arXiv:2603.15413cs.LGcs.AI2026-03被引 2

提出统一框架提升量化模型的可靠性和安全性,兼顾抗攻击与抗故障能力。

RESQ: A Unified Framework for REliability- and Security Enhancement of Quantized Deep Neural Networks

  • 分三阶段优化:抗扰动微调、模拟位翻转微调、轻量后处理
  • 对抗攻击鲁棒性提升最高10.35%,故障鲁棒性提升最高12.47%
  • 适用于对可靠性要求高的边缘AI部署场景

本文提出一种统一的三阶段框架,生成在可靠性与安全性之间平衡的量化深度神经网络。第一阶段通过微调降低特征表示对小扰动的敏感性,增强抗攻击能力;第二阶段在模拟位翻转故障下进行故障感知微调,提升容错能力;第三阶段采用轻量级后训练调整,融合量化以提高效率并进一步降低故障敏感性,同时不损害抗攻击能力。在ResNet18、VGG16、EfficientNet和Swin-Tiny模型上,于CIFAR-10、CIFAR-100和GTSRB数据集上的实验表明,对抗攻击鲁棒性最高提升10.35%,故障鲁棒性最高提升12.47%,同时保持量化网络的高精度。结果还揭示了非对称交互关系:故障鲁棒性提升通常增强抗攻击能力,但反之不成立。

原文摘要 · Abstract (English)

This work proposes a unified three-stage framework that produces a quantized DNN with balanced fault and attack robustness. The first stage improves attack resilience via fine-tuning that desensitizes feature representations to small input perturbations. The second stage reinforces fault resilience through fault-aware fine-tuning under simulated bit-flip faults. Finally, a lightweight post-training adjustment integrates quantization to enhance efficiency and further mitigate fault sensitivity without degrading attack resilience. Experiments on ResNet18, VGG16, EfficientNet, and Swin-Tiny in CIFAR-10, CIFAR-100, and GTSRB show consistent gains of up to 10.35% in attack resilience and 12.47% in fault resilience, while maintaining competitive accuracy in quantized networks. The results also highlight an asymmetric interaction in which improvements in fault resilience generally increase resilience to adversarial attacks, whereas enhanced adversarial resilience does not necessarily lead to higher fault resilience.

量化安全可靠性DNN

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。