将鲁棒ANN转为稀疏脉冲网络,实现能效与抗攻击性双重提升
Adversarially Robust Spiking Neural Networks with Sparse Connectivity
- 从鲁棒ANN提取稀疏连接与权重,转换生成稀疏脉冲网络
- 参数量减少100倍,能效提升8.6倍,仍保持高鲁棒性
- 适合边缘设备部署,兼顾低功耗与安全防御
在资源受限的嵌入式系统中部署深度神经网络,需创新算法以提升能效与内存效率。为增强系统对恶意攻击的可靠性,现有研究广泛探讨了现有架构的对抗鲁棒性。本文聚焦于对抗鲁棒性、内存与能效的交叉问题,提出一种神经网络转换算法,利用鲁棒预训练人工神经网络(ANN)中的稀疏连接与权重,生成稀疏且对抗鲁棒的脉冲神经网络(SNN)。该方法结合了SNN的能效架构与新颖的转换机制,通过稀疏连接与激活实现卓越性能,在内存占用降低100倍、能效提升8.6倍的同时,维持高水平的性能与对抗鲁棒性。
原文摘要 · Abstract (English)
Deployment of deep neural networks in resource-constrained embedded systems requires innovative algorithmic solutions to facilitate their energy and memory efficiency. To further ensure the reliability of these systems against malicious actors, recent works have extensively studied adversarial robustness of existing architectures. Our work focuses on the intersection of adversarial robustness, memory- and energy-efficiency in neural networks. We introduce a neural network conversion algorithm designed to produce sparse and adversarially robust spiking neural networks (SNNs) by leveraging the sparse connectivity and weights from a robustly pretrained artificial neural network (ANN). Our approach combines the energy-efficient architecture of SNNs with a novel conversion algorithm, leading to state-of-the-art performance with enhanced energy and memory efficiency through sparse connectivity and activations. Our models are shown to achieve up to 100x reduction in the number of weights to be stored in memory, with an estimated 8.6x increase in energy efficiency compared to dense SNNs, while maintaining high performance and robustness against adversarial threats.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。