low-latency Inference on the Edge for Particle Detectors
L. N. C. Jr, A. Kuusela, S. Li
Published: 2021
Learning Accurate Low-Bit Deep Neural Networks with Stochastic Quantization
Y. Dong, R. Ni, J. Li
Published: 2017
Defensive Quantization: When Efficiency Meets Robustness
Ji Lin, Chuang Gan, Song Han
Published: 4.18.2019
Quanos: Adversarial Noise Sensitivity driven Hybrid Quantization of Neural Networks
P. Panda
Published: 2020
A Survey on Sensor-based Threats and Attacks to Smart Devices and Applications
A. K. Sikder, G. Petracca, H. Aksu
Published: 2021
One pixel attack for fooling deep neural networks
Jiawei Su, Danilo Vasconcellos Vargas, Sakurai Kouichi
Published: 10.25.2017
Project Gradient Descent Adversarial Attack Against Multisource Remote Sensing Image Scene Classification
Y. Jiang, G. Yin, Y. Yuan, Q. Da
Published: 2021
QEBA: Query-Efficient Boundary-Based Blackbox Attack
Huichen Li, Xiaojun Xu, Xiaolu Zhang, Shuang Yang, Bo Li
Published: 5.29.2020
Detecting adversarial samples using influence functions and nearest neighbors
Gilad Cohen, Guillermo Sapiro, Raja Giryes
Published: 2020
WaveGuard: Understanding and Mitigating Audio Adversarial Examples
S. Hussain, P. Neekhara, S. Dubnov
Published: 2021
Luring Transferable Adversarial Perturbations for Deep Neural Networks
R. Bernhard, P.-A. Moellic, J.-M. Dutertre
Published: 2021
Adversarial robustness via fisher-rao regularization
M. Picot, F. Messina, M. Boudiaf, F. Labeau, I.B. Ayed, P. Piantanida
Published: 2022
Robust Large Margin Deep Neural Networks
J. Sokolic, R. Giryes, G. Sapiro, M. R. D. Rodrigues
Published: 2017
A survey of quantization methods for efficient neural network inference
A. Gholami, S. Kim, Z. Dong, Z. Yao, M. W. Mahoney, K. Keutzer
Published: 2022
Online Learning on Tiny Microcontrollers for Anomaly Detection in Water Distribution Systems
D. Pau, A. Khiari, D. Denaro
Published: 2021
Improving Adversarial Robustness in Weight-quantized Neural Networks
C. Song, E. Fallon, H. Li
Published: 2020
Robust Quantization of Deep Neural Networks
Y. Kim, J. Lee, Y. Kim, J. Seo
Published: 2020
On the Adversarial Robustness of Quantized Neural Networks
M. Gorsline, J. Smith, C. Merkel
Published: 2021
Mean-Value Theorem for B-Harmonic Functions
E. Shishkina
Published: 2022
Depthwise Convolution is all you need for Learning Multiple Visual Domains
Y. Guo, Y. Li, L. Wang, T. Rosing
Published: 2019
Enabling Binary Neural Network Training on the Edge
E. Wang, J. J. Davis, D. Moro
Published: 2021
A Comparison of Deep Networks with ReLU Activation Function and Linear Spline-type Methods
K. Eckle, J. Schmidt-Hieber
Published: 2019
Tempered Sigmoid Activations for Deep Learning with Differential Privacy
Nicolas Papernot, Abhradeep Thakurta, Shuang Song, Steve Chien, Úlfar Erlingsson
Published: 7.28.2020
Learning multiple layers of features from tiny images
Alex Krizhevsky, Geoffrey Hinton
Published: 2009
Reading digits in natural images with unsupervised feature learning
Yuval Netzer, Tao Wang, Adam Coates, Alessandro Bissacco, Bo Wu, Andrew Y Ng
Published: 2011
Towards Evaluating the Robustness of Neural Networks
Nicholas Carlini, David Wagner
Published: 8.17.2016
ZOO: Zeroth Order Optimization based Black-box Attacks to Deep Neural Networks without Training Substitute Models
Pin-Yu Chen, Huan Zhang, Yash Sharma, Jinfeng Yi, Cho-Jui Hsieh
Published: 8.14.2017
Adversarial Robustness Toolbox v1.0.0
Maria-Irina Nicolae, Mathieu Sinn, Minh Ngoc Tran, Beat Buesser, Ambrish Rawat, Martin Wistuba, Valentina Zantedeschi, Nathalie Baracaldo, Bryant Chen, Heiko Ludwig, Ian M. Molloy, Ben Edwards
Published: 7.3.2018
Random Noise Defense Against Query-Based Black-Box Attacks
Zeyu Qin, Yanbo Fan, Hongyuan Zha, Baoyuan Wu
Published: 4.23.2021
Cross-Validation
D. Berrar
Published: 2019
Reliable Accuracy Estimates from k-fold Cross Validation
T.-T. Wong, P.-Y. Yeh
Published: 2019
Share