arXiv:2608.04173cs.LGcs.CR2026-08中稿 · oral presentation …

研究剪枝与对抗训练如何共同影响神经网络在硬件故障下的可靠性。

Understanding Fault Tolerance of Adversarially Robust Pruned Models

论文配图:Understanding Fault Tolerance of Adversarially Robust Pruned Models
图 1 · 摘自论文原文
  • 通过三组实验分析剪枝、对抗训练与硬件故障的交互影响。
  • 对抗训练提升抗扰动能力,但增加对权重故障的敏感性。
  • 剪枝未显著提高故障敏感度,适合关注硬件可靠性的研究者。

部署在资源受限类脑硬件上的深度神经网络面临三个并行挑战:通过剪枝实现模型压缩、易受对抗输入扰动影响,以及易受硬件引起的权重故障(如恒零故障)影响。尽管这些因素各自已有研究,但其综合效应对模型可靠性的影响仍缺乏关注。本文针对卷积神经网络,基于在MNIST上训练的轻量三层CNN,开展三项实验:(1) 比较自然训练与对抗训练模型在同时遭遇硬件故障和对抗攻击下的容错能力;(2) 评估剪枝对对抗鲁棒性的影响;(3) 描绘故障率、对抗扰动强度与剪枝水平之间的联合准确率表面。结果表明,对抗训练虽提升抗输入扰动能力,但加剧了对恒零故障的敏感性;出乎意料的是,剪枝并未显著增加故障敏感度,且不同剪枝程度在各类故障率与攻击强度下表现稳定。研究强调需协同考虑对抗鲁棒性与硬件可靠性。

原文摘要 · Abstract (English)

Deep neural networks (DNNs) deployed on resource-constrained neuromorphic hardware face three concurrent challenges: the need for model compression through pruning, vulnerability to adversarial input perturbations, and susceptibility to hardware-induced weight faults such as stuck-at-zero errors. While each of these factors has been studied in isolation, their combined effects on model reliability have received little attention. This paper presents an empirical investigation of how pruning, adversarial training, and hardware fault injection interact to affect the robustness of convolutional neural networks. Using a compact three-layer CNN trained on MNIST, we conduct three experiments: (1) comparing the fault tolerance of naturally and adversarially trained models under simultaneous hardware faults and adversarial attacks, (2) evaluating how pruning affects adversarial robustness, and (3) characterizing the joint accuracy surface across fault rates, adversarial perturbation magnitudes, and pruning levels. Our results show that adversarial training improves robustness against input perturbations but increases sensitivity to stuck-at-zero weight faults. Contrary to intuition, pruning did not significantly increase fault sensitivity, and varying the pruning level had little effect across fault rates and attack strengths. These results highlight the need to jointly consider adversarial robustness and hardware reliability.

模型剪枝对抗鲁棒性硬件故障可靠性

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。