Adversarial Robustness of Multi-bit Convolutional Neural Networks

被引:0
|
作者
Frickenstein, Lukas [1 ]
Sampath, Shambhavi Balamuthu [1 ]
Mori, Pierpaolo [3 ]
Vemparala, Manoj-Rohit [1 ]
Fasfous, Nael [1 ]
Frickenstein, Alexander [1 ]
Unger, Christian [1 ]
Passerone, Claudio [3 ]
Stechele, Walter [2 ]
机构
[1] BMW Autonomous Driving, Unterschleissheim, Germany
[2] Tech Univ Munich, Munich, Germany
[3] Politecn Torino, Turin, Italy
关键词
Adversarial robustness; Neural network quantization; Multi-bit convolutional neural networks;
D O I
10.1007/978-3-031-47715-7_12
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Deploying convolutional neural networks (CNNs) on resource-constrained, embedded hardware constitutes challenges in balancing task-related accuracy and resource-efficiency. For safety-critical applications, a third optimization objective is crucial, namely the robustness of CNNs. To address these challenges, this paper investigates the tripartite optimization problem of task-related accuracy, resource-efficiency, and adversarial robustness of CNNs by utilizing multi-bit networks (MBNs). To better navigate the tripartite optimization space, this work thoroughly studies the design space of MBNs by varying the number of weight and activation bases. First, the pro-active defensive model MBN3x1 is identified, by conducting a systematic evaluation of the design space. This model achieves better adversarial accuracy (+10.3pp) against the first-order attack PGD-20 and has 1.3x lower bit-operations, with a slight degradation of natural accuracy (-2.4pp) when compared to a 2-bit fixed-point quantized implementation of ResNet-20 on CIFAR-10. Similar observations hold for deeper and wider ResNets trained on different datasets, such as CIFAR-100 and ImageNet. Second, this work shows that the defensive capability of MBNs can be increased by adopting a state-of-the-art adversarial training (AT) method. This results in an improvement of adversarial accuracy (+13.6pp) for MBN3 x 3, with a slight degradation in natural accuracy (-2.4pp) compared to the costly full-precision ResNet-56 on CIFAR-10, which has 7x more bit-operations. To the best of our knowledge, this is the first paper highlighting the improved robustness of differently configured MBNs and providing an analysis on their gradient flows.
引用
收藏
页码:157 / 174
页数:18
相关论文
共 50 条
  • [1] Exploring adversarial examples and adversarial robustness of convolutional neural networks by mutual information
    Zhang J.
    Qian W.
    Cao J.
    Xu D.
    Neural Computing and Applications, 2024, 36 (23) : 14379 - 14394
  • [2] Adversarial Robustness of Vision Transformers Versus Convolutional Neural Networks
    Ali, Kazim
    Bhatti, Muhammad Shahid
    Saeed, Atif
    Athar, Atifa
    Al Ghamdi, Mohammed A.
    Almotiri, Sultan H.
    Akram, Samina
    IEEE ACCESS, 2024, 12 : 105281 - 105293
  • [3] Sanitizing hidden activations for improving adversarial robustness of convolutional neural networks
    Mu, Tianshi
    Lin, Kequan
    Zhang, Huabing
    Wang, Jian
    JOURNAL OF INTELLIGENT & FUZZY SYSTEMS, 2021, 41 (02) : 3993 - 4003
  • [4] PTMQ: Post-training Multi-Bit Quantization of Neural Networks
    Xu, Ke
    Li, Zhongcheng
    Wang, Shanshan
    Zhang, Xingyi
    THIRTY-EIGHTH AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE, VOL 38 NO 14, 2024, : 16193 - 16201
  • [5] Multi-bit informed embedding watermarking with constant robustness
    Mayer, J
    Bermudez, JCM
    2005 International Conference on Image Processing (ICIP), Vols 1-5, 2005, : 689 - 692
  • [6] A Power Efficient Multi-Bit Accelerator for Memory Prohibitive Deep Neural Networks
    Shivapakash, Suhas
    Jain, Hardik
    Hellwich, Olaf
    Gerfers, Friedel
    2020 IEEE INTERNATIONAL SYMPOSIUM ON CIRCUITS AND SYSTEMS (ISCAS), 2020,
  • [7] Improving adversarial robustness of Bayesian neural networks via multi-task adversarial training
    Chen, Xu
    Liu, Chuancai
    Zhao, Yue
    Jia, Zhiyang
    Jin, Ge
    INFORMATION SCIENCES, 2022, 592 : 156 - 173
  • [8] On Robustness and Transferability of Convolutional Neural Networks
    Djolonga, Josip
    Yung, Jessica
    Tschannen, Michael
    Romijnders, Rob
    Beyer, Lucas
    Kolesnikov, Alexander
    Puigcerver, Joan
    Minderer, Matthias
    D'Amour, Alexander
    Moldovan, Dan
    Gelly, Sylvain
    Houlsby, Neil
    Zhai, Xiaohua
    Lucic, Mario
    2021 IEEE/CVF CONFERENCE ON COMPUTER VISION AND PATTERN RECOGNITION, CVPR 2021, 2021, : 16453 - 16463
  • [9] Robustness of Compressed Convolutional Neural Networks
    Wijayanto, Arie Wahyu
    Jin, Choong Jun
    Madhawa, Kaushalya
    Murata, Tsuyoshi
    2018 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2018, : 4829 - 4836
  • [10] A power efficiency enhancements of a multi-bit accelerator for memory prohibitive deep neural networks
    Shivapakash S.
    Jain H.
    Hellwich O.
    Gerfers F.
    IEEE Open Journal of Circuits and Systems, 2021, 2 : 156 - 169