让忆阻器网络更抗对抗攻击,只需训练时考虑器件非理想性。
Nonideality-aware training makes memristive networks more robust to adversarial attacks
- 训练时模拟器件非理想性,提升模型鲁棒性。
- 即使测试时未知具体非理想情况,仍显著增强抗攻击能力。
- 适合关注低功耗神经网络安全的硬件研究者。
神经网络已广泛应用于物体分类、自然语言处理等领域。采用忆阻器等模拟器件实现的系统具有更高的能效,有望拓展至更多场景。然而,这类系统更容易出现器件故障,且其对对抗攻击的脆弱性尚未被充分研究。本文探讨了非理想性感知训练——一种应对物理非理想性的常见技术——对对抗鲁棒性的影响。结果表明,即便在测试时对实际非理想性知之甚少,该训练方法也能显著提升模型的对抗鲁棒性。
原文摘要 · Abstract (English)
Neural networks are now deployed in a wide number of areas from object classification to natural language systems. Implementations using analog devices like memristors promise better power efficiency, potentially bringing these applications to a greater number of environments. However, such systems suffer from more frequent device faults and overall, their exposure to adversarial attacks has not been studied extensively. In this work, we investigate how nonideality-aware training - a common technique to deal with physical nonidealities - affects adversarial robustness. We find that adversarial robustness is significantly improved, even with limited knowledge of what nonidealities will be encountered during test time.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。